← Home

@ckeditor/ckeditor5-collaboration-core

Base utilities used by CKEditor 5 collaboration features to support multiple users working together in a rich text editor.

18
Versions
SEE LICENSE IN LICENSE.md
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

ckeditor

Keywords

CKEditorckeditor5ckeditor 5WYSIWYGWYSIWYWtextrich-textrichtexteditoreditinghtmloperational transformationotcollaborationcollaborativereal-timerealtimereal timeframework

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): Same-org deps added; version diff is non-adjacent so deps appear new but are expected. ai
source-diff obfuscated-file:src/utils/confirmmixin.js AI (source-diff): CKEditor proprietary obfuscation; stable pattern across all versions of this package. ai
source-diff obfuscated-file:src/utils/trim-html.js AI (source-diff): CKEditor proprietary obfuscated source; standard practice for this commercial package. ai
source-diff obfuscated-file:src/users.js AI (source-diff): CKEditor proprietary code; package declares obfuscated:true; standard copyright header; imports only CKEditor modules. ai
source-diff obfuscated-file:src/suggestions/suggestionsconversion.js AI (source-diff): CKEditor proprietary code; package declares obfuscated:true; standard copyright header; imports only CKEditor modules. ai
source-diff obfuscated-file:src/suggestions/integrations/shiftenter.js AI (source-diff): CKEditor proprietary code; package declares obfuscated:true; standard copyright header; imports only CKEditor modules. ai
source-diff obfuscated-file:src/utils/setupthreadkeyboardnavigation.js AI (source-diff): CKEditor proprietary code; package declares obfuscated:true; standard copyright header; imports only CKEditor modules. ai
source-diff obfuscated-file:src/utils/sanitizeEditorConfig.js AI (source-diff): CKEditor proprietary code; package declares obfuscated:true; standard copyright header; imports only CKEditor modules. ai
source-diff obfuscated-file:src/permissions.js AI (source-diff): CKEditor proprietary code; package declares obfuscated:true; standard copyright header; imports only CKEditor modules. ai
source-diff obfuscated-file:src/utils/confirmview.js AI (source-diff): CKEditor proprietary code; package declares obfuscated:true; standard copyright header; imports only CKEditor modules. ai
source-diff obfuscated-file:src/documentcompare.js AI (source-diff): CKEditor proprietary code; package declares obfuscated:true; standard copyright header; imports only CKEditor modules. ai
source-diff large-new-source-files AI (source-diff): CKEditor collaboration-core ships many obfuscated source files as part of its proprietary distribution; count is normal. ai
source-diff obfuscated-file:src/users/view/userview.js AI (source-diff): CKEditor proprietary code; package declares obfuscated:true; standard copyright header; imports only CKEditor modules. ai
semgrep semgrep:obfuscation-hex-functions AI (semgrep): CKEditor deliberately obfuscates commercial collaboration plugins (package.json declares "obfuscated": true). Legitimate IP protection, not malware. ai
semgrep semgrep:obfuscation-while-true AI (semgrep): CKEditor deliberately obfuscates commercial collaboration plugins (package.json declares "obfuscated": true). Legitimate IP protection, not malware. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-ui AI (phantom-deps): Same-org CKEditor monorepo dependency; indirect/peer import pattern is standard for this ecosystem. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-core AI (phantom-deps): Same-org CKEditor monorepo dependency; indirect/peer import pattern is standard for this ecosystem. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-engine AI (phantom-deps): Same-org CKEditor monorepo dependency; indirect/peer import pattern is standard for this ecosystem. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-theme-lark AI (phantom-deps): Same-org CKEditor monorepo dependency; theme package loaded by convention. ai
provenance no-provenance AI (provenance): Lack of Sigstore provenance is common (~88% of npm packages); not a disqualifier for established packages with strong ecosystem signals. ai
license uncommon-license:SEE LICENSE IN LICENSE.md AI (license): CKEditor's proprietary collaboration features use custom licensing; external LICENSE.md reference is standard for this org. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-link AI (dependencies): Sibling @ckeditor org package released in lockstep; routine monorepo pattern for CKEditor 5. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-core AI (dependencies): Sibling @ckeditor org package released in lockstep; routine monorepo pattern for CKEditor 5. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-icons AI (phantom-deps): Same-org sibling dep; may be used indirectly or for type re-exports in CKEditor monorepo. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-list AI (phantom-deps): Same-org sibling dep; may be used indirectly or for type re-exports in CKEditor monorepo. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-link AI (phantom-deps): Same-org sibling dep; may be used indirectly or for type re-exports in CKEditor monorepo. ai
phantom-deps phantom-dep:@types/luxon AI (phantom-deps): Type-only dependency declared for TypeScript consumers; not directly imported at runtime. ai
phantom-deps phantom-dep:diff AI (phantom-deps): Declared runtime dep used in config/type context; expected for CKEditor collaboration bundle. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-track-changes AI (dependencies): Sibling @ckeditor org package released in lockstep; routine monorepo pattern for CKEditor 5. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-comments AI (dependencies): Sibling @ckeditor org package released in lockstep; routine monorepo pattern for CKEditor 5. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-widget AI (dependencies): Sibling @ckeditor org package released in lockstep; routine monorepo pattern for CKEditor 5. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-widget AI (phantom-deps): Same-org sibling dep; may be used indirectly or for type re-exports in CKEditor monorepo. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-engine AI (dependencies): Sibling @ckeditor org package released in lockstep; routine monorepo pattern for CKEditor 5. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-utils AI (dependencies): Sibling @ckeditor org package released in lockstep; routine monorepo pattern for CKEditor 5. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-ui AI (dependencies): Sibling @ckeditor org package released in lockstep; routine monorepo pattern for CKEditor 5. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-list AI (dependencies): Sibling @ckeditor org package released in lockstep; routine monorepo pattern for CKEditor 5. ai

Versions (showing 18 of 18)

Version Deps Published
48.3.1 14 / 0
48.3.0 14 / 0
48.2.0 14 / 0
48.1.1 13 / 0
48.1.0 13 / 0
48.0.1 13 / 0
48.0.0 13 / 0
47.7.3 15 / 0
47.7.2 15 / 0
47.7.1 15 / 0
47.7.0 15 / 0
47.6.2 15 / 0
47.6.1 15 / 0
47.6.0 15 / 0
47.5.0 15 / 0
47.4.0 15 / 0
47.3.0 15 / 0
47.2.0 15 / 0

v48.3.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v48.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v47.7.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.