@wangeditor-next/editor
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | missing-githead | AI (provenance): Established editor package with clean history; missing gitHead is a CI/publish process change, not a security signal. | ai | |
| source-diff | obfuscated-file:dist/upload.js | AI (source-diff): Standard minified UMD bundle with Uppy upload integration; expected build artifact. | ai | |
| source-diff | obfuscated-file:dist/upload.mjs | AI (source-diff): Standard minified ESM bundle; expected build artifact. | ai | |
| source-diff | net-exec-file:dist/core.js | AI (source-diff): Network calls are editor fetch/XHR; dynamic code execution is standard UMD wrapper pattern. | ai | |
| source-diff | net-exec-file:dist/core.mjs | AI (source-diff): Same as core.js — UMD/ESM wrapper with editor network functionality. | ai | |
| source-diff | net-exec-file:dist/upload.js | AI (source-diff): Uppy upload library bundled; network calls are file upload XHR, not exfiltration. | ai | |
| source-diff | net-exec-file:dist/upload.mjs | AI (source-diff): Same as upload.js — Uppy ESM bundle with expected upload network calls. | ai | |
| phantom-deps | phantom-dep:@wangeditor-next/list-module | AI (phantom-deps): Same-org peer dependency declared for consumers; not directly imported in this bundle. | ai | |
| phantom-deps | phantom-dep:@wangeditor-next/video-module | AI (phantom-deps): Same-org peer dependency; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@wangeditor-next/basic-modules | AI (phantom-deps): Same-org peer dependency; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@wangeditor-next/code-highlight | AI (phantom-deps): Same-org peer dependency; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@wangeditor-next/upload-image-module | AI (phantom-deps): Same-org peer dependency; stable false positive for this package. | ai | |
| source-diff | obfuscated-file:dist/core.js | AI (source-diff): Standard minified UMD bundle for a rich-text editor; not obfuscated malware. | ai | |
| source-diff | obfuscated-file:dist/core.mjs | AI (source-diff): Standard minified ESM bundle; expected build artifact. | ai | |
| phantom-deps | phantom-dep:lodash.foreach | AI (phantom-deps): Used by bundled sub-packages; stable false positive. | ai | |
| phantom-deps | phantom-dep:lodash.isequal | AI (phantom-deps): Used by bundled sub-packages; stable false positive. | ai | |
| phantom-deps | phantom-dep:lodash.toarray | AI (phantom-deps): Used by bundled sub-packages; stable false positive. | ai | |
| phantom-deps | phantom-dep:lodash.debounce | AI (phantom-deps): Used by bundled sub-packages; stable false positive. | ai | |
| phantom-deps | phantom-dep:lodash.throttle | AI (phantom-deps): Used by bundled sub-packages; stable false positive. | ai | |
| phantom-deps | phantom-dep:@uppy/xhr-upload | AI (phantom-deps): Used by bundled sub-packages; stable false positive. | ai | |
| phantom-deps | phantom-dep:lodash.camelcase | AI (phantom-deps): Used by bundled sub-packages; stable false positive. | ai | |
| phantom-deps | phantom-dep:lodash.clonedeep | AI (phantom-deps): Used by bundled sub-packages; stable false positive. | ai | |
| phantom-deps | phantom-dep:nanoid | AI (phantom-deps): Used by bundled sub-packages; stable false positive for this editor package. | ai | |
| phantom-deps | phantom-dep:is-hotkey | AI (phantom-deps): Used by bundled sub-packages; stable false positive. | ai |
Versions (showing 30 of 30)
| Version | Deps | Published |
|---|---|---|
| 6.0.2 | 20 / 3 | |
| 6.0.1 | 20 / 3 | |
| 6.0.0 | 20 / 3 | |
| 5.7.16 | 20 / 3 | |
| 5.7.15 | 20 / 3 | |
| 5.7.14 | 20 / 3 | |
| 5.7.13 | 20 / 3 | |
| 5.7.12 | 20 / 3 | |
| 5.7.11 | 20 / 3 | |
| 5.7.10 | 20 / 3 | |
| 5.7.9 | 20 / 3 | |
| 5.7.8 | 20 / 3 | |
| 5.7.7 | 20 / 3 | |
| 5.7.6 | 20 / 3 | |
| 5.7.5 | 20 / 3 | |
| 5.7.4 | 20 / 3 | |
| 5.7.3 | 20 / 3 | |
| 5.7.2 | 20 / 3 | |
| 5.7.1 | 20 / 3 | |
| 5.7.0 | 20 / 3 | |
| 5.6.56 | 20 / 3 | |
| 5.6.55 | 20 / 3 | |
| 5.6.54 | 20 / 3 | |
| 5.6.53 | 20 / 3 | |
| 5.6.52 | 20 / 3 | |
| 5.6.51 | 20 / 3 | |
| 5.6.50 | 20 / 3 | |
| 5.6.49 | 20 / 3 | |
| 5.6.48 | 20 / 3 | |
| 5.6.31 | 21 / 0 |
v6.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v6.0.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.7.16
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.7.15
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.7.14
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.7.13
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.6.56
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.6.55
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.6.54
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.6.53
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: cycleccc.
v5.6.52
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: cycleccc.
v5.6.51
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: cycleccc.
v5.6.50
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: cycleccc.
v5.6.49
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: cycleccc.
v5.6.48
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
[Accepted risk] This version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: cycleccc.