From mboxrd@z Thu Jan 1 00:00:00 1970 Return-Path: Received: from ffbox0-bg.mplayerhq.hu (ffbox0-bg.ffmpeg.org [79.124.17.100]) by master.gitmailbox.com (Postfix) with ESMTP id D7EA248CD9 for ; Tue, 23 Apr 2024 19:04:22 +0000 (UTC) Received: from [127.0.1.1] (localhost [127.0.0.1]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTP id DE4A968D3A3; Tue, 23 Apr 2024 22:04:19 +0300 (EEST) Received: from NAM10-BN7-obe.outbound.protection.outlook.com (mail-bn7nam10on2101.outbound.protection.outlook.com [40.107.92.101]) by ffbox0-bg.mplayerhq.hu (Postfix) with ESMTPS id A57BA68D244 for ; Tue, 23 Apr 2024 22:04:13 +0300 (EEST) ARC-Seal: i=1; a=rsa-sha256; s=arcselector9901; d=microsoft.com; cv=none; b=Bp+Ue8bWQBhYFdI0D2VjhNnrwgj20SYFaLXMbqjnxoclCCe3tXp9uKzyWaVS4e/iheYUDatPIUhqEEfx2oBtpBq5UVbe0Z6riqjvBjIZV71f4kapYSe6jIbig25iUlIym2m1METiHhS0pZKuVCuO3PaSn/tFeLMjWBgJ2XKmekXdyj0DDWs4rBGJnKHl/gaf8gm6rF7+8/zpJjJG+yGyb9XHdRiT8vLSXrb3zhvBWRYZas/Bs3LVVCIKz/avcwbZHKV2CT2uKVIPnKMkV3ns7XczldGrGfLkBPz+PEPF2VkFOnEp8cSow4dKcUGQLkIsxmk6GFWkoxtg2YbqrjeLQQ== ARC-Message-Signature: i=1; a=rsa-sha256; c=relaxed/relaxed; d=microsoft.com; s=arcselector9901; h=From:Date:Subject:Message-ID:Content-Type:MIME-Version:X-MS-Exchange-AntiSpam-MessageData-ChunkCount:X-MS-Exchange-AntiSpam-MessageData-0:X-MS-Exchange-AntiSpam-MessageData-1; bh=ZvpMWEwcy/WNlTWVbWNKfVvzsKxwG0OnQmRpfLHndfQ=; b=BtJy/spj/YhCHhemcKMzM80dUeHFF4F7GrIKVANZL4Bes5epveMvWIklCbADuUPvNWao/L7JzF0B6u8xn3T+xxlUHD36cORzOtg9hXzMF3DVcKWqbkt/YzcBTgayDtZm12Qg6pVaFTsSO6UqC4skAf3Njah8dZknG88KMcwyNY6Hp9RbefzN5tzHzLcVdWXRQKiaw5Xxge456VuporKbfG0L4UK1R25U1GEzYtlBMnxzh9DDZc3dVFOMZeXWmsmplv6nvAxswlxaS3F6alDSOUaOqfPgs3egn0yTInoyKFN33PmTtaY/3a12Ee+gA1d5tXBXOBtqmd8yJg2lJqOTGQ== ARC-Authentication-Results: i=1; mx.microsoft.com 1; spf=pass smtp.mailfrom=microsoft.com; dmarc=pass action=none header.from=microsoft.com; dkim=pass header.d=microsoft.com; arc=none Received: from BYAPR21MB1608.namprd21.prod.outlook.com (2603:10b6:a02:c8::25) by BL1PR21MB3235.namprd21.prod.outlook.com (2603:10b6:208:39b::14) with Microsoft SMTP Server (version=TLS1_2, cipher=TLS_ECDHE_RSA_WITH_AES_256_GCM_SHA384) id 15.20.7544.5; Tue, 