← Home

@mux/ai

AI library for Mux

35
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

mux-npmjsdylanjhaphil-muxjsanford8

Keywords

muxvideoaillmopenaianthropicgooglegeminimultimodalvideo-analysissummarizationmoderationcaptionstranslationdubbingchaptersembeddingstypescript

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/index-CA7bG50u.d.ts AI (source-diff): TypeScript declaration file with long type lines from AI SDK generics; not obfuscated code. ai
provenance publisher-changed AI (provenance): Transition from individual maintainer to GitHub Actions CI publisher is consistent with Mux org automation; package metadata and repo URL unchanged. ai
source-diff obfuscated-file:dist/index-0a27mjs2.d.ts AI (source-diff): Bundled .d.ts type declaration files routinely have long lines; sample shows readable JSDoc and type exports, not obfuscation. ai
source-diff obfuscated-file:dist/index-BfsJvx3r.d.ts AI (source-diff): Bundled .d.ts files routinely have long lines from complex generics; sample shows readable TypeScript types, not obfuscation. ai
phantom-deps phantom-dep:p-retry AI (phantom-deps): Conditional SDK loading pattern; stable for this package. ai
phantom-deps phantom-dep:dotenv AI (phantom-deps): Conditional SDK loading pattern; stable for this package. ai
phantom-deps phantom-dep:openai AI (phantom-deps): Conditional SDK loading pattern; stable for this package. ai
phantom-deps phantom-dep:@mux/mux-node AI (phantom-deps): Same-org scoped package; conditional loading pattern. ai
phantom-deps phantom-dep:@anthropic-ai/sdk AI (phantom-deps): Conditional SDK loading pattern; stable for this package. ai
phantom-deps phantom-dep:@aws-sdk/client-s3 AI (phantom-deps): Framework-scoped SDK; conditional loading pattern. ai
phantom-deps phantom-dep:@aws-sdk/lib-storage AI (phantom-deps): Framework-scoped SDK; conditional loading pattern. ai
phantom-deps phantom-dep:@aws-sdk/s3-request-presigner AI (phantom-deps): Framework-scoped SDK; conditional loading pattern. ai
phantom-deps phantom-dep:zod AI (phantom-deps): Conditional SDK loading pattern; stable for this package. ai
source-diff obfuscated-file:dist/index-yn3fUDgv.d.ts AI (source-diff): Generated .d.ts bundle from tsup; long lines are complex TypeScript generics, not obfuscation. ai
typosquat typosquat.levenshtein:ajv AI (typosquat): Scoped @mux/ai package from legitimate Mux org; not a typosquat of ajv. ai
phantom-deps phantom-dep:dotenv-expand AI (phantom-deps): dotenv-expand is a listed runtime dependency; phantom-dep heuristic misfires here. ai
typosquat typosquat.levenshtein:qs AI (typosquat): Scoped @mux/ai package from legitimate Mux org; not a typosquat of qs. ai
typosquat typosquat.levenshtein:hapi AI (typosquat): Scoped @mux/ai package from legitimate Mux org; not a typosquat of hapi. ai
typosquat typosquat.levenshtein:pg AI (typosquat): Scoped @mux/ai package from legitimate Mux org; not a typosquat of pg. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped @mux/ai package from legitimate Mux org; not a typosquat of joi. ai

Versions (showing 35 of 35)

Version Deps Published
0.22.0 11 / 16
0.20.0 11 / 16
0.19.0 11 / 16
0.18.0 11 / 16
0.17.1 11 / 16
0.17.0 11 / 16
0.16.1 11 / 16
0.15.1 11 / 16
0.14.0 11 / 16
0.13.1 11 / 16
0.13.0 11 / 16
0.12.1 11 / 16
0.10.0 11 / 16
0.9.0 11 / 16
0.8.2 11 / 16
0.8.1 11 / 16
0.8.0 11 / 16
0.7.6 11 / 16
0.7.5 11 / 16
0.7.4 11 / 16
0.7.3 11 / 16
0.7.2 11 / 16
0.6.0 14 / 16
0.4.2 13 / 16
0.4.0 13 / 15
0.3.1 13 / 15
0.3.0 13 / 15
0.2.0 13 / 15
0.1.6 12 / 14
0.1.5 12 / 14
0.1.4 12 / 14
0.1.3 12 / 14
0.1.2 9 / 7
0.1.1 9 / 6
0.1.0 9 / 6

v0.22.0

2 findings
HIGH New obfuscated file: dist/index-0a27mjs2.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.20.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.19.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.18.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.17.0

2 findings
HIGH New obfuscated file: dist/index-BfsJvx3r.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.16.1

2 findings
HIGH New obfuscated file: dist/index-BfsJvx3r.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.15.1

2 findings
HIGH New obfuscated file: dist/index-yn3fUDgv.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.14.0

2 findings
HIGH New obfuscated file: dist/index-yn3fUDgv.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.13.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.12.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.10.0

2 findings
HIGH New obfuscated file: dist/index-CA7bG50u.d.ts source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.6

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.7.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.3.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.6

2 findings
HIGH Publisher changed: phil-mux → GitHub Actions (on 2025-12-04) provenance

This version was published by a different npm account than previous versions on 2025-12-04. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.5

2 findings
HIGH Publisher changed: phil-mux → GitHub Actions (on 2025-12-03) provenance

This version was published by a different npm account than previous versions on 2025-12-03. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.4

2 findings
HIGH Publisher changed: phil-mux → GitHub Actions (on 2025-12-03) provenance

This version was published by a different npm account than previous versions on 2025-12-03. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.