@ckeditor/ckeditor5-collaboration-core
Base utilities used by CKEditor 5 collaboration features to support multiple users working together in a rich text editor.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): Same-org deps added; version diff is non-adjacent so deps appear new but are expected. | ai | |
| source-diff | obfuscated-file:src/utils/confirmmixin.js | AI (source-diff): CKEditor proprietary obfuscation; stable pattern across all versions of this package. | ai | |
| source-diff | obfuscated-file:src/utils/trim-html.js | AI (source-diff): CKEditor proprietary obfuscated source; standard practice for this commercial package. | ai | |
| source-diff | obfuscated-file:src/users.js | AI (source-diff): CKEditor proprietary code; package declares obfuscated:true; standard copyright header; imports only CKEditor modules. | ai | |
| source-diff | obfuscated-file:src/suggestions/suggestionsconversion.js | AI (source-diff): CKEditor proprietary code; package declares obfuscated:true; standard copyright header; imports only CKEditor modules. | ai | |
| source-diff | obfuscated-file:src/suggestions/integrations/shiftenter.js | AI (source-diff): CKEditor proprietary code; package declares obfuscated:true; standard copyright header; imports only CKEditor modules. | ai | |
| source-diff | obfuscated-file:src/utils/setupthreadkeyboardnavigation.js | AI (source-diff): CKEditor proprietary code; package declares obfuscated:true; standard copyright header; imports only CKEditor modules. | ai | |
| source-diff | obfuscated-file:src/utils/sanitizeEditorConfig.js | AI (source-diff): CKEditor proprietary code; package declares obfuscated:true; standard copyright header; imports only CKEditor modules. | ai | |
| source-diff | obfuscated-file:src/permissions.js | AI (source-diff): CKEditor proprietary code; package declares obfuscated:true; standard copyright header; imports only CKEditor modules. | ai | |
| source-diff | obfuscated-file:src/utils/confirmview.js | AI (source-diff): CKEditor proprietary code; package declares obfuscated:true; standard copyright header; imports only CKEditor modules. | ai | |
| source-diff | obfuscated-file:src/documentcompare.js | AI (source-diff): CKEditor proprietary code; package declares obfuscated:true; standard copyright header; imports only CKEditor modules. | ai | |
| source-diff | large-new-source-files | AI (source-diff): CKEditor collaboration-core ships many obfuscated source files as part of its proprietary distribution; count is normal. | ai | |
| source-diff | obfuscated-file:src/users/view/userview.js | AI (source-diff): CKEditor proprietary code; package declares obfuscated:true; standard copyright header; imports only CKEditor modules. | ai | |
| semgrep | semgrep:obfuscation-hex-functions | AI (semgrep): CKEditor deliberately obfuscates commercial collaboration plugins (package.json declares "obfuscated": true). Legitimate IP protection, not malware. | ai | |
| semgrep | semgrep:obfuscation-while-true | AI (semgrep): CKEditor deliberately obfuscates commercial collaboration plugins (package.json declares "obfuscated": true). Legitimate IP protection, not malware. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-ui | AI (phantom-deps): Same-org CKEditor monorepo dependency; indirect/peer import pattern is standard for this ecosystem. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-core | AI (phantom-deps): Same-org CKEditor monorepo dependency; indirect/peer import pattern is standard for this ecosystem. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-engine | AI (phantom-deps): Same-org CKEditor monorepo dependency; indirect/peer import pattern is standard for this ecosystem. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-theme-lark | AI (phantom-deps): Same-org CKEditor monorepo dependency; theme package loaded by convention. | ai | |
| provenance | no-provenance | AI (provenance): Lack of Sigstore provenance is common (~88% of npm packages); not a disqualifier for established packages with strong ecosystem signals. | ai | |
| license | uncommon-license:SEE LICENSE IN LICENSE.md | AI (license): CKEditor's proprietary collaboration features use custom licensing; external LICENSE.md reference is standard for this org. | ai | |
| dependencies | unvetted-dep:@ckeditor/ckeditor5-link | AI (dependencies): Sibling @ckeditor org package released in lockstep; routine monorepo pattern for CKEditor 5. | ai | |
| dependencies | unvetted-dep:@ckeditor/ckeditor5-core | AI (dependencies): Sibling @ckeditor org package released in lockstep; routine monorepo pattern for CKEditor 5. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-icons | AI (phantom-deps): Same-org sibling dep; may be used indirectly or for type re-exports in CKEditor monorepo. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-list | AI (phantom-deps): Same-org sibling dep; may be used indirectly or for type re-exports in CKEditor monorepo. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-link | AI (phantom-deps): Same-org sibling dep; may be used indirectly or for type re-exports in CKEditor monorepo. | ai | |
| phantom-deps | phantom-dep:@types/luxon | AI (phantom-deps): Type-only dependency declared for TypeScript consumers; not directly imported at runtime. | ai | |
| phantom-deps | phantom-dep:diff | AI (phantom-deps): Declared runtime dep used in config/type context; expected for CKEditor collaboration bundle. | ai | |
| dependencies | unvetted-dep:@ckeditor/ckeditor5-track-changes | AI (dependencies): Sibling @ckeditor org package released in lockstep; routine monorepo pattern for CKEditor 5. | ai | |
| dependencies | unvetted-dep:@ckeditor/ckeditor5-comments | AI (dependencies): Sibling @ckeditor org package released in lockstep; routine monorepo pattern for CKEditor 5. | ai | |
| dependencies | unvetted-dep:@ckeditor/ckeditor5-widget | AI (dependencies): Sibling @ckeditor org package released in lockstep; routine monorepo pattern for CKEditor 5. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-widget | AI (phantom-deps): Same-org sibling dep; may be used indirectly or for type re-exports in CKEditor monorepo. | ai | |
| dependencies | unvetted-dep:@ckeditor/ckeditor5-engine | AI (dependencies): Sibling @ckeditor org package released in lockstep; routine monorepo pattern for CKEditor 5. | ai | |
| dependencies | unvetted-dep:@ckeditor/ckeditor5-utils | AI (dependencies): Sibling @ckeditor org package released in lockstep; routine monorepo pattern for CKEditor 5. | ai | |
| dependencies | unvetted-dep:@ckeditor/ckeditor5-ui | AI (dependencies): Sibling @ckeditor org package released in lockstep; routine monorepo pattern for CKEditor 5. | ai | |
| dependencies | unvetted-dep:@ckeditor/ckeditor5-list | AI (dependencies): Sibling @ckeditor org package released in lockstep; routine monorepo pattern for CKEditor 5. | ai |
Versions (showing 18 of 18)
| Version | Deps | Published |
|---|---|---|
| 48.3.1 | 14 / 0 | |
| 48.3.0 | 14 / 0 | |
| 48.2.0 | 14 / 0 | |
| 48.1.1 | 13 / 0 | |
| 48.1.0 | 13 / 0 | |
| 48.0.1 | 13 / 0 | |
| 48.0.0 | 13 / 0 | |
| 47.7.3 | 15 / 0 | |
| 47.7.2 | 15 / 0 | |
| 47.7.1 | 15 / 0 | |
| 47.7.0 | 15 / 0 | |
| 47.6.2 | 15 / 0 | |
| 47.6.1 | 15 / 0 | |
| 47.6.0 | 15 / 0 | |
| 47.5.0 | 15 / 0 | |
| 47.4.0 | 15 / 0 | |
| 47.3.0 | 15 / 0 | |
| 47.2.0 | 15 / 0 |
v48.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v48.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v47.7.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.