← Home

@tiptap/extension-gapcursor

99
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures No source commit

Maintainers

arnaugomeztiptappatrickbabertimoisik_bdbchsvenadlungtiptap-bot

Keywords

tiptaptiptap extension

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): tiptap-bot is the official tiptap organization's automated publishing account with 95 approved packages; publisher change reflects legitimate org-wide shift to bot publishing. ai
maintainer-change maintainer-added AI (maintainer-change): arnaugomeztiptap username clearly identifies a tiptap team member; addition is consistent with legitimate org growth, not a hostile takeover. ai
provenance missing-githead AI (provenance): SLSA provenance attestation via Sigstore provides stronger supply chain integrity than gitHead; missing gitHead is expected in CI/CD bot publishing environments. ai
publish-pattern dormant-publish AI (publish-pattern): Gap reflects major version jump (v2 → v3) for tiptap; large version bumps naturally follow extended development periods in monorepos. ai

Versions (showing 99 of 99)

Version Deps Published
3.29.2 0 / 1
3.29.1 0 / 1
3.29.0 0 / 1
3.28.0 0 / 1
3.27.4 0 / 1
3.27.3 0 / 1
3.27.2 0 / 1
3.27.1 0 / 1
3.27.0 0 / 1
3.26.1 0 / 1
3.26.0 0 / 1
3.25.0 0 / 1
3.24.0 0 / 1
3.23.6 0 / 1
3.23.5 0 / 1
3.23.4 0 / 1
3.23.2 0 / 1
3.23.1 0 / 1
3.22.5 0 / 1
3.22.4 0 / 1
3.22.3 0 / 1
3.22.2 0 / 1
3.22.1 0 / 1
3.22.0 0 / 1
3.21.0 0 / 1
3.20.6 0 / 1
3.20.5 0 / 1
3.20.4 0 / 1
3.20.3 0 / 1
3.20.2 0 / 1
3.20.1 0 / 1
3.20.0 0 / 1
3.19.0 0 / 1
3.18.0 0 / 1
3.17.1 0 / 1
3.17.0 0 / 1
3.16.0 0 / 1
3.15.3 0 / 1
3.15.2 0 / 1
3.15.1 0 / 1
3.15.0 0 / 1
3.14.0 0 / 1
3.13.0 0 / 1
3.12.1 0 / 1
3.12.0 0 / 1
3.11.1 0 / 1
3.11.0 0 / 1
3.10.8 0 / 1
3.10.7 0 / 1
3.10.6 0 / 1
3.10.5 0 / 1
3.10.4 0 / 1
3.10.3 0 / 1
3.10.2 0 / 1
3.10.1 0 / 1
3.10.0 0 / 1
3.9.1 0 / 1
3.9.0 0 / 1
3.8.0 0 / 1
3.7.2 0 / 1
3.7.1 0 / 1
3.7.0 0 / 1
3.6.7 0 / 1
3.6.6 0 / 1
3.6.5 0 / 1
3.6.4 0 / 1
3.6.3 0 / 1
3.6.2 0 / 1
3.6.1 0 / 1
3.6.0 0 / 1
3.5.3 0 / 1
3.5.2 0 / 1
3.5.1 0 / 1
3.5.0 0 / 1
3.4.6 0 / 1
3.4.5 0 / 1
3.4.4 0 / 1
3.4.3 0 / 1
3.4.2 0 / 1
3.4.1 0 / 1
3.4.0 0 / 1
3.3.1 0 / 1
3.3.0 0 / 1
3.2.2 0 / 1
3.2.1 0 / 1
3.2.0 0 / 1
3.1.0 0 / 1
3.0.9 0 / 1
3.0.8 0 / 1
3.0.7 0 / 1
3.0.6 0 / 1
3.0.5 0 / 1
3.0.4 0 / 1
3.0.3 0 / 1
3.0.2 0 / 1
3.0.1 0 / 1
3.0.0 0 / 2
2.27.1 0 / 2
2.27.0 0 / 2

v3.29.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.29.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.29.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.28.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.