← Home

@edifice.io/tiptap-extensions

Edifice Rich Text Editor Extensions

37
Versions
AGPL-3.0
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

wsejenkins

Keywords

edificerich text editortiptapextensions

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@tiptap/extension-bullet-list AI (phantom-deps): Library re-exports tiptap extensions; phantom-dep pattern is stable for this package. ai
phantom-deps phantom-dep:@tiptap/extension-ordered-list AI (phantom-deps): Library re-exports tiptap extensions; phantom-dep pattern is stable for this package. ai
phantom-deps phantom-dep:@tiptap/extension-horizontal-rule AI (phantom-deps): Library re-exports tiptap extensions; phantom-dep pattern is stable for this package. ai
phantom-deps phantom-dep:@tiptap/html AI (phantom-deps): Tiptap utility dep; referenced in config files, stable false positive for this package. ai
phantom-deps phantom-dep:@tiptap/starter-kit AI (phantom-deps): Tiptap peer dep; referenced in config, stable false positive for this package. ai
phantom-deps phantom-dep:prosemirror-view AI (phantom-deps): ProseMirror peer dep; referenced in config files, stable false positive. ai
phantom-deps phantom-dep:prosemirror-model AI (phantom-deps): ProseMirror peer dep; referenced in config files, stable false positive. ai
phantom-deps phantom-dep:prosemirror-transform AI (phantom-deps): ProseMirror peer dep; referenced in config files, stable false positive. ai
phantom-deps phantom-dep:@tiptap/extension-bold AI (phantom-deps): Tiptap extension peer dep; referenced in config, stable false positive. ai
phantom-deps phantom-dep:@tiptap/extension-code AI (phantom-deps): Tiptap extension peer dep; referenced in config, stable false positive. ai
phantom-deps phantom-dep:@tiptap/extension-text AI (phantom-deps): Tiptap extension peer dep; referenced in config, stable false positive. ai
phantom-deps phantom-dep:vite AI (phantom-deps): Build tool listed in dependencies for library build; not a runtime import. ai
phantom-deps phantom-dep:@tiptap/extension-strike AI (phantom-deps): Tiptap extension peer dep; referenced in config, stable false positive. ai
phantom-deps phantom-dep:@tiptap/extension-history AI (phantom-deps): Tiptap extension peer dep; referenced in config, stable false positive. ai
phantom-deps phantom-dep:@tiptap/extension-document AI (phantom-deps): Tiptap extension peer dep; referenced in config, stable false positive. ai
phantom-deps phantom-dep:@tiptap/extension-gapcursor AI (phantom-deps): Tiptap extension peer dep; referenced in config, stable false positive. ai
phantom-deps phantom-dep:@tiptap/extension-blockquote AI (phantom-deps): Tiptap extension peer dep; referenced in config, stable false positive. ai
phantom-deps phantom-dep:@tiptap/extension-code-block AI (phantom-deps): Tiptap extension peer dep; referenced in config, stable false positive. ai
phantom-deps phantom-dep:@tiptap/extension-dropcursor AI (phantom-deps): Tiptap extension peer dep; referenced in config, stable false positive. ai
phantom-deps phantom-dep:@tiptap/extension-hard-break AI (phantom-deps): Tiptap extension peer dep; referenced in config, stable false positive. ai
phantom-deps phantom-dep:@tiptap/extension-italic AI (phantom-deps): Tiptap extension peer dep; referenced in config, stable false positive. ai
phantom-deps phantom-dep:vite-plugin-dts AI (phantom-deps): Build tool listed in dependencies; not a runtime import. ai
phantom-deps phantom-dep:@tiptap/pm AI (phantom-deps): ProseMirror peer dep bundled for consumers; referenced in config, not direct import. ai

Versions (showing 37 of 37)

Version Deps Published
2.5.22 30 / 2
2.5.21 30 / 2
2.5.20 33 / 2
2.5.19 33 / 2
2.5.18 33 / 2
2.5.17 33 / 2
2.5.16 33 / 2
2.5.15 33 / 2
2.5.14 33 / 2
2.5.13 33 / 2
2.5.12 33 / 2
2.5.10 33 / 2
2.5.9 33 / 2
2.5.8 33 / 2
2.5.6 33 / 2
2.5.5 33 / 2
2.5.4 33 / 2
2.5.3 33 / 2
2.5.2 33 / 2
2.5.1 33 / 2
2.5.0 33 / 2
2.4.2 33 / 2
2.4.1 33 / 2
2.4.0 33 / 2
2.3.2 33 / 2
2.3.1 33 / 2
2.3.0 33 / 2
2.2.14 33 / 2
2.2.13 33 / 2
2.2.12 33 / 2
2.2.11 33 / 2
2.2.10 21 / 2
2.2.9 21 / 2
2.2.8 21 / 2
2.2.7 21 / 2
2.2.6 21 / 2
2.2.5 21 / 2

v2.5.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.5.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.5.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.5.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.5.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.4.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.2.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.