@wix/editor
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:@wix/admin | AI (dependencies): Internal Wix dependency consistent with this package's ecosystem; stable pattern across versions. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Wix internal CI-published package; no repo/keywords/homepage is standard for their monorepo artifacts. | ai | |
| license | uncommon-license:UNLICENSED | AI (license): Proprietary Wix package; UNLICENSED is appropriate for internal corporate packages. | ai | |
| provenance | no-provenance | AI (provenance): Internal Wix package; provenance attestation is a best-practice enhancement, not a blocker. | ai | |
| dependencies | unvetted-dep:@wix/editor-platform-environment-api | AI (dependencies): Internal @wix/* scoped dep consistent with Wix ecosystem. | ai | |
| dependencies | unvetted-dep:@wix/workspace | AI (dependencies): Internal @wix/* scoped dep consistent with Wix ecosystem; stable pattern across versions. | ai | |
| dependencies | unvetted-dep:@wix/public-editor-platform-interfaces | AI (dependencies): Internal @wix/* scoped dep consistent with Wix ecosystem. | ai | |
| dependencies | unvetted-dep:@wix/editor-platform-contexts | AI (dependencies): Internal @wix/* scoped dep consistent with Wix ecosystem. | ai | |
| dependencies | unvetted-dep:@wix/monitoring-browser-sdk-host | AI (dependencies): Internal @wix/* scoped dep consistent with Wix ecosystem. | ai | |
| dependencies | unvetted-dep:@wix/public-editor-platform-errors | AI (dependencies): Internal @wix/* scoped dep consistent with Wix ecosystem. | ai |
Versions (showing 100 of 221)
| Version | Deps | Published |
|---|---|---|
| 1.478.0 | 8 / 12 | |
| 1.477.0 | 8 / 12 | |
| 1.476.0 | 8 / 12 | |
| 1.475.0 | 8 / 12 | |
| 1.474.0 | 8 / 12 | |
| 1.473.0 | 8 / 12 | |
| 1.472.0 | 8 / 12 | |
| 1.471.0 | 8 / 12 | |
| 1.470.0 | 8 / 12 | |
| 1.469.0 | 8 / 12 | |
| 1.468.0 | 8 / 12 | |
| 1.467.0 | 8 / 12 | |
| 1.466.0 | 8 / 12 | |
| 1.465.0 | 8 / 12 | |
| 1.464.0 | 8 / 12 | |
| 1.463.0 | 8 / 12 | |
| 1.462.0 | 8 / 12 | |
| 1.461.0 | 8 / 12 | |
| 1.460.0 | 8 / 12 | |
| 1.459.0 | 8 / 12 | |
| 1.458.0 | 8 / 12 | |
| 1.457.0 | 8 / 12 | |
| 1.456.0 | 8 / 12 | |
| 1.455.0 | 8 / 12 | |
| 1.454.0 | 8 / 12 | |
| 1.453.0 | 8 / 12 | |
| 1.452.0 | 8 / 12 | |
| 1.451.0 | 8 / 12 | |
| 1.450.0 | 8 / 12 | |
| 1.449.0 | 8 / 12 | |
| 1.448.0 | 8 / 12 | |
| 1.447.0 | 8 / 12 | |
| 1.446.0 | 8 / 12 | |
| 1.445.0 | 8 / 12 | |
| 1.444.0 | 8 / 12 | |
| 1.443.0 | 8 / 12 | |
| 1.442.0 | 8 / 12 | |
| 1.441.0 | 8 / 12 | |
| 1.440.0 | 8 / 12 | |
| 1.439.0 | 8 / 12 | |
| 1.438.0 | 8 / 11 | |
| 1.437.0 | 8 / 11 | |
| 1.436.0 | 8 / 11 | |
| 1.435.0 | 8 / 11 | |
| 1.434.0 | 8 / 11 | |
| 1.433.0 | 8 / 11 | |
| 1.432.0 | 8 / 11 | |
| 1.431.0 | 8 / 10 | |
| 1.430.0 | 8 / 10 | |
| 1.429.0 | 8 / 10 | |
| 1.428.0 | 8 / 10 | |
| 1.427.0 | 8 / 10 | |
| 1.426.0 | 8 / 10 | |
| 1.425.0 | 8 / 10 | |
| 1.424.0 | 8 / 10 | |
| 1.423.0 | 8 / 10 | |
| 1.422.0 | 8 / 10 | |
| 1.421.0 | 8 / 10 | |
| 1.420.0 | 8 / 10 | |
| 1.419.0 | 8 / 10 | |
| 1.416.0 | 8 / 10 | |
| 1.415.0 | 8 / 10 | |
| 1.414.0 | 8 / 10 | |
| 1.413.0 | 8 / 10 | |
| 1.412.0 | 8 / 10 | |
| 1.411.0 | 8 / 10 | |
| 1.410.0 | 8 / 10 | |
| 1.409.0 | 8 / 10 | |
| 1.408.0 | 8 / 10 | |
| 1.407.0 | 8 / 10 | |
| 1.406.0 | 8 / 10 | |
| 1.405.0 | 8 / 10 | |
| 1.404.0 | 8 / 10 | |
| 1.403.0 | 8 / 10 | |
| 1.402.0 | 8 / 10 | |
| 1.401.0 | 8 / 10 | |
| 1.400.0 | 8 / 10 | |
| 1.399.0 | 8 / 10 | |
| 1.398.0 | 8 / 10 | |
| 1.397.0 | 8 / 10 | |
| 1.396.0 | 8 / 10 | |
| 1.395.0 | 8 / 10 | |
| 1.394.0 | 8 / 10 | |
| 1.393.0 | 7 / 10 | |
| 1.392.0 | 7 / 10 | |
| 1.391.0 | 7 / 10 | |
| 1.390.0 | 7 / 10 | |
| 1.389.0 | 7 / 10 | |
| 1.388.0 | 7 / 10 | |
| 1.387.0 | 7 / 10 | |
| 1.386.0 | 7 / 10 | |
| 1.385.0 | 7 / 10 | |
| 1.384.0 | 7 / 10 | |
| 1.383.0 | 7 / 10 | |
| 1.382.0 | 7 / 10 | |
| 1.381.0 | 7 / 10 | |
| 1.380.0 | 7 / 10 | |
| 1.379.0 | 7 / 10 | |
| 1.378.0 | 7 / 10 | |
| 1.377.0 | 7 / 10 |
v1.478.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.477.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.476.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.475.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.474.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.473.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.472.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.471.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.470.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.469.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.468.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.467.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.466.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.465.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.464.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.463.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.462.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.461.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.460.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.459.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.458.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.457.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.456.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.455.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.454.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.453.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.452.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.451.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.450.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.449.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.448.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.447.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.446.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.445.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.444.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.443.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.442.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.441.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.440.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.439.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.438.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.437.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.436.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.435.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.434.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.433.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.432.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.431.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.430.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.429.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.428.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.427.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.426.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.425.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.424.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.423.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.422.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.421.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.420.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.419.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.416.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.415.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.414.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.413.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.412.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.411.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.410.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.409.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.408.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.407.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.406.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.405.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.404.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.403.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.402.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.401.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.400.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.399.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.398.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.397.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.396.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.395.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.394.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.393.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.392.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.391.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.390.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.389.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.388.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.387.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.386.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.385.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.384.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.383.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.382.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.381.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.380.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.379.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.378.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.377.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.