@atlaskit/editor-common
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@atlassian/react-compiler-gating | AI (phantom-deps): Same Atlassian org scope; declared but not directly imported — config-only reference, stable false positive for this package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): editor-common is a large, actively maintained Atlassian editor library that regularly adds new source files as features expand. 25 new files is consistent with normal development cadence for this package. | ai | |
| phantom-deps | phantom-dep:@atlaskit/code | AI (phantom-deps): Monorepo pattern: same-org scope dependency declared at workspace root but not directly imported in this entry point; stable for @atlaskit packages. | ai | |
| phantom-deps | phantom-dep:@sentry/browser | AI (phantom-deps): Config-file reference without direct import is expected in monorepo; stable pattern for this package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Atlassian monorepo package with 109 approved dependents and a trusted publisher account; dormancy gaps are plausible for large enterprise monorepos and no other risk signals are present. | ai | |
| dependencies | unvetted-dep:markdown-it | AI (dependencies): markdown-it is a widely-used, legitimate markdown parsing library. Its use in an Atlassian editor package is expected and benign. | ai | |
| dependencies | unvetted-dep:@popperjs/core | AI (dependencies): @popperjs/core is a well-known, widely-used positioning library. Its use in a UI editor package is expected and benign. | ai | |
| phantom-deps | phantom-dep:prop-types | AI (phantom-deps): prop-types referenced in config files only; standard pattern for React component libraries. Not a real risk for this package. | ai | |
| provenance | no-provenance | AI (provenance): Atlassian's atlassianartifactteam has 129 approved packages without provenance; this is a stable publishing pattern for this org. | ai | |
| phantom-deps | phantom-dep:@sentry/integrations | AI (phantom-deps): Referenced in config files only; standard observability tooling pattern, not a real risk. | ai | |
| phantom-deps | phantom-dep:@atlaskit/css | AI (phantom-deps): Same org scope (@atlaskit); phantom dep finding is benign for Atlassian's own monorepo packages. | ai |
Versions (showing 100 of 522)
| Version | Deps | Published |
|---|---|---|
| 116.42.0 | 84 / 22 | |
| 116.41.0 | 84 / 20 | |
| 116.40.2 | 84 / 20 | |
| 116.40.1 | 84 / 20 | |
| 116.40.0 | 84 / 20 | |
| 116.39.1 | 84 / 20 | |
| 116.39.0 | 84 / 20 | |
| 116.38.0 | 84 / 19 | |
| 116.37.0 | 84 / 19 | |
| 116.36.0 | 84 / 19 | |
| 116.35.3 | 84 / 19 | |
| 116.35.2 | 84 / 19 | |
| 116.35.1 | 84 / 19 | |
| 116.35.0 | 84 / 19 | |
| 116.34.0 | 84 / 19 | |
| 116.33.4 | 84 / 19 | |
| 116.33.3 | 84 / 19 | |
| 116.33.2 | 84 / 19 | |
| 116.33.1 | 84 / 19 | |
| 116.33.0 | 84 / 19 | |
| 116.32.4 | 84 / 19 | |
| 116.32.3 | 84 / 19 | |
| 116.32.2 | 84 / 19 | |
| 116.32.1 | 84 / 19 | |
| 116.32.0 | 84 / 19 | |
| 116.31.0 | 84 / 19 | |
| 116.30.4 | 84 / 19 | |
| 116.30.3 | 84 / 19 | |
| 116.30.2 | 84 / 19 | |
| 116.30.1 | 84 / 19 | |
| 116.30.0 | 84 / 19 | |
| 116.29.0 | 84 / 19 | |
| 116.28.1 | 84 / 19 | |
| 116.28.0 | 84 / 19 | |
| 116.27.1 | 84 / 19 | |
| 116.27.0 | 84 / 19 | |
| 116.26.3 | 84 / 19 | |
| 116.26.2 | 84 / 19 | |
| 116.26.1 | 84 / 19 | |
| 116.26.0 | 84 / 19 | |
| 116.25.2 | 84 / 19 | |
| 116.25.1 | 84 / 19 | |
| 116.25.0 | 84 / 19 | |
| 116.24.5 | 84 / 19 | |
| 116.24.4 | 84 / 19 | |
| 116.24.3 | 84 / 19 | |
| 116.24.2 | 84 / 19 | |
| 116.24.1 | 84 / 19 | |
| 116.24.0 | 84 / 19 | |
| 116.23.2 | 84 / 19 | |
| 116.23.1 | 84 / 19 | |
| 116.23.0 | 84 / 19 | |
| 116.22.2 | 84 / 19 | |
| 116.22.1 | 84 / 19 | |
| 116.22.0 | 84 / 19 | |
| 116.21.1 | 84 / 19 | |
| 116.21.0 | 84 / 19 | |
| 116.20.1 | 84 / 17 | |
| 116.20.0 | 84 / 17 | |
| 116.19.5 | 84 / 17 | |
| 116.19.4 | 84 / 17 | |
| 116.19.3 | 84 / 17 | |
| 116.19.2 | 84 / 17 | |
| 116.19.1 | 84 / 17 | |
| 116.19.0 | 84 / 17 | |
| 116.18.1 | 84 / 17 | |
| 116.18.0 | 84 / 17 | |
| 116.17.4 | 84 / 17 | |
| 116.17.3 | 84 / 17 | |
| 116.17.2 | 84 / 17 | |
| 116.17.1 | 84 / 17 | |
| 116.17.0 | 84 / 17 | |
| 116.16.0 | 84 / 17 | |
| 116.15.0 | 84 / 17 | |
| 116.14.1 | 84 / 17 | |
| 116.14.0 | 84 / 17 | |
| 116.13.1 | 84 / 17 | |
| 116.13.0 | 84 / 17 | |
| 116.11.0 | 84 / 17 | |
| 116.10.1 | 83 / 18 | |
| 116.10.0 | 83 / 18 | |
| 116.9.1 | 83 / 18 | |
| 116.9.0 | 83 / 18 | |
| 116.8.0 | 83 / 18 | |
| 116.7.0 | 83 / 18 | |
| 116.6.1 | 83 / 18 | |
| 116.6.0 | 83 / 18 | |
| 116.5.0 | 83 / 18 | |
| 116.4.1 | 83 / 18 | |
| 116.4.0 | 83 / 18 | |
| 116.3.2 | 83 / 18 | |
| 116.3.1 | 83 / 18 | |
| 116.2.2 | 83 / 18 | |
| 116.2.1 | 83 / 18 | |
| 116.2.0 | 83 / 18 | |
| 116.1.0 | 83 / 18 | |
| 116.0.0 | 83 / 18 | |
| 115.16.1 | 83 / 18 | |
| 115.16.0 | 83 / 18 | |
| 115.15.4 | 83 / 18 |
v116.42.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.41.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.40.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.40.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.40.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.39.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.39.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.38.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.37.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.36.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.35.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.35.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.35.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.35.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.34.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.33.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.33.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.33.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.33.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.33.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.32.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.32.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.32.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.32.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.32.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.31.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.30.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.30.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.30.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.30.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.30.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.29.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.28.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.28.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.27.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.27.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.26.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.26.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.26.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.26.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.25.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.25.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.25.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.24.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.24.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.24.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.24.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.24.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.24.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.23.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.23.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.23.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.22.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.22.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.22.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.21.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.21.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.20.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.20.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.19.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.19.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.19.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.19.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.19.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.19.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.18.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.18.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.17.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.17.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.17.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.17.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.17.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v116.16.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.