gatsby-plugin-manifest
Gatsby plugin which adds a manifest.webmanifest to make sites progressive web apps
43
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
piehkathmbeckserhalp-netlifymlgualtieri-gatsbyfktylerbarnesdaniellewgatsby
Keywords
gatsbygatsby-pluginfaviconiconsmanifest.webmanifestprogressive-web-apppwa
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| phantom-deps | phantom-dep:sharp | AI (phantom-deps): Sharp is a documented runtime dependency for image processing; implicit dependency is expected and stable. | ai | |
| phantom-deps | phantom-dep:semver | AI (phantom-deps): Semver is a declared dependency used in configuration; phantom-dep finding is a false positive for this package. | ai | |
| phantom-deps | phantom-dep:gatsby-plugin-utils | AI (phantom-deps): gatsby-plugin-utils is a declared dependency referenced in config; phantom-dep is expected for plugin utilities. | ai | |
| semgrep | semgrep:child-process-import | AI (semgrep): safe-sharp.js uses child_process for sharp binary detection — long-standing pattern in the Gatsby monorepo. | ai | |
| provenance | publisher-changed | AI (provenance): Gatsby project transitioned to Netlify stewardship; publisher change from pieh to serhalp-netlify is an expected organizational transition. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Empty index.js is standard Gatsby plugin convention; mass publisher is a monorepo contributor pattern. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers (mlgualtieri-gatsby, serhalp-netlify) are Netlify-affiliated accounts consistent with Gatsby's organizational transition. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removal of wardpeet is part of the Gatsby→Netlify maintainer transition; not indicative of takeover. | ai |
Versions (showing 43 of 243)
| Version | Deps | Published |
|---|---|---|
| 2.0.16 | 3 / 4 | |
| 2.0.15 | 3 / 4 | |
| 2.0.14 | 3 / 4 | |
| 2.0.13 | 3 / 4 | |
| 2.0.12 | 3 / 4 | |
| 2.0.11 | 3 / 4 | |
| 2.0.10 | 3 / 4 | |
| 2.0.9 | 3 / 4 | |
| 2.0.8 | 3 / 4 | |
| 2.0.7 | 3 / 4 | |
| 2.0.6 | 3 / 3 | |
| 2.0.5 | 3 / 3 | |
| 2.0.4 | 3 / 3 | |
| 2.0.3 | 3 / 3 | |
| 2.0.2 | 3 / 3 | |
| 1.0.27 | 3 / 2 | |
| 1.0.26 | 3 / 2 | |
| 1.0.25 | 3 / 2 | |
| 1.0.24 | 3 / 2 | |
| 1.0.23 | 3 / 2 | |
| 1.0.22 | 3 / 2 | |
| 1.0.21 | 3 / 2 | |
| 1.0.20 | 3 / 2 | |
| 1.0.19 | 3 / 2 | |
| 1.0.18 | 3 / 2 | |
| 1.0.17 | 3 / 2 | |
| 1.0.16 | 3 / 2 | |
| 1.0.15 | 2 / 2 | |
| 1.0.14 | 2 / 2 | |
| 1.0.13 | 2 / 2 | |
| 1.0.12 | 2 / 2 | |
| 1.0.11 | 2 / 2 | |
| 1.0.10 | 2 / 2 | |
| 1.0.9 | 2 / 2 | |
| 1.0.8 | 2 / 2 | |
| 1.0.7 | 2 / 2 | |
| 1.0.6 | 2 / 1 | |
| 1.0.5 | 2 / 1 | |
| 1.0.4 | 2 / 1 | |
| 1.0.3 | 1 / 1 | |
| 1.0.2 | 1 / 1 | |
| 1.0.1 | 1 / 1 | |
| 1.0.0 | 1 / 1 |