← Home

@lobehub/editor

A powerful and extensible rich text editor built on Meta's Lexical framework, providing a modern editing experience with React integration.

25
Versions
MIT
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

amazing129arvinxxcanisminor1990lobehubbotnekomeowwwrdmclin2blueboylijian

Keywords

lobehubeditorlexical

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern new-deps-added AI (publish-pattern): remark/remark-gfm/remark-math are established, widely-used markdown packages; addition is consistent with editor feature expansion. ai
dependencies unvetted-dep:remark-supersub AI (dependencies): Small remark plugin for superscript/subscript syntax; low-risk utility dep consistent with this editor package's feature set. ai
phantom-deps phantom-dep:mermaid AI (phantom-deps): Bundled library; deps may be re-exported or used indirectly without direct import in analyzed files. ai
phantom-deps phantom-dep:polished AI (phantom-deps): Bundled library; deps may be re-exported or used indirectly without direct import in analyzed files. ai
phantom-deps phantom-dep:ts-key-enum AI (phantom-deps): Bundled library; deps may be re-exported or used indirectly without direct import in analyzed files. ai
install-scripts install-script:postinstall AI (install-scripts): Postinstall applies a local lexical patch (documented in pnpm.patchedDependencies); not arbitrary remote code execution. ai
phantom-deps phantom-dep:remark-supersub AI (phantom-deps): Bundled library; deps may be re-exported or used indirectly without direct import in analyzed files. ai
phantom-deps phantom-dep:react-merge-refs AI (phantom-deps): Bundled library; deps may be re-exported or used indirectly without direct import in analyzed files. ai
phantom-deps phantom-dep:@lexical/link AI (phantom-deps): Bundled library; deps may be re-exported or used indirectly without direct import in analyzed files. ai
phantom-deps phantom-dep:ahooks AI (phantom-deps): Bundled library; deps may be re-exported or used indirectly without direct import in analyzed files. ai

Versions (showing 25 of 25)

Version Deps Published
4.16.0 38 / 35
4.15.1 35 / 36
4.13.0 35 / 36
4.12.0 35 / 36
4.11.0 35 / 36
4.10.6 35 / 36
4.10.3 35 / 36
4.10.0 35 / 36
4.9.9 35 / 36
4.9.8 35 / 36
4.9.7 35 / 36
4.9.6 35 / 36
4.7.0 35 / 36
3.2.2 33 / 36
3.2.1 33 / 36
3.2.0 33 / 36
3.1.1 33 / 36
3.1.0 33 / 39
3.0.0 33 / 39
2.2.0 34 / 38
2.1.1 34 / 38
2.1.0 34 / 38
2.0.5 34 / 38
2.0.4 34 / 38
2.0.3 34 / 38

v4.16.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.15.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.13.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.12.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.11.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.10.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.10.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.9.9

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.9.8

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.9.7

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.9.6

2 findings
HIGH Package has 'postinstall' script install-scripts

Script: node ./scripts/postinstall-lexical-patch.cjs

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v4.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v2.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v2.0.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v2.0.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.