What's new
Every release, in plain words. Most changes come from two places: real upgrades we do, and scanning 850+ open-source React Native and Expo apps, more every week, to find what the tool gets wrong. Run npx nativekeel to always get the latest. Full notes on GitHub.
0.1.67
11 October 2026
- FixThe Codex plugin can scan projects again. Since 0.1.64, a server started inside a plugin folder needed
NATIVEKEEL_MCP_ROOTS, but Codex does not let users set environment variables for a plugin's server, so every scan from the plugin was refused. Codex starts plugin servers in the plugin's own folder, which says nothing about the open project, so the boundary there is your home folder again. To limit it to one project, configure the server yourself in~/.codex/config.tomlwithNATIVEKEEL_MCP_ROOTS. The tools stay read-only, never run project code and never return source code. Claude Code is not affected: it starts the server in the project folder.
0.1.66
11 October 2026
Six native Android checks trace archive entry paths into file writes and incoming Intent fields into launches, WebViews, local SQL and file reads/writes. An explicit exported manifest entry and matching Java/Kotlin class are required for Intent findings; literal Gradle namespaces are supported. Reports state the attacker prerequisites, Android 14/16 protections and verification steps. Guarded or complex flows are unresolved, not marked safe.
270 tests pass. A read-only pass over 922 repositories produced no new matching findings; this is scope calibration, not a security certificate. No app or malicious sample was run. Coverage and limits →
0.1.65
11 October 2026
nativekeel securityand MCPsecurity_audit: a focused report of data exposure, account access and code execution risks.- Eight new checks: credentials in telemetry and URLs, WebView/network data evaluated as code, external input in SQLite query text, PKCE disabled, implicit OAuth tokens, and broad private FileProvider paths.
- New findings include source evidence, attacker prerequisites, a fix and local verification steps. SARIF points to the evidence. Reports show coverage limits; zero findings is not a passed security assessment.
0.1.64
11 October 2026
- SecuritySafer scans from AI agents. MCP checks project file reads against allowed roots, rejects unsafe dependency names, and keeps malware stop warnings in upgrade plans, error explanations and verification results. A project with suspected malware no longer gets a plan that starts by running tests. Removed instruction-like object keys are not echoed in diagnostic paths. These defenses reduce risk; text filtering cannot make an agent immune to prompt injection.
- SecurityMore access-control checks for mobile backends. Finds Firebase write rules that only require sign-in and supported Supabase migrations with unconditional SELECT and UPDATE/DELETE policies for anonymous or signed-in users. Reports source locations and prerequisites; does not claim the rules are deployed or that a live attack succeeded. Public reads, insert-only forms and restrictive policies are handled conservatively.
- ConfigurationPlugin servers need explicit project roots. Set
NATIVEKEEL_MCP_ROOTSin the MCP server environment when it starts inside a plugin directory. The home folder is no longer granted automatically. For monorepos, allow the workspace root if hoisted dependencies must be read.
0.1.63
11 October 2026
- AI agentsCodex plugin.
codex plugin marketplace add AlicanAkyol/nativekeel, thencodex plugin add nativekeel@nativekeel. It adds the MCP server, pinned to the release, and the same skill as the Claude Code plugin, so Codex checks the project before upgrades and library changes, explains errors and verifies the upgrade before you commit. Built on the open Agent Plugins format and installed with Codex CLI 0.162. - SecurityFolder boundary for servers started inside a plugin. Codex starts plugin servers in the plugin's own folder, which says nothing about the project you have open. There NativeKeel uses your home folder as the boundary, or only the folders in
NATIVEKEEL_MCP_ROOTSwhen you set it.
0.1.62
11 October 2026
- NewCheck an upgrade before you commit it.
npx nativekeel verifycompares the project as committed (HEAD, or--baseany branch, tag or commit) with your working tree: what got fixed, what is new, and how React Native, Expo and the dependencies moved. It exits with 1 when the change adds a critical or high finding, so it works as a pre-commit or CI check. AI agents get the same as theverify_upgradeMCP tool, and the Claude Code plugin tells Claude to run it after an upgrade. The committed version is unpacked withgit archiveinto a temporary folder outside the project and deleted afterwards; revisions that look like options or ranges are refused, and the repository's own git config cannot make it run anything.
0.1.61
11 October 2026
- NewExplain an error.
npx nativekeel explain "<error>"(or pipe a log into it), andexplain_errorfor AI agents over MCP: what a build, launch, crash or App Store / Google Play review error means and the fix. Add--path .to see where your project is affected, from the same checks as the scan. It covers 21 errors we reproduced or verified at the source, among them-[AppDelegate window]: unrecognized selectorwith the React Native 0.88 template,'RCTComponent.h' file not found,InteractionManagerremoved in 0.87, ITMS-91061, Xcode 27's UIScene requirement, the 16 KB page size warning and App Store 5.1.1(v). The error text is matched on your machine and never sent anywhere. - AI agentsThe Claude Code plugin installs NativeKeel from a lockfile with the package's integrity hash instead of downloading it on every start, and has an icon.
0.1.60
11 October 2026
- FixExpo SDKs are named with the React Native version they ship ("Expo SDK 58 (beta, React Native 0.88)"). In our test an AI agent read "SDK 58" next to the React Native 0.87 changes and told the user SDK 58 ships 0.87.
