← Home

@tiptap/pm

prosemirror wrapper package for tiptap

51
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

arnaugomeztiptappatrickbabertimoisik_bdbchsvenadlungtiptap-bot

Keywords

prosemirrortiptap

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
publish-pattern dormant-publish AI (publish-pattern): tiptap-bot has strong track record (210 approved); SLSA provenance confirms CI/CD publish; no content changes from prior approved version. ai
dependencies unvetted-dep:prosemirror-menu AI (dependencies): prosemirror-menu is a canonical ProseMirror ecosystem package; its use as a dependency of @tiptap/pm is expected and stable across versions. ai
dependencies unvetted-dep:prosemirror-collab AI (dependencies): prosemirror-collab is a canonical ProseMirror ecosystem package; its use as a dependency of @tiptap/pm is expected and stable across versions. ai
dependencies unvetted-dep:prosemirror-inputrules AI (dependencies): prosemirror-inputrules is a canonical ProseMirror ecosystem package; its use as a dependency of @tiptap/pm is expected and stable across versions. ai
dependencies unvetted-dep:prosemirror-schema-basic AI (dependencies): prosemirror-schema-basic is a canonical ProseMirror ecosystem package; its use as a dependency of @tiptap/pm is expected and stable across versions. ai
dependencies unvetted-dep:prosemirror-trailing-node AI (dependencies): prosemirror-trailing-node is a well-known ProseMirror plugin; its use as a dependency of @tiptap/pm is expected and stable across versions. ai
typosquat typosquat.levenshtein:pg AI (typosquat): @tiptap/pm is a scoped package where 'pm' stands for ProseMirror. It is not a typosquat of the PostgreSQL client 'pg'. This is a stable false positive for this package. ai
typosquat typosquat.levenshtein:qs AI (typosquat): @tiptap/pm is a legitimate scoped ProseMirror wrapper package, not a typosquat of 'qs'. Stable false positive. ai
dependencies unvetted-dep:prosemirror-tables AI (dependencies): prosemirror-tables is an official ProseMirror ecosystem package, entirely expected as a dependency of a ProseMirror wrapper. ai
dependencies unvetted-dep:prosemirror-changeset AI (dependencies): prosemirror-changeset is an official ProseMirror ecosystem package, entirely expected as a dependency of a ProseMirror wrapper. ai
dependencies unvetted-dep:prosemirror-gapcursor AI (dependencies): prosemirror-gapcursor is an official ProseMirror ecosystem package, entirely expected as a dependency of a ProseMirror wrapper. ai
dependencies unvetted-dep:prosemirror-schema-list AI (dependencies): prosemirror-schema-list is an official ProseMirror ecosystem package, entirely expected as a dependency of a ProseMirror wrapper. ai

Versions (showing 51 of 80)

View all versions
Version Deps Published
3.29.1 13 / 0
3.29.0 13 / 0
3.28.0 13 / 0
3.27.4 13 / 0
3.27.3 13 / 0
3.27.2 13 / 0
3.27.1 13 / 0
3.27.0 13 / 0
3.26.1 13 / 0
3.26.0 13 / 0
3.25.0 13 / 0
3.24.0 13 / 0
3.23.6 12 / 0
3.23.5 12 / 0
3.23.4 12 / 0
3.23.2 12 / 0
3.23.1 12 / 0
3.22.5 12 / 0
3.22.4 12 / 0
3.22.3 18 / 0
3.22.2 18 / 0
3.22.1 18 / 0
3.22.0 18 / 0
3.21.0 18 / 0
3.20.6 18 / 0
3.13.0 18 / 0
3.12.1 18 / 0
3.12.0 18 / 0
3.11.1 18 / 0
3.11.0 18 / 0
3.10.8 18 / 0
3.10.7 18 / 0
3.10.6 18 / 0
3.10.5 18 / 0
3.10.4 18 / 0
3.10.3 18 / 0
3.10.2 18 / 0
3.10.1 18 / 0
3.10.0 18 / 0
3.9.1 18 / 0
3.9.0 18 / 0
3.8.0 18 / 0
3.7.2 18 / 0
3.7.1 18 / 0
3.7.0 18 / 0
3.6.7 18 / 0
3.6.6 18 / 0
3.6.5 18 / 0
3.6.4 18 / 0
3.6.3 18 / 0
3.6.2 18 / 0

v3.29.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.29.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.28.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.22.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.22.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.20.6

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: tiptap-bot → GitHub Actions (on 2026-03-27, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (tiptap-bot) on 2026-03-27, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.