@vimeo/player
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file-transition:dist/player.es.js | AI (source-diff): Bundled player SDK; XHR + babel-runtime regenerator, no hostile destination. | ai | |
| source-diff | net-exec-file-transition:dist/player.min.js | AI (source-diff): Minified build of same player code, benign. | ai | |
| source-diff | net-exec-file-transition:dist/player.js | AI (source-diff): Same bundled build output, benign player code. | ai | |
| provenance | publisher-changed-stale | AI (provenance): Publisher change is a stable Vimeo team transition. | ai | |
| maintainer-change | maintainer-takeover | AI (maintainer-change): Legitimate Vimeo org handoff, live 1602d without unpublish; not a hijack. | ai | |
| provenance | missing-githead | AI (provenance): Publish-env change on trusted first-party package; no behavioral risk. | ai | |
| dependencies | unvetted-dep:es6-collections | AI (dependencies): Legacy polyfill dep, stable and benign for this old official package. | ai | |
| email-domain | unclaimed-email:https://vimeo.com | AI (email-domain): The author field contains a URL (https://vimeo.com), not an email address. The analyzer is misinterpreting the URL as an email domain. vimeo.com is a live, well-known domain — stable false positive for this package. | ai | |
| dependencies | unvetted-dep:weakmap-polyfill | AI (dependencies): weakmap-polyfill is a small, well-known polyfill that has been a stable dependency of this package across many versions. No security concerns. | ai |
Versions (showing 69 of 69)
| Version | Deps | Published |
|---|---|---|
| 2.30.4 | 2 / 32 | |
| 2.30.3 | 2 / 32 | |
| 2.30.2 | 2 / 32 | |
| 2.30.1 | 2 / 32 | |
| 2.30.0 | 2 / 32 | |
| 2.29.7 | 2 / 32 | |
| 2.29.6 | 2 / 31 | |
| 2.29.5 | 2 / 31 | |
| 2.29.4 | 2 / 31 | |
| 2.29.3 | 2 / 31 | |
| 2.29.2 | 2 / 31 | |
| 2.29.1 | 2 / 31 | |
| 2.29.0 | 2 / 32 | |
| 2.28.0 | 2 / 32 | |
| 2.27.1 | 2 / 32 | |
| 2.27.0 | 2 / 32 | |
| 2.26.0 | 2 / 32 | |
| 2.25.1 | 2 / 32 | |
| 2.25.0 | 2 / 32 | |
| 2.24.0 | 2 / 32 | |
| 2.23.1 | 2 / 32 | |
| 2.23.0 | 2 / 32 | |
| 2.22.0 | 2 / 32 | |
| 2.21.0 | 2 / 32 | |
| 2.20.1 | 2 / 33 | |
| 2.20.0 | 2 / 33 | |
| 2.19.0 | 2 / 32 | |
| 2.18.0 | 2 / 32 | |
| 2.17.1 | 2 / 32 | |
| 2.17.0 | 2 / 32 | |
| 2.16.4 | 2 / 32 | |
| 2.16.3 | 2 / 32 | |
| 2.16.2 | 2 / 32 | |
| 2.16.1 | 2 / 32 | |
| 2.16.0 | 2 / 32 | |
| 2.15.3 | 2 / 32 | |
| 2.15.0 | 2 / 32 | |
| 2.14.1 | 2 / 32 | |
| 2.14.0 | 2 / 32 | |
| 2.13.0 | 2 / 32 | |
| 2.12.2 | 2 / 32 | |
| 2.12.1 | 2 / 32 | |
| 2.12.0 | 2 / 33 | |
| 2.11.0 | 2 / 33 | |
| 2.10.0 | 2 / 33 | |
| 2.9.1 | 2 / 33 | |
| 2.9.0 | 2 / 33 | |
| 2.8.2 | 2 / 33 | |
| 2.8.1 | 2 / 33 | |
| 2.8.0 | 2 / 33 | |
| 2.7.0 | 2 / 34 | |
| 2.6.7 | 2 / 33 | |
| 2.6.6 | 2 / 33 | |
| 2.6.5 | 2 / 33 | |
| 2.6.4 | 2 / 33 | |
| 2.6.3 | 2 / 33 | |
| 2.6.1 | 2 / 26 | |
| 2.6.0 | 2 / 26 | |
| 2.5.0 | 2 / 26 | |
| 2.4.0 | 2 / 26 | |
| 2.3.1 | 2 / 26 | |
| 2.3.0 | 2 / 26 | |
| 2.2.1 | 2 / 26 | |
| 2.2.0 | 2 / 26 | |
| 2.1.1 | 2 / 26 | |
| 2.1.0 | 2 / 26 | |
| 2.0.2 | 2 / 26 | |
| 2.0.1 | 2 / 25 | |
| 2.0.0 | 2 / 25 |
v2.26.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.25.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.25.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.24.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.23.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.23.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.21.0
2 findingsThis version was published by a different npm account (vimeo-npmbot) than the most recent previously approved version (luwes) on 2024-01-02. It has since remained available on npm for 929 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.20.1
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: rowankrishnan.
