← Home

@wistia/wistia-player-react

50
Versions
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

wistia_engineeringokizersheldonatwistia

Keywords

wistiavideoplayerembedweb componentcustom elementreact

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/mjs/wistia-player-PIEQE36A.mjs AI (source-diff): Webpack bundle for Wistia video player SDK; network+exec pattern is inherent to a video embed library, not malware. ai
source-diff net-exec-file:dist/mjs/wistia-player-TH2PEY6N.mjs AI (source-diff): Large webpack bundle of the Wistia player SDK; network+exec pattern is expected for a video player embed library. ai
source-diff net-exec-file:dist/mjs/wistia-player-NRHMVWJQ.mjs AI (source-diff): Webpack bundle for Wistia video player SDK; network+exec pattern is expected for dynamic script loading in a media player. ai
source-diff net-exec-file:dist/mjs/wistia-player-CA3ZQHXK.mjs AI (source-diff): Webpack-bundled Wistia player; network+exec pattern is inherent to a video player loading its own scripts, not malware. ai
source-diff net-exec-file:dist/mjs/wistia-player-L3FGFFN4.mjs AI (source-diff): Webpack-bundled video player output; network+exec pattern is inherent to the player's design, not malware. ai
source-diff net-exec-file:dist/mjs/wistia-player-W7JEK3YT.mjs AI (source-diff): Webpack-bundled Wistia player artifact; network+exec pattern is expected for an embeddable video player, not malware. ai
source-diff net-exec-file:dist/mjs/wistia-player-JV5AKUF3.mjs AI (source-diff): Webpack-bundled Wistia player artifact; network+exec pattern is the player loading its own scripts, not malware. ai
source-diff net-exec-file:dist/mjs/wistia-player-L32JEHH6.mjs AI (source-diff): Webpack-bundled video player SDK; network+exec pattern is inherent to the wistia-player embed architecture, not malware. ai
source-diff net-exec-file:dist/mjs/wistia-player-OT73HWX2.mjs AI (source-diff): Webpack bundle for Wistia video player; network+exec pattern is standard player embed behavior, not malware. ai
source-diff net-exec-file:dist/mjs/wistia-player-YSPWISPG.mjs AI (source-diff): Webpack bundle of @wistia/wistia-player; network+exec pattern is standard player embed behavior, not malware. ai
source-diff net-exec-file:dist/mjs/wistia-player-LDNTTEZL.mjs AI (source-diff): Webpack bundle for Wistia video player SDK; dynamic script loading is expected for a media embed library. ai
source-diff net-exec-file:dist/mjs/wistia-player-JFREZSBE.mjs AI (source-diff): Webpack-bundled player artifact; network+exec pattern is inherent to the Wistia video player bundle, not malware. ai
source-diff net-exec-file:dist/mjs/wistia-player-6Y735SL7.mjs AI (source-diff): Webpack bundle for Wistia video player; network+exec pattern is inherent to a video embed SDK, not malware. ai
source-diff net-exec-file:dist/mjs/wistia-player-3VB6IIEW.mjs AI (source-diff): Webpack-bundled Wistia player; dynamic script loading is core to video embed functionality, not malware. ai
source-diff net-exec-file:dist/mjs/wistia-player-HVZ6K3MN.mjs AI (source-diff): Webpack-bundled Wistia player SDK; network+exec pattern is inherent to a video player library, not malware. ai
source-diff net-exec-file:dist/mjs/wistia-player-HE5EHMCD.mjs AI (source-diff): Wistia video player SDK legitimately loads scripts/iframes for video playback; webpack bundle pattern is consistent across versions. ai
source-diff net-exec-file:dist/mjs/wistia-player-R64EQRPA.mjs AI (source-diff): Webpack-bundled Wistia player SDK; network+exec pattern is inherent to a video player loading scripts, not malware. ai
source-diff net-exec-file:dist/mjs/wistia-player-EMELY44T.mjs AI (source-diff): Webpack-bundled video player SDK from Wistia; network+exec pattern is inherent to the player's script-loading design, not malware. ai
source-diff net-exec-file:dist/mjs/wistia-player-HZKZ5A2T.mjs AI (source-diff): Webpack-bundled video player SDK; network calls and script execution are expected for a media player component. ai
source-diff net-exec-file:dist/mjs/wistia-player-7D6CZ7AF.mjs AI (source-diff): Webpack-bundled Wistia player artifact; network+exec pattern is expected for a video player SDK loading its own scripts. ai
source-diff net-exec-file:dist/mjs/wistia-player-URLZXOOY.mjs AI (source-diff): Webpack-bundled video player artifact; network+exec pattern is expected for a media player SDK, not malware. ai
source-diff net-exec-file:dist/mjs/wistia-player-T2NSDI5N.mjs AI (source-diff): Webpack-bundled Wistia player SDK; network+exec pattern is expected for a video player embed library. ai
source-diff net-exec-file:dist/mjs/wistia-player-B2YCJL7Y.mjs AI (source-diff): Webpack-bundled Wistia player asset; dynamic script loading is inherent to the video player's design, not malicious. ai
source-diff net-exec-file:dist/mjs/wistia-player-553ZER6Y.mjs AI (source-diff): Webpack-bundled video player code; network+exec pattern is expected for a media player library from Wistia's official org. ai
source-diff net-exec-file:dist/mjs/wistia-player-MY2EMXVV.mjs AI (source-diff): Webpack bundle artifact for Wistia player; network+exec pattern is standard player embed behavior, not malware. ai
source-diff net-exec-file:dist/mjs/wistia-player-BK7A5CHY.mjs AI (source-diff): Webpack-bundled media player SDK; network calls and script execution are expected for Wistia player functionality, not malware. ai
source-diff net-exec-file:dist/mjs/wistia-player-ZYXJZKTK.mjs AI (source-diff): Large webpack bundle of @wistia/wistia-player; net+exec pattern is standard bundled player code, not malware. ai
source-diff net-exec-file:dist/mjs/wistia-player-G7EUXEFC.mjs AI (source-diff): Webpack-bundled Wistia player; dynamic script loading is core to the media player's architecture, not malware. ai
source-diff net-exec-file:dist/mjs/wistia-player-FIDHPNDO.mjs AI (source-diff): Webpack bundle of the Wistia player dependency; network+exec pattern is standard player embed behavior, not malware. ai
source-diff net-exec-file:dist/mjs/wistia-player-YR6DGSTN.mjs AI (source-diff): Webpack bundle of the Wistia player SDK; network+exec pattern is inherent to a video player library, not malware. ai
dependencies unvetted-dep:@wistia/wistia-player AI (dependencies): First-party sibling package from same @wistia org; React wrapper depending on the core player is expected and stable. ai
provenance no-provenance AI (provenance): Established Wistia org package; lack of provenance is consistent across all versions and not a risk indicator here. ai

