This repository is a build system for stock upstream FFmpeg and its supporting
libraries (x264, x265, kvazaar, dav1d, SVT-AV1, OpenSSL, GnuTLS, and others — the TLS
backend varies by license cell). It does not vendor or fork that upstream source — each
library is fetched from its official upstream at a pinned release tag and built at CI time,
into a git-ignored, ephemeral .build/ tree. A small number of targeted build-time patches
are applied in the open, in scripts/, to make a source compile for a target it does not yet
support (for example skipping FFmpeg's videotoolbox symbols that the Mac Catalyst SDK marks
unavailable); none add functionality, and each is visible in the script that applies it. The only source original to this
repository is the build tooling (shell scripts and GitHub Actions workflows) plus a
small compile/runtime smoke test (scripts/test/smoke.c).
In scope — report here:
- Vulnerabilities in our build tooling (shell scripts, workflows) — e.g. command injection, unsafe download/verification, secret handling.
- Supply-chain concerns in how we fetch or pin upstream sources.
Out of scope — please report upstream instead:
- Vulnerabilities in FFmpeg or any bundled library's own source code. Those belong to the respective upstream projects; we track and adopt fixed upstream releases through our version-update process. They are not defects in this repository.
- CodeQL — the C we own (
scripts/test/) and our GitHub Actions workflows. - ShellCheck — our shell scripts.
Both run on pull requests and pushes to main, with results in the Security tab.
Upstream library source is never checked out into an analyzed path, so upstream CVEs
are not attributed to this repository.
Please open a private report via the repository's Security → Report a vulnerability page (GitHub private vulnerability reporting), or contact the maintainers directly. We aim to acknowledge within a few business days.