← Home

@lexical/react

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

fantactukazurfyxacywatsonipavlov001trueadmetrepum

Keywords

reactlexicaleditorrich-text

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff source-size-tripled AI (source-diff): Monorepo build output growth; expected for this package. ai
source-diff obfuscated-file:LexicalCheckListPlugin.prod.mjs AI (source-diff): Minified prod build output; benign for this package. ai
source-diff obfuscated-file:LexicalCharacterLimitPlugin.prod.mjs AI (source-diff): Minified prod build output; benign for this package. ai
source-diff obfuscated-file:LexicalHashtagPlugin.dev.mjs AI (source-diff): Dev build output; benign for this package. ai
source-diff obfuscated-file:LexicalCollaborationPlugin.prod.mjs AI (source-diff): Minified prod build output; benign for this package. ai
source-diff obfuscated-file:LexicalAutoLinkPlugin.prod.mjs AI (source-diff): Minified prod build output; benign for this package. ai
source-diff obfuscated-file:LexicalNodeMenuPlugin.prod.mjs AI (source-diff): Minified prod build output; benign for this package. ai
source-diff obfuscated-file:LexicalContextMenuPlugin.prod.mjs AI (source-diff): Minified prod build output; benign for this package. ai
source-diff obfuscated-file:LexicalTypeaheadMenuPlugin.prod.mjs AI (source-diff): Minified prod build output; benign for this package. ai
source-diff obfuscated-file:LexicalTreeView.prod.mjs AI (source-diff): Minified prod build output with Meta header/readable imports; not obfuscation. ai
provenance publisher-changed-stale AI (provenance): 2022 publisher change unremoved 1565d; inconsistent with takeover. ai
source-diff obfuscated-file:LexicalHashtagPlugin.prod.js AI (source-diff): Minified Rollup build output with Meta license header; not obfuscation. ai
source-diff obfuscated-file:LexicalHashtagPlugin.dev.js AI (source-diff): Long lines are Unicode regex tables in build output, not obfuscation. ai
maintainer-change maintainer-added AI (maintainer-change): Legit org handoff to acywatson, stable on npm for years. ai
dependencies unvetted-dep:@lexical/helpers AI (dependencies): Same-org sibling package in the Lexical monorepo, not an unvetted third party. ai
phantom-deps phantom-dep:@lexical/helpers AI (phantom-deps): Same-org monorepo dependency; heuristic false positive. ai
phantom-deps phantom-dep:react-error-boundary AI (phantom-deps): Config-referenced error boundary; stable for this package. ai
phantom-deps phantom-dep:@lexical/code AI (phantom-deps): Same-org monorepo dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@lexical/clipboard AI (phantom-deps): Same-org monorepo dependency; stable pattern for this package. ai
phantom-deps phantom-dep:@lexical/selection AI (phantom-deps): Same-org monorepo dependency; stable pattern for this package. ai
dependencies unvetted-dep:@lexical/a11y AI (dependencies): Same-org sibling package, same version, part of lexical monorepo lockstep release. ai
publish-pattern new-deps-added AI (publish-pattern): New dep is first-party @lexical/* sibling, not an external/unrelated package. ai
provenance missing-githead AI (provenance): gitHead dropped as part of CI/CD migration; SLSA attestation provides stronger provenance. ai
provenance publisher-changed AI (provenance): Transition from manual publish (zurfyx) to GitHub Actions CI/CD is expected for facebook/lexical. ai
source-diff obfuscated-file:dist/LexicalDraggableBlockPlugin.prod.js AI (source-diff): Standard production minified bundle for this package; stable pattern across versions. ai
source-diff obfuscated-file:dist/LexicalCollaborationPlugin.prod.js AI (source-diff): Standard production minified bundle for this package; stable pattern across versions. ai
source-diff obfuscated-file:dist/LexicalCharacterLimitPlugin.prod.js AI (source-diff): Standard production minified bundle for this package; stable pattern across versions. ai
source-diff large-new-source-files AI (source-diff): Monorepo build restructuring; all files are expected dist outputs. ai
dependencies unvetted-dep:@lexical/plain-text AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/rich-text AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/extension AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/overflow AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/markdown AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/history AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/hashtag AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/dragon AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/utils AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/table AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/text AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/mark AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/list AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
dependencies unvetted-dep:@lexical/yjs AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. Not a third-party dependency. ai
dependencies unvetted-dep:@lexical/link AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai
provenance no-provenance AI (provenance): Lexical does not publish with Sigstore provenance; this is consistent across all versions and is not a security disqualifier for this established package. ai
phantom-deps phantom-dep:@lexical/mark AI (phantom-deps): Same-org sibling dependency; phantom import is a packaging detail, not a security concern for this monorepo package. ai
dependencies unvetted-dep:@lexical/devtools-core AI (dependencies): First-party sibling package in the @lexical monorepo, always released at the same version. ai

