← Home

@tiptap/react

81
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

arnaugomeztiptappatrickbabertimoisik_bdbchsvenadlungtiptap-bot

Keywords

tiptaptiptap react components

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
semgrep semgrep:api-obfuscation-reflect AI (semgrep): Reflect.get() is used as the standard Proxy trap fallback in ReactNodeViewRenderer — idiomatic JS Proxy pattern, not obfuscation. Stable for this package. ai
phantom-deps phantom-dep:@types/use-sync-external-store AI (phantom-deps): @types/use-sync-external-store provides types for the co-listed use-sync-external-store dependency; its presence as a runtime dep is a packaging convention, not a security concern. ai

Versions (showing 81 of 81)

Version Deps Published
3.29.2 3 / 6
3.29.1 3 / 6
3.29.0 3 / 6
3.28.0 3 / 6
3.27.4 3 / 6
3.27.3 3 / 6
3.27.2 3 / 6
3.27.1 3 / 6
3.27.0 3 / 6
3.26.1 3 / 6
3.26.0 3 / 6
3.25.0 3 / 6
3.24.0 3 / 6
3.23.6 3 / 6
3.23.5 3 / 6
3.23.4 3 / 6
3.23.2 3 / 6
3.23.1 3 / 6
3.22.5 3 / 6
3.22.4 3 / 6
3.22.3 3 / 6
3.22.2 3 / 6
3.22.1 3 / 6
3.22.0 3 / 6
3.21.0 3 / 6
3.20.6 3 / 6
3.13.0 3 / 6
3.12.1 3 / 6
3.12.0 3 / 6
3.11.1 3 / 6
3.11.0 3 / 6
3.10.8 3 / 6
3.10.7 3 / 6
3.10.6 3 / 6
3.10.5 3 / 6
3.10.4 3 / 6
3.10.3 3 / 6
3.10.2 3 / 6
3.10.1 3 / 6
3.10.0 3 / 6
3.9.1 3 / 6
3.9.0 3 / 6
3.8.0 3 / 6
3.7.2 3 / 6
3.7.1 3 / 6
3.7.0 3 / 6
3.6.7 3 / 6
3.6.6 3 / 6
3.6.5 3 / 6
3.6.4 3 / 6
3.6.3 3 / 6
3.6.2 3 / 6
3.6.1 3 / 6
3.6.0 3 / 6
3.5.3 3 / 6
3.5.2 3 / 6
3.5.1 3 / 6
3.5.0 3 / 6
3.4.6 3 / 6
3.4.5 3 / 6
3.4.4 3 / 6
3.4.3 3 / 6
3.4.2 3 / 6
3.4.1 3 / 6
3.4.0 3 / 6
3.3.1 3 / 6
3.3.0 3 / 6
3.2.2 3 / 6
3.2.1 3 / 6
3.2.0 3 / 6
3.1.0 3 / 6
3.0.9 3 / 6
3.0.8 3 / 6
3.0.7 3 / 6
3.0.6 3 / 6
3.0.5 3 / 6
3.0.4 3 / 6
3.0.3 3 / 6
3.0.2 3 / 6
3.0.1 3 / 6
3.0.0 4 / 6

v3.29.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.29.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.29.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.28.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.27.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.