SDK Supply Chain

Third-Party SDK Signatures and Supply-Chain Checks

Apple keeps a list of commonly used third-party SDKs, among them the Firebase 1 libraries, GoogleSignIn, SDWebImage 25,628 , Lottie 176,690 , Capacitor 243,123 and Flutter 16,720 . Since 1 May 2024, an app that adds one must ship a version with its own privacy manifest and, when the SDK arrives as a precompiled binary such as an .xcframework, a valid signature from its author. React Native 36,878 and Expo 6,418 's modules are not on the list and compile from source, so the rule starts to matter when you add a binary analytics or crash-reporting SDK.

The larger risk is the 1,028 npm 2,036 packages behind the app. npm verifies each one's registry signature and reports provenance attestations, which link a package to its source and build. Ubuntu 225 's npm 9.2.0 fails on a registry key that expired in January 2025, so use a current npm:

Verifying registry signatures with this machine's npm 9.2.0, then with npm 11Shell
npm audit signatures
npx -y npm@11 audit signatures
Output
npm ERR! code EEXPIREDSIGNATUREKEY
...
1028 packages have verified registry signatures
186 packages have verified attestations

npm audit --omit=dev then checks the shipped dependencies against GitHub 29 's advisory database. It reported 14 moderate issues from two advisories, a denial of service in decode-uri-component (under expo-router 6,418 ) and a bounds check in uuid (under the xcode package that prebuild uses), and offered a trap: "fix available via npm audit fix --force. Will install expo@46.0.21, which is a breaking change". --force would drag BookNest back eleven Expo SDKs. Read each advisory and ask whether the code runs in the app on input an attacker controls; xcode runs only during prebuild on your machine, so wait for an Expo patch and apply it with npx expo install --fix. Commit package-lock.json, install with npm ci in CI, and let Dependabot 29 or OSV-Scanner 11,098 (https://github.com/google/osv-scanner 11,098 ) (Apache-2.0, which also reads Gradle 19,597 and CocoaPods 66,002 lockfiles) watch for new advisories; Snyk 12,590 and Socket are commercial, with free tiers, and add reachability analysis and malicious-package detection.