Versions (showing 50 of 50)

Version Deps Published
0.7.0 2 / 14
0.6.22 2 / 14
0.6.21 2 / 14
0.6.20 2 / 14
0.6.19 2 / 14
0.6.18 2 / 14
0.6.17 2 / 14
0.6.16 2 / 14
0.6.15 2 / 14
0.6.14 2 / 14
0.6.13 2 / 14
0.6.12 2 / 14
0.6.11 2 / 14
0.6.10 2 / 14
0.6.9 2 / 14
0.6.8 2 / 14
0.6.7 2 / 14
0.6.6 2 / 14
0.6.5 2 / 14
0.6.4 2 / 14
0.6.3 2 / 14
0.6.2 2 / 14
0.6.1 2 / 14
0.6.0 2 / 14
0.5.1 2 / 14
0.5.0 2 / 14
0.4.3 2 / 14
0.4.2 2 / 14
0.4.1 2 / 14
0.4.0 2 / 14
0.3.19 2 / 14
0.3.18 2 / 14
0.3.17 2 / 14
0.3.16 2 / 14
0.3.15 2 / 14
0.3.14 2 / 14
0.3.13 2 / 14
0.3.12 2 / 14
0.3.11 2 / 14
0.3.1 2 / 14
0.2.0 2 / 14
0.1.3 1 / 14
0.1.1 1 / 14
0.0.115 1 / 14
0.0.114 1 / 14
0.0.108 1 / 14
0.0.107 1 / 14
0.0.96 1 / 14
0.0.3 1 / 13
0.0.1 1 / 13

v0.0.108

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.107

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.96

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.3

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.0.1

1 finding
INFO No provenance attestation provenance

[Accepted risk] Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.