jodit
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:es5/polyfills.fat.min.js | AI (source-diff): Webpack-bundled polyfills with standard UMD wrapper and globalThis fallback; not malicious. | ai | |
| source-diff | net-exec-file:es5/polyfills.js | AI (source-diff): Webpack-bundled polyfills with standard UMD wrapper and globalThis fallback; not malicious. | ai | |
| source-diff | net-exec-file:es5/polyfills.min.js | AI (source-diff): Minified variant of the same polyfills bundle; not malicious. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher changed from xdan to GitHub Actions CI/CD with SLSA provenance from the same canonical repo (xdan/jodit). This is a pipeline modernization. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Jodit is a long-established WYSIWYG editor (3719 days, 720 versions) with no relation to the 'joi' validation library. The name similarity is coincidental; this is a stable false positive. | ai | |
| semgrep | semgrep:new-function-constructor | AI (semgrep): The new Function() call is in a webpack runtime polyfill for globalThis resolution — a standard, benign pattern in bundled ES5 output. Not a security concern for this package. | ai |
Versions (showing 48 of 48)
| Version | Deps | Published |
|---|---|---|
| 4.13.10 | 0 / 0 | |
| 4.13.9 | 0 / 0 | |
| 4.13.8 | 0 / 0 | |
| 4.13.7 | 0 / 0 | |
| 4.13.6 | 0 / 0 | |
| 4.13.5 | 0 / 0 | |
| 4.13.3 | 0 / 0 | |
| 4.12.44 | 0 / 0 | |
| 4.12.43 | 0 / 0 | |
| 4.12.41 | 0 / 0 | |
| 4.12.39 | 0 / 0 | |
| 4.12.38 | 0 / 0 | |
| 4.12.37 | 0 / 0 | |
| 4.12.36 | 0 / 0 | |
| 4.12.35 | 0 / 0 | |
| 4.12.34 | 0 / 0 | |
| 4.12.33 | 0 / 0 | |
| 4.12.32 | 0 / 0 | |
| 4.12.31 | 0 / 0 | |
| 4.12.30 | 0 / 0 | |
| 4.12.29 | 0 / 0 | |
| 4.12.28 | 0 / 0 | |
| 4.12.27 | 0 / 0 | |
| 4.12.26 | 0 / 0 | |
| 4.12.25 | 0 / 0 | |
| 4.12.24 | 0 / 0 | |
| 4.12.23 | 0 / 0 | |
| 4.12.22 | 0 / 0 | |
| 4.12.21 | 0 / 0 | |
| 4.12.20 | 0 / 0 | |
| 4.12.18 | 0 / 0 | |
| 4.12.17 | 0 / 0 | |
| 4.12.16 | 0 / 0 | |
| 4.12.15 | 0 / 0 | |
| 4.12.14 | 0 / 0 | |
| 4.12.13 | 0 / 0 | |
| 4.12.12 | 0 / 0 | |
| 4.12.11 | 0 / 0 | |
| 4.12.10 | 0 / 0 | |
| 4.12.9 | 0 / 0 | |
| 4.12.8 | 0 / 0 | |
| 4.12.7 | 0 / 0 | |
| 4.12.6 | 0 / 0 | |
| 4.12.5 | 0 / 0 | |
| 4.12.4 | 0 / 0 | |
| 4.12.3 | 0 / 0 | |
| 4.12.2 | 0 / 0 | |
| 4.6.12 | 1 / 0 |
v4.13.10
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.13.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.13.8
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.13.7
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.13.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.13.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.13.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.12.44
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.12.43
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.12.41
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.12.39
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.12.38
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.12.37
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.12.36
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.12.35
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.12.34
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v4.12.33
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.