@trapar-waves/react-visgl-maplibre
A React-based geospatial visualization template integrating Three.js, Deck.gl, and MapLibre for 3D map interactions and rich geospatial data rendering.
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| dependencies | unvetted-dep:react-three-map | AI (dependencies): Legitimate vis.gl/three ecosystem dep matching package's stated purpose. | ai | |
| phantom-deps | phantom-dep:deck.gl | AI (phantom-deps): Peer/indirect dep pattern in deck.gl stack; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:maplibre-gl | AI (phantom-deps): Peer/indirect dep pattern for MapLibre integration; stable false positive for this package. | ai | |
| phantom-deps | phantom-dep:@luma.gl/core | AI (phantom-deps): Peer/indirect dep pattern in luma.gl/deck.gl stack; stable false positive. | ai | |
| phantom-deps | phantom-dep:@deck.gl/react | AI (phantom-deps): Peer/indirect dep pattern in deck.gl stack; stable false positive. | ai | |
| phantom-deps | phantom-dep:three | AI (phantom-deps): Peer/indirect dep pattern in Three.js/deck.gl stack; declared for bundler resolution, not direct import. | ai | |
| phantom-deps | phantom-dep:@loaders.gl/tiles | AI (phantom-deps): Peer/indirect dep pattern in loaders.gl stack; stable false positive. | ai | |
| phantom-deps | phantom-dep:@deck.gl/geo-layers | AI (phantom-deps): Peer/indirect dep pattern in deck.gl stack; stable false positive. | ai | |
| phantom-deps | phantom-dep:@loaders.gl/3d-tiles | AI (phantom-deps): Peer/indirect dep pattern in loaders.gl stack; stable false positive. | ai | |
| phantom-deps | phantom-dep:@luma.gl/webgl | AI (phantom-deps): Peer/indirect dep pattern in luma.gl stack; stable false positive. | ai | |
| install-scripts | install-script:postinstall | FP sweep: benign dev-tooling install script (git-hooks/husky/patch-package/build/codegen etc.), verified from tarball; not malware. Flip disposition to accept. | sean |
Versions (showing 36 of 36)
| Version | Deps | Published |
|---|---|---|
| 1.2.0 | 21 / 24 | |
| 1.1.23 | 21 / 21 | |
| 1.1.22 | 21 / 21 | |
| 1.1.21 | 21 / 21 | |
| 1.1.20 | 21 / 21 | |
| 1.1.19 | 21 / 21 | |
| 1.1.18 | 21 / 21 | |
| 1.1.17 | 21 / 21 | |
| 1.1.16 | 21 / 21 | |
| 1.1.15 | 21 / 21 | |
| 1.1.14 | 21 / 21 | |
| 1.1.13 | 21 / 21 | |
| 1.1.12 | 21 / 21 | |
| 1.1.11 | 21 / 21 | |
| 1.1.10 | 21 / 21 | |
| 1.1.9 | 21 / 21 | |
| 1.1.8 | 21 / 21 | |
| 1.1.7 | 21 / 21 | |
| 1.1.6 | 21 / 21 | |
| 1.1.5 | 21 / 21 | |
| 1.1.4 | 21 / 21 | |
| 1.1.3 | 21 / 21 | |
| 1.1.2 | 21 / 21 | |
| 1.1.1 | 21 / 21 | |
| 1.1.0 | 21 / 21 | |
| 1.0.10 | 21 / 19 | |
| 1.0.9 | 21 / 15 | |
| 1.0.8 | 21 / 15 | |
| 1.0.7 | 21 / 15 | |
| 1.0.6 | 21 / 15 | |
| 1.0.5 | 21 / 15 | |
| 1.0.4 | 21 / 15 | |
| 1.0.3 | 21 / 15 | |
| 1.0.2 | 21 / 15 | |
| 1.0.1 | 21 / 15 | |
| 1.0.0 | 21 / 15 |
v1.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.