Files
av-tools/SOURCE.md

6.0 KiB

Source and reproducibility record

This file identifies the source corresponding to av-tools 0.1.0. It is not a substitute for satisfying a component's licence or for delivering complete Corresponding Source with an object-code release.

av-tools

  • Canonical repository: git@git.add-ideas.de:zemion/av-tools.git
  • Browser source: https://git.add-ideas.de/zemion/av-tools
  • Version: 0.1.0
  • Release source identity: immutable annotated tag v0.1.0 (refs/tags/v0.1.0) in the canonical repository.
  • Application licence: GPL-3.0-or-later; full GPL version 3 terms in LICENSE.
  • Copyright: Copyright © 2026 Albrecht Degering.

The release tag is the source identity because embedding a commit's own hash inside that commit is impossible. Before publishing binary bytes, verify that the tag exists, is annotated, points to the reviewed release commit and is available without authentication:

test "$(git cat-file -t v0.1.0)" = tag
git rev-parse v0.1.0^{commit}
git ls-remote --tags \
  https://git.add-ideas.de/zemion/av-tools.git refs/tags/v0.1.0

The Toolbox manifest names the canonical repository and SPDX licence. Publish the tag/source archive beside the binary release and checksum.

Pinned npm inputs

package-lock.json is authoritative. The FFmpeg-related runtime packages are:

Package Exact version npm integrity
@ffmpeg/ffmpeg 0.12.15 sha512-1C8Obr4GsN3xw+/1Ww6PFM84wSQAGsdoTuTWPOj2OizsRDLT4CXTaVjPhkw6ARyDus1B9X/L2LiXHqYYsGnRFw==
@ffmpeg/util 0.12.2 sha512-ouyoW+4JB7WxjeZ2y6KpRvB+dLp7Cp4ro8z0HIVpZVCM7AwFlHa0c4R8Y/a4M3wMqATpYKhC7lSFHQ0T11MEDw==
@ffmpeg/types (transitive) 0.12.4 sha512-k9vJQNBGTxE5AhYDtOYR5rO5fKsspbg51gbcwtbkw2lCdoIILzklulcjJfIDwrtn7XhDeF2M+THwJ2FGrLeV6A==
@ffmpeg/core 0.12.10 sha512-dzNplnn2Nxle2c2i2rrDhqcB19q9cglCkWnoMTDN9Q9l3PvdjZWd1HfSPjCNWc/p8Q3CT+Es9fWOR0UhAeYQZA==
@ffmpeg/core-mt 0.12.10 sha512-atyRTOpa58bLCIgd6GXBZAXWyWD3AUoQyzxqjvGhp9MuSzdILtOTI62ffLswBsCnLq15lQ8IETHUpm1oe4V9FQ==

Install exact packages and recreate the copied same-origin assets without a network fetch during the production build:

npm ci
npm run vendor:ffmpeg
npm run vendor:verify
npm run build

scripts/copy-ffmpeg-assets.mjs copies the ESM distributions from the installed core packages; it does not download them. The copied bytes are:

Release path Bytes SHA-256
vendor/ffmpeg/0.12.10/st/ffmpeg-core.js 111804 67a48f11645f85439f3fde4f2119042c16b374b910206b7a7a24f342e28dcae3
vendor/ffmpeg/0.12.10/st/ffmpeg-core.wasm 32232419 9f57947a5bd530d8f00c5b3f2cb2a3492faa7e5d823315342d6a8656d0a6b7b7
vendor/ffmpeg/0.12.10/mt/ffmpeg-core.js 128947 270a2e6ff945e173238610669a3f7132df5f9c52698a9bf708cf5c2ab6bda0de
vendor/ffmpeg/0.12.10/mt/ffmpeg-core.wasm 32718323 be2c97605366b78f3f13e21b52e81a55a79e1f29c133b03a68ec187b1a2ec41a
vendor/ffmpeg/0.12.10/mt/ffmpeg-core.worker.js 2115 f77898d631dc010b45c29c23cb4379c611a7d7b131bf591d08a656bb729a4ca3

Corresponding ffmpeg.wasm and FFmpeg source

  • Upstream ffmpeg.wasm release tag containing @ffmpeg/ffmpeg 0.12.15, @ffmpeg/core 0.12.10 and @ffmpeg/core-mt 0.12.10: v12.15 at 71aa99d37c02a7b4c435275ca9ef50e612f6efa1.
  • FFmpeg source selected by that revision's Dockerfile: tag n5.1.4, peeled Git commit 4729204c17f756e186d622060088371d10b34f7e.
  • Emscripten image selected upstream: emscripten/emsdk:3.1.40.

Obtain and inspect those sources:

git clone https://github.com/ffmpegwasm/ffmpeg.wasm.git
git -C ffmpeg.wasm checkout 71aa99d37c02a7b4c435275ca9ef50e612f6efa1

git clone https://git.ffmpeg.org/ffmpeg.git ffmpeg
git -C ffmpeg checkout 4729204c17f756e186d622060088371d10b34f7e

The upstream build control files are Dockerfile, Makefile, build/ffmpeg.sh, build/ffmpeg-wasm.sh and the other scripts under build/ at the ffmpeg.wasm release revision. make prd builds single-thread; make prd-mt builds multithread.

The Dockerfile uses branch names for two inputs. Repository history resolves those refs to tips that predate the ffmpeg.wasm v12.15 release and have not changed since:

  • x264 4-cores: 33cac6b77d5b9259c552156013a817ab23119612;
  • x265 3.4: 2bb5520e9596f361bf0ed81b3b8da0d7fd999069;
  • LAME master: 2badea1974ae36cb8312afe99cff1e6b3b5decee.

Use those immutable commits when assembling Corresponding Source:

git clone https://github.com/ffmpegwasm/x264.git
git -C x264 checkout 33cac6b77d5b9259c552156013a817ab23119612

git clone https://github.com/ffmpegwasm/x265.git
git -C x265 checkout 2bb5520e9596f361bf0ed81b3b8da0d7fd999069

git clone https://github.com/ffmpegwasm/lame.git
git -C lame checkout 2badea1974ae36cb8312afe99cff1e6b3b5decee

scripts/ffmpeg-source-lock.json records every source selected by the upstream build as an immutable Git commit. Create the deterministic Corresponding Source bundle and sidecar with:

npm run source:package

The command writes release/ffmpeg-core-0.12.10-corresponding-source.tar.xz and its .sha256 sidecar. Pass -- --force only to replace those exact outputs. The npm packages contain the resulting binaries but not every linked component's source and legal file, so publish this reviewed bundle and the notices beside the object code. A homepage link alone is not asserted to satisfy GPL source obligations.

See docs/FFMPEG_BUILD.md for the observed version/configuration and THIRD_PARTY_NOTICES.md for component roles and terms.