What's new
Every release, in plain words. Most changes come from two places: real upgrades we do, and scanning 450+ open-source React Native and Expo apps to find what the tool gets wrong. Run npx nativekeel to always get the latest. Full notes on GitHub.
0.1.18
6 October 2026
- Security"No fixed release" is said plainly. When the vulnerable range includes the newest published version (expr-eval 2.0.2, for example), the plan no longer says "update". It says no fix exists: replace the package, or make sure it never handles untrusted input. When the advisory only says "up to 4.17.23", the version to install is now the actual next release (lodash 4.18.1).
- PlanLibrary updates that fit your current React Native. Before the React Native steps, the plan used to suggest the newest Reanimated or Gesture Handler even when it needs a newer React Native. It now stops at the newest version your current React Native supports, and the React Native steps move them further.
- PlanFamilies move together. All
@react-navigation/*packages (and all@react-native-firebase/*) are one step, since mixed major versions crash at runtime. React Navigation is no longer mistaken for a native module, and renamed community packages (such as@react-native-community/masked-view) are recognised as native even withoutnode_modules, so the plan says "swap it" instead of "replace it some day". - PlanHermes appears in one step, not two, and version ranges read "2.32+ (2.x line)" instead of "2.32–2.99.x".
- FixThe HTML report showed bold plan steps as
**text**. It now renders them in bold.
0.1.17
6 October 2026
- SecurityEvery vulnerable package now says which version fixes it. Advisories written as "up to and including 1.13.4" were not read, so a package with 35 advisories showed "check the advisories" instead of "fixed in 1.20.0". It is now in the title and in the plan step. 378 of 381 vulnerable packages in our test set get a fixed version.
- AccuracyMore advisories that cannot reach a mobile app are counted as low: axios' HTTP/2 adapter, proxy and
NO_PROXYhandling, server-side request forgery and cloud metadata leaks. They stay visible in the details. - ExperienceLess noise in Expo apps. Packages whose version the Expo SDK decides (
expo-*, Reanimated, Screens, AsyncStorage, …) no longer appear one by one as "a major version behind". They are one line: "19 packages move with the Expo SDK upgrade", sincenpx expo install --fixmoves them. Across our test set, 3,700 low findings became that one line.
0.1.16
6 October 2026
- SecurityDeep links. Web links (
https://your.domain/...) that are not verified withautoVerify: Android 12+ opens them in the browser instead of your app, and older Android lets any app that registers the same links receive them, including login, reset and invite links. And the template URL schememyapp://, which 72 of the 470 apps we scan still ship: another app with the same scheme can open your links, and catch your sign-in redirect when you use expo-auth-session, Clerk or AppAuth. Both under MASVS-PLATFORM. - AccuracyTested on 180 more open-source apps (450+ in total, zero tool failures). Fixed what they showed:
.DS_Storefiles caught in a patch are no longer reported as "build output that will not apply", and keystores inside test fixtures are not release keys. - ExperienceThe HTML report wraps long file paths and code on phone screens.
0.1.15
6 October 2026
- ExperienceMonorepos. Run at the root of a monorepo and NativeKeel lists the app folders to scan (
npx nativekeel apps/mobile) instead of stopping with "not a React Native app". Libraries are not suggested. - PlanAn app that needs no React Native or Expo upgrade gets an Action plan, not an "Upgrade plan".
- DocsThe README and npm page list every check by group: upgrade, store, crashes, security (by OWASP MASVS) and performance.
0.1.14
6 October 2026
- SecuritySecrets in Expo config. Secret-looking values in
app.json/app.configextraand inEXPO_PUBLIC_variables ship inside the app; secrets ineas.jsonbuild env are committed to the repo (found a Sentry auth token this way in two open-source apps). Public SDK keys such as RevenueCat's are left alone. - StabilityAPIs removed from React Native core.
AsyncStorage,Picker,Slider,WebView,ViewPropTypesand 23 others imported from'react-native'throw or are undefined on current versions. Reported as a crash now when the installed version already removed them, or as a step before the upgrade, with the replacement package for each. The list comes from React Native's own source.
0.1.13
6 October 2026
- PerformanceSpeed up the app. A new plan phase for the static signs of jank and weight: a FlatList inside a ScrollView that renders every row, animations driven from the JavaScript thread, console logs left in release builds, whole-library imports of lodash and moment, and oversized images the app actually requires (repo screenshots are not counted).
- SecurityReverse engineering. Source maps packaged into the app (they give back your original code), and release builds with Hermes or R8 off. Reported honestly: obfuscation only slows an attacker down, so secrets and trust decisions belong on the server. A new MASVS-RESILIENCE group in the security overview.
0.1.12
5 October 2026
- SecurityHacking risks, mapped to OWASP MASVS. Every security finding now names its MASVS group, and reports show a security overview: which groups were checked and how many issues each has.
- SecurityOpen Firebase rules. Realtime Database, Firestore and Storage rules that let anyone read or write, root rules that give every signed-in user everything, and test-mode rules (open until a date, or expired). Public folders such as event images are left alone.