0.1.59
11 October 2026
- UpgradeWhat changes in the next version, in your code. Release notes list everything; NativeKeel now lists only the changes that touch your app, each with
file:lineand what to do, and includes the next version while it is still in beta. For React Native 0.87:InteractionManager, theStatusBarbackgroundColor/translucentprops,Modal animated, booleankeyboardShouldPersistTaps, deep imports that become type errors, bare#import <RCT…h>lines, Node.js 22.13+. For Expo SDK 58 (beta): R8 on by default in release builds,File.write()becoming async, libSQL removed from expo-sqlite, foreground notifications shown by default, the expo-router navigation rework,NODE_ENVset before.envloads, and more. Measured on 675 open-source apps: 578 are touched by at least one change, most often R8 (479 apps), theStatusBarprops (103) andInteractionManager(47). We added this after watching an AI agent find the SDK 58 changes on the web that NativeKeel did not know about.
0.1.58
11 October 2026
- AI agentsThe Claude Code plugin runs an exact NativeKeel version instead of whatever is latest on npm, and updates with each release. Its README lists what it runs, what it reads and the only data it sends (package names and versions, to npm, React Native Directory and unpkg; no source code, no telemetry).
0.1.57
11 October 2026
- AI agentsClaude Code plugin.
claude plugin marketplace add AlicanAkyol/nativekeel, thenclaude plugin install nativekeel@nativekeel. It adds the MCP server and a skill that tells Claude when to use it: before upgrading React Native or Expo, adding a native library, preparing a store release, or running a project you did not write. In our test Claude used it without being asked, took 7 turns instead of 16, and found a store-blocking issue it missed on its own. Details. - AI agentsOne-click install in Cursor and VS Code, and a one-line
AGENTS.mdrule for agents without MCP. - SecurityMCP server started in the filesystem root. Some clients start servers in
/, which made every folder readable to the scan. That folder no longer counts; name your projects withNATIVEKEEL_MCP_ROOTS.
0.1.56
11 October 2026
- SecurityMalware planted in a project, found before you run it. Fake job tests and sample projects sent to developers hide code that steals credentials and crypto wallets. They use three tricks: a VS Code task with
"runOn": "folderOpen"that runs when the folder is opened, code hidden after a long run of spaces at the end ofbabel.config.js(Babel loads it on every start and build), and JavaScript saved as a font file. While scanning 925 open-source React Native and Expo repositories we found four that still contain it, one with 69 stars and 17 forks, and in one the commit titled "Remove injected malware" is the one that adds it. NativeKeel now reports these as critical and says not to install, start or open the project until it is cleaned. It reads these files and never runs anything from the project, so it is safe to run first on a repository you do not trust. With 0 false alarms on the other 921 repositories. Over MCP, the result carries a warning telling the AI agent not to run the project. - SecurityVisible auto-run tasks. A VS Code task that runs on folder open but does nothing suspicious is a medium note, so whoever clones the repository knows what runs.
0.1.55
10 October 2026
- AI agentsListed in the official MCP Registry as
io.github.AlicanAkyol/nativekeel, so MCP clients and directories that read the registry can find and install it. Every release updates the listing from GitHub Actions: ownership is proven with the workflow's OIDC token (no stored secret), and the publisher tool is pinned and checksum-verified.
0.1.54
10 October 2026
- SecurityKeychain items readable while the device is locked. The "Always" accessibility levels (
ACCESSIBLE.ALWAYSin react-native-keychain,SecureStore.ALWAYSin expo-secure-store,kSecAttrAccessibleAlwaysand theirTHIS_DEVICE_ONLYvariants) let an item be read whether or not the device is locked, so the passcode no longer protects it. Apple deprecated them in iOS 12. Reported as medium with the replacement (AFTER_FIRST_UNLOCKfor background access,WHEN_UNLOCKEDotherwise). Found in 3 of 880+ open-source apps: two Lightning wallets and a clinic records app. (OWASP MASVS-STORAGE)
0.1.53
10 October 2026
- NewNativeKeel for AI coding agents (MCP).
npx nativekeel mcplets Claude Code, Codex, Cursor and other MCP clients scan a project, get the upgrade plan and check a library against your React Native version, instead of guessing. Read-only, scans only the folders you allow, never returns source code, and removes text in the repository that tries to give the agent instructions. Set it up. - SecurityA scanned repository can no longer run a command through git. NativeKeel runs
git ls-filesto know which files are committed, and a repository's own.git/configcan make that run a program (core.fsmonitor; checked with git 2.50.1). That matters when you scan a project you did not create, such as a zip with its.gitfolder. Every option that runs a program is now switched off for the scan, and a test plants one and fails if it runs. - DocsSECURITY.md now explains how untrusted projects are handled, how the MCP server is isolated, and for each security check what it can and cannot detect.
