@atlaskit/editor-common
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@atlassian/react-compiler-gating | AI (phantom-deps): Same Atlassian org scope; declared but not directly imported — config-only reference, stable false positive for this package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): editor-common is a large, actively maintained Atlassian editor library that regularly adds new source files as features expand. 25 new files is consistent with normal development cadence for this package. | ai | |
| phantom-deps | phantom-dep:@atlaskit/code | AI (phantom-deps): Monorepo pattern: same-org scope dependency declared at workspace root but not directly imported in this entry point; stable for @atlaskit packages. | ai | |
| phantom-deps | phantom-dep:@sentry/browser | AI (phantom-deps): Config-file reference without direct import is expected in monorepo; stable pattern for this package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Atlassian monorepo package with 109 approved dependents and a trusted publisher account; dormancy gaps are plausible for large enterprise monorepos and no other risk signals are present. | ai | |
| dependencies | unvetted-dep:markdown-it | AI (dependencies): markdown-it is a widely-used, legitimate markdown parsing library. Its use in an Atlassian editor package is expected and benign. | ai | |
| dependencies | unvetted-dep:@popperjs/core | AI (dependencies): @popperjs/core is a well-known, widely-used positioning library. Its use in a UI editor package is expected and benign. | ai | |
| phantom-deps | phantom-dep:prop-types | AI (phantom-deps): prop-types referenced in config files only; standard pattern for React component libraries. Not a real risk for this package. | ai | |
| provenance | no-provenance | AI (provenance): Atlassian's atlassianartifactteam has 129 approved packages without provenance; this is a stable publishing pattern for this org. | ai | |
| phantom-deps | phantom-dep:@sentry/integrations | AI (phantom-deps): Referenced in config files only; standard observability tooling pattern, not a real risk. | ai | |
| phantom-deps | phantom-dep:@atlaskit/css | AI (phantom-deps): Same org scope (@atlaskit); phantom dep finding is benign for Atlassian's own monorepo packages. | ai |
Versions (showing 100 of 523)
| Version | Deps | Published |
|---|---|---|
| 114.19.0 | 82 / 17 | |
| 114.18.3 | 82 / 17 | |
| 114.18.2 | 82 / 17 | |
| 114.18.1 | 82 / 17 | |
| 114.18.0 | 82 / 17 | |
| 114.17.0 | 82 / 17 | |
| 114.16.0 | 82 / 17 | |
| 114.15.0 | 82 / 17 | |
| 114.14.0 | 82 / 17 | |
| 114.13.3 | 82 / 17 | |
| 114.13.2 | 82 / 17 | |
| 114.13.1 | 82 / 17 | |
| 114.13.0 | 82 / 17 | |
| 114.12.3 | 82 / 17 | |
| 114.12.2 | 82 / 17 | |
| 114.12.1 | 82 / 17 | |
| 114.12.0 | 82 / 17 | |
| 114.11.1 | 82 / 17 | |
| 114.10.1 | 82 / 17 | |
| 114.10.0 | 82 / 17 | |
| 114.9.0 | 82 / 17 | |
| 114.8.1 | 82 / 17 | |
| 114.8.0 | 82 / 17 | |
| 114.1.1 | 82 / 16 | |
| 113.0.0 | 82 / 15 | |
| 112.19.1 | 82 / 15 | |
| 112.19.0 | 82 / 15 | |
| 112.18.5 | 82 / 15 | |
| 112.18.0 | 82 / 15 | |
| 112.16.0 | 83 / 15 | |
| 112.14.0 | 83 / 15 | |
| 112.13.8 | 83 / 15 | |
| 112.13.7 | 83 / 15 | |
| 112.13.5 | 83 / 15 | |
| 112.13.4 | 83 / 15 | |
| 112.13.3 | 84 / 15 | |
| 112.13.2 | 84 / 15 | |
| 112.13.1 | 84 / 15 | |
| 112.13.0 | 84 / 15 | |
| 112.12.1 | 84 / 15 | |
| 112.12.0 | 84 / 15 | |
| 112.11.3 | 84 / 15 | |
| 112.11.2 | 84 / 15 | |
| 112.11.1 | 84 / 15 | |
| 112.11.0 | 84 / 15 | |
| 112.10.1 | 84 / 15 | |
| 112.10.0 | 84 / 15 | |
| 112.9.1 | 84 / 15 | |
| 112.9.0 | 84 / 15 | |
| 112.8.4 | 84 / 15 | |
| 112.8.3 | 84 / 15 | |
| 112.8.2 | 84 / 15 | |
| 112.8.1 | 84 / 15 | |
| 112.8.0 | 84 / 15 | |
| 112.7.5 | 84 / 15 | |
| 112.7.4 | 85 / 15 | |
| 112.7.3 | 85 / 15 | |
| 112.7.2 | 85 / 15 | |
| 112.7.1 | 85 / 15 | |
| 112.7.0 | 85 / 15 | |
| 112.6.1 | 85 / 15 | |
| 112.6.0 | 85 / 15 | |
| 112.5.2 | 85 / 15 | |
| 112.5.1 | 85 / 15 | |
| 112.5.0 | 85 / 15 | |
| 112.4.4 | 85 / 15 | |
| 112.4.3 | 85 / 15 | |
| 112.4.2 | 85 / 15 | |
| 112.4.1 | 85 / 15 | |
| 112.4.0 | 85 / 15 | |
| 112.3.2 | 85 / 15 | |
| 112.3.1 | 85 / 15 | |
| 112.3.0 | 85 / 15 | |
| 112.2.3 | 85 / 15 | |
| 112.2.2 | 85 / 15 | |
| 112.2.1 | 85 / 15 | |
| 112.2.0 | 85 / 15 | |
| 112.1.0 | 85 / 15 | |
| 112.0.1 | 85 / 15 | |
| 112.0.0 | 85 / 15 | |
| 111.35.1 | 85 / 15 | |
| 111.35.0 | 85 / 15 | |
| 111.34.1 | 85 / 15 | |
| 111.34.0 | 85 / 15 | |
| 111.33.0 | 85 / 15 | |
| 111.32.1 | 85 / 15 | |
| 111.32.0 | 85 / 15 | |
| 111.31.0 | 85 / 15 | |
| 111.30.3 | 85 / 15 | |
| 111.30.2 | 85 / 15 | |
| 111.30.1 | 85 / 15 | |
| 111.30.0 | 85 / 15 | |
| 111.29.1 | 85 / 15 | |
| 111.29.0 | 85 / 15 | |
| 111.28.4 | 85 / 15 | |
| 111.28.3 | 85 / 15 | |
| 111.28.2 | 85 / 15 | |
| 111.28.1 | 85 / 15 | |
| 111.28.0 | 85 / 15 | |
| 111.27.0 | 85 / 15 |
v114.19.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.18.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.18.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.18.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.18.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.17.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.16.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.15.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.14.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.13.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.13.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.12.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.12.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.12.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.12.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.11.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.10.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.8.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.8.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.18.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.16.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.8.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.8.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.7.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.7.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.7.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.7.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.7.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.7.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.6.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.6.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.5.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.5.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.4.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.4.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.4.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.4.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.3.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.2.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.2.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.2.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.2.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.1.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.0.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v112.0.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v111.35.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v111.35.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v111.34.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v111.34.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v111.33.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v111.32.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v111.32.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v111.31.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v111.30.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v111.30.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v111.30.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v111.30.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v111.29.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v111.29.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v111.28.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v111.28.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v111.28.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v111.28.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v111.28.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v111.27.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.