@ckeditor/ckeditor5-revision-history
Document revision history feature for CKEditor 5.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | no-provenance | AI (provenance): CKSource does not use Sigstore provenance across their package portfolio; this is consistent with all their published packages. | ai | |
| semgrep | semgrep:obfuscation-while-true | AI (semgrep): CKEditor commercial plugins intentionally ship obfuscated source (declared via 'obfuscated: true' in package.json). This is their documented proprietary code protection practice. | ai | |
| semgrep | semgrep:obfuscation-hex-functions | AI (semgrep): CKEditor commercial plugins intentionally ship obfuscated source using javascript-obfuscator. Declared via 'obfuscated: true' in package.json. | ai | |
| source-diff | obfuscated-file:src/ui/revisionviewer/changesnavigationview.js | AI (source-diff): CKEditor intentionally obfuscates proprietary commercial plugin source. Copyright header and 'obfuscated: true' in package.json confirm this is expected. | ai | |
| source-diff | obfuscated-file:src/ui/revision/createrevisionactionsdropdown.js | AI (source-diff): CKEditor intentionally obfuscates proprietary commercial plugin source. Copyright header and 'obfuscated: true' in package.json confirm this is expected. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-core | AI (phantom-deps): Same-org CKEditor dependency declared for type resolution; phantom-dep false positive for monorepo packages. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-engine | AI (phantom-deps): Same-org CKEditor dependency declared for type resolution; phantom-dep false positive for monorepo packages. | ai | |
| phantom-deps | phantom-dep:luxon | AI (phantom-deps): Package ships obfuscated dist bundle (obfuscated:true in package.json); static import analysis cannot detect usage. luxon is a declared runtime dep used internally. | ai | |
| phantom-deps | phantom-dep:es-toolkit | AI (phantom-deps): Package ships obfuscated dist bundle; es-toolkit is a declared runtime dep used internally, not detectable via static import analysis. | ai | |
| phantom-deps | phantom-dep:@types/luxon | AI (phantom-deps): Type package bundled with obfuscated dist; false positive for this package's distribution model. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-icons | AI (phantom-deps): Same-org dep used in obfuscated bundle; static analysis cannot detect imports in compiled output. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-widget | AI (phantom-deps): Same-org dep used in obfuscated bundle; static analysis cannot detect imports in compiled output. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-autosave | AI (phantom-deps): Same-org dep used in obfuscated bundle; static analysis cannot detect imports in compiled output. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-comments | AI (phantom-deps): Same-org dep used in obfuscated bundle; static analysis cannot detect imports in compiled output. | ai |
Versions (showing 18 of 18)
| Version | Deps | Published |
|---|---|---|
| 48.3.1 | 12 / 0 | |
| 48.3.0 | 12 / 0 | |
| 48.2.0 | 12 / 0 | |
| 48.1.1 | 12 / 0 | |
| 48.1.0 | 12 / 0 | |
| 48.0.1 | 12 / 0 | |
| 48.0.0 | 12 / 0 | |
| 47.7.3 | 14 / 0 | |
| 47.7.2 | 14 / 0 | |
| 47.7.1 | 14 / 0 | |
| 47.7.0 | 14 / 0 | |
| 47.6.2 | 14 / 0 | |
| 47.6.1 | 14 / 0 | |
| 47.6.0 | 14 / 0 | |
| 47.5.0 | 14 / 0 | |
| 47.4.0 | 14 / 0 | |
| 47.3.0 | 14 / 0 | |
| 47.2.0 | 14 / 0 |
v48.3.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v48.3.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v47.7.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.