No SLSA provenancenpm registry signaturesgitHead linked
Without SLSA provenance there is no cryptographic link between this
tarball and the public source — the axios compromise (March 2026)
relied on exactly this gap.
Maintainers
react-native-botfb
Keywords
babelpresetreact-native
Accepted risks
Findings the reviewer chose to accept rather than block on.
Source
Rule
Reason
Accepted by
When
phantom-deps
phantom-dep:@babel/core
AI (phantom-deps): Babel presets load plugins by convention; @babel/core is a framework-scoped dependency loaded dynamically, not directly imported.
ai
phantom-deps
phantom-dep:@babel/template
AI (phantom-deps): Babel presets load plugins by convention; @babel/template is a framework-scoped dependency loaded dynamically, not directly imported.
ai
bogus-package
bogus-package
AI (bogus-package): False positive: react-native-bot is Facebook's official React Native automation account, not a spam publisher. Repository confirms legitimacy.