oblador/react-native-keychain
53.3
Adequate · 28 September 2026
3.9k
lines of production code
Kotlin
with TypeScript, Objective-C
2
measurements over time
What this system is
This system is a React Native library that provides secure credential storage by wrapping native iOS Keychain and Android Keystore APIs. It supports various encryption methods, including AES-GCM and RSA, and offers configurable access controls such as biometric authentication and device passcode fallback. The project includes a comprehensive example application for testing these security features and maintains versioned documentation for developers.
How it got here
2015–2016 — Android rewrite and React Native 0.77 modernization
6 changes.
The project underwent a significant modernization, starting with a complete rewrite of the Android module in Kotlin to introduce AES-GCM encryption, DataStore migration, and TurboModule support. This was accompanied by a comprehensive infrastructure overhaul, including updates to React Native 0.77, the New Architecture, and the adoption of react-native-test-app and Detox for testing.
2017–2025 — New architecture support and testing infrastructure
10 changes.
The project updated its iOS implementation to support Turbo Modules and migrated its documentation site to Docusaurus for versioned guides. Significant effort was invested in establishing robust end-to-end testing infrastructure using Detox for both Android and iOS, including comprehensive test suites for security features and access control.
Features
Added Android Detox integration test and Gradle wrapper scripts
The KeychainExample Android project now includes an end-to-end integration test suite using Detox, with a new DetoxTest class configured to run against the MainActivity. Additionally, the project now ships with the standard Gradle wrapper scripts (gradlew and gradlew.bat), enabling users to build and run the example app without manually installing Gradle.
KeychainExample/android · high confidence
Added Android build scaffolding with Gradle wrapper
The Android module now includes the standard Gradle wrapper scripts (gradlew, gradlew.bat) and an .npmignore file to support building Android components. This change provides the necessary infrastructure for developers to execute Gradle tasks locally without requiring a pre-installed Gradle environment, establishing the baseline build configuration for the Android portion of the project.
android · high confidence
Example app now supports configurable security storage and access control options
The KeychainExample app has been updated to demonstrate advanced security features, allowing users to select specific storage types (AES-CBC, AES-GCM, AES-GCM without authentication, RSA) and access control methods (None, Passcode, Password, Biometry) when saving credentials. This change introduces UI controls for these options and maps them to the underlying Keychain API, enabling developers to test how different encryption and authentication configurations affect credential storage and retrieval on both iOS and Android platforms.
KeychainExample/src · high confidence
Project initialization and repository structure overhaul
The repository has been initialized with a comprehensive project structure, including TypeScript configuration, ESLint and Prettier rules, and a new README that documents the library's features, installation, and maintainers. This change establishes the foundational tooling and documentation for the react-native-keychain library, preparing it for development and distribution.
(repo-wide) · high confidence
Behavioural changes
Android implementation rewritten in Kotlin with modern encryption and storage
The Android module has been completely rewritten in Kotlin, replacing the previous Java implementation. This update introduces AES-GCM encryption (with and without biometric authentication) alongside the existing AES-CBC and RSA options, and migrates persistent storage from SharedPreferences to Android DataStore. It also adds support for strong biometric authentication, device passcode fallback, and StrongBox hardware security, while registering the module as a TurboModule for improved performance.
android/src · high confidence
Default authentication prompt text for credential retrieval
When retrieving generic passwords or internet credentials, the system now displays a default authentication prompt with the title "Authenticate to retrieve secret" and a "Cancel" button if the caller does not provide custom \authenticationPrompt\ options. This behavior is implemented via the new \normalizeAuthPrompt\ utility in \src/normalizeOptions.ts\, which merges user-provided prompt settings with these defaults before passing them to the native keychain manager.
src · high confidence
Migrate KeychainExample to react-native-test-app and modern tooling
The KeychainExample has been migrated from the legacy example structure to use react-native-test-app, introducing a new configuration ecosystem including a Detox end-to-end test setup, a modern Metro configuration with peer dependency handling, and a Babel setup using @react-native/babel-preset. This change updates the example's build and test infrastructure to support current React Native standards, including TypeScript support and multi-platform resource definitions, while removing the previous unit test suite in favor of the new e2e testing framework.
