@modelcontextprotocol/server-map
MCP App Server example with CesiumJS 3D globe and geocoding
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Zod is a runtime dependency for schema validation; directly imported in server code. | ai | |
| phantom-deps | phantom-dep:cors | AI (phantom-deps): CORS middleware is a runtime dependency; directly imported and used in Express setup. | ai | |
| phantom-deps | phantom-dep:express | AI (phantom-deps): Express is the core HTTP server framework; directly imported and used throughout. | ai | |
| phantom-deps | phantom-dep:@modelcontextprotocol/ext-apps | AI (phantom-deps): Same-org scoped dependency; declared and used as a runtime dependency. | ai |
Versions (showing 19 of 19)
| Version | Deps | Published |
|---|---|---|
| 1.7.3 | 5 / 8 | |
| 1.7.2 | 5 / 8 | |
| 1.7.1 | 5 / 8 | |
| 1.7.0 | 5 / 8 | |
| 1.6.0 | 5 / 8 | |
| 1.5.0 | 5 / 8 | |
| 1.4.0 | 5 / 8 | |
| 1.3.2 | 5 / 8 | |
| 1.3.1 | 5 / 8 | |
| 1.3.0 | 5 / 8 | |
| 1.2.2 | 5 / 8 | |
| 1.2.1 | 5 / 8 | |
| 1.2.0 | 5 / 8 | |
| 1.1.2 | 5 / 8 | |
| 1.1.1 | 5 / 8 | |
| 1.0.1 | 5 / 8 | |
| 1.0.0 | 5 / 8 | |
| 0.4.2 | 5 / 8 | |
| 0.4.1 | 5 / 8 |
v1.7.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.2.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.2.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.4.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.