← Home

@atlaskit/editor-plugin-code-block-advanced

CodeBlockAdvanced plugin for @atlaskit/editor-core

51
Versions
Apache-2.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

atlassianartifactteam

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@atlaskit/editor-plugin-selection-marker AI (dependencies): First-party Atlassian @atlaskit scoped package; legitimate dependency for this Atlassian editor plugin. ai
dependencies unvetted-dep:@atlaskit/platform-feature-flags AI (dependencies): First-party Atlassian @atlaskit scoped package; legitimate dependency for this Atlassian editor plugin. ai
dependencies unvetted-dep:@atlaskit/editor-plugin-selection AI (dependencies): First-party Atlassian @atlaskit scoped package; legitimate dependency for this Atlassian editor plugin. ai
dependencies unvetted-dep:@atlaskit/editor-plugin-code-block AI (dependencies): First-party Atlassian @atlaskit scoped package; legitimate dependency for this Atlassian editor plugin. ai
dependencies unvetted-dep:@atlaskit/editor-plugin-find-replace AI (dependencies): First-party Atlassian @atlaskit scoped package; legitimate dependency for this Atlassian editor plugin. ai
dependencies unvetted-dep:@atlaskit/editor-plugin-editor-disabled AI (dependencies): First-party Atlassian @atlaskit scoped package; legitimate dependency for this Atlassian editor plugin. ai
dependencies unvetted-dep:@atlaskit/code AI (dependencies): First-party Atlassian @atlaskit scoped package; legitimate dependency for this Atlassian editor plugin. ai
dependencies unvetted-dep:@atlaskit/tokens AI (dependencies): First-party Atlassian @atlaskit scoped package; legitimate dependency for this Atlassian editor plugin. ai
dependencies unvetted-dep:@atlaskit/adf-schema AI (dependencies): First-party Atlassian @atlaskit scoped package; legitimate dependency for this Atlassian editor plugin. ai
dependencies unvetted-dep:codemirror-lang-elixir AI (dependencies): Legitimate CodeMirror 6 language extension for Elixir syntax highlighting; expected for an advanced code block editor plugin. ai
dependencies unvetted-dep:@codemirror/language-data AI (dependencies): Official @codemirror scoped package from the CodeMirror 6 project; well-known editor framework dependency. ai
dependencies unvetted-dep:@atlaskit/editor-prosemirror AI (dependencies): First-party Atlassian @atlaskit scoped package; legitimate dependency for this Atlassian editor plugin. ai
dependencies unvetted-dep:@atlaskit/tmp-editor-statsig AI (dependencies): First-party Atlassian @atlaskit scoped package; legitimate dependency for this Atlassian editor plugin. ai
dependencies unvetted-dep:@atlaskit/prosemirror-history AI (dependencies): First-party Atlassian @atlaskit scoped package; legitimate dependency for this Atlassian editor plugin. ai
phantom-deps phantom-dep:codemirror-lang-elixir AI (phantom-deps): Language plugin referenced in config for dynamic loading; not a security concern for this editor plugin package. ai
phantom-deps phantom-dep:@codemirror/lang-markdown AI (phantom-deps): Language plugin referenced in config for dynamic loading; not a security concern for this editor plugin package. ai
phantom-deps phantom-dep:@xiechao/codemirror-lang-handlebars AI (phantom-deps): Language plugin referenced in config for dynamic loading; not a security concern for this editor plugin package. ai
provenance no-provenance AI (provenance): Atlassian publishes via atlassianartifactteam with consistent track record; lack of Sigstore provenance is common and not a risk signal here. ai
phantom-deps phantom-dep:cm6-graphql AI (phantom-deps): Language plugin referenced in config for dynamic loading; not a security concern for this editor plugin package. ai

Versions (showing 51 of 108)

View all versions
Version Deps Published
11.0.1 25 / 2
11.0.0 25 / 2
10.1.9 25 / 2
10.1.8 25 / 2
10.1.7 25 / 2
10.1.6 25 / 2
10.1.5 25 / 2
10.1.4 25 / 1
10.1.3 25 / 1
10.1.2 25 / 1
10.1.1 25 / 1
10.1.0 25 / 1
10.0.20 25 / 1
10.0.19 25 / 1
10.0.18 25 / 1
10.0.17 25 / 1
10.0.16 25 / 1
10.0.15 25 / 1
10.0.14 25 / 1
10.0.13 25 / 1
10.0.12 25 / 1
10.0.11 25 / 1
10.0.10 25 / 1
10.0.9 25 / 1
10.0.8 25 / 1
10.0.7 25 / 1
10.0.6 25 / 1
10.0.5 25 / 1
10.0.4 25 / 1
10.0.3 25 / 1
10.0.2 25 / 1
10.0.1 25 / 1
10.0.0 25 / 1
9.0.0 25 / 0
8.0.31 25 / 0
8.0.30 25 / 0
8.0.29 25 / 0
8.0.28 25 / 0
8.0.27 25 / 0
8.0.26 25 / 0
8.0.25 25 / 0
8.0.24 25 / 0
8.0.23 25 / 0
8.0.22 25 / 0
8.0.21 25 / 0
8.0.20 25 / 0
8.0.19 25 / 0
8.0.18 25 / 0
8.0.17 25 / 0
8.0.16 25 / 0
8.0.15 25 / 0

v11.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v11.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.9

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.7

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.1.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.20

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.19

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.18

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.17

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.16

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.14

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.13

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.12

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.11

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.10

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.8

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.0.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v10.0.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v10.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v9.0.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.31

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.30

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.29

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.28

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.27

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.26

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.25

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.24

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.23

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.22

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.21

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.20

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.19

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.18

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.17

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.16

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v8.0.15

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.