← Home

@ckeditor/ckeditor5-merge-fields

Merge fields feature for CKEditor 5.

18
Versions
SEE LICENSE IN LICENSE.md
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

ckeditor

Keywords

ckeditorckeditor5ckeditor 5ckeditor5-featureckeditor5-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern dormant-publish AI (publish-pattern): Package has 1039 versions in registry indicating active publishing history; dormancy reflects analyzer tracking gap, not actual inactivity. ai
source-diff obfuscated-file:build/merge-fields.js AI (source-diff): build/merge-fields.js is a pre-built DLL bundle; obfuscation is intentional per CKSource commercial licensing. Content shows legitimate translation strings and SVG assets. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-ui AI (phantom-deps): Same-org CKEditor peer dependency declared for compatibility; resolved via umbrella ckeditor5 package in monorepo structure. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-core AI (phantom-deps): Same-org CKEditor peer dependency; normal monorepo pattern for CKEditor 5 plugins. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-image AI (phantom-deps): Same-org CKEditor peer dependency; normal monorepo pattern for CKEditor 5 plugins. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-widget AI (phantom-deps): Same-org CKEditor peer dependency; normal monorepo pattern for CKEditor 5 plugins. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-mention AI (phantom-deps): Same-org CKEditor peer dependency; normal monorepo pattern for CKEditor 5 plugins. ai
semgrep semgrep:obfuscation-while-true AI (semgrep): CKEditor commercial plugins explicitly declare obfuscated:true in package.json; javascript-obfuscator output is intentional IP protection by CKSource, not malware. ai
semgrep semgrep:obfuscation-hex-functions AI (semgrep): CKEditor commercial plugins explicitly declare obfuscated:true in package.json; hex-prefixed names are intentional javascript-obfuscator output by CKSource. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-ui AI (dependencies): Same-org CKEditor dependency published by CKSource at matching version; not an independent risk. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-core AI (dependencies): Same-org CKEditor dependency published by CKSource at matching version; not an independent risk. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-image AI (dependencies): Same-org CKEditor dependency published by CKSource at matching version; not an independent risk. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-utils AI (dependencies): Same-org CKEditor dependency published by CKSource at matching version; not an independent risk. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-engine AI (dependencies): Same-org CKEditor dependency published by CKSource at matching version; not an independent risk. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-widget AI (dependencies): Same-org CKEditor dependency published by CKSource at matching version; not an independent risk. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-mention AI (dependencies): Same-org CKEditor dependency published by CKSource at matching version; not an independent risk. ai
phantom-deps phantom-dep:es-toolkit AI (phantom-deps): es-toolkit is a legitimate utility library; phantom classification likely due to indirect import patterns in CKEditor's build system. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-icons AI (phantom-deps): Same-org CKEditor icons package; phantom classification is a build artifact, not a security concern. ai

Versions (showing 18 of 18)

Version Deps Published
48.3.1 9 / 0
48.3.0 9 / 0
48.2.0 9 / 0
48.1.1 9 / 0
48.1.0 9 / 0
48.0.1 9 / 0
48.0.0 9 / 0
47.7.3 9 / 0
47.7.2 9 / 0
47.7.1 9 / 0
47.7.0 9 / 0
47.6.2 9 / 0
47.6.1 9 / 0
47.6.0 9 / 0
47.5.0 9 / 0
47.4.0 9 / 0
47.3.0 9 / 0
47.2.0 9 / 0

v48.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v48.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v47.7.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.