← Package details

Runtime evidence / smoke tested

react19.3.0

Observed 2026-10-09 10:13 UTC · Linux amd64 / glibc

Download JSON
Immutable loading evidence badge for react
Passed

All applicable planned loading observations completed.

This is loading evidence. It does not establish functional correctness or package safety.

Runtime matrix

4 pinned runtimes · production_ce416e976d3b4c51b252859d31c1fa7c

Import uses ESM; require uses CommonJS. Root modes use fresh sandboxes. Subpath batches share module caches and globals. Select a result to inspect its evidence.

Does react work in Node.js, Bun and Deno?

All applicable planned loading checks completed. The runtimes used the same installed dependency snapshot. Test environment: Linux amd64 / glibc, with install scripts and execution networking disabled. Successful import or require does not prove that package functions, native features or your application work.

Does react work with Node.js?

react@19.3.0 passed the applicable loading checks in Node.js 24.21.0. 8 passed · 0 failed.

react@19.3.0 passed the applicable loading checks in Node.js 26.10.0. 8 passed · 0 failed.

Does react work with Bun?

react@19.3.0 passed the applicable loading checks in Bun 1.4.2. 8 passed · 0 failed.

Does react work with Deno?

react@19.3.0 passed the applicable loading checks in Deno 2.9.7. 8 passed · 0 failed.

Compare npm package compatibility across Node.js, Bun and Deno · Browse observed runtime loading failures

Shared preparation

Passed

1 installed packages · 0 optional dependencies omitted · lifecycle scripts disabled

The omitted count covers locked optional dependencies. Optional peers are separate and are not automatically installed.

Static manifest, native and script observations

Static indicators are context; their presence alone does not establish a prerequisite or failure.

Coverage and evidence

Node.js 24.21.0 · Root · ESM importPassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Node.js 24.21.0 · Root · CommonJS requirePassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Node.js 24.21.0 · Subpaths · ESM importPassed

3 passed · 0 failed · 3 observed of 3 planned

Evidence JSON
Node.js 24.21.0 · Subpaths · CommonJS requirePassed

3 passed · 0 failed · 3 observed of 3 planned

Evidence JSON
Node.js 26.10.0 · Root · ESM importPassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Node.js 26.10.0 · Root · CommonJS requirePassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Node.js 26.10.0 · Subpaths · ESM importPassed

3 passed · 0 failed · 3 observed of 3 planned

Evidence JSON
Node.js 26.10.0 · Subpaths · CommonJS requirePassed

3 passed · 0 failed · 3 observed of 3 planned

Evidence JSON
Bun 1.4.2 · Root · ESM importPassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Bun 1.4.2 · Root · CommonJS requirePassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Bun 1.4.2 · Subpaths · ESM importPassed

3 passed · 0 failed · 3 observed of 3 planned

Evidence JSON
Bun 1.4.2 · Subpaths · CommonJS requirePassed

3 passed · 0 failed · 3 observed of 3 planned

Evidence JSON
Deno 2.9.7 · Root · ESM importPassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Deno 2.9.7 · Root · CommonJS requirePassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Deno 2.9.7 · Subpaths · ESM importPassed

3 passed · 0 failed · 3 observed of 3 planned

Evidence JSON
Deno 2.9.7 · Subpaths · CommonJS requirePassed

3 passed · 0 failed · 3 observed of 3 planned

Evidence JSON
Planner omissions
pattern
0
non executable
1
not exported
0
invalid subpath
0
coverage limit
0
  • ./package.json — non executable

Reproduce these inputs

Download the recorded inputs and exact dependency lock. These files do not include the CLI, runtime images or installed packages.

Local replay requires setup. The CLI currently runs from the CompatLab source repository on a qualified Linux amd64/runsc host. Hosted runtime images are not yet distributed for public download; an operator must supply the exact images named in this report. A fresh image build does not substitute for them. CLI setup and replay requirements

Command for a configured host

Run from the built CompatLab repository with both downloads in that directory and the exact runtime images loaded. Rebuilding creates a new snapshot generation.

sudo "$(command -v node)" apps/cli/dist/bin.js reproduce ./71195e62-f2db-4c09-9e3b-ab89b5d2af7c-reproduction.json --rebuild --lockfile ./package-lock.json --json

The original worker last reported its sealed snapshot as available. Verified reuse requires those actual bytes in your local state directory.

Exact provenance
artifact
react@19.3.0
integrity
sha512-E8LUcbtBWt20bbl2YoHfx4ZDBdxVTfOKtCZn9cDSJ4l6/nuoApcpIBcj47t2wZoVX8g2ZHuMHbiShgCR1T5Sog==
tarball
https://registry.npmjs.org/react/-/react-19.3.0.tgz
snapshot
5e535a35-3493-4f42-aecb-bb052a0c62b9
generation
a400e305-d137-4bf4-a8ca-c151ddaead7f
lockDigest
1f7bd328921d699e124b36574876fc84a483549bf2c5194db8783db96ef66e01
treeDigest
97bcfb43a1a384ec0a75c1bf543387601be90f4f8c573ee8979df0a36464f16a
installerImage
node:24.21.0-bookworm-slim@sha256:5cbc7caba8c2c0f0bca675d1b61b9f2857e1cf1853c6164ee9dd409501a936e7
preparationProfile
npm_11_19_0_linux_amd64_v2
harness
load_v2
planner
explicit_exports_v1
policy
runtime_limits_v2
classifier
classifier_v2
classifiedAt
2026-10-09T10:13:09.687Z

node_24_21_0

sha256:e3a5a41a242a766e69f326b91f9ed9280c5719ad3e9ab54f0ac28bfc71d77794

Built 2026-10-04 15:20 UTC · runtime_image_v1

node_26_10_0

sha256:5d2fa297021c7db25494856bb25e2cddecbb020722ce1e0f2101385a063c0611

Built 2026-10-04 15:20 UTC · runtime_image_v1

bun_1_4_2

sha256:fd67412f5baad0c2b1038367df9cf2d4b33237d3815e16eedae16cfd94ab3182

Built 2026-10-04 15:21 UTC · runtime_image_v1

deno_2_9_7

sha256:3b0f993e5ec0b1d4e8e09bc50ae53f142f7347d0baf96cefe7a8cfe7a00f7958

Built 2026-10-04 15:21 UTC · runtime_image_v1

Evidence limitations

  • Only installation and loading were observed; functional correctness and package safety are not established.
  • Subpath batches share module caches and globals; root modes use separate fresh sandboxes.
  • Package-visible harness observations can be tampered with. They are not adversarial attestation.
  • Evidence applies to these exact artifacts, dependency snapshot, runtime images and Linux amd64/glibc policy.
  • Runtime error codes are captured observations and can also be thrown by package code.