@atlaskit/editor-common
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:@atlassian/react-compiler-gating | AI (phantom-deps): Same Atlassian org scope; declared but not directly imported — config-only reference, stable false positive for this package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): editor-common is a large, actively maintained Atlassian editor library that regularly adds new source files as features expand. 25 new files is consistent with normal development cadence for this package. | ai | |
| phantom-deps | phantom-dep:@atlaskit/code | AI (phantom-deps): Monorepo pattern: same-org scope dependency declared at workspace root but not directly imported in this entry point; stable for @atlaskit packages. | ai | |
| phantom-deps | phantom-dep:@sentry/browser | AI (phantom-deps): Config-file reference without direct import is expected in monorepo; stable pattern for this package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Atlassian monorepo package with 109 approved dependents and a trusted publisher account; dormancy gaps are plausible for large enterprise monorepos and no other risk signals are present. | ai | |
| dependencies | unvetted-dep:markdown-it | AI (dependencies): markdown-it is a widely-used, legitimate markdown parsing library. Its use in an Atlassian editor package is expected and benign. | ai | |
| dependencies | unvetted-dep:@popperjs/core | AI (dependencies): @popperjs/core is a well-known, widely-used positioning library. Its use in a UI editor package is expected and benign. | ai | |
| phantom-deps | phantom-dep:prop-types | AI (phantom-deps): prop-types referenced in config files only; standard pattern for React component libraries. Not a real risk for this package. | ai | |
| provenance | no-provenance | AI (provenance): Atlassian's atlassianartifactteam has 129 approved packages without provenance; this is a stable publishing pattern for this org. | ai | |
| phantom-deps | phantom-dep:@sentry/integrations | AI (phantom-deps): Referenced in config files only; standard observability tooling pattern, not a real risk. | ai | |
| phantom-deps | phantom-dep:@atlaskit/css | AI (phantom-deps): Same org scope (@atlaskit); phantom dep finding is benign for Atlassian's own monorepo packages. | ai |
Versions (showing 100 of 522)
| Version | Deps | Published |
|---|---|---|
| 115.15.3 | 83 / 18 | |
| 115.15.2 | 83 / 18 | |
| 115.15.1 | 83 / 18 | |
| 115.15.0 | 83 / 18 | |
| 115.14.0 | 83 / 18 | |
| 115.13.0 | 83 / 18 | |
| 115.12.0 | 83 / 18 | |
| 115.10.2 | 83 / 18 | |
| 115.10.1 | 83 / 18 | |
| 115.10.0 | 83 / 18 | |
| 115.9.0 | 83 / 18 | |
| 115.8.2 | 83 / 18 | |
| 115.8.1 | 83 / 18 | |
| 115.8.0 | 83 / 18 | |
| 115.7.5 | 83 / 18 | |
| 115.7.4 | 83 / 18 | |
| 115.7.3 | 83 / 18 | |
| 115.7.2 | 83 / 18 | |
| 115.7.1 | 83 / 18 | |
| 115.7.0 | 83 / 18 | |
| 115.6.0 | 83 / 18 | |
| 115.5.1 | 83 / 18 | |
| 115.5.0 | 83 / 18 | |
| 115.4.0 | 83 / 18 | |
| 115.3.0 | 83 / 18 | |
| 115.2.2 | 83 / 18 | |
| 115.2.1 | 83 / 18 | |
| 115.2.0 | 83 / 18 | |
| 115.1.0 | 83 / 18 | |
| 115.0.3 | 83 / 18 | |
| 115.0.2 | 83 / 18 | |
| 115.0.1 | 83 / 18 | |
| 115.0.0 | 83 / 18 | |
| 114.55.0 | 83 / 18 | |
| 114.54.2 | 83 / 18 | |
| 114.54.1 | 83 / 18 | |
| 114.54.0 | 83 / 18 | |
| 114.53.0 | 83 / 18 | |
| 114.52.0 | 83 / 18 | |
| 114.51.1 | 83 / 18 | |
| 114.51.0 | 83 / 18 | |
| 114.50.3 | 83 / 18 | |
| 114.50.2 | 83 / 18 | |
| 114.50.1 | 83 / 18 | |
| 114.50.0 | 83 / 18 | |
| 114.49.0 | 83 / 18 | |
| 114.48.1 | 83 / 18 | |
| 114.48.0 | 83 / 18 | |
| 114.47.3 | 83 / 18 | |
| 114.47.2 | 83 / 18 | |
| 114.47.1 | 83 / 18 | |
| 114.47.0 | 83 / 18 | |
| 114.46.0 | 83 / 18 | |
| 114.45.0 | 83 / 18 | |
| 114.44.0 | 83 / 18 | |
| 114.43.0 | 83 / 18 | |
| 114.42.0 | 83 / 18 | |
| 114.41.0 | 83 / 18 | |
| 114.40.0 | 83 / 17 | |
| 114.39.0 | 83 / 17 | |
| 114.38.0 | 83 / 17 | |
| 114.37.0 | 83 / 17 | |
| 114.36.2 | 83 / 17 | |
| 114.36.1 | 83 / 17 | |
| 114.36.0 | 83 / 17 | |
| 114.35.0 | 83 / 17 | |
| 114.34.0 | 83 / 17 | |
| 114.33.2 | 83 / 17 | |
| 114.33.1 | 83 / 17 | |
| 114.33.0 | 83 / 17 | |
| 114.32.4 | 83 / 17 | |
| 114.32.3 | 83 / 17 | |
| 114.32.2 | 83 / 17 | |
| 114.32.1 | 83 / 17 | |
| 114.32.0 | 83 / 17 | |
| 114.31.0 | 83 / 17 | |
| 114.30.6 | 83 / 17 | |
| 114.30.5 | 82 / 17 | |
| 114.30.4 | 82 / 17 | |
| 114.30.3 | 82 / 17 | |
| 114.30.2 | 82 / 17 | |
| 114.30.1 | 82 / 17 | |
| 114.30.0 | 82 / 17 | |
| 114.29.0 | 82 / 17 | |
| 114.28.0 | 82 / 17 | |
| 114.27.0 | 82 / 17 | |
| 114.26.1 | 82 / 17 | |
| 114.26.0 | 82 / 17 | |
| 114.25.2 | 82 / 17 | |
| 114.25.1 | 82 / 17 | |
| 114.25.0 | 82 / 17 | |
| 114.24.0 | 82 / 17 | |
| 114.23.0 | 82 / 17 | |
| 114.22.1 | 82 / 17 | |
| 114.22.0 | 82 / 17 | |
| 114.21.0 | 82 / 17 | |
| 114.20.1 | 82 / 17 | |
| 114.20.0 | 82 / 17 | |
| 114.19.2 | 82 / 17 | |
| 114.19.1 | 82 / 17 |
v114.43.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.42.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.41.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.40.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.39.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.38.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.37.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.36.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.36.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.36.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.35.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.34.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.33.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.33.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.32.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.32.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.32.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.32.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.32.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.31.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.30.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.30.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.30.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.30.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.30.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.30.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.30.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.29.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.28.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.27.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.26.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.26.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.25.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.25.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.25.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.24.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.23.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.22.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.22.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.21.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.20.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.20.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.19.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v114.19.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.