push-notifications — independently scanned and version-tracked by SaferSkills.
SaferSkills independently audited push-notifications (Agent Skill) and scored it 100/100 (green). The audit ran 55 deterministic rules across Security, Supply Chain, Maintenance, Transparency, and Community; it found 0 high-severity and 0 lower-severity findings. The full rule-by-rule trace and per-finding evidence are below. Free, methodology-open.
Findings & checks · 0 flagged
Every scanned point with the score it earned and what moved between them.
First recorded scan — no prior version to compare against.
The primary manifest — the file an agent reads to learn what this artifact does.
You do NOT call APNs or FCM directly. Expo's push service handles the routing.
cd mobile
npx expo install expo-notifications expo-device expo-constantsAdd to app.json:
{
"expo": {
"plugins": [
[
"expo-notifications",
{
"icon": "./assets/notification-icon.png",
"color": "#ffffff",
"sounds": ["./assets/notification-sound.wav"]
}
]
]
}
}Add to your app initialization (e.g. app/_layout.tsx):
import * as Notifications from "expo-notifications";
import * as Device from "expo-device";
import Constants from "expo-constants";
// Handle notifications when app is in foreground
Notifications.setNotificationHandler({
handleNotification: async () => ({
shouldShowAlert: true,
shouldPlaySound: true,
shouldSetBadge: false,
}),
});
export async function registerForPushNotifications(): Promise<string | null> {
if (!Device.isDevice) {
console.warn("Push notifications require a physical device");
return null;
}
const { status: existingStatus } = await Notifications.getPermissionsAsync();
let finalStatus = existingStatus;
if (existingStatus !== "granted") {
const { status } = await Notifications.requestPermissionsAsync();
finalStatus = status;
}
if (finalStatus !== "granted") {
return null;
}
const projectId = Constants.expoConfig?.extra?.eas?.projectId;
const token = (await Notifications.getExpoPushTokenAsync({ projectId })).data;
return token; // looks like: ExponentPushToken[xxxxx]
}projectId comes from eas.json or app.json → expo.extra.eas.projectId. Find it in expo.dev under your project settings.
After registration, save the token to your database:
// lib/notifications.ts
import { supabase } from "./supabase";
import { registerForPushNotifications } from "./pushNotifications";
export async function syncPushToken(userId: string) {
const token = await registerForPushNotifications();
if (!token) return;
await supabase.from("push_tokens").upsert(
{ user_id: userId, token, platform: Platform.OS },
{ onConflict: "token" }
);
}Database schema:
create table push_tokens (
id uuid primary key default gen_random_uuid(),
user_id uuid references auth.users not null,
token text unique not null,
platform text not null, -- ios | android
created_at timestamptz default now()
);
alter table push_tokens enable row level security;
create policy "users manage own tokens" on push_tokens
using (auth.uid() = user_id)
with check (auth.uid() = user_id);Call syncPushToken after login:
supabase.auth.onAuthStateChange((event, session) => {
if (event === "SIGNED_IN" && session?.user) {
syncPushToken(session.user.id);
}
});// supabase/functions/send-notification/index.ts
import { createClient } from "npm:@supabase/supabase-js@2";
const EXPO_PUSH_URL = "https://exp.host/--/api/v2/push/send";
interface PushMessage {
to: string;
title: string;
body: string;
data?: Record<string, unknown>;
sound?: "default" | null;
badge?: number;
}
export async function sendPushNotification(
userIds: string[],
notification: Omit<PushMessage, "to">
) {
const supabase = createClient(
Deno.env.get("PUBLIC_SUPABASE_URL")!,
Deno.env.get("SUPABASE_SERVICE_ROLE_KEY")!
);
const { data: tokens } = await supabase
.from("push_tokens")
.select("token")
.in("user_id", userIds);
if (!tokens?.length) return;
const messages: PushMessage[] = tokens.map(({ token }) => ({
to: token,
sound: "default",
...notification,
}));
// Expo accepts up to 100 messages per request
const chunks = chunk(messages, 100);
for (const batch of chunks) {
await fetch(EXPO_PUSH_URL, {
method: "POST",
headers: { "Content-Type": "application/json" },
body: JSON.stringify(batch),
});
}
}
function chunk<T>(arr: T[], size: number): T[][] {
return Array.from({ length: Math.ceil(arr.length / size) }, (_, i) =>
arr.slice(i * size, i * size + size)
);
}Required for iOS push notifications in production builds.
Expo Push, enable Apple Push Notifications service (APNs).p8 file — download once onlyUpload to Expo:
.p8 key, enter Key ID and Team IDOr via CLI:
eas credentials --platform ios
# Select: Push Notifications → Upload APNs keycom.yourorg.appname)google-services.json → place in mobile/google-services.jsonAdd to app.json:
{
"expo": {
"android": {
"googleServicesFile": "./google-services.json"
}
}
}Upload FCM key to Expo:
eas credentials --platform android
# Select: Push Notifications → Upload FCM keyimport { useEffect, useRef } from "react";
import * as Notifications from "expo-notifications";
import { router } from "expo-router";
export function useNotificationNavigation() {
const responseListener = useRef<Notifications.Subscription>();
useEffect(() => {
// App opened from notification
responseListener.current = Notifications.addNotificationResponseReceivedListener(
(response) => {
const data = response.notification.request.content.data;
if (data?.screen) {
router.push(data.screen as string);
}
}
);
return () => {
responseListener.current?.remove();
};
}, []);
}Pass data: { screen: "/orders/123" } when sending to deep-link on tap.
# Test with Expo CLI (dev build or Expo Go)
npx expo push:send --to "ExponentPushToken[xxx]" --title "Test" --body "Hello"
# Or use the Expo push tool
open https://expo.dev/notificationsPhysical device required for testing — simulator/emulator does not receive push notifications.
Notifications work in Expo Go but not in production build — APNs key not uploaded to Expo. Run eas credentials --platform ios and verify Push Notifications key is configured.
Android notifications not delivered — google-services.json missing or wrong package name. Verify package in app.json matches Firebase project.
Token is null on simulator — Expected. Push tokens only work on physical devices. Check with Device.isDevice.
"DeviceNotRegistered" error — Token is stale (user uninstalled/reinstalled app). Delete the token from push_tokens table when this error is returned by Expo Push API.
Notification not shown when app is in foreground — Set shouldShowAlert: true in setNotificationHandler. By default foreground notifications are silent.
iOS notification permission denied — You can only ask for permission once. If denied, user must go to Settings manually. Always explain why before requesting.
Badge count not clearing — Call Notifications.setBadgeCountAsync(0) on app foreground:
AppState.addEventListener("change", (state) => {
if (state === "active") Notifications.setBadgeCountAsync(0);
});~30 seconds. Free. No account. Every finding cites a rule and a line of evidence.