# Bundle provenance

The four assets were copied byte for byte from the original fixture attached to
[VHS PR #1614](https://github.com/videojs/http-streaming/pull/1614).
The static adaptation changes the page and telemetry collection. It does not change the player bundles or add a track removal workaround.

| Asset | Source |
| --- | --- |
| `bundles/video.core-8.24.1.min.js` | `video.js@8.24.1/dist/video.core.min.js` downloaded from jsDelivr |
| `bundles/video-js-8.24.1.min.css` | `video.js@8.24.1/dist/video-js.min.css` downloaded from jsDelivr |
| `bundles/vhs-before.js` | VHS 3.17.5 built from [a9f9d7ac0264b373f14da1bb2f2e7fe8f2775c4f](https://github.com/videojs/http-streaming/commit/a9f9d7ac0264b373f14da1bb2f2e7fe8f2775c4f) |
| `bundles/vhs-after.js` | Unreleased PR #1614 build from [db62124a387621f88321cd4e07c30e24af4e2827](https://github.com/videojs/http-streaming/commit/db62124a387621f88321cd4e07c30e24af4e2827) |

Both VHS bundles were built locally with `npm ci` and `npm run build-prod`.
The output is `dist/videojs-http-streaming.js`. The patched bundle still identifies its package version as 3.17.5.
The commit identifies the proposed change. It is not a released VHS version.

[SHA256SUMS.txt](SHA256SUMS.txt) records the copied assets. Run `npm run check` to verify them.

The following upstream notices are included unchanged:

- [VHS license](licenses/VHS-LICENSE.txt) including its AES implementation notice.
- [Video.js license](licenses/VIDEOJS-LICENSE.txt).

The Apple BipBop media is streamed from its public CDN and is not redistributed in this repository.
