@ckeditor/ckeditor5-comments
Collaborative comments feature for CKEditor 5.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:build/comments.js | AI (source-diff): CKSource intentionally obfuscates proprietary source; stable across versions. | ai | |
| semgrep | semgrep:obfuscation-hex-functions | AI (semgrep): CKEditor commercial plugin ships intentionally obfuscated source (package.json declares "obfuscated": true). IP protection, not malware. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-ui | AI (phantom-deps): Same-org CKEditor peer dependency; normal for CKEditor's modular architecture. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-core | AI (phantom-deps): Same-org CKEditor peer dependency; normal for CKEditor's modular architecture. | ai | |
| semgrep | semgrep:obfuscation-while-true | AI (semgrep): CKEditor commercial plugin ships intentionally obfuscated source (package.json declares "obfuscated": true). IP protection, not malware. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-clipboard | AI (phantom-deps): Same-org CKEditor peer dependency; normal for CKEditor's modular architecture. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-theme-lark | AI (phantom-deps): Same-org CKEditor peer dependency; normal for CKEditor's modular architecture. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-engine | AI (phantom-deps): Same-org CKEditor peer dependency; normal for CKEditor's modular architecture. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-revision-history | AI (phantom-deps): Same-org CKEditor package declared as dep in a compiled ESM bundle; static import analysis unreliable for bundled dist output. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-undo | AI (phantom-deps): Same-org CKEditor package declared as dep in a compiled ESM bundle; static import analysis unreliable for bundled dist output. | ai | |
| license | uncommon-license:SEE LICENSE IN LICENSE.md | AI (license): Standard CKSource commercial license declaration for CKEditor 5 premium features; expected for this package. | ai | |
| phantom-deps | phantom-dep:es-toolkit | AI (phantom-deps): Legitimate utility library dependency; may be used indirectly in bundled output. Not a malicious phantom dep. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-enter | AI (phantom-deps): Same-org CKEditor package declared as dep in a compiled ESM bundle; static import analysis unreliable for bundled dist output. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-icons | AI (phantom-deps): Same-org CKEditor package declared as dep in a compiled ESM bundle; static import analysis unreliable for bundled dist output. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-typing | AI (phantom-deps): Same-org CKEditor package declared as dep in a compiled ESM bundle; static import analysis unreliable for bundled dist output. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-widget | AI (phantom-deps): Same-org CKEditor package declared as dep in a compiled ESM bundle; static import analysis unreliable for bundled dist output. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-paragraph | AI (phantom-deps): Same-org CKEditor package declared as dep in a compiled ESM bundle; static import analysis unreliable for bundled dist output. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-select-all | AI (phantom-deps): Same-org CKEditor package declared as dep in a compiled ESM bundle; static import analysis unreliable for bundled dist output. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-source-editing | AI (phantom-deps): Same-org CKEditor package declared as dep in a compiled ESM bundle; static import analysis unreliable for bundled dist output. | ai |
Versions (showing 18 of 18)
| Version | Deps | Published |
|---|---|---|
| 48.3.1 | 16 / 0 | |
| 48.3.0 | 16 / 0 | |
| 48.2.0 | 16 / 0 | |
| 48.1.1 | 16 / 0 | |
| 48.1.0 | 16 / 0 | |
| 48.0.1 | 16 / 0 | |
| 48.0.0 | 16 / 0 | |
| 47.7.3 | 19 / 0 | |
| 47.7.2 | 19 / 0 | |
| 47.7.1 | 19 / 0 | |
| 47.7.0 | 19 / 0 | |
| 47.6.2 | 19 / 0 | |
| 47.6.1 | 19 / 0 | |
| 47.6.0 | 19 / 0 | |
| 47.5.0 | 19 / 0 | |
| 47.4.0 | 19 / 0 | |
| 47.3.0 | 19 / 0 | |
| 47.2.0 | 18 / 0 |
v48.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v48.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v47.7.3
25 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator. Artifact: obfuscated (_0x-array) — true obfuscation signature.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.