0.1.52
10 October 2026
- App StoreXcode 27: the UIScene life cycle. Built with the iOS 27 SDK, an app that has not adopted the scene life cycle stops at launch ("UIScene life cycle is required for apps built with this SDK"), and App Store Connect requires that SDK from April 2027. NativeKeel now says whether your app has adopted it and what to do: React Native 0.88 is the first template with it; Expo SDK 57 opts in with
ios.enableSceneSupport; SDK 58 has it by default. 767 of 833 iOS apps in our scan have not adopted it yet. What to change. - CrashWhat breaks after the move. Deep links and universal links that are still handled only in AppDelegate stop arriving. Libraries that read the window from the app delegate crash with "-[AppDelegate window]: unrecognized selector" on the React Native 0.88 template. We reproduced this on that template and sent fixes to react-native-blob-util and react-native-google-mobile-ads. NativeKeel lists the installed packages that do it and the one-line workaround.
- FixStore review checks were not running. Since 0.1.42, a refactor left the account deletion (5.1.1(v)), Sign in with Apple (4.8) and iOS SDK privacy manifest (ITMS-91061) checks out of the report. They run again, and a new test fails if any check stops being called.
0.1.51
9 October 2026
- SecurityRecovery phrases and private keys copied to the clipboard. Keyboards with clipboard history and cloud clipboard sync keep a copy, every app the user pastes into receives it, and on Android 9 and older any background app can read it. Reported as medium when a seed phrase, mnemonic, private key or secret key goes to the clipboard and is not cleared again (a timer that clears it after a minute counts as cleared). Found in 8 of 869 open-source apps, almost all crypto wallets. (OWASP MASVS-STORAGE)
- Play Storeexpo-sqlite's sqlite-vec option breaks 16 KB alignment. With
withSQLiteVecExtension(oruseLibSQLon SDK 57), expo-sqlite adds a prebuilt 64-bit library that is 4 KB aligned, so Google Play will block the app's updates from 1 February 2027. We found it by checking the prebuilt libraries of the 259 native packages our test apps use most, and reported it to Expo (expo/expo#51329) and upstream (sqlite-vec#254). The default expo-sqlite build is fine.
0.1.50
9 October 2026
- Upgradesreact-native-push-notification and React Native 0.82. The library calls
getReactNativeHost()when the FCM token refreshes and when a notification action is tapped. From React Native 0.82 that getter throws unlessMainApplicationstill overrides it, and the 0.82 template no longer does. The finding now warns about it before the upgrade. - Behind the scenesWe scanned the Android code of the 259 native libraries our test apps use most, looking for the two patterns that crash under the New Architecture:
@ReactMethodfunctions that return something (react-native-track-player 4.x, now with a fix) and unguardedgetReactNativeHost()calls. Every other hit turned out to be guarded, a codegen override, dead code or an example app. The popular ecosystem is in good shape here.
0.1.49
9 October 2026
- Upgradesreact-native-track-player: what the registries do not tell you. Version 5, the New Architecture rewrite, is a different package (
@rntp/player) under a commercial license. The free 4.x line does not compile with Kotlin 2.1 and crashes at launch with the New Architecture on Android. The finding now says so, and points to our pull request with the fixes (apply it with patch-package until it is released), or to expo-audio for simple playback.
0.1.48
9 October 2026
- AccuracyFace ID with expo-local-authentication is not a crash. Without
NSFaceIDUsageDescription, most biometrics libraries crash on iOS 17+, and that stays high.expo-local-authenticationchecks for the key itself and skips Face ID instead, so it is now a medium "Face ID never shows" finding. - AccuracyVulnerability counts show what reaches a mobile app. axios advisories about proxies,
no_proxy, SSRF and the Node.js HTTP adapter cannot reach React Native, which uses XMLHttpRequest. The title now reads "21 known vulnerabilities (+11 for Node.js only)" instead of 32. - FixReact Native release candidates show their full version (
0.88.0-rc.4), not0.88.0. - Behind the scenesChecked on Expo Go, the Yoroi and Valora wallets.
0.1.47
9 October 2026
- SecurityAI provider keys that ship inside the app. Reading
process.env.EXPO_PUBLIC_OPENAI_API_KEY(or a Gemini, Anthropic, Groq, OpenRouter, Replicate, fal.ai… key) in app code compiles the key into the JavaScript bundle, even though.envis never committed. The same goes forreact-native-configandreact-native-dotenv. Anyone who unpacks the app can run requests on your bill. Reported as high, with a note when the app also calls the provider directly; server folders and Expo API routes are left out. Found in 12 of 869 open-source apps, almost all AI features added in the last year (what we found). - AccuracyA private key in a
.envfile used only by server code (Expo API routes) is reported as committed to the repository, not as shipped inside the app: Expo inlines onlyEXPO_PUBLIC_variables. The public demo keys thatsupabase startgives every developer are no longer reported. - Behind the scenesWe added 148 open-source health and wellbeing apps to the test set and measured a "health data sent to analytics" check on them. It found no real case (most of these apps use no analytics at all), so it is not shipped.
