@mux/playback-core
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:hls.js | AI (dependencies): hls.js is the canonical HLS streaming library; expected and legitimate dependency for a media playback package. | ai | |
| dependencies | unvetted-dep:mux-embed | AI (dependencies): mux-embed is Mux's own analytics/embed library; expected dependency for @mux/playback-core. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Monorepo sub-package; minimal README and no keywords are cosmetic issues, not spam indicators for this established Mux library. | ai |
Versions (showing 18 of 18)
| Version | Deps | Published |
|---|---|---|
| 0.35.0 | 2 / 14 | |
| 0.34.1 | 2 / 14 | |
| 0.34.0 | 2 / 14 | |
| 0.33.3 | 2 / 14 | |
| 0.33.2 | 2 / 14 | |
| 0.33.1 | 2 / 14 | |
| 0.32.2 | 2 / 14 | |
| 0.32.1 | 2 / 14 | |
| 0.32.0 | 2 / 14 | |
| 0.31.4 | 2 / 14 | |
| 0.31.3 | 2 / 14 | |
| 0.31.2 | 2 / 14 | |
| 0.31.1 | 2 / 14 | |
| 0.31.0 | 2 / 14 | |
| 0.30.1 | 2 / 14 | |
| 0.30.0 | 2 / 13 | |
| 0.29.1 | 2 / 13 | |
| 0.29.0 | 2 / 13 |
v0.35.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.34.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.34.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.33.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.33.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.33.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.32.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.32.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.32.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.31.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.31.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.31.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.31.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.31.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.30.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.30.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.29.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.29.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.