The Expo CLI
No confirmed malicious attack surface was established. Telemetry and platform commands occur during explicit CLI actions and are constrained to Expo services or local development tools.
Package source references dynamic require/import behavior.
internal/unstable-expo-updates-exports.jsView on unpkg · L2Source gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
build/src/utils/errors.jsView on unpkg · L41Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
build/src/start/platforms/android/adbReverse.jsView on unpkg · L66A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
build/src/api/user/expoSsoLauncher.js#virtual:normalized:round1View on unpkgThe package includes coding-agent and sandbox detection dependencies.
package.jsonView on unpkg · L2This report applies to @expo/cli@57.0.22.
See version security history for other recorded verdicts.
Evidence last updated: .
Package source references dynamic require/import behavior.
internal/unstable-expo-updates-exports.jsView on unpkg · L2A bounded semantic-analysis stage reached its safety limit; remaining detectors completed, but this package requires AI review.
build/src/api/user/expoSsoLauncher.js#virtual:normalized:round1View on unpkgSource gates dangerous network, credential, or execution behavior behind CI, host, platform, time, or geo fingerprint checks.
build/src/utils/errors.jsView on unpkg · L41Package metadata claims a different repository identity while copied source loads a runtime dependency bridge.
build/src/start/platforms/android/adbReverse.jsView on unpkg · L66The package includes coding-agent and sandbox detection dependencies.
package.jsonView on unpkg · L2