← Home

@theia/ffmpeg

Theia FFMPEG reader utility.

4
Versions
EPL-2.0 OR GPL-2.0-only WITH Classpath-exception-2.0
License
Yes
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures gitHead linked

Maintainers

eclipsetheiavince-fugnittobhufmannmarc.dumaispaul-marechalmsujewtsmaederjfaltermeierjhelmingeclipse-theia-botsgrabandndoschek

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
install-scripts install-script:install AI (install-scripts): node-gyp rebuild is the standard native addon build pattern for this established Theia package. ai
bogus-package bogus-package AI (bogus-package): Established Eclipse Theia monorepo package; sparse README/keywords are typical for sub-packages in large monorepos. ai

Versions (showing 4 of 4)

Version Deps Published
1.70.2 3 / 1
1.66.2 3 / 1
1.66.1 3 / 1
1.61.1 3 / 1

v1.66.2

2 findings
HIGH Package has 'install' script install-scripts

Script: node-gyp rebuild

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v1.66.1

2 findings
HIGH Package has 'install' script install-scripts

Script: node-gyp rebuild

INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v0.2). This is the strongest supply chain integrity signal.

v1.61.1

2 findings
HIGH Package has 'install' script install-scripts

Script: node-gyp rebuild

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.