0.1.46
9 October 2026
- AccuracyMixed React Navigation majors: a crash only with two copies of the core. NativeKeel now reads the lockfile (npm, Yarn, pnpm and Bun). If two majors of
@react-navigation/nativeorcoreare installed, navigators run against a different container and crash: still high. With one copy, a navigator from the other major usually runs (a large open-source wallet ships this way), so it is reported as an unsupported mix (medium). - AccuracyWebView file-URL flags on web pages.
allowUniversalAccessFromFileURLsonly matters for pages loaded fromfile://. A WebView that only opens web URLs gets a low "remove the flag" note. Bundled, downloaded or inline HTML keeps the high finding, including when the address is defined in another file the screen imports. - AccuracyLocal fallback keystores. A keystore with a throwaway password (
"password"), used only in theelsebranch when the real signing values come from Gradle properties, is not reported as a leaked release key. A real password in that branch is still reported. - AccuracyLibraries whose native side
react-native.config.jsbuilds from another folder (a shim that links Reanimated 3 on a legacy-architecture Android build) are not checked against the installed version's architecture support.Math.randomin a mock or dummy response is not reported. A private key in a test file is low (a test key pair protects nothing, unless it is reused).
0.1.45
9 October 2026
- AccuracyMonorepo packages are yours, not npm's. In large monorepos (we re-checked three big wallet apps), packages linked with
workspace:,link:,file:orportal:are developed in the same repository. NativeKeel used to look up their name on npm and report an unrelated publish date ("no release since 2023"). They are skipped now. Packages that a pnpmcatalog:pins to an npm version are still checked, because they do come from npm. - FixWording of the Expo SDK step for a single newer package.
0.1.44
9 October 2026
- PerformanceRedux selectors that re-render on every store update.
useSelector(state => ({ ... })), or a fallback likestate.x[id] || {}, returns a new value on every call, so the component re-renders whenever anything in the store changes. Reported with the fix (select values separately,shallowEqual, or a constant fallback). - FixPerformance findings could point at the wrong line in files with block comments. They point at the right line now.
- Behind the scenesWe measured other re-render patterns on 653 apps and did not ship them: effects without dependencies that set state (22 hits, almost all harmless because they set the same value), inline Context values (155 apps, impact depends on how often the provider renders), and Zustand 5 object selectors (no confirmed case; the one hit used a different store library). Real re-render costs need a profiler on a device; we only report patterns that are wrong every time.
0.1.43
9 October 2026
- AccuracyLess noise about general JavaScript utilities. A small, finished utility such as
clsxwas rated like a React Native library when React Native Directory marks it unmaintained. It has no effect on React Native upgrades, so it is now low. Packages tied to React Native stay medium: by name, through areact-nativedependency, or through a sibling in the same scope (@rneui/themedbuilds on@rneui/base). Found while scanning more large open-source apps (wallets and a travel app).
0.1.42
9 October 2026
- AccuracyTested on large open-source production apps. We added well-known open-source apps with millions of users (hardware and crypto wallets, a forum platform) to the test set. They showed two things to fix:
- React Native declared through Yarn's patch protocol (
patch:react-native@npm%3A0.83.4#…) or annpm:alias was read as "no version", so the version checks were skipped and the New Architecture looked off. Both are read now. - Packages newer than the Expo SDK expects were treated like older ones, with
npx expo install --fixas the advice, which would downgrade a version the team chose on purpose. Older versions are still the build and crash risk they were; newer ones are now low (medium for a major) with the right advice: list them inexpo.install.excludeafter testing. Packages already in that list, Expo's own opt-out, are no longer reported.
- React Native declared through Yarn's patch protocol (
0.1.41
9 October 2026
- DocsThe example report in the README, on the homepage and in the share image showed an older "Start here" and security line than the tool prints today. They match again, and a check now compares them with the tool's own output before every release.
- AccuracyTested with dependencies installed on 17 open-source apps that are published in the App Store or Google Play: no new false alarms, and all 79 packages reported as unused were confirmed unused.
0.1.40
8 October 2026
- ExperienceTell us when NativeKeel is wrong. Every report now ends with a link to a short form for a wrong or missed finding. Nothing is sent automatically, and the form asks for the finding's title, not your code. Reports from real apps are how most of this month's accuracy fixes happened.
- AccuracyOn a React Native release candidate ahead of the latest stable (0.88 RC while 0.87 is stable), library compatibility tables do not cover it yet. Instead of calling Reanimated or Screens incompatible, NativeKeel says the tables do not cover it.
- Behind the scenesOur test set now looks first for open-source apps that link their App Store or Google Play page, which have real users: 30 added this week, 94 already in.
0.1.39
8 October 2026
- AccuracyWhen deciding whether a removed React Native API is still used, names inside
/* … */comments (including JSX comments) no longer count as uses.
0.1.38
8 October 2026
- AccuracyRemoved core APIs: used or only imported? An import of
DatePickerAndroid,AsyncStorageand the like from'react-native'was reported as a crash. In release builds such an import is simplyundefined(only development builds throw), so it only fails where the code calls it. NativeKeel now checks whether the name is used beyond the import: if it is, it stays a crash risk; if not, it is a low "unused import, delete it". Found because a production app that works fine was told otherwise.
0.1.37
8 October 2026
- AccuracyLessons from a real production app. NativeKeel was run on a private production app with its dependencies installed. The output showed five things we got wrong, all fixed:
- A prerelease of the next major (React Navigation 8 alpha) was called "a major version behind", and the plan suggested the latest stable: a downgrade. Packages are now "behind" only when npm's latest is newer than what you have.
react-native-edge-to-edgeandreact-native-bootsplashwork through a theme instyles.xml, without an import. They were listed as unused; removing them would break the app's look.- A JavaScript package that ships an empty iOS podspec (
react-native-render-html) was treated as a native module and rated high. - The missing Folly coroutine flag was rated high on an app already on React Native 0.80+, which builds fine. It is now a warning before you move to 0.80, and a low note after.
