@ckeditor/ckeditor5-source-editing
Source editing feature for CKEditor 5.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | new-deps-added | AI (publish-pattern): New deps (ckeditor5, @ckeditor/ckeditor5-theme-lark) are first-party same-org packages pinned to the same version; consistent with CKEditor 5 monorepo restructuring. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): CKEditor maintains multiple version branches; 47.x is an older branch receiving backport patches while 48.x is the current line. Dormancy on older branches is expected for this monorepo. | ai | |
| phantom-deps | phantom-dep:@ckeditor/ckeditor5-theme-lark | AI (phantom-deps): Same-org @ckeditor/ scoped theme package; declared as dep but used at theme/build level rather than direct import. Normal pattern for CKEditor5 monorepo packages. | ai | |
| dependencies | unvetted-dep:@ckeditor/ckeditor5-utils | AI (dependencies): First-party CKEditor 5 dependency published by the same organization; expected internal dependency for all CKEditor plugins. | ai | |
| dependencies | unvetted-dep:@ckeditor/ckeditor5-ui | AI (dependencies): First-party CKEditor 5 dependency published by the same organization; expected internal dependency for all CKEditor plugins. | ai | |
| license | uncommon-license:SEE LICENSE IN LICENSE.md | AI (license): Standard CKEditor 5 licensing approach used consistently across all @ckeditor/* packages; not a security concern. | ai | |
| dependencies | unvetted-dep:@ckeditor/ckeditor5-core | AI (dependencies): First-party CKEditor 5 dependency published by the same organization; expected internal dependency for all CKEditor plugins. | ai | |
| dependencies | unvetted-dep:@ckeditor/ckeditor5-icons | AI (dependencies): First-party CKEditor 5 dependency published by the same organization; expected internal dependency for all CKEditor plugins. | ai |
Versions (showing 15 of 15)
| Version | Deps | Published |
|---|---|---|
| 48.2.0 | 4 / 0 | |
| 48.1.1 | 4 / 0 | |
| 48.1.0 | 4 / 0 | |
| 48.0.1 | 4 / 0 | |
| 48.0.0 | 4 / 0 | |
| 47.7.2 | 6 / 0 | |
| 47.7.1 | 6 / 0 | |
| 47.7.0 | 6 / 0 | |
| 47.6.2 | 6 / 0 | |
| 47.6.1 | 6 / 0 | |
| 47.6.0 | 6 / 0 | |
| 47.5.0 | 6 / 0 | |
| 47.4.0 | 6 / 0 | |
| 47.3.0 | 6 / 0 | |
| 47.2.0 | 6 / 0 |
v48.2.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v48.1.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v48.1.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v48.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v48.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v47.7.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v47.7.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v47.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v47.6.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v47.6.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v47.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v47.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v47.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v47.3.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v47.2.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.