@remotion/promo-pages
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/Users/jonathanburger/remotion2/packages/promo-pages/dist/prompts/PromptsSubmit.js | AI (source-diff): Bundled vendor chunk, minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/Users/jonathanburger/remotion2/packages/promo-pages/dist/prompts/PromptsShow.js | AI (source-diff): Bundled vendor chunk (vidstack), minified build output not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/Users/jonathanburger/remotion2/packages/promo-pages/dist/Homepage.js | AI (source-diff): Bundled build output, not obfuscation; path is local build artifact of monorepo bundler. | ai | |
| source-diff | obfuscated-file:dist/prompts/PromptsShow.js | AI (source-diff): Bundled build output (bun/esbuild banner), not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/prompts/PromptsSubmit.js | AI (source-diff): Bundled build output (bun/esbuild banner), not obfuscation. | ai | |
| dependencies | unvetted-dep:bun-plugin-tailwind | AI (dependencies): Build-time Tailwind plugin used in bun bundle scripts; not a runtime dependency for consumers. | ai | |
| source-diff | obfuscated-file:dist/components/homepage/CommunityStatsItems.js | AI (source-diff): Compiled TypeScript/JSX output; readable React component code, long lines from inlined SVG. | ai | |
| source-diff | obfuscated-file:dist/components/experts/ExpertsPage.js | AI (source-diff): Readable transpiled TypeScript/JSX; long lines from bundled JSX, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/components/design.js | AI (source-diff): Readable transpiled TypeScript/JSX; long lines from bundled imports, not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/Users/jonathanburger/remotion/packages/promo-pages/dist/prompts/PromptsSubmit.js | AI (source-diff): Standard esbuild bundle output with readable source comments; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/Users/jonathanburger/remotion/packages/promo-pages/dist/prompts/PromptsShow.js | AI (source-diff): Standard esbuild bundle output with readable source comments; not malicious obfuscation. | ai | |
| source-diff | obfuscated-file:dist/Users/jonathanburger/remotion/packages/promo-pages/dist/Homepage.js | AI (source-diff): Standard esbuild bundle output with readable source comments; not malicious obfuscation. | ai | |
| phantom-deps | phantom-dep:@vidstack/react | AI (phantom-deps): Referenced in config files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@remotion/media | AI (phantom-deps): Internal remotion monorepo package; phantom-dep is a false positive for bundled/config-referenced deps. | ai | |
| phantom-deps | phantom-dep:bun-plugin-tailwind | AI (phantom-deps): Build tool referenced in bundle config; stable false positive. | ai | |
| phantom-deps | phantom-dep:@remotion/design | AI (phantom-deps): Internal remotion monorepo package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@remotion/web-renderer | AI (phantom-deps): Internal remotion monorepo package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@remotion/svg-3d-engine | AI (phantom-deps): Internal remotion monorepo package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@remotion/animated-emoji | AI (phantom-deps): Internal remotion monorepo package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@remotion/lottie | AI (phantom-deps): Internal remotion monorepo package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@remotion/player | AI (phantom-deps): Internal remotion monorepo package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@remotion/shapes | AI (phantom-deps): Internal remotion monorepo package; stable false positive. | ai | |
| phantom-deps | phantom-dep:@remotion/paths | AI (phantom-deps): Internal remotion monorepo package; stable false positive. | ai | |
| phantom-deps | phantom-dep:polished | AI (phantom-deps): Referenced in config/bundle files; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:create-video | AI (phantom-deps): Internal remotion tooling; referenced in config, not directly imported. | ai | |
| phantom-deps | phantom-dep:@mediabunny/ac3 | AI (phantom-deps): Referenced in config files; stable false positive for this package. | ai |
Versions (showing 100 of 118)
| Version | Deps | Published |
|---|---|---|
| 4.0.499 | 21 / 14 | |
| 4.0.498 | 21 / 14 | |
| 4.0.497 | 21 / 14 | |
| 4.0.496 | 21 / 14 | |
| 4.0.495 | 21 / 14 | |
| 4.0.494 | 21 / 14 | |
| 4.0.493 | 21 / 14 | |
| 4.0.492 | 21 / 14 | |
| 4.0.491 | 21 / 14 | |
| 4.0.490 | 21 / 14 | |
| 4.0.489 | 21 / 14 | |
| 4.0.488 | 21 / 14 | |
| 4.0.487 | 21 / 14 | |
| 4.0.486 | 21 / 14 | |
| 4.0.485 | 21 / 14 | |
| 4.0.484 | 21 / 14 | |
| 4.0.483 | 21 / 14 | |
| 4.0.482 | 21 / 14 | |
| 4.0.481 | 21 / 14 | |
| 4.0.479 | 21 / 14 | |
| 4.0.478 | 21 / 14 | |
| 4.0.477 | 21 / 14 | |
| 4.0.476 | 21 / 14 | |
| 4.0.475 | 21 / 14 | |
| 4.0.474 | 21 / 14 | |
| 4.0.473 | 21 / 14 | |
| 4.0.472 | 21 / 14 | |
| 4.0.471 | 21 / 14 | |
| 4.0.470 | 21 / 14 | |
| 4.0.469 | 21 / 14 | |
| 4.0.468 | 21 / 14 | |
| 4.0.467 | 21 / 14 | |
| 4.0.466 | 21 / 14 | |
| 4.0.465 | 21 / 14 | |
| 4.0.464 | 21 / 14 | |
| 4.0.463 | 21 / 14 | |
| 4.0.462 | 21 / 14 | |
| 4.0.461 | 21 / 14 | |
| 4.0.460 | 21 / 14 | |
| 4.0.459 | 21 / 14 | |
| 4.0.458 | 21 / 14 | |
| 4.0.457 | 21 / 14 | |
| 4.0.456 | 21 / 14 | |
| 4.0.455 | 21 / 14 | |
| 4.0.454 | 21 / 14 | |
| 4.0.453 | 21 / 14 | |
| 4.0.452 | 21 / 14 | |
| 4.0.451 | 21 / 14 | |
| 4.0.450 | 21 / 14 | |
| 4.0.449 | 21 / 14 | |
| 4.0.448 | 21 / 14 | |
| 4.0.447 | 21 / 14 | |
| 4.0.446 | 21 / 14 | |
| 4.0.445 | 21 / 14 | |
| 4.0.444 | 21 / 14 | |
| 4.0.443 | 21 / 14 | |
| 4.0.442 | 21 / 14 | |
| 4.0.441 | 21 / 14 | |
| 4.0.440 | 21 / 14 | |
| 4.0.439 | 21 / 14 | |
| 4.0.438 | 21 / 14 | |
| 4.0.437 | 21 / 14 | |
| 4.0.436 | 21 / 14 | |
| 4.0.435 | 21 / 14 | |
| 4.0.434 | 21 / 14 | |
| 4.0.433 | 21 / 14 | |
| 4.0.431 | 17 / 14 | |
| 4.0.425 | 17 / 14 | |
| 4.0.424 | 17 / 14 | |
| 4.0.421 | 17 / 14 | |
| 4.0.420 | 17 / 14 | |
| 4.0.419 | 17 / 14 | |
| 4.0.417 | 17 / 14 | |
| 4.0.416 | 17 / 14 | |
