← Home

@tailor-cms/ce-html-edit

Tailor CMS HTML editor authoring component

5
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures No source commit

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

droguljicee_adminikovacundersc0perkusan00

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@intevation/tiptap-extension-office-paste AI (phantom-deps): Bundled build pattern; stable FP. ai
phantom-deps phantom-dep:@tiptap/extension-placeholder AI (phantom-deps): Bundled build pattern; stable FP. ai
phantom-deps phantom-dep:@tiptap/extension-superscript AI (phantom-deps): Bundled build pattern; stable FP. ai
phantom-deps phantom-dep:@tiptap/extension-table-header AI (phantom-deps): Bundled build pattern; stable FP. ai
phantom-deps phantom-dep:lodash-es AI (phantom-deps): Bundled Vue component; lodash-es used at build time, not directly imported in analyzed files. ai
phantom-deps phantom-dep:validator AI (phantom-deps): Same bundled build pattern; stable false positive for this package. ai
phantom-deps phantom-dep:@tiptap/pm AI (phantom-deps): Tiptap peer/transitive dep resolved at build time; stable FP. ai
phantom-deps phantom-dep:@tiptap/starter-kit AI (phantom-deps): Bundled build pattern; stable FP for this package. ai
phantom-deps phantom-dep:@tiptap/extension-color AI (phantom-deps): Bundled build pattern; stable FP. ai
phantom-deps phantom-dep:@tiptap/extension-table AI (phantom-deps): Bundled build pattern; stable FP. ai
phantom-deps phantom-dep:@tiptap/extension-highlight AI (phantom-deps): Bundled build pattern; stable FP. ai
phantom-deps phantom-dep:@tiptap/extension-paragraph AI (phantom-deps): Bundled build pattern; stable FP. ai
phantom-deps phantom-dep:@tiptap/extension-subscript AI (phantom-deps): Bundled build pattern; stable FP. ai
phantom-deps phantom-dep:@tiptap/extension-table-row AI (phantom-deps): Bundled build pattern; stable FP. ai
phantom-deps phantom-dep:@tiptap/extension-underline AI (phantom-deps): Bundled build pattern; stable FP. ai
phantom-deps phantom-dep:@tiptap/extension-text-align AI (phantom-deps): Bundled build pattern; stable FP. ai
phantom-deps phantom-dep:@tiptap/extension-font-family AI (phantom-deps): Bundled build pattern; stable FP. ai
bogus-package bogus-package AI (bogus-package): Package is part of the established @tailor-cms org (author field links to github.com/tailor-cms). Missing README/keywords/repo URL are quality issues, not security signals. ai
provenance no-provenance AI (provenance): No provenance is common (~88% of npm packages); no other risk signals elevate this concern for this package. ai
phantom-deps phantom-dep:@tailor-cms/cek-common AI (phantom-deps): Same-org package; phantom dep flag is expected for intra-org dependencies in a monorepo/component library setup. ai

Versions (showing 5 of 5)

Version Deps Published
2.0.0 16 / 10
0.2.1 15 / 8
0.1.6 22 / 8
0.1.5 22 / 8
0.1.4 22 / 8

v2.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.6

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.5

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.4

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.