← Home

shaka-player

43
Versions
License
No
Install Scripts
Attested
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation (unverified) npm registry signatures gitHead linked

Maintainers

joeyparrishshaka-bottheodab

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff net-exec-file:dist/shaka-player.experimental.debug.js AI (source-diff): Closure-compiled experimental bundle; network+eval patterns are build output, stable for this package. ai
npm-metadata url-dep:jsdoc AI (npm-metadata): devDependency pinned to maintainer fork at specific commit; no runtime impact. ai
npm-metadata url-dep:karma AI (npm-metadata): devDependency pinned to maintainer fork; no runtime impact. ai
npm-metadata url-dep:eslint-config-google AI (npm-metadata): devDependency pinned to specific commit on google org repo; no runtime impact. ai
npm-metadata url-dep:google-closure-library AI (npm-metadata): devDependency pinned to maintainer fork at specific commit; no runtime impact. ai
npm-metadata url-dep:eslint-plugin-shaka-rules AI (npm-metadata): devDependency pointing to local file path; no runtime impact. ai

Versions (showing 43 of 43)

Version Deps Published
5.2.3 0 / 58
5.2.2 0 / 58
5.2.1 0 / 58
5.2.0 0 / 58
5.1.13 0 / 54
5.1.12 0 / 54
5.1.11 0 / 54
5.1.10 0 / 54
5.1.9 0 / 54
5.1.8 0 / 54
5.1.7 0 / 54
5.1.6 0 / 54
5.1.5 0 / 54
5.1.4 0 / 54
5.1.2 0 / 54
5.0.3 0 / 54
5.0.2 0 / 54
5.0.1 0 / 54
5.0.0 0 / 54
4.16.19 0 / 55
4.16.18 0 / 55
4.16.17 0 / 55
4.16.16 0 / 55
4.16.15 0 / 55
4.16.14 0 / 55
4.16.13 0 / 55
4.16.12 0 / 55
4.16.11 0 / 55
4.16.10 0 / 55
4.16.9 0 / 55
4.16.8 0 / 55
4.15.31 0 / 55
4.15.30 0 / 55
4.15.29 0 / 55
4.15.28 0 / 55
4.15.27 0 / 55
4.15.26 0 / 55
4.15.25 0 / 55
4.15.24 0 / 55
4.15.23 0 / 55
4.15.22 0 / 55
4.15.21 0 / 55
4.15.20 0 / 55

v5.2.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.1.13

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.1.12

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v5.0.3

2 findings
HIGH New file with network + code execution: dist/shaka-player.experimental.debug.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.2

2 findings
HIGH New file with network + code execution: dist/shaka-player.experimental.debug.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.1

2 findings
HIGH New file with network + code execution: dist/shaka-player.experimental.debug.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.0.0

2 findings
HIGH New file with network + code execution: dist/shaka-player.experimental.debug.js source-diff

Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.16.19

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.16.18

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.16.17

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.16.16

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.16.15

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.16.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.16.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.16.12

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: joeyparrish → shaka-bot (on 2025-12-15, known maintainer) provenance

This version was published by a different npm account (shaka-bot) than the most recent previously approved version (joeyparrish) on 2025-12-15, but shaka-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.16.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.16.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.16.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.16.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v4.15.31

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.15.30

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.15.29

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.15.28

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.15.27

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.15.26

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.15.25

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.15.24

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: joeyparrish → shaka-bot (on 2025-12-15, known maintainer) provenance

This version was published by a different npm account (shaka-bot) than the most recent previously approved version (joeyparrish) on 2025-12-15, but shaka-bot is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.

v4.15.23

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.15.22

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.15.21

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.15.20

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.