| 4.0.415 | 17 / 14 | |
| 4.0.414 | 14 / 14 | |
| 4.0.413 | 14 / 14 | |
| 4.0.412 | 14 / 14 | |
| 4.0.411 | 14 / 14 | |
| 4.0.410 | 14 / 14 | |
| 4.0.409 | 14 / 14 | |
| 4.0.408 | 14 / 14 | |
| 4.0.407 | 14 / 14 | |
| 4.0.406 | 14 / 14 | |
| 4.0.405 | 14 / 14 | |
| 4.0.404 | 14 / 14 | |
| 4.0.403 | 14 / 14 | |
| 4.0.402 | 14 / 14 | |
| 4.0.401 | 14 / 14 | |
| 4.0.400 | 14 / 14 | |
| 4.0.399 | 14 / 14 | |
| 4.0.398 | 14 / 14 | |
| 4.0.397 | 14 / 14 | |
| 4.0.396 | 14 / 14 | |
| 4.0.395 | 14 / 14 | |
| 4.0.394 | 14 / 14 | |
| 4.0.393 | 14 / 14 | |
| 4.0.392 | 14 / 14 | |
| 4.0.391 | 14 / 14 | |
| 4.0.390 | 14 / 14 |
v4.0.499
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.498
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.497
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.496
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.495
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.494
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.493
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.492
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.491
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.490
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.489
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.488
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.487
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.486
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.485
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.484
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.483
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.482
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.481
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.479
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.478
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.477
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.476
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.475
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.474
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.473
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.472
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.471
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.470
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.469
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.468
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.467
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.466
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.465
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.464
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.462
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.460
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.459
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.456
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.455
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.453
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.452
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.451
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.450
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.449
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.448
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.447
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.446
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.445
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.444
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.442
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v4.0.441
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.440
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.439
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.438
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.437
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.436
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.435
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.434
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.433
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.431
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.425
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.424
4 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.421
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.420
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.419
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.417
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.416
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.415
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.414
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.413
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.412
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.411
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.410
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.409
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.408
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.407
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.406
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.405
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.404
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.403
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.402
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.401
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.400
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.399
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.398
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.397
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.396
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.395
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.394
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.393
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.392
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.391
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v4.0.390
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.