KeychainExample · high confidence
Updated iOS workspace configuration for KeychainExample
The KeychainExample iOS project now uses a new workspace structure that includes the ReactTestApp project via autolinking, replacing the previous setup. This change ensures the example app correctly references the test app dependencies and standardizes the Xcode environment configuration.
KeychainExample/ios · medium confidence
Website migrated to Docusaurus with versioned documentation
The documentation site has been rebuilt using Docusaurus, introducing a new configuration structure (docusaurus.config.ts, sidebars.ts) and a custom CSS theme. This change enables versioned documentation, preserving the v9.0.x API reference and guides alongside the current docs, and adds new content including a guide on unit testing with Jest, a data persistence overview, and a comparison of secure hardware versus software storage on Android.
website · high confidence
iOS Keychain Manager supports Turbo Modules
The iOS implementation for the keychain manager has been updated to support the new architecture. The native module now conditionally implements the \NativeKeychainManagerSpec\ protocol when the new architecture is enabled, allowing it to function as a Turbo Module, while retaining the legacy \RCTBridgeModule\ interface for older setups.
ios · high confidence
Test coverage
Added end-to-end tests for access control, security levels, and storage types; Configured end-to-end testing infrastructure with Detox; Refactor e2e tests with new helper utilities.
Dependencies
Example app and library build configuration updated for React Native 0.77 and New Architecture
The KeychainExample app and the library's Android build files have been updated to support React Native 0.77.1 and enable the New Architecture (TurboModules and Fabric) by default. The example project now uses \react-native-test-app\ for bootstrapping, includes Detox for end-to-end testing, and specifies CocoaPods 1.15.2 while excluding known problematic versions (1.15.0, 1.15.1). On Android, the library's \build.gradle\ now targets SDK 34, uses Android Gradle Plugin 8.3.1, and conditionally includes New Architecture source directories. The main \package.json\ has been bumped to version 10.0.0.
(dependencies) · high confidence
Update Gradle wrapper to version 8.6
The Android build system now uses Gradle 8.6 via the wrapper configuration. This ensures consistent build environments across development and CI by pinning the specific Gradle distribution version.
android/gradle · high confidence
Updated Gradle wrapper to version 8.11.1
The Android example project now uses Gradle wrapper version 8.11.1 for building, replacing the previous version. This ensures consistent build environments and leverages the latest Gradle features and improvements for the KeychainExample Android module.
KeychainExample/android/gradle · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 57 → 53 (-3.8)
- Rubric changed (rubric-2026.09.8 → rubric-2026.09.16) — scores are not directly comparable.
Lenses
- Code Health 90 → 91 (+0.5)
- Architecture 100 → 98 (-1.6)
- Maturity 65 → 65 (+0.0)
- Readiness 55 → 42 (-13.8)
- Security 46 → 57 (+10.8)
- Performance 60 (new)
Resolved (167)
- Critical CVE: [CVE redacted] (yarn.lock)
- Critical CVE: [CVE redacted] (yarn.lock)
- Critical CVE: [CVE redacted] (yarn.lock)
- Critical CVE: [CVE redacted] (yarn.lock)
- Documentation: no installation or build instructions (README.md)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- High CVE: [CVE redacted] (yarn.lock)
- …and 147 more
New (21)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High CVE: [GHSA redacted] (yarn.lock)
- High vulnerability: [GHSA redacted] (yarn.lock)
- Medium CVE: [GHSA redacted] (yarn.lock)
- Medium CVE: [GHSA redacted] (yarn.lock)
- Medium CVE: [GHSA redacted] (yarn.lock)
- Medium CVE: [GHSA redacted] (yarn.lock)
- Medium CVE: [GHSA redacted] (yarn.lock)
- Medium CVE: [GHSA redacted] (yarn.lock)
- Medium CVE: [GHSA redacted] (yarn.lock)
- Medium CVE: [GHSA redacted] (yarn.lock)
- Medium CVE: [GHSA redacted] (yarn.lock)
- Medium CVE: [GHSA redacted] (yarn.lock)
- Medium CVE: [GHSA redacted] (yarn.lock)
- Medium CVE: [GHSA redacted] (yarn.lock)
- …and 1 more
Architecture
- Unchanged — 0 containers · 1 contexts · 0 edges
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
oblador/react-native-keychain was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 6be201b1f353359320a6f01a77f6060984825a6f — the exact code this score is about.
- Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-2d9048c36d26.