← Home

@mux/mux-player

36
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

jsanford8dylanjhaphil-muxmux-npmjs

Keywords

videomuxplayerhlsweb-component

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/base.mjs AI (source-diff): Minified build output from esbuilder; standard for this package's dist files. ai
publish-pattern dormant-publish AI (publish-pattern): Mux org package with SLSA provenance; dormancy reflects release cadence, not compromise. ai
dependencies unvetted-dep:media-chrome AI (dependencies): media-chrome is a well-known open-source media web component library; expected dependency for a video player package like @mux/mux-player. ai
dependencies unvetted-dep:player.style AI (dependencies): player.style is a CSS theming library used by Mux player; expected companion dependency with no meaningful risk. ai
dependencies unvetted-dep:@mux/mux-video AI (dependencies): First-party Mux package from the same muxinc/elements monorepo; expected core dependency. ai
dependencies unvetted-dep:@mux/playback-core AI (dependencies): First-party Mux package from the same muxinc/elements monorepo; expected core dependency. ai

Versions (showing 36 of 36)

Version Deps Published
3.13.2 4 / 18
3.13.0 4 / 18
3.12.0 4 / 18
3.11.8 4 / 18
3.11.7 4 / 18
3.11.6 4 / 18
3.11.5 4 / 18
3.11.4 4 / 18
3.10.2 4 / 18
3.10.1 4 / 18
3.10.0 4 / 18
3.9.2 4 / 18
3.9.1 4 / 18
3.9.0 4 / 18
3.8.0 4 / 18
3.7.0 4 / 18
3.6.1 4 / 18
3.6.0 4 / 18
3.5.3 4 / 18
3.5.2 4 / 18
3.5.1 4 / 18
3.5.0 4 / 18
3.4.1 4 / 18
3.4.0 4 / 18
3.3.4 4 / 18
3.3.3 4 / 18
3.3.2 4 / 18
3.3.1 4 / 18
3.3.0 4 / 18
3.2.4 4 / 18
3.2.3 4 / 18
3.2.2 4 / 18
3.2.1 4 / 18
3.2.0 4 / 18
3.1.0 4 / 18
3.0.0 4 / 16

v3.13.2

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: mux-npmjs → GitHub Actions (on unknown date, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (mux-npmjs) on unknown date, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.3.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.