← Home

@mapbox/geojson-area

calculate the physical area of a geojson geometry

2
Versions
BSD-2-Clause
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

aaronlidmanaarthykcajashtonajithrankaaliceykuoalinapazalulshamishas157amyleewandreasviglakisansisapendletonarunasankbatpadbenjamintdbhouselbkowshikbrendanmcfarlandbsudekumcamillacaroscamilleannecaptainbarbosachaupowcolleenmcginnisdanieljhdanpatdanswickdasulitdavidtheclarkdnomadbdthompsonemilymcafeeemilymduboisenffreenerdgeohackerghoshkajgretacbian29ianshwardingallsisiyujacquestardiejfirebaughjothirnadhjrpruit1k-mahoneykaibot3000kaidalgleishkarenzsheakaritotpkatydecorahkkaeferl-rlaurierlbudlily-chailucaswojlxbarthlyzidiamondmaningmapbox-adminmapsammateovmattfickemayaqgaomcwhittemoremiccolismiles-devmokobmollymerpmorganherlockermournermsirenkonatslaughternickcordellanickidlugashoinioxidasepdgoodmanperrygeoplanemadpratikyadavrclarkrodowirub21rumcryan-baumannsaikia.abhisheksamanbbsbma44scothisspringmeyersrividyacbtcqlthemarextmcwtony-cjtristenuvollmervincentsvirginiayungwho8mycakeswillwhitexrwangyhahnzmully

Keywords

geojsonareageodesy

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
email-domain unclaimed-email:gmail.colm AI (email-domain): Typo of gmail.com in a legacy maintainer field; established Mapbox package, not an active hijack risk. ai
email-domain unclaimed-email:wilhel.me AI (email-domain): Stale maintainer email on a 9-year-old Mapbox package; no evidence of active exploitation. ai
dependencies unvetted-dep:wgs84 AI (dependencies): wgs84 is a known Mapbox/tmcw constants package; stable dependency for this geospatial utility. ai

Versions (showing 2 of 2)

Version Deps Published
0.2.2 1 / 2
0.2.1 1 / 1

v0.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.