react-native-reanimated
More powerful alternative to Animated library for React Native.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:lodash.isequal | AI (phantom-deps): Legitimate build dependency used in codebase; phantom-dep pattern is normal for utility libraries. | ai | |
| phantom-deps | phantom-dep:@babel/preset-typescript | AI (phantom-deps): Framework-scoped Babel plugin loaded by convention; standard pattern for build tooling. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-object-assign | AI (phantom-deps): Framework-scoped Babel plugin loaded by convention; standard pattern for build tooling. | ai | |
| semgrep | semgrep:eval-usage | AI (semgrep): eval() is used intentionally to execute serialized worklet functions generated by Reanimated's own Babel plugin at build time. This is a documented, core design pattern of the library, not a supply-chain risk. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-class-properties | AI (phantom-deps): Same as above — Babel plugin loaded by convention, not direct import. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-classes | AI (phantom-deps): Babel plugins are loaded by convention through the Babel plugin system, not via direct imports. This is expected for a library that ships a Babel transform. | ai | |
| phantom-deps | phantom-dep:@babel/plugin-transform-unicode-regex | AI (phantom-deps): Same as above — Babel plugin loaded by convention, not direct import. | ai |
Versions (showing 100 of 276)
| Version | Deps | Published |
|---|---|---|
| 4.4.0 | 2 / 34 | |
| 4.3.1 | 2 / 36 | |
| 4.2.1 | 2 / 29 | |
| 4.2.0 | 2 / 29 | |
| 4.1.6 | 2 / 54 | |
| 4.1.5 | 2 / 54 | |
| 4.1.4 | 2 / 54 | |
| 4.1.3 | 2 / 54 | |
| 4.1.2 | 2 / 54 | |
| 4.1.1 | 2 / 54 | |
| 4.1.0 | 2 / 54 | |
| 4.0.3 | 2 / 53 | |
| 4.0.2 | 2 / 53 | |
| 4.0.1 | 2 / 53 | |
| 4.0.0 | 2 / 53 | |
| 3.19.5 | 12 / 54 | |
| 3.19.4 | 12 / 54 | |
| 3.19.3 | 12 / 54 | |
| 3.19.2 | 12 / 54 | |
| 3.19.1 | 12 / 54 | |
| 3.19.0 | 12 / 54 | |
| 3.18.2 | 12 / 54 | |
| 3.18.1 | 12 / 54 | |
| 3.18.0 | 12 / 54 | |
| 3.17.5 | 12 / 54 | |
| 3.17.4 | 12 / 54 | |
| 3.17.3 | 12 / 54 | |
| 3.17.2 | 12 / 54 | |
| 3.17.1 | 12 / 54 | |
| 3.17.0 | 12 / 54 | |
| 3.16.7 | 11 / 55 | |
| 3.16.6 | 11 / 55 | |
| 3.16.5 | 11 / 55 | |
| 3.16.4 | 11 / 55 | |
| 3.16.3 | 11 / 55 | |
| 3.16.2 | 11 / 55 | |
| 3.16.1 | 11 / 55 | |
| 3.16.0 | 11 / 55 | |
| 3.15.5 | 11 / 55 | |
| 3.15.4 | 11 / 55 | |
| 3.15.3 | 11 / 55 | |
| 3.15.2 | 11 / 55 | |
| 3.15.1 | 11 / 55 | |
| 3.15.0 | 11 / 55 | |
| 3.14.0 | 8 / 55 | |
| 3.13.0 | 8 / 55 | |
| 3.12.1 | 8 / 56 | |
| 3.12.0 | 8 / 56 | |
| 3.11.0 | 8 / 55 | |
| 3.10.1 | 8 / 55 | |
| 3.10.0 | 8 / 55 | |
| 3.9.0 | 8 / 55 | |
| 3.8.1 | 8 / 52 | |
| 3.8.0 | 8 / 52 | |
| 3.7.2 | 4 / 58 | |
| 3.7.1 | 4 / 58 | |
| 3.7.0 | 4 / 58 | |
| 3.6.3 | 4 / 58 | |
| 3.6.2 | 4 / 58 | |
| 3.6.1 | 4 / 58 | |
| 3.6.0 | 4 / 57 | |
| 3.5.4 | 4 / 57 | |
| 3.5.3 | 4 / 57 | |
| 3.5.2 | 4 / 57 | |
| 3.5.1 | 4 / 57 | |
| 3.5.0 | 4 / 57 | |
| 3.4.2 | 4 / 55 | |
| 3.4.1 | 4 / 54 | |
| 3.4.0 | 4 / 54 | |
| 3.3.0 | 4 / 53 | |
| 3.2.0 | 4 / 53 | |
| 3.1.0 | 4 / 49 | |
| 3.0.2 | 7 / 43 | |
| 3.0.1 | 7 / 43 | |
| 3.0.0 | 7 / 43 | |
| 2.17.0 | 6 / 42 | |
| 2.16.0 | 6 / 42 | |
| 2.15.0 | 6 / 42 | |
| 2.14.4 | 7 / 41 | |
| 2.14.3 | 7 / 41 | |
| 2.14.2 | 7 / 41 | |
| 2.14.1 | 7 / 41 | |
| 2.14.0 | 7 / 41 | |
| 2.13.0 | 7 / 41 | |
| 2.12.0 | 7 / 41 | |
| 2.11.0 | 7 / 41 | |
| 2.10.0 | 7 / 41 | |
| 2.9.1 | 8 / 40 | |
| 2.9.0 | 8 / 40 | |
| 2.8.0 | 7 / 40 | |
| 2.7.0 | 7 / 40 | |
| 2.6.0 | 7 / 41 | |
| 2.5.0 | 7 / 41 | |
| 2.4.1 | 7 / 41 | |
| 2.4.0 | 7 / 41 | |
| 2.3.3 | 7 / 40 | |
| 2.3.2 | 7 / 40 | |
| 2.3.1 | 7 / 40 | |
| 2.3.0 | 7 / 40 | |
| 2.2.4 | 4 / 38 |
v4.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.3.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.2.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.1.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.1.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.1.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.1.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.1.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.1.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.19.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.19.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.19.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.19.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.19.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.19.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.18.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.18.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.18.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.17.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.17.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.17.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.17.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.17.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.17.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.16.7
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.16.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.16.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.16.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.16.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.16.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.16.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.16.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.15.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.15.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.15.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.15.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.15.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.15.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.14.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.13.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.12.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.12.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.11.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.10.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.10.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.9.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.8.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.8.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.7.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.7.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.7.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.6.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.6.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.6.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.6.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.3
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.5.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.4.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v3.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.