@googlemaps/js-api-loader
6
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
google-wombotwangelakenoughcbaueratworkanglarettryanbaumann
Keywords
googlemaps
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/index.cjs | AI (source-diff): Rollup+Terser minified bundle; standard build output for this package. | ai | |
| source-diff | net-exec-file:dist/index.cjs | AI (source-diff): Library's purpose is to dynamically load Google Maps JS API via script injection. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @types/google.maps is the official types package for this library's domain. | ai | |
| dependencies | unvetted-dep:@types/google.maps | AI (dependencies): @types/google.maps is the official Google Maps TypeScript definitions package; well-known and legitimate in this context. | ai | |
| phantom-deps | phantom-dep:@types/google.maps | AI (phantom-deps): @types/* packages are convention-loaded by TypeScript and not directly imported; phantom-dep finding is a stable false positive for this package. | ai | |
| publish-pattern | dormant-publish | AI (publish-pattern): Major version bump (v1→v2) from Google's official publisher bot explains the long gap; not indicative of account takeover. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers appear to be Google Maps platform engineers; published via Google's wombat proxy with official repo URL confirming legitimacy. | ai |