@ldn-viz/maps
5
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
ldn-viz
Keywords
svelte
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | no-description | AI (npm-metadata): Scoped org package; missing description is a style issue, not a malware signal for this established package. | ai | |
| dependencies | unvetted-dep:terra-draw | AI (dependencies): terra-draw is a legitimate open-source drawing library for maps; no malware indicators. | ai | |
| dependencies | unvetted-dep:@ldn-viz/utils | AI (dependencies): Same org scope (@ldn-viz); internal utility package, stable false positive. | ai | |
| phantom-deps | phantom-dep:@deck.gl/layers | AI (phantom-deps): deck.gl layers used in config/re-exports; stable false positive for this mapping library. | ai | |
| phantom-deps | phantom-dep:@deck.gl/mapbox | AI (phantom-deps): Same pattern as other deck.gl phantom deps. | ai | |
| phantom-deps | phantom-dep:@deck.gl/geo-layers | AI (phantom-deps): Same pattern as other deck.gl phantom deps. | ai | |
| typosquat | typosquat.levenshtein:hapi | AI (typosquat): Scoped @ldn-viz/maps package; Levenshtein match to 'hapi' is a false positive with no semantic similarity. | ai | |
| phantom-deps | phantom-dep:terra-draw-maplibre-gl-adapter | AI (phantom-deps): Terra-draw adapter referenced in config; stable false positive for this mapping library. | ai | |
| phantom-deps | phantom-dep:@ldn-viz/utils | AI (phantom-deps): Same-org utility package; used in config/re-exports, stable false positive. | ai | |
| phantom-deps | phantom-dep:svelte-floating-ui | AI (phantom-deps): Svelte UI utility used in component config; stable false positive. | ai | |
| phantom-deps | phantom-dep:@turf/turf | AI (phantom-deps): Geo library used in config/re-exports in Svelte component packages; stable false positive. | ai | |
| phantom-deps | phantom-dep:@turf/centroid | AI (phantom-deps): Same as @turf/turf — config/re-export pattern in Svelte library. | ai |