← Home

@ckeditor/ckeditor5-source-editing

Source editing feature for CKEditor 5.

15
Versions
SEE LICENSE IN LICENSE.md
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

ckeditor

Keywords

ckeditorckeditor5ckeditor 5ckeditor5-featureckeditor5-plugin

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): New deps (ckeditor5, @ckeditor/ckeditor5-theme-lark) are first-party same-org packages pinned to the same version; consistent with CKEditor 5 monorepo restructuring. ai
publish-pattern dormant-publish AI (publish-pattern): CKEditor maintains multiple version branches; 47.x is an older branch receiving backport patches while 48.x is the current line. Dormancy on older branches is expected for this monorepo. ai
phantom-deps phantom-dep:@ckeditor/ckeditor5-theme-lark AI (phantom-deps): Same-org @ckeditor/ scoped theme package; declared as dep but used at theme/build level rather than direct import. Normal pattern for CKEditor5 monorepo packages. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-utils AI (dependencies): First-party CKEditor 5 dependency published by the same organization; expected internal dependency for all CKEditor plugins. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-ui AI (dependencies): First-party CKEditor 5 dependency published by the same organization; expected internal dependency for all CKEditor plugins. ai
license uncommon-license:SEE LICENSE IN LICENSE.md AI (license): Standard CKEditor 5 licensing approach used consistently across all @ckeditor/* packages; not a security concern. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-core AI (dependencies): First-party CKEditor 5 dependency published by the same organization; expected internal dependency for all CKEditor plugins. ai
dependencies unvetted-dep:@ckeditor/ckeditor5-icons AI (dependencies): First-party CKEditor 5 dependency published by the same organization; expected internal dependency for all CKEditor plugins. ai

Versions (showing 15 of 15)

Version Deps Published
48.2.0 4 / 0
48.1.1 4 / 0
48.1.0 4 / 0
48.0.1 4 / 0
48.0.0 4 / 0
47.7.2 6 / 0
47.7.1 6 / 0
47.7.0 6 / 0
47.6.2 6 / 0
47.6.1 6 / 0
47.6.0 6 / 0
47.5.0 6 / 0
47.4.0 6 / 0
47.3.0 6 / 0
47.2.0 6 / 0

v48.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v48.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v48.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v48.0.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v48.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v47.7.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v47.7.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v47.7.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v47.6.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v47.6.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v47.6.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v47.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v47.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v47.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v47.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.