@atlaskit/editor-common
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@atlassian/react-compiler-gating | AI (phantom-deps): Same Atlassian org scope; declared but not directly imported — config-only reference, stable false positive for this package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): editor-common is a large, actively maintained Atlassian editor library that regularly adds new source files as features expand. 25 new files is consistent with normal development cadence for this package. | ai | |
| phantom-deps | phantom-dep:@atlaskit/code | AI (phantom-deps): Monorepo pattern: same-org scope dependency declared at workspace root but not directly imported in this entry point; stable for @atlaskit packages. | ai | |
| phantom-deps | phantom-dep:@sentry/browser | AI (phantom-deps): Config-file reference without direct import is expected in monorepo; stable pattern for this package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Atlassian monorepo package with 109 approved dependents and a trusted publisher account; dormancy gaps are plausible for large enterprise monorepos and no other risk signals are present. | ai | |
| dependencies | unvetted-dep:markdown-it | AI (dependencies): markdown-it is a widely-used, legitimate markdown parsing library. Its use in an Atlassian editor package is expected and benign. | ai | |
| dependencies | unvetted-dep:@popperjs/core | AI (dependencies): @popperjs/core is a well-known, widely-used positioning library. Its use in a UI editor package is expected and benign. | ai | |
| phantom-deps | phantom-dep:prop-types | AI (phantom-deps): prop-types referenced in config files only; standard pattern for React component libraries. Not a real risk for this package. | ai | |
| provenance | no-provenance | AI (provenance): Atlassian's atlassianartifactteam has 129 approved packages without provenance; this is a stable publishing pattern for this org. | ai | |
| phantom-deps | phantom-dep:@sentry/integrations | AI (phantom-deps): Referenced in config files only; standard observability tooling pattern, not a real risk. | ai | |
| phantom-deps | phantom-dep:@atlaskit/css | AI (phantom-deps): Same org scope (@atlaskit); phantom dep finding is benign for Atlassian's own monorepo packages. | ai |
Versions (showing 51 of 522)
| Version | Deps | Published |
|---|---|---|
| 116.42.0 | 84 / 22 | |
| 116.41.0 | 84 / 20 | |
| 116.40.2 | 84 / 20 | |
| 116.40.1 | 84 / 20 | |
| 116.40.0 | 84 / 20 | |
| 116.39.1 | 84 / 20 | |
| 116.39.0 | 84 / 20 | |
| 116.38.0 | 84 / 19 | |
| 116.37.0 | 84 / 19 | |
| 116.36.0 | 84 / 19 | |
| 116.35.3 | 84 / 19 | |
| 116.35.2 | 84 / 19 | |
| 116.35.1 | 84 / 19 | |
| 116.35.0 | 84 / 19 | |
| 116.34.0 | 84 / 19 | |
| 116.33.4 | 84 / 19 | |
| 116.33.3 | 84 / 19 | |
| 116.33.2 | 84 / 19 | |
| 116.33.1 | 84 / 19 | |
| 116.33.0 | 84 / 19 | |
| 116.32.4 | 84 / 19 | |
| 116.32.3 | 84 / 19 | |
| 116.32.2 | 84 / 19 | |
| 116.32.1 | 84 / 19 | |
| 116.32.0 | 84 / 19 | |
| 116.31.0 | 84 / 19 | |
| 116.30.4 | 84 / 19 | |
| 116.30.3 | 84 / 19 | |
| 116.30.2 | 84 / 19 | |
| 116.30.1 | 84 / 19 | |
| 116.30.0 | 84 / 19 | |
| 116.29.0 | 84 / 19 | |
| 116.28.1 | 84 / 19 | |
| 116.28.0 | 84 / 19 | |
| 116.27.1 | 84 / 19 | |
| 116.27.0 | 84 / 19 | |
| 116.26.3 | 84 / 19 | |
| 116.26.2 | 84 / 19 | |
| 116.26.1 | 84 / 19 | |
| 116.26.0 | 84 / 19 | |
| 116.25.2 | 84 / 19 | |
| 116.25.1 | 84 / 19 | |
| 116.25.0 | 84 / 19 | |
| 116.24.5 | 84 / 19 | |
| 116.24.4 | 84 / 19 | |
| 116.24.3 | 84 / 19 | |
| 116.24.2 | 84 / 19 | |
| 116.24.1 | 84 / 19 | |
| 116.24.0 | 84 / 19 | |
| 116.23.2 | 84 / 19 | |
| 116.23.1 | 84 / 19 |
v116.42.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.41.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.40.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.40.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.40.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.39.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.39.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.38.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.37.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.36.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.35.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.35.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.35.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.35.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.34.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.33.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.33.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.33.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.33.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.33.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.32.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.32.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.32.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.32.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.32.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.31.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.30.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.30.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.30.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.30.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.30.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.29.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.28.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.28.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.27.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.27.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.26.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.26.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.26.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.26.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.25.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.25.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.25.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.24.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.24.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.24.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.24.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.24.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.24.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.23.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.23.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.