← Home

@ckeditor/ckeditor5-revision-history

Document revision history feature for CKEditor 5.

18
Versions
SEE LICENSE IN LICENSE.md
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

ckeditor

Keywords

CKEditorckeditor5ckeditor 5WYSIWYGWYSIWYWtextrich-textrichtexteditoreditinghtmlcollaborationframeworkrevision historyversion historyversioning

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance no-provenance AI (provenance): CKSource does not use Sigstore provenance across their package portfolio; this is consistent with all their published packages. ai
semgrep semgrep:obfuscation-while-true AI (semgrep): CKEditor commercial plugins intentionally ship obfuscated source (declared via 'obfuscated: true' in package.json). This is their documented proprietary code protection practice. ai
semgrep semgrep:obfuscation-hex-functions AI (semgrep): CKEditor commercial plugins intentionally ship obfuscated source using javascript-obfuscator. Declared via 'obfuscated: true' in package.json. ai
source-diff obfuscated-file:src/ui/revisionviewer/changesnavigationview.js AI (source-diff): CKEditor intentionally obfuscates proprietary commercial plugin source. Copyright header and 'obfuscated: true' in package.json confirm this is expected. ai
source-diff obfuscated-file:src/ui/revision/createrevisionactionsdropdown.js AI (source-diff): CKEditor intentionally obfuscates proprietary commercial plugin source. Copyright header and 'obfuscated: true' in package.json confirm this is expected. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-core AI (phantom-deps): Same-org CKEditor dependency declared for type resolution; phantom-dep false positive for monorepo packages. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-engine AI (phantom-deps): Same-org CKEditor dependency declared for type resolution; phantom-dep false positive for monorepo packages. ai
phantom-deps phantom-dep:luxon AI (phantom-deps): Package ships obfuscated dist bundle (obfuscated:true in package.json); static import analysis cannot detect usage. luxon is a declared runtime dep used internally. ai
phantom-deps phantom-dep:es-toolkit AI (phantom-deps): Package ships obfuscated dist bundle; es-toolkit is a declared runtime dep used internally, not detectable via static import analysis. ai
phantom-deps phantom-dep:@types/luxon AI (phantom-deps): Type package bundled with obfuscated dist; false positive for this package's distribution model. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-icons AI (phantom-deps): Same-org dep used in obfuscated bundle; static analysis cannot detect imports in compiled output. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-widget AI (phantom-deps): Same-org dep used in obfuscated bundle; static analysis cannot detect imports in compiled output. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-autosave AI (phantom-deps): Same-org dep used in obfuscated bundle; static analysis cannot detect imports in compiled output. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-comments AI (phantom-deps): Same-org dep used in obfuscated bundle; static analysis cannot detect imports in compiled output. ai

Versions (showing 18 of 18)

Version Deps Published
48.3.1 12 / 0
48.3.0 12 / 0
48.2.0 12 / 0
48.1.1 12 / 0
48.1.0 12 / 0
48.0.1 12 / 0
48.0.0 12 / 0
47.7.3 14 / 0
47.7.2 14 / 0
47.7.1 14 / 0
47.7.0 14 / 0
47.6.2 14 / 0
47.6.1 14 / 0
47.6.0 14 / 0
47.5.0 14 / 0
47.4.0 14 / 0
47.3.0 14 / 0
47.2.0 14 / 0

v48.3.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v48.3.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v47.7.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.