← Home

@ckeditor/ckeditor5-comments

Collaborative comments feature for CKEditor 5.

18
Versions
SEE LICENSE IN LICENSE.md
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

ckeditor

Keywords

CKEditorckeditor5ckeditor 5WYSIWYGWYSIWYWtextrich-textrichtexteditoreditinghtmloperational transformationotcollaborationcollaborativereal-timerealtimeframeworkcommentscommentdiscussiondiscussions

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:build/comments.js AI (source-diff): CKSource intentionally obfuscates proprietary source; stable across versions. ai
semgrep semgrep:obfuscation-hex-functions AI (semgrep): CKEditor commercial plugin ships intentionally obfuscated source (package.json declares "obfuscated": true). IP protection, not malware. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-ui AI (phantom-deps): Same-org CKEditor peer dependency; normal for CKEditor's modular architecture. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-core AI (phantom-deps): Same-org CKEditor peer dependency; normal for CKEditor's modular architecture. ai
semgrep semgrep:obfuscation-while-true AI (semgrep): CKEditor commercial plugin ships intentionally obfuscated source (package.json declares "obfuscated": true). IP protection, not malware. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-clipboard AI (phantom-deps): Same-org CKEditor peer dependency; normal for CKEditor's modular architecture. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-theme-lark AI (phantom-deps): Same-org CKEditor peer dependency; normal for CKEditor's modular architecture. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-engine AI (phantom-deps): Same-org CKEditor peer dependency; normal for CKEditor's modular architecture. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-revision-history AI (phantom-deps): Same-org CKEditor package declared as dep in a compiled ESM bundle; static import analysis unreliable for bundled dist output. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-undo AI (phantom-deps): Same-org CKEditor package declared as dep in a compiled ESM bundle; static import analysis unreliable for bundled dist output. ai
license uncommon-license:SEE LICENSE IN LICENSE.md AI (license): Standard CKSource commercial license declaration for CKEditor 5 premium features; expected for this package. ai
phantom-deps phantom-dep:es-toolkit AI (phantom-deps): Legitimate utility library dependency; may be used indirectly in bundled output. Not a malicious phantom dep. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-enter AI (phantom-deps): Same-org CKEditor package declared as dep in a compiled ESM bundle; static import analysis unreliable for bundled dist output. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-icons AI (phantom-deps): Same-org CKEditor package declared as dep in a compiled ESM bundle; static import analysis unreliable for bundled dist output. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-typing AI (phantom-deps): Same-org CKEditor package declared as dep in a compiled ESM bundle; static import analysis unreliable for bundled dist output. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-widget AI (phantom-deps): Same-org CKEditor package declared as dep in a compiled ESM bundle; static import analysis unreliable for bundled dist output. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-paragraph AI (phantom-deps): Same-org CKEditor package declared as dep in a compiled ESM bundle; static import analysis unreliable for bundled dist output. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-select-all AI (phantom-deps): Same-org CKEditor package declared as dep in a compiled ESM bundle; static import analysis unreliable for bundled dist output. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-source-editing AI (phantom-deps): Same-org CKEditor package declared as dep in a compiled ESM bundle; static import analysis unreliable for bundled dist output. ai

Versions (showing 18 of 18)

Version Deps Published
48.3.1 16 / 0
48.3.0 16 / 0
48.2.0 16 / 0
48.1.1 16 / 0
48.1.0 16 / 0
48.0.1 16 / 0
48.0.0 16 / 0
47.7.3 19 / 0
47.7.2 19 / 0
47.7.1 19 / 0
47.7.0 19 / 0
47.6.2 19 / 0
47.6.1 19 / 0
47.6.0 19 / 0
47.5.0 19 / 0
47.4.0 19 / 0
47.3.0 19 / 0
47.2.0 18 / 0

v48.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v48.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v47.7.3

25 findings
HIGH New obfuscated file: src/comments/addcommentthreadcommand.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/annotations/annotation.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/annotations/annotationcollection.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/annotations/annotations.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/annotations/annotationsuis.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/annotations/view/annotationview.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/comments/ui/view/basecommentthreadview.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/comments/ui/view/basecommentview.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/comments/integrations/clipboard.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/comments/ui/view/commentinputview.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: build/comments.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: src/comments/commentsarchive.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/comments/commentsarchiveui.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/comments/ui/view/commentsarchiveview.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/comments/commentsediting.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/comments/ui/view/commentslistview.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/commentsonly.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/comments/commentsrepository.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/comments/commentsui.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/comments/ui/view/commentthreadheaderview.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/comments/ui/view/commentthreadinputview.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/comments/ui/view/commentthreadview.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/comments/ui/view/commentview.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

HIGH New obfuscated file: src/utils/common-translations.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.