← Home

draft-js

A React framework for building text editors.

27
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

claudioprofbflarniesophiebitszpao

Keywords

draftjseditorreactrichtext

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
maintainer-change maintainer-added AI (maintainer-change): draft-js is a Facebook/Meta OSS project; claudiopro and sophiebits are known Meta engineers. Maintainer transition is legitimate. ai
maintainer-change maintainer-removed AI (maintainer-change): Removal of hellendag and tylercraft is consistent with a legitimate team transition at Meta for this well-established OSS project. ai
provenance publisher-changed AI (provenance): Publisher change from flarnie to claudiopro reflects a legitimate Meta/Facebook internal maintainer transition; both are known Meta engineers contributing to draft-js. ai
source-diff large-new-source-files AI (source-diff): Minor version bump (0.10.5 → 0.11.2) for an active framework naturally adds source files; no obfuscation or suspicious code patterns indicated. ai
provenance no-provenance AI (provenance): Package published in 2019, predating npm Sigstore provenance support; absence is expected for this era. ai
bogus-package bogus-package AI (bogus-package): Stub/placeholder version with no content is expected for draft-js 0.0.0; the package is legitimate and published by a highly trusted author with a long track record. ai
npm-metadata suspicious-initial-version AI (npm-metadata): 0.0.0 is a legitimate placeholder/stub version for this well-established package published by a trusted, long-standing npm publisher (zpao). ai
dependencies unvetted-dep:fbjs AI (dependencies): fbjs is Facebook's own utility library, a stable and expected dependency for draft-js across all versions. ai
dependencies unvetted-dep:immutable AI (dependencies): immutable (Immutable.js) is a well-known, widely-used data structure library; a stable and expected dependency for draft-js. ai

Versions (showing 27 of 27)

Version Deps Published
0.11.7 3 / 38
0.11.6 3 / 38
0.11.5 3 / 38
0.11.4 3 / 39
0.11.2 3 / 41
0.11.1 3 / 41
0.11.0 3 / 40
0.10.5 3 / 37
0.10.4 3 / 35
0.10.3 4 / 34
0.10.2 3 / 34
0.10.1 3 / 32
0.10.0 3 / 31
0.9.1 3 / 31
0.9.0 3 / 31
0.8.1 3 / 31
0.8.0 2 / 32
0.7.0 2 / 27
0.6.0 2 / 27
0.5.0 2 / 27
0.4.0 2 / 27
0.3.0 2 / 26
0.2.2 2 / 24
0.2.1 2 / 24
0.2.0 2 / 24
0.1.0 2 / 22
0.0.0 0 / 0