← Home

@mux/mux-video

A custom mux video element for the browser that Just Works™

51
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

jsanford8dylanjhaphil-muxmux-npmjs

Keywords

videomuxplayerhlsweb-component

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
dependencies unvetted-dep:@types/google_interactive_media_ads_types AI (dependencies): Official @types package matching existing IMA ads feature; low risk type-only dep. ai
phantom-deps phantom-dep:@types/google_interactive_media_ads_types AI (phantom-deps): Types package loaded ambiently by convention, not directly imported. ai
publish-pattern new-deps-added AI (publish-pattern): Single type-definitions dependency addition, consistent with package's ads functionality. ai
source-diff obfuscated-file:dist/base.mjs AI (source-diff): esbuild --minify output; build scripts confirm minification; SLSA provenance attests CI build. ai
source-diff obfuscated-file:dist/ads/index.mjs AI (source-diff): esbuild --minify output; build scripts confirm minification; SLSA provenance attests CI build. ai
source-diff obfuscated-file:dist/ads/mixin/index.mjs AI (source-diff): esbuild --minify output; build scripts confirm minification; SLSA provenance attests CI build. ai
dependencies unvetted-dep:@mux/playback-core AI (dependencies): First-party Mux package; expected core dependency for @mux/mux-video. ai
dependencies unvetted-dep:castable-video AI (dependencies): castable-video is a legitimate web component for Chromecast support; expected dependency for a video player package. ai
dependencies unvetted-dep:custom-media-element AI (dependencies): custom-media-element is a well-known base class for media web components; expected dependency for this package. ai
dependencies unvetted-dep:@mux/mux-data-google-ima AI (dependencies): First-party Mux package for Google IMA ads integration; expected dependency for @mux/mux-video ads support. ai
dependencies unvetted-dep:media-tracks AI (dependencies): media-tracks is a well-known web media component library; expected dependency for a video web component from Mux. ai

Versions (showing 51 of 77)

View all versions
Version Deps Published
0.31.2 6 / 17
0.31.0 5 / 18
0.30.7 5 / 18
0.30.6 5 / 18
0.30.5 5 / 18
0.30.4 5 / 18
0.30.3 5 / 18
0.30.2 5 / 18
0.29.2 5 / 18
0.29.1 5 / 18
0.29.0 5 / 18
0.28.2 5 / 18
0.28.1 5 / 18
0.28.0 5 / 18
0.27.2 5 / 18
0.27.1 5 / 18
0.27.0 5 / 18
0.26.1 5 / 18
0.26.0 5 / 17
0.25.3 4 / 16
0.25.2 4 / 16
0.25.1 4 / 16
0.25.0 4 / 16
0.24.5 4 / 16
0.24.4 4 / 16
0.24.3 4 / 16
0.24.2 4 / 16
0.24.1 4 / 16
0.24.0 4 / 16
0.23.1 4 / 14
0.23.0 4 / 14
0.22.0 4 / 14
0.21.0 4 / 14
0.20.2 4 / 14
0.20.1 4 / 14
0.20.0 4 / 14
0.19.0 4 / 14
0.18.1 4 / 14
0.18.0 4 / 14
0.17.5 4 / 16
0.17.4 4 / 16
0.17.3 4 / 16
0.17.2 4 / 16
0.17.1 4 / 16
0.17.0 4 / 16
0.16.5 4 / 16
0.16.4 4 / 16
0.16.3 4 / 16
0.16.2 4 / 16
0.16.1 4 / 16
0.16.0 4 / 16

v0.31.2

2 findings
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

INFO Publisher changed: mux-npmjs → GitHub Actions (on 2026-07-23, now via trusted publisher with provenance) provenance

This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (mux-npmjs) on 2026-07-23, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.

v0.25.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.25.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.5

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.24.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.23.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.23.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v0.22.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.21.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.20.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.20.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.20.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.19.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.18.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.18.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.17.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.17.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.17.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.17.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.17.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.17.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.16.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.