- A React Native upgrade step asked to move a library that was already in the range it needs.
0.1.36
8 October 2026
- StoreRelease builds signed with the debug key. The React Native template signs release builds with the public debug key, and Google Play refuses the upload ("signed in debug mode"). NativeKeel now reports it when nothing else signs the build: projects built with EAS, or signed in CI with Fastlane or a signing action, are recognised and left alone. 62 apps in our test set. A fix page shows the setup that keeps passwords out of the repository.
0.1.35
8 October 2026
- FixThe npm page showed "What's new in 0.1.33" after 0.1.34 was out. A test now fails the release when the README or this page do not name the version being published, so it cannot happen again.
0.1.34
8 October 2026
- DocsThe GitHub Action gets a shorter description for the GitHub Marketplace, and the npm page a clearer description and keywords. New on the site: React Native fixes, one page per common build error, store rejection and crash, with the cause, the fix and the sources.
0.1.33
8 October 2026
- Experience"Start here" also weighs package replacements and cleanups by severity: an unmaintained native module now comes before a deprecated component that still works.
0.1.32
8 October 2026
- Experience"Start here" leads with what matters most. The three steps at the end of every report used to follow a fixed order of topics, so a minor version mismatch could come before a package with 35 known vulnerabilities. They are now ordered by the most severe finding behind each step, and then by urgency. Crash fixes inside the plan are sorted the same way.
0.1.31
8 October 2026
- AccuracyTested the way you run it: with dependencies installed. Most of our test set is scanned straight from GitHub, without
node_modules. This time we installed the dependencies of 22 recent apps (scripts disabled) and compared both scans. With packages installed NativeKeel sees more, as it should: a second copy of React, patches that no longer match, Kotlin modules that fail on the New Architecture, packages off the Expo SDK. Two things were wrong, and are fixed:- An Expo SDK written as a major only (
"expo": "^54") was not recognised withoutnode_modules, so the app was treated as plain React Native and told its React Native was unsupported. 9 apps in our test set. expo-system-ui,expo-splash-screen,expo-dev-clientandexpo-updateswork fromapp.jsonor register natively, without an import: they were listed as unused. Removing them would break dark mode, the splash screen or updates. The other 44 "unused" packages we checked by hand really were unused.
- An Expo SDK written as a major only (
0.1.30
7 October 2026
- StoreiOS SDKs too old for Apple's privacy manifest rule. Apple lists SDKs (Firebase, SDWebImage, Lottie, GoogleUtilities, Alamofire and others) that must ship a privacy manifest: App Store Connect refuses a new app that includes an old version, or an update that adds one. NativeKeel reads
ios/Podfile.lockand names the React Native package that pulls each one in, since that is what you update: SDWebImage 5.11.1 usually comes fromreact-native-fast-image, old Firebase from@react-native-firebase. The first version with a manifest for each SDK is read from the CocoaPods specs by a script, not typed by hand. 24 of 116 apps with a Podfile.lock in our test set. - AccuracyThe "hermes" on Apple's list is a 2015 Imgur project, not React Native's engine (the React Native team confirmed this with Apple), so React Native's Hermes is not reported.
0.1.29
7 October 2026
- StoreAccount deletion. The App Store requires apps that let people create an account to let them delete it from inside the app (guideline 5.1.1(v)), and Google Play requires an in-app path plus a web link. It is one of the most common rejection reasons. NativeKeel now flags apps whose code signs users up (Firebase, Supabase, Amplify, Appwrite, Clerk or your own
/signupAPI) with no deletion anywhere. Links to another service's sign-up page and device registration are not counted. 43 apps in our test set. - StoreSign in with Apple. Guideline 4.8: an iOS app that uses Google or Facebook login for the user's account must also offer a privacy-focused login, and Sign in with Apple qualifies. Reported with Apple's exceptions spelled out. 11 apps.
- Behind the scenesApp Tracking Transparency was measured and not shipped: without the prompt, ad SDKs simply cannot track, which costs ad revenue but is not a rejection. We only call something a rejection when it is one.
0.1.28
7 October 2026
- StabilityA release build that talks to your laptop. An API address like
10.0.2.2(the Android emulator's name for your computer),192.168.x.x,localhostor an ngrok tunnel, used outside any development-only branch, works on your machine and fails on every user's phone. NativeKeel now finds these and points to the line. Development branches (__DEV__, dev environment flags), settings screens where users enter their own server, named local fallbacks, local-service probes and server-only code are left alone. 21 apps in our test set ship one. - Behind the scenes
evalandnew Functionwere measured too: 9 apps, almost all legitimate (web-only files, debug tools). Not shipped as a check.
0.1.27
7 October 2026
- StoreThe build error waiting behind the target SDK bump. Google Play requires API 36 for updates. Apps still targeting 30 or lower usually have activities or receivers with an intent-filter and no
android:exported; from target 31 that stops the build. NativeKeel lists them and the plan fixes them first, before the target SDK step. 107 apps in our test set would hit this. - Behind the scenesTwo candidates measured and not shipped: missing Android 13 notification permission (10 of 11 apps already request it at runtime, and Firebase Messaging and Notifee declare it for you), and WebViews opening a URL from a deep link (no case in 653 apps). We add a check when real apps show the problem, not before.
