@ckeditor/ckeditor5-real-time-collaboration
A set of CKEditor 5 features enabling real-time collaboration within the editor using CKEditor Cloud Services.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:src/realtimecollaborativecomments/cloudservicescommentsadapter.js | AI (source-diff): CKEditor intentionally obfuscates proprietary collaboration source files; package.json declares obfuscated:true and copyright header confirms this is deliberate IP protection by CKSource. | ai | |
| source-diff | obfuscated-file:src/realtimecollaborativetrackchanges/cloudservicestrackchangesadapter.js | AI (source-diff): CKEditor intentionally obfuscates proprietary collaboration source files; package.json declares obfuscated:true and copyright header confirms this is deliberate IP protection by CKSource. | ai | |
| source-diff | obfuscated-file:src/realtimecollaborativerevisionhistory/cloudservicesrevisionhistoryadapter.js | AI (source-diff): CKEditor intentionally obfuscates proprietary collaboration source files; package.json declares obfuscated:true and copyright header confirms this is deliberate IP protection by CKSource. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-core | AI (phantom-deps): Same-org sibling dependency; false positive for CKEditor monorepo structure. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-ui | AI (phantom-deps): Same-org sibling dependency; phantom detection is a false positive for CKEditor's monorepo-style package structure. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-comments | AI (phantom-deps): Same-org sibling dependency; false positive for CKEditor monorepo structure. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-theme-lark | AI (phantom-deps): Same-org sibling dependency; false positive for CKEditor monorepo structure. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-track-changes | AI (phantom-deps): Same-org sibling dependency; false positive for CKEditor monorepo structure. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-cloud-services | AI (phantom-deps): Same-org sibling dependency; false positive for CKEditor monorepo structure. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-revision-history | AI (phantom-deps): Same-org sibling dependency; false positive for CKEditor monorepo structure. | ai | |
| dependencies | unvetted-dep:ckeditor5-collaboration | AI (dependencies): ckeditor5-collaboration is a companion CKEditor premium package released in lockstep at the same version; part of the expected CKEditor commercial ecosystem. | ai | |
| semgrep | semgrep:obfuscation-hex-functions | AI (semgrep): CKEditor premium packages intentionally ship obfuscated code; package.json declares 'obfuscated: true'. This is a stable, documented practice for this package family. | ai | |
| semgrep | semgrep:obfuscation-while-true | AI (semgrep): Same as above — intentional obfuscation explicitly declared in package.json for CKEditor commercial plugin protection. | ai | |
| dependencies | unvetted-dep:@ckeditor/ckeditor5-track-changes | AI (dependencies): Sibling CKEditor 5 package from the same org; expected dependency for real-time collaboration features. Stable across versions. | ai | |
| dependencies | unvetted-dep:@ckeditor/ckeditor-cloud-services-collaboration | AI (dependencies): CKSource cloud services package; expected dependency for this real-time collaboration package. Stable across versions. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-editor-multi-root | AI (phantom-deps): Same-org monorepo package; indirect usage via re-exports is expected in CKEditor's package structure. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-engine | AI (phantom-deps): Same-org monorepo package; indirect usage via re-exports is expected in CKEditor's package structure. | ai | |
| phantom-deps | phantom-dep:es-toolkit | AI (phantom-deps): es-toolkit is a declared dependency used in build/config context; phantom detection is a false positive for this package's build setup. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-operations-compressor | AI (phantom-deps): Same-org monorepo package; indirect usage via re-exports is expected in CKEditor's package structure. | ai | |
| provenance | no-provenance | AI (provenance): CKEditor is an established commercial vendor; lack of Sigstore provenance is consistent with their publishing pipeline across all 1550+ versions. | ai |
Versions (showing 18 of 18)
| Version | Deps | Published |
|---|---|---|
| 48.3.1 | 13 / 0 | |
| 48.3.0 | 13 / 0 | |
| 48.2.0 | 13 / 0 | |
| 48.1.1 | 13 / 0 | |
| 48.1.0 | 13 / 0 | |
| 48.0.1 | 13 / 0 | |
| 48.0.0 | 13 / 0 | |
| 47.7.3 | 15 / 0 | |
| 47.7.2 | 15 / 0 | |
| 47.7.1 | 15 / 0 | |
| 47.7.0 | 15 / 0 | |
| 47.6.2 | 15 / 0 | |
| 47.6.1 | 15 / 0 | |
| 47.6.0 | 15 / 0 | |
| 47.5.0 | 15 / 0 | |
| 47.4.0 | 15 / 0 | |
| 47.3.0 | 15 / 0 | |
| 47.2.0 | 15 / 0 |
v48.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v48.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v47.7.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.