This version was published by a different npm account (rowankrishnan) than the most recent previously approved version (luwes) on 2023-05-25. It has since remained available on npm for 1151 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.20.0
6 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: rowankrishnan.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This file did not combine network calls with dynamic code execution in the previously greenflagged version, and now does. Gaining both halves in an existing file is a hallmark of a dropper/loader introduced by an update.
This version was published by a different npm account (rowankrishnan) than the most recent previously approved version (luwes) on 2023-05-25. It has since remained available on npm for 1151 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.19.0
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: rowankrishnan.
This version was published by a different npm account (rowankrishnan) than the most recent previously approved version (luwes) on 2023-04-21. It has since remained available on npm for 1185 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.18.0
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: rowankrishnan.
This version was published by a different npm account (rowankrishnan) than the most recent previously approved version (luwes) on 2022-10-04. It has since remained available on npm for 1384 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.1
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: rowankrishnan.
This version was published by a different npm account (rowankrishnan) than the most recent previously approved version (luwes) on 2022-06-27. It has since remained available on npm for 1483 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.17.0
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: rowankrishnan.
This version was published by a different npm account (rowankrishnan) than the most recent previously approved version (luwes) on 2022-06-09. It has since remained available on npm for 1501 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.4
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brandonhrowe.
This version was published by a different npm account (brandonhrowe) than the most recent previously approved version (luwes) on 2022-02-28. It has since remained available on npm for 1602 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.3
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: brandonhrowe.
This version was published by a different npm account (brandonhrowe) than the most recent previously approved version (luwes) on 2022-02-01. It has since remained available on npm for 1629 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.2
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: rowankrishnan.
This version was published by a different npm account (rowankrishnan) than the most recent previously approved version (luwes) on 2021-11-09. It has since remained available on npm for 1713 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.1
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: rowankrishnan.
This version was published by a different npm account (rowankrishnan) than the most recent previously approved version (luwes) on 2021-09-08. It has since remained available on npm for 1775 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.16.0
3 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: rowankrishnan.
This version was published by a different npm account (rowankrishnan) than the most recent previously approved version (luwes) on 2021-07-29. It has since remained available on npm for 1816 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.15.3
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: luwes.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.15.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: luwes.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.14.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: luwes.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.14.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: luwes.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.13.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: luwes.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.12.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: luwes.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.12.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: luwes.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.12.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: luwes.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.11.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: luwes.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.10.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: luwes.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.9.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: luwes.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.9.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: luwes.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.2
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: luwes.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.1
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: luwes.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.8.0
2 findingsThis version has no gitHead field linking it to a source commit, but previous versions did. This suggests the publish environment changed. Published by: luwes.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.7.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.7
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.6
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.4
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.6.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.5.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.4.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.3.0
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.2.0
2 findingsThis version was published by a different npm account (luwes) than the most recent previously approved version (bdougherty) on 2017-09-07. It has since remained available on npm for 3237 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.1
2 findingsThis version was published by a different npm account (luwes) than the most recent previously approved version (bdougherty) on 2017-08-31. It has since remained available on npm for 3244 days without being unpublished, which is inconsistent with an account takeover — those are typically removed by npm shortly after discovery.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.1.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.2
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.