@ckeditor/ckeditor5-remove-format
Remove format feature for CKEditor 5.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): CKEditor5 consolidated individual @ckeditor/* packages into the umbrella 'ckeditor5' package; this dependency change is part of documented architectural restructuring, not suspicious injection. | ai | |
| dependencies | unvetted-dep:@ckeditor/ckeditor5-core | AI (dependencies): Sibling CKEditor5 monorepo package, always released at the same version. Not a third-party or suspicious dependency. | ai | |
| dependencies | unvetted-dep:@ckeditor/ckeditor5-icons | AI (dependencies): Sibling CKEditor5 monorepo package, always released at the same version. Not a third-party or suspicious dependency. | ai | |
| dependencies | unvetted-dep:@ckeditor/ckeditor5-ui | AI (dependencies): Sibling CKEditor5 monorepo package, always released at the same version. Not a third-party or suspicious dependency. | ai | |
| dependencies | unvetted-dep:@ckeditor/ckeditor5-engine | AI (dependencies): Sibling CKEditor5 monorepo package, always released at the same version. Not a third-party or suspicious dependency. | ai | |
| license | uncommon-license:SEE LICENSE IN LICENSE.md | AI (license): Standard CKEditor5 license declaration referencing their well-known commercial/open-source dual-license model. Stable across all CKEditor5 packages. | ai | |
| dependencies | unvetted-dep:@ckeditor/ckeditor5-utils | AI (dependencies): Sibling CKEditor5 monorepo package, always released at the same version. Not a third-party or suspicious dependency. | ai |
Versions (showing 15 of 15)
| Version | Deps | Published |
|---|---|---|
| 48.2.0 | 5 / 0 | |
| 48.1.1 | 5 / 0 | |
| 48.1.0 | 5 / 0 | |
| 48.0.1 | 5 / 0 | |
| 48.0.0 | 5 / 0 | |
| 47.7.2 | 5 / 0 | |
| 47.7.1 | 5 / 0 | |
| 47.7.0 | 5 / 0 | |
| 47.6.2 | 5 / 0 | |
| 47.6.1 | 5 / 0 | |
| 47.6.0 | 5 / 0 | |
| 47.5.0 | 5 / 0 | |
| 47.4.0 | 5 / 0 | |
| 47.3.0 | 5 / 0 | |
| 47.2.0 | 5 / 0 |
v48.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v48.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v48.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v48.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v48.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v47.7.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v47.7.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v47.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v47.6.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v47.6.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v47.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v47.5.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v47.4.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v47.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v47.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.