23 Apr 2024 19:04:10 +0000 Received: from BYAPR21MB1608.namprd21.prod.outlook.com ([fe80::386e:2245:1122:e222]) by BYAPR21MB1608.namprd21.prod.outlook.com ([fe80::386e:2245:1122:e222%4]) with mapi id 15.20.7544.007; Tue, 23 Apr 2024 19:04:09 +0000 To: "ffmpeg-devel@ffmpeg.org" Thread-Topic: Request for Official GitHub Mirror of rtmpdump for Enhanced Security Thread-Index: AQHalbEFqsvc4r44sEK5eJFGaxSvtg== Date: Tue, 23 Apr 2024 19:04:08 +0000 Message-ID: <9BEEA291-A15B-4912-90D7-44BC6217EB2C@microsoft.com> Accept-Language: en-US Content-Language: en-US X-MS-Has-Attach: X-MS-TNEF-Correlator: x-ms-publictraffictype: Email x-ms-traffictypediagnostic: BYAPR21MB1608:EE_|BL1PR21MB3235:EE_ x-ms-office365-filtering-correlation-id: ffa13ccc-232c-401c-f7d0-08dc63c8279b x-ms-exchange-senderadcheck: 1 x-ms-exchange-antispam-relay: 0 x-microsoft-antispam: BCL:0; ARA:13230031|376005|1800799015|366007|38070700009; x-microsoft-antispam-message-info: =?utf-8?B?UWU5Nnlpak53Y0NCWGlhaTJlT2ozNkNiZjBidGZNcGVIYkF6T3I4WXV4UUdW?= =?utf-8?B?ejdJbml3a0hOc2tQWWNBTEgxYldrdkY1YzhVRVVSR1RNY09iSSs4NHNHWjJR?= =?utf-8?B?MFJ6a2luWFhCdjJQd1BMVStBUFlmc0ZmdFhWMk1YamhZOE1rZGpTSE4venhC?= =?utf-8?B?NGU4azJFY3ZIV1NhRGJyeDltNzk5dnl5NlpucGhwZ2x3YVc5TDNLU0Z1OGVG?= =?utf-8?B?c1d5dncyU0xzUDVmcmlJM09QNzNCTGZPUWZNdytRT0d3SVZYbkZqNFZyQzVL?= =?utf-8?B?aUk0emxMdmc0UTI1aHk4ODBER2NYaTJOMUpDaWRnakt2QUlLNlpDR215YThv?= =?utf-8?B?em9XU25lR2tOUy82eTdRY1BhOWloblh4LzBLNjVDV1pMVjJBT1JObFNzS1VU?= =?utf-8?B?Ykt0SlNvQW5QR1B2TWk3b2ZOdkltSVdSWnRINys0SExTNlBDeE9nMUpJa2ZH?= =?utf-8?B?V05RcnNOVSt4QkNxaWR0NzJTSHFBd1YxWUtQUWUrcnIxTEMrYU5XS0ZiYmMz?= =?utf-8?B?c0pxNzhrZ29xV2JCMUkzSzhXSG51RlFhK0JHMjJ2bTZnblNqOGRNdnpTd0R6?= =?utf-8?B?U1JpR0hOM1lyaE5FbmNPbUc3dnNvSUVSWVZVUlk2aVZlRmpyUFNSV09CYlM5?= =?utf-8?B?UTYrNHJjRmczZkRGdjRneTk0L1kyTDNOR0QvWENSekpjRGQ5STlPQUNRVWxo?= =?utf-8?B?RkxwYkUxWXM0QUFyWEtDbmhacHVMSGl2WDFsVVdhVEtlbDJ5VXVtanFrelZx?= =?utf-8?B?SzBQQU1JYXo2WXlqSWtrb3Z3aUtFcWlqMGJBQTZDRjluMDkvSEl2NFFzdGVR?= =?utf-8?B?VUFYR1owS0dtWHd0VU9lUzlTZmZ3eVh3QWZzdFF4SGQ3Ny9TOGxTTmV3VFVN?= =?utf-8?B?SUJZRUtEOGJiODB6dUpFRlpvYkd5MHZXNm9pcThML3VDeGs5VVNtRzZVa3RC?= =?utf-8?B?ZE8rVGRUcnJkdkZQcEhHWmZHSTBvSjIyYXY0S3lGWDRPTDU3L3FqVFVJT3Zz?