0.1.26
7 October 2026
- StabilityPackages Expo did not test with your SDK. Each Expo SDK pins the library versions it is tested with. A native module from another release is one of the most common causes of build failures and launch crashes in Expo apps. NativeKeel now compares every pinned package (not only Reanimated, Screens and Gesture Handler) and rates the gap: a major difference is high, a minor one medium, a patch low. In our test set, 144 of 390 Expo apps with a lockfile have at least one, most often Reanimated, safe-area-context and Screens. The fix is one command:
npx expo install --fix. - StabilityA library bumped ahead of React Native. When a native library declares that it needs a newer React Native than the app has (Clipboard 1.14 needs 0.73, the app is on 0.72), builds commonly fail or the first call crashes. Only lower bounds count: loose upper caps such as
^0.60.0on 0.62 are ignored, since apps run fine with them. - AccuracyA TLS bypass set on
react-native-blob-utilis judged by how requests use it: never used, it is not reported; tied to a setting (trusty: !certVerification, for self-hosted servers), it is high instead of critical. Found while checking well-known open-source apps. - PrivacyIn Expo projects without
node_modules, NativeKeel asks unpkg for the versions your Expo SDK expects, sending only theexpoversion number. The privacy page, README and SECURITY.md list every request.
0.1.25
7 October 2026
- SecuritySupabase tables without row level security. The anon key ships inside every copy of the app, so a table in the public schema without RLS can be read and changed by anyone through Supabase's REST API. NativeKeel reads the migrations under
supabase/and lists the tables that never enable it (a commented-outenable row level securitydoes not count). Tables in other schemas and RLS enabled in a loop are recognised. In our test set: 3 of the 15 apps with Supabase migrations, one of them a starter template with payment and invoice log tables open. - StorePermissions Google Play restricts. Photo and video access (enforced since May 2025: use the photo picker unless your app is a gallery), all files access, app installs, background location, SMS and call log, full-screen intents and exact alarms each need a core use case and a Play Console declaration, or the app is rejected or removed. Permissions you remove with
tools:node="remove"or Expo'sblockedPermissionsare not counted. Each rule was checked on Google Play's policy pages. Found in 24 apps.
0.1.24
7 October 2026
- Accuracy200 more apps, all pushed to GitHub in the last month. Our test set now grows every week from recently updated React Native and Expo apps (653 scanned, zero tool failures). What they showed, now fixed:
- A private key is reported only when there is a key: form placeholders (
-----BEGIN … Paste your key here), elided samples and constants holding just the header line are not keys. Real keys are still found. - Reanimated 4 without
react-native-workletsin package.json is fine when the lockfile has it: npm 7+ and pnpm install peer dependencies on their own. - A test keystore used as a local fallback (
storeFile file('test.keystore'), password123456) is not a release key. - MD5 on a password is low, with an explanation, when it is the Subsonic API's own token format: the app has no choice there.
- A private key is reported only when there is a key: form placeholders (
- ExperienceNo more waiting on a slow network. A scan now spends at most 90 seconds on npm and React Native Directory; if they are slow, the report arrives with a note on what is missing instead of hanging.
0.1.23
6 October 2026
- StabilitySafeAreaView on Android 15. The
SafeAreaViewfrom'react-native'only ever applied to iOS. Apps that target API level 35 or higher (Expo SDK 52+ do) are drawn edge-to-edge on Android 15 and newer, so screens wrapped in it already sit under the status bar there. When your target SDK is 35+, NativeKeel now says so and rates it medium;react-native-safe-area-contextfixes both platforms. 29 apps in our test set are in this situation.
0.1.22
6 October 2026
- SecurityAuth tokens in plain storage, found by what is stored. The check used to look only at the storage key (
setItem('access_token', …)). It now also catches tokens saved under a constant (setItem(TOKEN_KEY, token)) or inside an object (JSON.stringify({ token })). Push notification and device tokens are left alone, and web-only files (*.web.ts) are skipped since the web has no Keychain. In our test set this finds 13 apps instead of 4. - DocsThe homepage and npm page link to what we found in 470 open-source apps.
0.1.21
6 October 2026
- Correction16 KB pages: the right date. NativeKeel said Google Play already rejects updates without 16 KB page support and rated it critical. Google's current page (updated September 2026) says the policy applies since November 2025, Play Console warns now, and Play blocks updates from 1 February 2027. Until then the finding is high, with that date; from 1 February 2027 it becomes critical on its own. Found by our upstream check, which now also watches this date.
0.1.20
6 October 2026
- UpgradeAPIs React Native has announced it will remove. React Native 0.87 deprecated
ImageBackground,DrawerLayoutAndroidandUTFSequence(and 0.81SafeAreaView): they still work and log a warning, and once removed, every screen that imports them crashes. NativeKeel now lists where you use them and what to use instead. In our test set, 139 of 470 apps import at least one, most oftenSafeAreaVieworImageBackground(how to migrate). - StoreThe Google Play target SDK message knows when the extension period ends (1 November 2026) and stops mentioning it afterwards.
