@wordpress/editor
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): Active Gutenberg monorepo package; dormancy signal is a false positive for this well-established package. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @wordpress/ui is a same-org WordPress package; low risk for this monorepo. | ai | |
| phantom-deps | phantom-dep:client-zip | AI (phantom-deps): client-zip is a declared runtime dep used in build config; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:@wordpress/base-styles | AI (phantom-deps): SCSS-only dep; not imported in JS but used in build pipeline — stable false positive for this monorepo package. | ai | |
| phantom-deps | phantom-dep:@wordpress/reusable-blocks | AI (phantom-deps): Same-org dep used indirectly; phantom-dep heuristic false positive for this package. | ai |
Versions (showing 29 of 29)
| Version | Deps | Published |
|---|---|---|
| 14.51.0 | 56 / 6 | |
| 14.50.0 | 56 / 4 | |
| 14.49.1 | 56 / 4 | |
| 14.49.0 | 56 / 4 | |
| 14.48.1 | 56 / 4 | |
| 14.48.0 | 55 / 1 | |
| 14.47.0 | 55 / 1 | |
| 14.46.0 | 55 / 1 | |
| 14.45.0 | 55 / 1 | |
| 14.44.0 | 55 / 1 | |
| 14.43.0 | 55 / 1 | |
| 14.42.0 | 54 / 1 | |
| 14.41.0 | 53 / 1 | |
| 14.40.2 | 54 / 1 | |
| 14.40.1 | 53 / 1 | |
| 14.40.0 | 53 / 1 | |
| 14.39.0 | 50 / 1 | |
| 14.38.0 | 48 / 1 | |
| 14.37.0 | 48 / 0 | |
| 14.36.0 | 48 / 0 | |
| 14.35.0 | 48 / 0 | |
| 14.33.11 | 48 / 0 | |
| 14.33.10 | 48 / 0 | |
| 14.33.9 | 48 / 0 | |
| 14.33.8 | 48 / 0 | |
| 14.33.7 | 48 / 0 | |
| 14.33.6 | 48 / 0 | |
| 14.33.5 | 48 / 0 | |
| 14.33.4 | 48 / 0 |
v14.51.0
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (desrosj) than the most recent previously approved version (gutenbergplugin) on 2026-07-14, but desrosj is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v14.50.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.49.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.49.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.42.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.41.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.40.2
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (desrosj) than the most recent previously approved version (gutenbergplugin) on 2026-06-30, but desrosj is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v14.40.1
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (gutenbergplugin) than the most recent previously approved version (peterwilsoncc) on 2026-02-23, but gutenbergplugin is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v14.40.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.39.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.38.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.37.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.36.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.35.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.33.11
2 findingsPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
This version was published by a different npm account (peterwilsoncc) than the most recent previously approved version (gutenbergplugin) on 2026-01-29, but peterwilsoncc is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v14.33.10
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.33.9
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.33.8
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.33.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.33.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v14.33.5
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v14.33.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.