THIRD-PARTY-NOTICES.md, at the repository root and again in frontend/media/, records Mediabunny as MPL-2.0 and links the upstream source, but gives no URL for the MPL-2.0 text itself.
MPL-2.0 asks that a recipient be told how to obtain a copy of the licence. In practice this is satisfied only by the banner Mediabunny preserves inside the compiled worker, which is not somewhere a reader of the notices file will look.
Direction: add the canonical licence URL beside the licence name in both copies.
THIRD-PARTY-NOTICES.md, at the repository root and again infrontend/media/, records Mediabunny as MPL-2.0 and links the upstream source, but gives no URL for the MPL-2.0 text itself.MPL-2.0 asks that a recipient be told how to obtain a copy of the licence. In practice this is satisfied only by the banner Mediabunny preserves inside the compiled worker, which is not somewhere a reader of the notices file will look.
Direction: add the canonical licence URL beside the licence name in both copies.