← Home

@blocknote/xl-ai

9
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

yousefedmatthewlipskinperez0111

Keywords

aillmreactjavascripteditortypescriptprosemirrorwysiwygrich-text-editornotionyjsblock-basedtiptap

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:unified AI (phantom-deps): Monorepo package; unified is a runtime dep used in bundled output, not directly imported at source level. ai
phantom-deps phantom-dep:react-dom AI (phantom-deps): Declared as peer dep and runtime dep; phantom-dep heuristic fires incorrectly for peer deps in monorepos. ai
phantom-deps phantom-dep:@tiptap/core AI (phantom-deps): Transitive/bundled usage in a ProseMirror/Tiptap-based editor; stable false positive for this package. ai
phantom-deps phantom-dep:remark-parse AI (phantom-deps): Runtime dep used in bundled output; phantom-dep heuristic misfires for this package. ai
phantom-deps phantom-dep:remark-stringify AI (phantom-deps): Runtime dep used in bundled output; phantom-dep heuristic misfires for this package. ai
phantom-deps phantom-dep:@blocknote/mantine AI (phantom-deps): Same-org sibling package; phantom-dep heuristic is a known false positive for monorepo cross-package deps. ai

Versions (showing 9 of 9)

Version Deps Published
0.51.4 21 / 30
0.51.3 21 / 30
0.51.2 21 / 30
0.51.1 21 / 30
0.51.0 21 / 30
0.50.0 24 / 29
0.49.0 24 / 29
0.48.1 24 / 29
0.48.0 24 / 29

v0.51.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.51.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.51.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.51.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.51.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.50.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.49.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.48.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.