react-native-best-practices

Warn

Audited by Socket on Feb 24, 2026

1 alert found:

Anomaly
AnomalyLOW
references/bundle-code-splitting.md

The file is documentation/tutorial code showing how to implement lazy-loaded, remotely fetched chunks and module federation with Re.Pack. The content itself is not malware, but it describes a pattern that — if used without additional protections — permits execution of arbitrary remote code and expands the supply-chain attack surface. Primary risks: fetching executable code from external servers/CDNs (or developer servers) without demonstrated integrity/authentication checks, and caching that code locally without shown validation. Recommend adding cryptographic integrity checks (signatures/content-addressing), origin allowlists, strict deployment controls, and runtime verification before using in production.

Confidence: 90%Severity: 60%
Audit Metadata
Analyzed At
Feb 24, 2026, 06:57 AM
Package URL
pkg:socket/skills-sh/storybookjs%2Freact-native%2Freact-native-best-practices%2F@3acdb7584744c65515b9a47728b5bd832c808213