- Behind the scenesWe now check upstream on a schedule: new React Native and Expo releases, the libraries' compatibility tables, what each Expo SDK pins, what React Native deprecates, and Google Play's policy page. This release came from that check.
0.1.19
6 October 2026
- PlanBetter plans for apps that are far behind. On an old React Native (0.62, say), the step before the upgrade no longer suggests the newest release of each library, which usually needs a much newer React Native. It asks for the newest release that supports your version and shows the latest for reference. Reanimated, Gesture Handler and Screens are left to the React Native steps, which pick tested versions for each hop.
- PlanSecurity steps for packages that the React Native upgrade moves anyway (React Native itself, Reanimated) say so, and when to update them early: if you ship before reaching those steps.
0.1.18
6 October 2026
- Security"No fixed release" is said plainly. When the vulnerable range includes the newest published version (expr-eval 2.0.2, for example), the plan no longer says "update". It says no fix exists: replace the package, or make sure it never handles untrusted input. When the advisory only says "up to 4.17.23", the version to install is now the actual next release (lodash 4.18.1).
- PlanLibrary updates that fit your current React Native. Before the React Native steps, the plan used to suggest the newest Reanimated or Gesture Handler even when it needs a newer React Native. It now stops at the newest version your current React Native supports, and the React Native steps move them further.
- PlanFamilies move together. All
@react-navigation/*packages (and all@react-native-firebase/*) are one step, since mixed major versions crash at runtime. React Navigation is no longer mistaken for a native module, and renamed community packages (such as@react-native-community/masked-view) are recognised as native even withoutnode_modules, so the plan says "swap it" instead of "replace it some day". - PlanHermes appears in one step, not two, and version ranges read "2.32+ (2.x line)" instead of "2.32–2.99.x".
- FixThe HTML report showed bold plan steps as
**text**. It now renders them in bold.
0.1.17
6 October 2026
- SecurityEvery vulnerable package now says which version fixes it. Advisories written as "up to and including 1.13.4" were not read, so a package with 35 advisories showed "check the advisories" instead of "fixed in 1.20.0". It is now in the title and in the plan step. 378 of 381 vulnerable packages in our test set get a fixed version.
- AccuracyMore advisories that cannot reach a mobile app are counted as low: axios' HTTP/2 adapter, proxy and
NO_PROXYhandling, server-side request forgery and cloud metadata leaks. They stay visible in the details. - ExperienceLess noise in Expo apps. Packages whose version the Expo SDK decides (
expo-*, Reanimated, Screens, AsyncStorage, …) no longer appear one by one as "a major version behind". They are one line: "19 packages move with the Expo SDK upgrade", sincenpx expo install --fixmoves them. Across our test set, 3,700 low findings became that one line.
0.1.16
6 October 2026
- SecurityDeep links. Web links (
https://your.domain/...) that are not verified withautoVerify: Android 12+ opens them in the browser instead of your app, and older Android lets any app that registers the same links receive them, including login, reset and invite links. And the template URL schememyapp://, which 72 of the 470 apps we scan still ship: another app with the same scheme can open your links, and catch your sign-in redirect when you use expo-auth-session, Clerk or AppAuth. Both under MASVS-PLATFORM. - AccuracyTested on 180 more open-source apps (450+ in total, zero tool failures). Fixed what they showed:
.DS_Storefiles caught in a patch are no longer reported as "build output that will not apply", and keystores inside test fixtures are not release keys. - ExperienceThe HTML report wraps long file paths and code on phone screens.
0.1.15
6 October 2026
- ExperienceMonorepos. Run at the root of a monorepo and NativeKeel lists the app folders to scan (
npx nativekeel apps/mobile) instead of stopping with "not a React Native app". Libraries are not suggested. - PlanAn app that needs no React Native or Expo upgrade gets an Action plan, not an "Upgrade plan".
- DocsThe README and npm page list every check by group: upgrade, store, crashes, security (by OWASP MASVS) and performance.
0.1.14
6 October 2026
- SecuritySecrets in Expo config. Secret-looking values in
app.json/app.configextraand inEXPO_PUBLIC_variables ship inside the app; secrets ineas.jsonbuild env are committed to the repo (found a Sentry auth token this way in two open-source apps). Public SDK keys such as RevenueCat's are left alone. - StabilityAPIs removed from React Native core.
AsyncStorage,Picker,Slider,WebView,ViewPropTypesand 23 others imported from'react-native'throw or are undefined on current versions. Reported as a crash now when the installed version already removed them, or as a step before the upgrade, with the replacement package for each. The list comes from React Native's own source.
0.1.13
6 October 2026
- PerformanceSpeed up the app. A new plan phase for the static signs of jank and weight: a FlatList inside a ScrollView that renders every row, animations driven from the JavaScript thread, console logs left in release builds, whole-library imports of lodash and moment, and oversized images the app actually requires (repo screenshots are not counted).
- SecurityReverse engineering. Source maps packaged into the app (they give back your original code), and release builds with Hermes or R8 off. Reported honestly: obfuscation only slows an attacker down, so secrets and trust decisions belong on the server. A new MASVS-RESILIENCE group in the security overview.
0.1.12
5 October 2026
- SecurityHacking risks, mapped to OWASP MASVS. Every security finding now names its MASVS group, and reports show a security overview: which groups were checked and how many issues each has.