- SecurityTLS certificate checks turned off. Trust-all managers, hostname verifiers that accept everything, WebViews that proceed on SSL errors and iOS sessions that trust any server. A bypass behind a "trust my self-signed server" setting is reported as such, at lower severity.
- SecurityWeak cryptography and token storage. Hardcoded encryption keys, MD5/SHA-1 on passwords, ECB mode, Math.random for nonces and salts, auth tokens in AsyncStorage.
- AccuracyDependencies installed from git are never matched against npm advisories (a wallet app was flagged with a malware advisory that belongs to a different package with the same name).
0.1.11
5 October 2026
- FixThe GitHub Action works. A colon inside one input description made
action.ymlinvalid, souses: AlicanAkyol/nativekeel@v0failed to load. It is fixed, the Action now has anexit-codeoutput, and a workflow runs it on a sample app on every change so this cannot slip again.
0.1.10
5 October 2026
- ExperienceStart here. Every report now opens with the three most urgent first steps (leaked keys, crash risks, store deadlines, security gaps), in the terminal and in the HTML report. On the real app our case study is based on, it picked the same three priorities we had reached by hand.
- StabilityMissing iOS permission texts. Using the camera, photos, location, microphone, contacts, calendars, Bluetooth or Face ID without the matching Info.plist description makes iOS close the app and App Review reject it. Expo config plugins are taken into account.
- PlanStore deadlines (target SDK, 16 KB pages, privacy manifest) now sit together at the start of the plan.
0.1.9
5 October 2026
- SecurityAndroid components open to every app. Services, receivers and providers exported without a permission. Widgets and receivers for system broadcasts are left alone, because Android needs them exported.
- SecurityAPI calls over plain HTTP. fetch, axios and WebSocket calls to real hosts over http:// or ws://; local addresses and links opened in the browser are ignored.
- ExpoOld Expo projects (SDK 44 and earlier) are read correctly: React Native comes from Expo's fork, and the plan uses the right upgrade command for each SDK (the legacy CLI before SDK 46). For very long jumps it also weighs starting a fresh project.
0.1.8
5 October 2026
- SecurityKnown vulnerabilities in what you ship. Advisories from the GitHub Advisory Database for the exact versions in your lockfile or node_modules (npm, yarn, pnpm). Advisories that only affect Node.js servers stay visible at low severity instead of raising false alarms.
- SecurityPasswords leaking into logs and databases. Follows a password through intermediate variables into crash reports, analytics, remote database writes or plain AsyncStorage. Built from a real leak we found in a production app.
- SecurityUnsafe WebViews and Android backups. WebViews that let page scripts read local files or mix HTTP into HTTPS;
allowBackupwithout backup rules. - StabilityCrash risks. Reanimated without its Babel plugin or react-native-worklets, mixed Firebase or React Navigation majors, a second copy of React or React Native inside a dependency.
- PlanNew phases: Fix crash risks and Close security gaps.
0.1.7
4 October 2026
- PlanFor old apps, library versions recommended before the New Architecture switch now run on the legacy architecture, each library stays on its major line, and forced major migrations are flagged.
- PlanRenamed community packages (async-storage, cameraroll, masked-view, viewpager, picker, clipboard, netinfo) get a "swap and update imports" step.
- ReportsThe HTML report folds outdated packages into one table; GitHub code scanning links work for folders with spaces.
0.1.6
4 October 2026
- PlanUpgrade plans reviewed line by line on real apps. The Google Play 16 KB deadline is now explicit; managed Expo apps get EAS commands instead of android/ios ones; abandoned JavaScript packages no longer pose as upgrade blockers; a nearly current app is no longer sized like a migration.
- AccuracyPatched packages, alias fields and Node core polyfills are never reported as unused.
0.1.5
4 October 2026
- PlanApps older than React Native 0.76 now get the New Architecture switch at the right point of the upgrade (it was treated as already on).
- PlanExpo: SDK-managed packages move with
npx expo install --fix, never bumped past the SDK. - AccuracyReanimated compatibility is generated from Reanimated's own data; the iOS privacy manifest is recognised as generated by React Native 0.75+; npm rate limits are retried and reported instead of silently missing checks.
0.1.4
4 October 2026
- AccuracyFirst run against 32 open-source apps: 11 fixes, from piped JSON output being cut off to placeholder secrets reported as real.
- Monorepospnpm and Bun catalog versions are resolved.
0.1.3
4 October 2026
- PlanEvery upgrade plan starts with a safety net: UI flows on both platforms before the first change. On a real upgrade they caught a post-login crash, a frozen sign-up and an invisible button.
0.1.2
4 October 2026
- StabilityNew known issue from a real upgrade:
react-native-linear-gradient2.x around a Modal crashes on the New Architecture.
0.1.0 – 0.1.1
3 October 2026
- First release: support status, New Architecture blockers, Google Play target SDK and 16 KB pages, iOS privacy manifest, 14 secret patterns, unused packages, upgrade plan, HTML/Markdown/SARIF/JSON output, baseline for CI and a GitHub Action. Published with npm provenance.