@googlemaps/markerclusterer
3
Versions
—
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
google-wombotwangelakenoughanglarett
Keywords
clustergooglemapsmarker
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| publish-pattern | dormant-publish | AI (publish-pattern): Google-managed package published via wombat-dressing-room; dormancy reflects team cadence, not takeover. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers added under Google's wombat proxy; consistent with legitimate org-level team change. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): fast-equals and @types/supercluster are well-known, benign packages replacing fast-deep-equal. | ai | |
| dependencies | unvetted-dep:@types/supercluster | AI (dependencies): @types/supercluster provides TypeScript type definitions for supercluster; benign and expected in a TypeScript library. | ai | |
| phantom-deps | phantom-dep:@types/supercluster | AI (phantom-deps): Type packages declared as runtime deps is a known pattern for TypeScript libraries to ensure consumers receive type definitions. | ai | |
| dependencies | unvetted-dep:supercluster | AI (dependencies): supercluster is a well-known Mapbox geospatial clustering library; it is a natural and expected dependency for a marker clustering package. Stable false positive for this package. | ai |
v2.6.2
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v2.6.1
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v2.5.3
1 finding
LOW
No provenance attestation
provenance
Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.