@byteplus/veplayer-plugin
## 简介 `@volcengine/veplayer-plugin` 是基于 VepPlayer 的插件集合,为 VePlayer 提供更多扩展能力和解决方案。
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | large-new-source-files | AI (source-diff): New plugin bundles for existing player features, not injected code. | ai | |
| source-diff | encoded-string-file:esm/index.development.js | AI (source-diff): Base64 WASM/codec data table, consistent with media SDK internals. | ai | |
| source-diff | obfuscated-file:umd/veplayer.strategy.rtm.adaptive.buffer.production.js | AI (source-diff): Bundled/minified build output (rollup/webpack banner), not true obfuscation. | ai | |
| source-diff | net-exec-file:umd/veplayer.strategy.rtm.adaptive.buffer.production.js | AI (source-diff): Standard bundled polyfills + wasm base64 blob for media parsing, no exfil behavior. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): Large corp publisher with strong track record; routine team rotation. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Routine team rotation for established BytePlus org account. | ai | |
| source-diff | net-exec-file:umd/veplayer.plugin.ad.production.js | AI (source-diff): Same pattern as esm variant; legitimate IMA SDK integration. | ai | |
| source-diff | obfuscated-file:esm/veplayer.plugin.hlsjs.production.js | AI (source-diff): Bundled hls.js library; minification is expected. | ai | |
| source-diff | net-exec-file:esm/veplayer.plugin.hlsjs.production.js | AI (source-diff): hls.js bundle uses Function('return this') global detection; legitimate pattern. | ai | |
| source-diff | obfuscated-file:umd/veplayer.plugin.hlsjs.production.js | AI (source-diff): Bundled hls.js UMD variant; minification expected. | ai | |
| source-diff | net-exec-file:umd/veplayer.plugin.hlsjs.production.js | AI (source-diff): Same as ESM variant; legitimate hls.js bundle pattern. | ai | |
| source-diff | net-exec-file:esm/veplayer.strategy.base.development.js | AI (source-diff): Strategy module bundle; network+exec pattern from bundled polyfills. | ai | |
| source-diff | net-exec-file:umd/veplayer.strategy.base.development.js | AI (source-diff): Strategy module bundle; same pattern. | ai | |
| source-diff | net-exec-file:esm/veplayer.strategy.base.production.js | AI (source-diff): Bundled polyfill pattern; not malicious. | ai | |
| source-diff | obfuscated-file:umd/veplayer.strategy.base.production.js | AI (source-diff): Minified UMD strategy bundle. | ai | |
| source-diff | net-exec-file:umd/veplayer.strategy.base.production.js | AI (source-diff): Same bundled polyfill pattern. | ai | |
| source-diff | net-exec-file:esm/veplayer.strategy.rtm.adaptive.buffer.development.js | AI (source-diff): RTM adaptive buffer module; bundled polyfill pattern. | ai | |
| source-diff | net-exec-file:umd/veplayer.strategy.rtm.adaptive.buffer.development.js | AI (source-diff): Same pattern. | ai | |
| source-diff | obfuscated-file:esm/veplayer.strategy.rtm.adaptive.buffer.production.js | AI (source-diff): Minified production bundle. | ai | |
| source-diff | net-exec-file:esm/veplayer.strategy.rtm.adaptive.buffer.production.js | AI (source-diff): Bundled polyfill pattern. | ai | |
| source-diff | obfuscated-file:esm/veplayer.strategy.base.production.js | AI (source-diff): Minified strategy bundle; expected for production build. | ai | |
| source-diff | obfuscated-file:esm/veplayer.plugin.ad.development.js | AI (source-diff): Standard bundled/minified media plugin output; consistent with legitimate video player package pattern. | ai | |
| source-diff | obfuscated-file:umd/veplayer.plugin.ad.development.js | AI (source-diff): Standard bundled/minified media plugin output. | ai | |
| source-diff | obfuscated-file:esm/veplayer.plugin.ad.production.js | AI (source-diff): Standard minified production bundle for ad plugin. | ai | |
| source-diff | obfuscated-file:umd/veplayer.plugin.ad.production.js | AI (source-diff): Standard minified production bundle for ad plugin. | ai | |
| source-diff | net-exec-file:esm/veplayer.plugin.ad.production.js | AI (source-diff): Network calls are IMA SDK loading; dynamic code execution is Function('return this') global detection pattern in bundled polyfills. | ai | |
| bogus-package | bogus-package | AI (bogus-package): BytePlus SDK family; missing metadata is a style issue, not a risk signal — stable across versions. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 2.12.1 | 0 / 0 | |
| 2.12.0 | 0 / 0 | |
| 2.11.1 | 0 / 0 | |
| 2.10.3 | 0 / 0 | |
| 2.10.2 | 0 / 0 | |
| 2.10.1 | 0 / 0 | |
| 2.4.0 | 0 / 0 |
v2.11.1
15 findingsModified file contains 10 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 10 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.3
17 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 10 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 10 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.2
17 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 10 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 10 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.1
17 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Modified file contains 10 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 10 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 3 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Modified file contains 1 long encoded string(s) (200+ chars). These are commonly used to hide malicious payloads.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.