= =?utf-8?B?R2xuVUN1QVQ4OXU1ek1BMzFJbW1hd2Y2Y2ZXQUl4Z25LZkZyMzllQkgzeGtO?= =?utf-8?B?SkVobG90UHFJSmhRRTlFSkx6bzgxY3I2dFo0VzVFTTUyem1rem9ZRk9VWGN1?= =?utf-8?B?aExVNGlhMVBTKzVXTlc3K0lLUU5tVVBraVZ3cnlRT0NCdjFySll4OUIwMmxu?= =?utf-8?B?T2tsamtnVHVFZ2EvNG15d3FnNWJGN0ZpdmJobnp3azMvMVUwSFZVa1FRaDl4?= =?utf-8?B?dEZoSFQ4Ui94TUQzUFl2enRjK3B4RjQ3KzVHdXkyUm45elJibWdqeWxTRi9k?= =?utf-8?B?SndTcnlmdmMvNXZVaW40bkZ0Y2pTNDQ4RE82TlBqUytEZGgzZ2oyc24wZVhs?= =?utf-8?B?WFVCK1NaVUdrUkxMVSsrdlYvSTlFZlkzMEg3Ly8wZmhiQnMrTUZPQ0xXZHFZ?= =?utf-8?B?emZtNUtTbnFxS21oVnpNWGwyOThnRVVRbnBFcGIrMm5DM25xckpqcDEybkRJ?= =?utf-8?B?Y01tUi9sTVhLbEsyMVVabjBFV2t2dENWdmNiVzJtUTRHenZZVGd0R29xc0Fo?= =?utf-8?B?WFF3K0Z1aUhmYnFsNnlrRlFuZTcwR1JMVjNXNVI1dWpCMTVERUl2R2JYRGNw?= =?utf-8?B?THpZYkJFZ3hiaW9vREtYWFpjWWdMMERWeW9mbDFLZ2poWU0vOEFCbXdLWUFo?= =?utf-8?B?dGpZb0FYUFFIdy9LRWx3MnNNVkJFckg2QnY4eEprYlRlaVBZT2p0bmxQaHN4?= =?utf-8?B?UHErNzdkdTIxeHZJRCtnUDhVWGRnU01vUklCd3l2dTAzWUt0c0tnT2hhZndl?= =?utf-8?B?RjNHOGhlUTYrQmRvNWhuUT09?= x-forefront-antispam-report: CIP:255.255.255.255; CTRY:; LANG:en; SCL:1; SRV:; IPV:NLI; SFV:NSPM; H:BYAPR21MB1608.namprd21.prod.outlook.com; PTR:; CAT:NONE; SFS:(13230031)(376005)(1800799015)(366007)(38070700009); DIR:OUT; SFP:1102; x-ms-exchange-antispam-messagedata-chunkcount: 1 x-ms-exchange-antispam-messagedata-0: =?utf-8?B?QjFqRnlya3FyYjBvRndGVmxWMDl5WTJUajU4Qk9aYnRPSDNJdS9Wd3hjUVRZ?= =?utf-8?B?eFd5b1pOaVIwTk5YTDZEWElEWUY0ZzRJc3lVUlBDdFh2NS8xSkQ5ajM2eXFt?= =?utf-8?B?akcxaUUwREtRWUp2dHRUa05oRzlmOXU4SkY0MEdvTURJTEUvMU5VWG9PR2xS?= =?utf-8?B?VHQ2bi8ySDJETUNWWGsxc05zaC8xTDF5dG1mTmJYN29VQ2toeVhTMlZ0TVNP?= =?utf-8?B?WTJLOGdzZ3JYYWFXYzQyVitSeWZKQS81cVRMZnpKc0RGZ3U0ZEs0ak9oaGR4?= =?utf-8?B?OUFjRFU4SUFhdXhZaml1dTlUakxrd0w3T0cxaVJUbEw4RVB3OTlKR1laK3Zn?= =?utf-8?B?VDRZVEFFb0g1ZWRTajZZY3RMSjIwYjdGaWkzL1hlYTltb0FhL2M4SCtqL3VP?= =?utf-8?B?cWRRVjh0N25rUy9keE5ibElCUjM0aUR5aGFLNnVCVTlCbUJreFNlcDU4OUti?= =?utf-8?B?bE1LbXgyZjZCdmNydDdid0lOZWVmQjc2S1gyaVZFNHUzNDZJdk90alMxVmR0?= =?utf-8?B?V0Y0NDlaNlZWOUZla2FodFd4Z1M0Y09XeGRZS3h5c2VLMUJvS0JWbXpVR1lP?= =?utf-8?B?cVo2SXlWU2tBVjdkVGJLajJyL3I2aFBMVnFYR3VIRWZRZ0hsa1V5NGpiYWRY?