Versions (showing 51 of 136)

View all versions
Version Deps Published
0.48.0 20 / 2
0.47.0 20 / 2
0.46.0 19 / 2
0.45.0 20 / 2
0.44.0 19 / 2
0.43.0 19 / 2
0.42.0 19 / 2
0.41.0 19 / 2
0.40.0 19 / 2
0.39.0 19 / 2
0.38.2 19 / 2
0.38.1 19 / 2
0.38.0 19 / 2
0.37.0 19 / 2
0.36.2 19 / 2
0.36.1 19 / 2
0.36.0 19 / 2
0.35.0 18 / 2
0.34.0 18 / 2
0.33.1 18 / 2
0.33.0 18 / 2
0.32.1 18 / 0
0.32.0 18 / 0
0.31.2 17 / 0
0.31.1 17 / 0
0.31.0 17 / 0
0.30.0 17 / 0
0.29.0 17 / 0
0.28.0 17 / 0
0.27.2 20 / 0
0.27.1 20 / 0
0.27.0 20 / 0
0.26.0 20 / 0
0.25.0 20 / 0
0.24.0 20 / 0
0.23.1 20 / 0
0.23.0 20 / 0
0.22.0 20 / 0
0.21.0 20 / 0
0.20.2 20 / 0
0.20.1 20 / 0
0.20.0 20 / 0
0.19.0 20 / 0
0.18.0 20 / 0
0.17.1 20 / 0
0.17.0 20 / 0
0.16.1 20 / 0
0.16.0 20 / 0
0.15.0 20 / 0
0.14.5 20 / 0
0.14.4 19 / 0

v0.48.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.47.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.42.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zurfyx.

v0.41.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zurfyx.

v0.40.0

2 findings
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Missing gitHead — previous versions had it provenance

[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: zurfyx.

v0.30.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.29.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.28.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.27.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.27.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.27.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.26.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.25.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.24.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.23.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.23.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.22.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.21.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.20.2

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.20.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.20.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.19.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.18.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.17.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.17.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.16.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.16.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.15.0

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.14.5

12 findings
HIGH New obfuscated file: LexicalTypeaheadMenuPlugin.prod.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalContextMenuPlugin.prod.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalNodeMenuPlugin.prod.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalAutoLinkPlugin.prod.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalCollaborationPlugin.prod.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalCharacterLimitPlugin.prod.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalCheckListPlugin.prod.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: trueadm → acywatson (on 2024-04-17, unremoved on npm for 825d) provenance

This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2024-04-17. It has since remained available on npm for 825 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.14.4

12 findings
HIGH New obfuscated file: LexicalTypeaheadMenuPlugin.prod.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalContextMenuPlugin.prod.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalNodeMenuPlugin.prod.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.prod.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalAutoLinkPlugin.prod.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalCollaborationPlugin.prod.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.js source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalHashtagPlugin.dev.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalCharacterLimitPlugin.prod.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

HIGH New obfuscated file: LexicalCheckListPlugin.prod.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

MEDIUM Publisher changed: trueadm → acywatson (on 2024-04-16, unremoved on npm for 825d) provenance

This version was published by a different npm account (acywatson) than the most recent previously approved version (trueadm) on 2024-04-16. It has since remained available on npm for 825 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.

INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.