@ckeditor/ckeditor5-ai
AI features for CKEditor 5.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:build/ai.js | AI (source-diff): CKSource intentionally obfuscates proprietary AI source; declared obfuscated:true in package.json. | ai | |
| provenance | no-provenance | AI (provenance): Consistent with prior approved versions; not a risk signal. | ai | |
| source-diff | obfuscated-file:src/aiactions/aiactions.js | AI (source-diff): CKSource proprietary obfuscation with legal banner; intentional across all versions. | ai | |
| phantom-deps | phantom-dep:morphdom | AI (phantom-deps): Declared dependency used indirectly in this modular CKEditor package; not a phantom in the malicious sense. | ai | |
| phantom-deps | phantom-dep:es-toolkit | AI (phantom-deps): Declared dependency used indirectly in this modular CKEditor package; not a phantom in the malicious sense. | ai | |
| phantom-deps | phantom-dep:htmlparser2 | AI (phantom-deps): Declared dependency used indirectly in this modular CKEditor package; not a phantom in the malicious sense. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-ui | AI (phantom-deps): Same-org @ckeditor scoped package declared as dependency; indirect usage is expected in modular CKEditor architecture. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-core | AI (phantom-deps): Same-org @ckeditor scoped package declared as dependency; indirect usage is expected in modular CKEditor architecture. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-icons | AI (phantom-deps): Same-org @ckeditor scoped package declared as dependency; indirect usage is expected in modular CKEditor architecture. | ai | |
| semgrep | semgrep:obfuscation-while-true | AI (semgrep): CKSource intentionally obfuscates commercial AI plugin code; package.json declares 'obfuscated: true'. This is a stable characteristic of this package, not malicious. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-engine | AI (phantom-deps): Same-org @ckeditor scoped package declared as dependency; indirect usage is expected in modular CKEditor architecture. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-clipboard | AI (phantom-deps): Same-org @ckeditor scoped package declared as dependency; indirect usage is expected in modular CKEditor architecture. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-theme-lark | AI (phantom-deps): Same-org @ckeditor scoped package declared as dependency; indirect usage is expected in modular CKEditor architecture. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-markdown-gfm | AI (phantom-deps): Same-org @ckeditor scoped package declared as dependency; indirect usage is expected in modular CKEditor architecture. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-cloud-services | AI (phantom-deps): Same-org @ckeditor scoped package declared as dependency; indirect usage is expected in modular CKEditor architecture. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-real-time-collaboration | AI (phantom-deps): Same-org @ckeditor scoped package declared as dependency; indirect usage is expected in modular CKEditor architecture. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-table | AI (phantom-deps): Same-org @ckeditor scoped package declared as dependency; indirect usage is expected in modular CKEditor architecture. | ai | |
| semgrep | semgrep:obfuscation-hex-functions | AI (semgrep): CKSource intentionally obfuscates commercial AI plugin code; package.json declares 'obfuscated: true'. Hex-prefixed names are expected javascript-obfuscator output for this package. | ai | |
| phantom-deps | phantom-dep:diff | AI (phantom-deps): Declared dependency used indirectly in this modular CKEditor package; not a phantom in the malicious sense. | ai |
Versions (showing 16 of 16)
| Version | Deps | Published |
|---|---|---|
| 48.3.1 | 20 / 0 | |
| 48.3.0 | 20 / 0 | |
| 48.2.0 | 20 / 0 | |
| 48.1.1 | 20 / 0 | |
| 48.1.0 | 20 / 0 | |
| 48.0.1 | 20 / 0 | |
| 48.0.0 | 20 / 0 | |
| 47.7.3 | 22 / 0 | |
| 47.7.2 | 22 / 0 | |
| 47.7.1 | 22 / 0 | |
| 47.7.0 | 22 / 0 | |
| 47.6.1 | 23 / 0 | |
| 47.6.0 | 23 / 0 | |
| 47.5.0 | 23 / 0 | |
| 47.4.0 | 23 / 0 | |
| 47.2.0 | 23 / 0 |
v48.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v48.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v47.7.3
37 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.