= =?utf-8?B?bjJ4emgybmVxL1AvZVdxbW1Nb3FRaGh3eGZESjAxVkdIMVdLK0I4WlIrTTQy?= =?utf-8?B?aHdyVUxvMXBzK1hPcHlxbmNxUVRpZzhMbGluY1lyMGhGaUtqcW9jWWlhSDFp?= =?utf-8?B?aU5kcDRmd21PM0dZb093Y2h6c0VIdXRtWVRpRGxSVkYwOCtsbWQ5bzJISUZC?= =?utf-8?B?TExrTlhxbFlPVjNUbm95NmRSU2FhUGFGMUt1ZnFKWlBObEF5T2dTN2ZmU25W?= =?utf-8?B?LzdKeERkZHllWUk4QVN5K3ZmMGVhVDR2T0R2QkpvdXhkd2I0RDhLcjZRd0NR?= =?utf-8?B?d2tjNU8rUmdWNGVDWDlpU0pDNDk0d2FaYWs1K3Q5Y3MvVHhTZ1Z0NXdBeGkw?= =?utf-8?B?MnhhWEZlc2xIWUs2KzNCNlNzUlZ3OGFhSTVzamEzS1U2Z1VocmpmOXU1SjFQ?= =?utf-8?B?OEFRdUxvYjhMbnhCVStFM0VTY1UyazdubStnY2FXS2pLU2lyVUFSOFZPbzl1?= =?utf-8?B?R1R4WkJZbCt1VkhPRHAwcTJhemsvWSt3SGRmMTlEdnROUlVTVUIwTER4VFBF?= =?utf-8?B?UHpQNTVJakF5OXZxV2tIUVdwazVPWXB1SVRtSmliQXYrWmpTd0ZYLzlRdnlp?= =?utf-8?B?WXA1TkFjLzBhVlNrbjhHM1UxT0hJdnZjdjNkVERVMkZ3Y1N1UG9ISkRVMG0z?= =?utf-8?B?ZldsVlhSNk9Kd2NablZTZGZKZzBQMzdnbmRBbmxDVVI3TjVUcFRRMnUyOFBn?= =?utf-8?B?SkRmWVhLdFdPWWNidGlSYzZqbUxoUG92QlZCSFZjQjNyalVHZ0tKejNYWnRv?= =?utf-8?B?bkpIRjZBclQ0VTBlS3loUGFLdUl5ODUrQ2ZBakkwdVlPRTRWMFdFTjdaeW1E?= =?utf-8?B?UXVyMGNJTDk2QStjbWM2eEtmUTBuNU16ZG5ha2RJdXd6TUpSNVRkZkN3TkR5?= =?utf-8?B?RWdOSTVIajdCaVlORzJtcXJXQW1qaWxZNXNFd3ZrUHArRkd6TGRYazdhYlc2?= =?utf-8?B?bHFLdG1LdE5keEI2NTk3d1Bxdk0xMHpSb0dIUWl4ZW52UHhqZVU2eTZadEdT?= =?utf-8?B?cXR3Z0lMNXJiV0NnNSt3UWtHSGZkUXgvOHIzNDBYSFhwNVJGYlVFVFRCZ1Nn?= =?utf-8?B?K1FDcU1vZ0ZJQ2tBdHdzNGI3dm82aUdiKzFlalBuVDZVclhQRkVNQ2EzMnBH?= =?utf-8?B?aDM3MHJqTnpnem80cTRFQ2lJZVR0L2I2Sk1YK21Qbnl5cUlNWElBalQ5d0Z6?= =?utf-8?B?bTBQbyswelRnRURMTnlDZjFEVEZLemFFSWJlYVM0QjNEUUlSNUZQY29IWkNH?= =?utf-8?B?Y0ZtY0xwNENOTDFzOXlYSGlaaDBNRnIxcUp3ekFINEZ4Rk1tTUVpSVhrNEhL?= =?utf-8?B?a2VkVDNZdFZQVU85SnkxL3JIL0dZU3RuM21PdVhmWnVaL0RlZGNaZTZzZUFE?= =?utf-8?Q?33/ilk?= MIME-Version: 1.0 X-OriginatorOrg: microsoft.com X-MS-Exchange-CrossTenant-AuthAs: Internal X-MS-Exchange-CrossTenant-AuthSource: BYAPR21MB1608.namprd21.prod.outlook.com X-MS-Exchange-CrossTenant-Network-Message-Id: ffa13ccc-232c-401c-f7d0-08dc63c8279b X-MS-Exchange-CrossTenant-originalarrivaltime: 23 Apr 2024 19:04:08.8385 (UTC) X-MS-Exchange-CrossTenant-fromentityheader: Hosted X-MS-Exchange-CrossTenant-id: 72f988bf-86f1-41af-91ab-2d7cd011db47 X-MS-Exchange-CrossTenant-mailboxtype: HOSTED X-MS-Exchange-CrossTenant-userprincipalname: /1ZwguxMvUipFqmAxEpqjkLYsmS8bbpVNsjSHpLfv3ApOCDeOWw6MoPWICiyG5NI8egXa+Mx53dSUjPfpKR0EQ== X-MS-Exchange-Transport-CrossTenantHeadersStamped: BL1PR21MB3235 X-Content-Filtered-By: Mailman/MimeDel 2.1.29 Subject: [FFmpeg-devel] Request for Official GitHub Mirror of rtmpdump for Enhanced Security X-BeenThere: ffmpeg-devel@ffmpeg.org X-Mailman-Version: 2.1.29 Precedence: list List-Id: FFmpeg development discussions and patches List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , From: Javier Matos Denizac via ffmpeg-devel Reply-To: FFmpeg development discussions and patches Cc: Javier Matos Denizac Content-Type: text/plain; charset="us-ascii" Content-Transfer-Encoding: 7bit Errors-To: ffmpeg-devel-bounces@ffmpeg.org Sender: "ffmpeg-devel" Archived-At: List-Archive: List-Post: Dear FFmpeg team, My name is Javier Matos, and I am part of the vcpkg team at Microsoft. vcpkg is an open-source package manager designed to help developers manage C++ libraries across platforms in a consistent manner. I am reaching out to inquire if FFmpeg could host an official GitHub mirror for the `rtmpdump` repository on `github.com/FFmpeg`. Currently, vcpkg uses a mirrored version from `github.com/mirror/rtmpdump`, which is not maintained by the original authors, posing a significant supply chain risk due to potential unauthorized modifications. Alternatively, while we could switch to using the repository at `git://git.ffmpeg.org/rtmpdump.git`, this source lacks support for SHA512 checksums, complicating asset caching and security verification crucial for ensuring the integrity of the code during downloads. An official GitHub mirror hosted by FFmpeg would address these issues by providing a secure, verifiable source that we can integrate with vcpkg. Thank you for considering this request. I look forward to your feedback. Best regards, Javier Matos _______________________________________________ ffmpeg-devel mailing list ffmpeg-devel@ffmpeg.org https://ffmpeg.org/mailman/listinfo/ffmpeg-devel To unsubscribe, visit link above, or email ffmpeg-devel-request@ffmpeg.org with subject "unsubscribe".