@trapar-waves/react-visgl-maplibre
A React-based geospatial visualization template integrating Three.js, Deck.gl, and MapLibre for 3D map interactions and rich geospatial data rendering.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:three | AI (phantom-deps): Peer/indirect dep pattern in Three.js/deck.gl stack; declared for bundler resolution, not direct import. | ai | |
| phantom-deps | phantom-dep:deck.gl | AI (phantom-deps): Peer/indirect dep pattern in deck.gl stack; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:maplibre-gl | AI (phantom-deps): Peer/indirect dep pattern for MapLibre integration; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@luma.gl/core | AI (phantom-deps): Peer/indirect dep pattern in luma.gl/deck.gl stack; stable false positive. | ai | |
| phantom-deps | phantom-dep:@deck.gl/react | AI (phantom-deps): Peer/indirect dep pattern in deck.gl stack; stable false positive. | ai | |
| phantom-deps | phantom-dep:@luma.gl/webgl | AI (phantom-deps): Peer/indirect dep pattern in luma.gl stack; stable false positive. | ai | |
| phantom-deps | phantom-dep:@loaders.gl/tiles | AI (phantom-deps): Peer/indirect dep pattern in loaders.gl stack; stable false positive. | ai | |
| phantom-deps | phantom-dep:@deck.gl/geo-layers | AI (phantom-deps): Peer/indirect dep pattern in deck.gl stack; stable false positive. | ai | |
| phantom-deps | phantom-dep:@loaders.gl/3d-tiles | AI (phantom-deps): Peer/indirect dep pattern in loaders.gl stack; stable false positive. | ai |
Versions (showing 5 of 5)
| Version | Deps | Published |
|---|---|---|
| 1.0.10 | 21 / 19 | |
| 1.0.9 | 21 / 15 | |
| 1.0.6 | 21 / 15 | |
| 1.0.5 | 21 / 15 | |
| 1.0.4 | 21 / 15 |
v1.0.10
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.9
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.6
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.5
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.4
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.