← Home

@mux/mux-player-react

36
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

jsanford8dylanjhaphil-muxmux-npmjs

Keywords

videomuxplayerhlsreact

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/-SWV3FE67.mjs AI (source-diff): esbuild-minified bundle output, not obfuscation; expected for this build pipeline. ai
source-diff obfuscated-file:dist/-AEZJPQJB.mjs AI (source-diff): esbuild minified bundle output, not obfuscation; hashed dist filenames change per build. ai
source-diff obfuscated-file:dist/-CBOVDSGD.mjs AI (source-diff): esbuild --minify bundle output, not obfuscation; stable for this build pipeline. ai
source-diff obfuscated-file:dist/-T5DHXUJT.mjs AI (source-diff): esbuild-minified bundle output, not obfuscation; expected for this build pipeline. ai
source-diff obfuscated-file:dist/-K4EMAKSX.mjs AI (source-diff): esbuild --minify bundle output, not obfuscation; standard for this build pipeline. ai
source-diff obfuscated-file:dist/-XIFKRW4S.mjs AI (source-diff): esbuild minified ESM bundle output, not obfuscation; matches build script. ai
source-diff obfuscated-file:dist/-O7MF7KTF.mjs AI (source-diff): esbuild minified bundle output, not obfuscation; matches documented build for this package. ai
source-diff obfuscated-file:dist/-GRAOFKCH.mjs AI (source-diff): esbuild-minified bundle output, not obfuscation; matches documented build flow. ai
source-diff obfuscated-file:dist/-Q3C7RHRC.mjs AI (source-diff): esbuild minified bundle output, not obfuscation; expected build artifact for this package. ai
source-diff obfuscated-file:dist/-HAETQ6JR.mjs AI (source-diff): esbuild-minified bundle output, not obfuscation; expected for this build pipeline. ai
source-diff obfuscated-file:dist/-NVCSOJ3U.mjs AI (source-diff): esbuild-minified dist output per documented build; not obfuscation. ai
source-diff obfuscated-file:dist/-5Z6NQIRW.mjs AI (source-diff): esbuild-minified dist output from the package's own build pipeline; not obfuscation. ai
source-diff obfuscated-file:dist/-GRS5X4TZ.mjs AI (source-diff): esbuild-minified bundle output; consistent with build scripts in package.json. Stable FP for this package. ai
source-diff obfuscated-file:dist/-5WVTFKRM.mjs AI (source-diff): esbuild-minified bundle output; consistent with build scripts in package.json. Stable FP for this package. ai
source-diff obfuscated-file:dist/-JV5XE2MO.mjs AI (source-diff): esbuild-minified bundle output; consistent with documented build pipeline for this package. ai
source-diff obfuscated-file:dist/-QQATPRK2.mjs AI (source-diff): esbuild --minify output; consistent with build scripts and prior versions. ai
source-diff obfuscated-file:dist/-VMG67VUR.mjs AI (source-diff): esbuild --minify output; consistent with build scripts and prior versions. ai
source-diff obfuscated-file:dist/-W6F6BQLK.mjs AI (source-diff): esbuild-minified bundle output; standard for this package's build pipeline. ai
source-diff obfuscated-file:dist/-GVE4IPC5.mjs AI (source-diff): esbuild --minify output (code-split chunk); stable pattern for this package. ai
source-diff obfuscated-file:dist/-CMETF44P.mjs AI (source-diff): esbuild --minify output for code-split chunk; standard for this package's build pipeline. ai
source-diff obfuscated-file:dist/-I7FKDHZE.mjs AI (source-diff): esbuild --minify output (code-split chunk); standard for this package's build pipeline. ai
source-diff obfuscated-file:dist/-7QSXIX4N.mjs AI (source-diff): esbuild-minified bundle output; standard for this package's build pipeline. ai
source-diff obfuscated-file:dist/-KWFP7TC7.mjs AI (source-diff): esbuild-minified bundle output; consistent with build config and prior versions. ai
source-diff obfuscated-file:dist/-6Q2IQRPZ.mjs AI (source-diff): esbuild --minify output (code-split chunk from lazy build); stable pattern for this package. ai
source-diff obfuscated-file:dist/-ROK4AKYD.mjs AI (source-diff): esbuild --minify output; standard build artifact for this package. ai
source-diff obfuscated-file:dist/-SE2QKKFU.mjs AI (source-diff): esbuild --minify output; consistent with build scripts and prior versions. ai
source-diff obfuscated-file:dist/-WLQCDVLW.mjs AI (source-diff): esbuild --minify output; standard bundled dist for this package. ai
source-diff obfuscated-file:dist/-LTJRRAKL.mjs AI (source-diff): esbuild-minified bundle output; consistent with build scripts in package.json. ai
phantom-deps phantom-dep:prop-types AI (phantom-deps): prop-types is declared as a runtime dep and externalized in esbuild build scripts; phantom-dep is a false positive here. ai
source-diff obfuscated-file:dist/-2SMMP33F.mjs AI (source-diff): esbuild minified output from lazy-splitting; content is readable React player code, not obfuscation. ai

Versions (showing 36 of 36)

Version Deps Published
3.13.2 3 / 10
3.13.0 3 / 10
3.12.0 3 / 10
3.11.8 3 / 10
3.11.7 3 / 10
3.11.6 3 / 10
3.11.5 3 / 10
3.11.4 3 / 10
3.10.2 3 / 10
3.10.1 3 / 10
3.10.0 3 / 10
3.9.2 3 / 10
3.9.1 3 / 10
3.9.0 3 / 10
3.8.0 3 / 10
3.7.0 3 / 10
3.6.1 3 / 10
3.6.0 3 / 10
3.5.3 3 / 10
3.5.2 3 / 10
3.5.1 3 / 10
3.5.0 3 / 10
3.4.1 3 / 10
3.4.0 3 / 10
3.3.4 3 / 10
3.3.3 3 / 10
3.3.2 3 / 10
3.3.1 3 / 10
3.3.0 3 / 10
3.2.4 3 / 10
3.2.3 3 / 10
3.2.2 3 / 10
3.2.1 3 / 10
3.2.0 3 / 10
3.1.0 3 / 10
3.0.0 3 / 10

v3.13.2

3 findings
HIGH New obfuscated file: dist/-SWV3FE67.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: mux-npmjs → GitHub Actions (on 2026-07-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (mux-npmjs) on 2026-07-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v3.3.4

2 findings
HIGH New obfuscated file: dist/-NVCSOJ3U.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.3

2 findings
HIGH New obfuscated file: dist/-AEZJPQJB.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.2

2 findings
HIGH New obfuscated file: dist/-T5DHXUJT.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.1

2 findings
HIGH New obfuscated file: dist/-CBOVDSGD.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.3.0

2 findings
HIGH New obfuscated file: dist/-Q3C7RHRC.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.4

2 findings
HIGH New obfuscated file: dist/-K4EMAKSX.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.3

2 findings
HIGH New obfuscated file: dist/-XIFKRW4S.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.2

2 findings
HIGH New obfuscated file: dist/-HAETQ6JR.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.1

2 findings
HIGH New obfuscated file: dist/-O7MF7KTF.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.2.0

2 findings
HIGH New obfuscated file: dist/-GRAOFKCH.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v3.1.0

2 findings
HIGH New obfuscated file: dist/-5Z6NQIRW.mjs source-diff

Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v3.0.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.