
Research
/Security News
OpenAPI React Query Codegen Compromised in Mini Shai-Hulud npm Supply Chain Attack
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.
@react-email/editor
Advanced tools
A rich text editor for editing and building email templates, built on top of Tiptap and React Email.
packages/editor/src/
├── core/ # Editor core: hooks, serializer, event bus, types
├── extensions/ # Tiptap extensions for email elements (button, heading, columns, etc.)
├── plugins/ # ProseMirror plugins
├── ui/ # UI components (bubble menus, slash command, inspector)
├── utils/ # Shared utilities
└── email-editor/ # Main editor component
The package exposes multiple entry points for granular imports:
@react-email/editor — Main editor component and top-level API@react-email/editor/core — Serializer, types, and event bus@react-email/editor/extensions — Tiptap extensions for all supported email elements@react-email/editor/ui — UI components (bubble menus, slash command, inspector)@react-email/editor/plugins — ProseMirror plugins@react-email/editor/utils — Shared utilitiesnpm install @react-email/editor
# Build the package
pnpm build
# Run type checking
pnpm typecheck
# Run all tests
pnpm test
# Run unit tests only
pnpm test:unit
# Run browser tests only
pnpm test:browser
# Watch mode for tests
pnpm test:watch
For full usage guide and API reference, see the Editor documentation.
MIT
FAQs
A rich text editor for editing and building email templates
The npm package @react-email/editor receives a total of 61,128 weekly downloads. As such, @react-email/editor popularity was classified as popular.
We found that @react-email/editor demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 5 open source maintainers collaborating on the project.

Research
/Security News
Ten malicious OpenAPI React Query Codegen versions were published to npm in the Mini Shai-Hulud attack, all with valid provenance.

Security News
Socket joins more than 100 technology, cybersecurity, and financial organizations calling for a global surge in cyber defense.

Product
Enterprise security teams can now detect malware, credential theft, suspicious network activity, and risky updates across Microsoft Edge extensions.