- SecurityOpen Firebase rules. Realtime Database, Firestore and Storage rules that let anyone read or write, root rules that give every signed-in user everything, and test-mode rules (open until a date, or expired). Public folders such as event images are left alone.
- SecurityTLS certificate checks turned off. Trust-all managers, hostname verifiers that accept everything, WebViews that proceed on SSL errors and iOS sessions that trust any server. A bypass behind a "trust my self-signed server" setting is reported as such, at lower severity.
- SecurityWeak cryptography and token storage. Hardcoded encryption keys, MD5/SHA-1 on passwords, ECB mode, Math.random for nonces and salts, auth tokens in AsyncStorage.
- AccuracyDependencies installed from git are never matched against npm advisories (a wallet app was flagged with a malware advisory that belongs to a different package with the same name).
0.1.11
5 October 2026
- FixThe GitHub Action works. A colon inside one input description made
action.ymlinvalid, souses: AlicanAkyol/nativekeel@v0failed to load. It is fixed, the Action now has anexit-codeoutput, and a workflow runs it on a sample app on every change so this cannot slip again.
0.1.10
5 October 2026
- ExperienceStart here. Every report now opens with the three most urgent first steps (leaked keys, crash risks, store deadlines, security gaps), in the terminal and in the HTML report. On the real app our case study is based on, it picked the same three priorities we had reached by hand.
- StabilityMissing iOS permission texts. Using the camera, photos, location, microphone, contacts, calendars, Bluetooth or Face ID without the matching Info.plist description makes iOS close the app and App Review reject it. Expo config plugins are taken into account.
- PlanStore deadlines (target SDK, 16 KB pages, privacy manifest) now sit together at the start of the plan.
0.1.9
5 October 2026
- SecurityAndroid components open to every app. Services, receivers and providers exported without a permission. Widgets and receivers for system broadcasts are left alone, because Android needs them exported.
- SecurityAPI calls over plain HTTP. fetch, axios and WebSocket calls to real hosts over http:// or ws://; local addresses and links opened in the browser are ignored.
- ExpoOld Expo projects (SDK 44 and earlier) are read correctly: React Native comes from Expo's fork, and the plan uses the right upgrade command for each SDK (the legacy CLI before SDK 46). For very long jumps it also weighs starting a fresh project.
0.1.8
5 October 2026
- SecurityKnown vulnerabilities in what you ship. Advisories from the GitHub Advisory Database for the exact versions in your lockfile or node_modules (npm, yarn, pnpm). Advisories that only affect Node.js servers stay visible at low severity instead of raising false alarms.
- SecurityPasswords leaking into logs and databases. Follows a password through intermediate variables into crash reports, analytics, remote database writes or plain AsyncStorage. Built from a real leak we found in a production app.
- SecurityUnsafe WebViews and Android backups. WebViews that let page scripts read local files or mix HTTP into HTTPS;
allowBackupwithout backup rules. - StabilityCrash risks. Reanimated without its Babel plugin or react-native-worklets, mixed Firebase or React Navigation majors, a second copy of React or React Native inside a dependency.
- PlanNew phases: Fix crash risks and Close security gaps.
0.1.7
4 October 2026
- PlanFor old apps, library versions recommended before the New Architecture switch now run on the legacy architecture, each library stays on its major line, and forced major migrations are flagged.
- PlanRenamed community packages (async-storage, cameraroll, masked-view, viewpager, picker, clipboard, netinfo) get a "swap and update imports" step.
- ReportsThe HTML report folds outdated packages into one table; GitHub code scanning links work for folders with spaces.
0.1.6
4 October 2026
- PlanUpgrade plans reviewed line by line on real apps. The Google Play 16 KB deadline is now explicit; managed Expo apps get EAS commands instead of android/ios ones; abandoned JavaScript packages no longer pose as upgrade blockers; a nearly current app is no longer sized like a migration.
- AccuracyPatched packages, alias fields and Node core polyfills are never reported as unused.
0.1.5
4 October 2026
- PlanApps older than React Native 0.76 now get the New Architecture switch at the right point of the upgrade (it was treated as already on).
- PlanExpo: SDK-managed packages move with
npx expo install --fix, never bumped past the SDK. - AccuracyReanimated compatibility is generated from Reanimated's own data; the iOS privacy manifest is recognised as generated by React Native 0.75+; npm rate limits are retried and reported instead of silently missing checks.
0.1.4
4 October 2026
- AccuracyFirst run against 32 open-source apps: 11 fixes, from piped JSON output being cut off to placeholder secrets reported as real.
- Monorepospnpm and Bun catalog versions are resolved.
0.1.3
4 October 2026
- PlanEvery upgrade plan starts with a safety net: UI flows on both platforms before the first change. On a real upgrade they caught a post-login crash, a frozen sign-up and an invisible button.
0.1.2
4 October 2026
- StabilityNew known issue from a real upgrade:
react-native-linear-gradient2.x around a Modal crashes on the New Architecture.
0.1.0 – 0.1.1
3 October 2026
- First release: support status, New Architecture blockers, Google Play target SDK and 16 KB pages, iOS privacy manifest, 14 secret patterns, unused packages, upgrade plan, HTML/Markdown/SARIF/JSON output, baseline for CI and a GitHub Action. Published with npm provenance.