← Home

@lobehub/editor

A powerful and extensible rich text editor built on Meta's Lexical framework, providing a modern editing experience with React integration.

51
Versions
MIT
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

sudongyueryutengjingamazing129arvinxxcanisminor1990lobehubbotnekomeowwwrdmclin2blueboylijian

Keywords

lobehubeditorlexical

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): Lobehub org addition; SLSA provenance unchanged, no behavioral change in this or prior versions. ai
source-diff obfuscated-file:es/renderer/engine/shiki.js AI (source-diff): Standard Babel-transpiled build output for shiki renderer; not malicious. ai
source-diff obfuscated-file:es/editor-kernel/lexical/Lexical.dev.js AI (source-diff): Meta Platforms Lexical library bundled output with MIT license header; legitimate dependency artifact. ai
source-diff obfuscated-file:es/plugins/image/react/components/ImageEditPopover.js AI (source-diff): Standard Babel-transpiled build output; same pattern as other build artifacts in this package. ai
source-diff obfuscated-file:es/plugins/codemirror-block/react/CodemirrorNode.js AI (source-diff): Babel-bundled output from @lobehub/codemirror integration; not malicious obfuscation. ai
source-diff obfuscated-file:es/plugins/codemirror-block/lib/index.js AI (source-diff): Babel-bundled output from @lobehub/codemirror integration; not malicious obfuscation. ai
phantom-deps phantom-dep:@floating-ui/react AI (phantom-deps): Declared as a runtime dep and used transitively; phantom-dep heuristic false positive for this package. ai
phantom-deps phantom-dep:@lexical/code-shiki AI (phantom-deps): Part of the lexical ecosystem deps; referenced in config, stable false positive for this package. ai
publish-pattern new-deps-added AI (publish-pattern): remark/remark-gfm/remark-math are established, widely-used markdown packages; addition is consistent with editor feature expansion. ai
dependencies unvetted-dep:remark-supersub AI (dependencies): Small remark plugin for superscript/subscript syntax; low-risk utility dep consistent with this editor package's feature set. ai
phantom-deps phantom-dep:ahooks AI (phantom-deps): Bundled library; deps may be re-exported or used indirectly without direct import in analyzed files. ai
phantom-deps phantom-dep:remark-supersub AI (phantom-deps): Bundled library; deps may be re-exported or used indirectly without direct import in analyzed files. ai
phantom-deps phantom-dep:@lexical/link AI (phantom-deps): Bundled library; deps may be re-exported or used indirectly without direct import in analyzed files. ai
phantom-deps phantom-dep:ts-key-enum AI (phantom-deps): Bundled library; deps may be re-exported or used indirectly without direct import in analyzed files. ai
phantom-deps phantom-dep:polished AI (phantom-deps): Bundled library; deps may be re-exported or used indirectly without direct import in analyzed files. ai
phantom-deps phantom-dep:mermaid AI (phantom-deps): Bundled library; deps may be re-exported or used indirectly without direct import in analyzed files. ai
phantom-deps phantom-dep:react-merge-refs AI (phantom-deps): Bundled library; deps may be re-exported or used indirectly without direct import in analyzed files. ai
install-scripts install-script:postinstall AI (install-scripts): Postinstall applies a local lexical patch (documented in pnpm.patchedDependencies); not arbitrary remote code execution. ai

Versions (showing 51 of 84)

View all versions
Version Deps Published
4.20.2 40 / 35
4.18.1 38 / 35
4.17.2 38 / 35
4.17.1 38 / 35
4.17.0 38 / 35
4.16.0 38 / 35
4.15.1 35 / 36
4.14.0 35 / 36
4.13.0 35 / 36
4.12.0 35 / 36
4.11.0 35 / 36
4.10.6 35 / 36
4.10.3 35 / 36
4.10.1 35 / 36
4.10.0 35 / 36
4.9.9 35 / 36
4.9.8 35 / 36
4.9.7 35 / 36
4.9.6 35 / 36
4.9.5 35 / 36
4.9.2 35 / 36
4.9.1 35 / 36
4.8.3 35 / 36
4.8.0 35 / 36
4.7.0 35 / 36
4.6.2 34 / 36
4.6.1 34 / 36
4.6.0 35 / 36
4.5.0 35 / 36
4.2.0 34 / 36
4.1.1 33 / 36
4.0.2 33 / 36
3.12.1 33 / 36
3.11.0 33 / 36
3.5.0 33 / 36
3.4.0 33 / 36
3.3.2 33 / 36
3.3.1 33 / 36
3.3.0 34 / 36
3.2.2 33 / 36
3.2.1 33 / 36
3.2.0 33 / 36
3.1.1 33 / 36
3.1.0 33 / 39
3.0.0 33 / 39
2.2.0 34 / 38
2.1.1 34 / 38
2.1.0 34 / 38
2.0.5 34 / 38
2.0.4 34 / 38
2.0.3 34 / 38

v4.20.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.18.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.0.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.