← Home

@ckeditor/ckeditor5-real-time-collaboration

A set of CKEditor 5 features enabling real-time collaboration within the editor using CKEditor Cloud Services.

18
Versions
SEE LICENSE IN LICENSE.md
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

ckeditor

Keywords

CKEditorckeditor5ckeditor 5WYSIWYGWYSIWYWtextrich-textrichtexteditoreditinghtmloperational transformationotcollaborationcollaborativereal-timerealtimeframework

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:src/realtimecollaborativecomments/cloudservicescommentsadapter.js AI (source-diff): CKEditor intentionally obfuscates proprietary collaboration source files; package.json declares obfuscated:true and copyright header confirms this is deliberate IP protection by CKSource. ai
source-diff obfuscated-file:src/realtimecollaborativetrackchanges/cloudservicestrackchangesadapter.js AI (source-diff): CKEditor intentionally obfuscates proprietary collaboration source files; package.json declares obfuscated:true and copyright header confirms this is deliberate IP protection by CKSource. ai
source-diff obfuscated-file:src/realtimecollaborativerevisionhistory/cloudservicesrevisionhistoryadapter.js AI (source-diff): CKEditor intentionally obfuscates proprietary collaboration source files; package.json declares obfuscated:true and copyright header confirms this is deliberate IP protection by CKSource. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-core AI (phantom-deps): Same-org sibling dependency; false positive for CKEditor monorepo structure. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-ui AI (phantom-deps): Same-org sibling dependency; phantom detection is a false positive for CKEditor's monorepo-style package structure. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-comments AI (phantom-deps): Same-org sibling dependency; false positive for CKEditor monorepo structure. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-theme-lark AI (phantom-deps): Same-org sibling dependency; false positive for CKEditor monorepo structure. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-track-changes AI (phantom-deps): Same-org sibling dependency; false positive for CKEditor monorepo structure. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-cloud-services AI (phantom-deps): Same-org sibling dependency; false positive for CKEditor monorepo structure. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-revision-history AI (phantom-deps): Same-org sibling dependency; false positive for CKEditor monorepo structure. ai
dependencies unvetted-dep:ckeditor5-collaboration AI (dependencies): ckeditor5-collaboration is a companion CKEditor premium package released in lockstep at the same version; part of the expected CKEditor commercial ecosystem. ai
semgrep semgrep:obfuscation-hex-functions AI (semgrep): CKEditor premium packages intentionally ship obfuscated code; package.json declares 'obfuscated: true'. This is a stable, documented practice for this package family. ai
semgrep semgrep:obfuscation-while-true AI (semgrep): Same as above — intentional obfuscation explicitly declared in package.json for CKEditor commercial plugin protection. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-track-changes AI (dependencies): Sibling CKEditor 5 package from the same org; expected dependency for real-time collaboration features. Stable across versions. ai
dependencies unvetted-dep:@ckeditor/ckeditor-cloud-services-collaboration AI (dependencies): CKSource cloud services package; expected dependency for this real-time collaboration package. Stable across versions. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-editor-multi-root AI (phantom-deps): Same-org monorepo package; indirect usage via re-exports is expected in CKEditor's package structure. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-engine AI (phantom-deps): Same-org monorepo package; indirect usage via re-exports is expected in CKEditor's package structure. ai
phantom-deps phantom-dep:es-toolkit AI (phantom-deps): es-toolkit is a declared dependency used in build/config context; phantom detection is a false positive for this package's build setup. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-operations-compressor AI (phantom-deps): Same-org monorepo package; indirect usage via re-exports is expected in CKEditor's package structure. ai
provenance no-provenance AI (provenance): CKEditor is an established commercial vendor; lack of Sigstore provenance is consistent with their publishing pipeline across all 1550+ versions. ai

Versions (showing 18 of 18)

Version Deps Published
48.3.1 13 / 0
48.3.0 13 / 0
48.2.0 13 / 0
48.1.1 13 / 0
48.1.0 13 / 0
48.0.1 13 / 0
48.0.0 13 / 0
47.7.3 15 / 0
47.7.2 15 / 0
47.7.1 15 / 0
47.7.0 15 / 0
47.6.2 15 / 0
47.6.1 15 / 0
47.6.0 15 / 0
47.5.0 15 / 0
47.4.0 15 / 0
47.3.0 15 / 0
47.2.0 15 / 0

v48.3.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v48.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v47.7.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.