← Home

gatsby-plugin-mdx

MDX integration for Gatsby

51
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

piehkathmbeckserhalp-netlifymlgualtieri-gatsbybiscarch

Keywords

gatsbygatsby-pluginmdxmarkdownremarkrehype

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Publisher change reflects Netlify's organizational transition of Gatsby maintainership; serhalp-netlify has 5581 approved packages and 533-day history. Legitimate handoff. ai
maintainer-change maintainer-added AI (maintainer-change): New maintainers (mlgualtieri-gatsby, serhalp-netlify) have -gatsby/-netlify suffixes consistent with Netlify's Gatsby org transition. Not a hostile takeover signal. ai
maintainer-change maintainer-removed AI (maintainer-change): Removal of prior maintainer fk is consistent with the documented Netlify/Gatsby organizational transition. No malicious indicators present. ai
phantom-deps phantom-dep:acorn AI (phantom-deps): gatsby-plugin-mdx declares deps for plugin/config resolution, not direct imports. This is a stable pattern in the Gatsby ecosystem. ai
phantom-deps phantom-dep:astring AI (phantom-deps): Same as acorn — declared for plugin resolution, not direct import. Stable false positive for this package. ai
phantom-deps phantom-dep:acorn-jsx AI (phantom-deps): Same as acorn — declared for plugin resolution, not direct import. Stable false positive for this package. ai
phantom-deps phantom-dep:mdast-util-mdx AI (phantom-deps): Same as acorn — declared for plugin resolution, not direct import. Stable false positive for this package. ai
phantom-deps phantom-dep:remark-unwrap-images AI (phantom-deps): Same as acorn — declared for plugin resolution, not direct import. Stable false positive for this package. ai
phantom-deps phantom-dep:estree-util-build-jsx AI (phantom-deps): Same as acorn — declared for plugin resolution, not direct import. Stable false positive for this package. ai
phantom-deps phantom-dep:mdast-util-to-markdown AI (phantom-deps): Same as acorn — declared for plugin resolution, not direct import. Stable false positive for this package. ai
phantom-deps phantom-dep:rehype-infer-description-meta AI (phantom-deps): Same as acorn — declared for plugin resolution, not direct import. Stable false positive for this package. ai

Versions (showing 51 of 252)

Hide prereleases View all versions
Version Deps Published
5.16.0 19 / 11
5.15.0 19 / 11
5.14.1 19 / 11
5.14.0 19 / 11
5.13.1 19 / 11
5.13.0 19 / 11
5.12.3 19 / 11
5.12.2 19 / 11
5.12.1 19 / 11
5.12.0 19 / 11
5.11.0 19 / 11
5.10.0 19 / 11
5.9.0 19 / 11
5.8.0 19 / 11
5.7.0 19 / 11
5.6.0 19 / 11
5.5.0 19 / 11
5.4.0 19 / 11
5.3.1 19 / 11
5.3.0 19 / 11
5.2.0 19 / 11
5.1.0 19 / 11
5.0.0 19 / 11
4.4.0 18 / 11
4.3.0 18 / 11
4.2.1 18 / 11
4.2.0 18 / 11
4.1.1 18 / 11
4.1.0 18 / 11
4.0.0 18 / 11
3.20.0 38 / 5
3.19.0 38 / 5
3.18.1 38 / 5
3.18.0 38 / 5
3.17.0 38 / 5
3.16.1 38 / 5
3.16.0 38 / 5
3.15.2 38 / 5
3.15.1 38 / 5
3.15.0 38 / 5
3.14.0 38 / 5
3.13.0 38 / 5
3.12.1 38 / 5
3.12.0 38 / 5
3.11.1 38 / 5
3.11.0 38 / 5
3.10.2 38 / 5
3.10.1 38 / 5
3.10.0 38 / 5
3.9.1 38 / 5
3.9.0 38 / 5

v5.16.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.15.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.14.1

2 findings
HIGH Publisher changed: serhalp-netlify → pieh (on 2025-04-07) provenance

This version was published by a different npm account than previous versions on 2025-04-07. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.14.0

2 findings
HIGH Publisher changed: pieh → serhalp-netlify (on 2024-11-06) provenance

This version was published by a different npm account than previous versions on 2024-11-06. This could indicate a legitimate maintainer transition or an account compromise.

LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.13.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.13.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.12.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.12.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.12.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.12.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: lekoarts → pieh (on 2023-08-24) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2023-08-24. This could indicate a legitimate maintainer transition or an account compromise.

v5.11.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.10.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.9.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: pieh → lekoarts (on 2023-04-18) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2023-04-18. This could indicate a legitimate maintainer transition or an account compromise.

v5.8.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.7.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: lekoarts → pieh (on 2023-02-21) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2023-02-21. This could indicate a legitimate maintainer transition or an account compromise.

v5.6.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: pieh → lekoarts (on 2023-02-07) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2023-02-07. This could indicate a legitimate maintainer transition or an account compromise.

v5.5.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: lekoarts → pieh (on 2023-01-24) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2023-01-24. This could indicate a legitimate maintainer transition or an account compromise.

v5.4.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: marvinjudehk → lekoarts (on 2023-01-10) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2023-01-10. This could indicate a legitimate maintainer transition or an account compromise.

v5.3.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.3.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: pieh → marvinjudehk (on 2022-12-13) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2022-12-13. This could indicate a legitimate maintainer transition or an account compromise.

v5.2.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v5.1.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: pieh → tyhopp (on 2022-11-22) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2022-11-22. This could indicate a legitimate maintainer transition or an account compromise.

v5.0.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: marvinjudehk → pieh (on 2022-11-08) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2022-11-08. This could indicate a legitimate maintainer transition or an account compromise.

v4.4.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.3.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: tyhopp → marvinjudehk (on 2022-09-27) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2022-09-27. This could indicate a legitimate maintainer transition or an account compromise.

v4.2.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v4.2.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: j0sh77 → tyhopp (on 2022-09-13) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2022-09-13. This could indicate a legitimate maintainer transition or an account compromise.

v4.1.1

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: pieh → j0sh77 (on 2022-09-08) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2022-09-08. This could indicate a legitimate maintainer transition or an account compromise.

v4.1.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: marvinjudehk → pieh (on 2022-08-30) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2022-08-30. This could indicate a legitimate maintainer transition or an account compromise.

v4.0.0

2 findings
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

INFO Publisher changed: pieh → marvinjudehk (on 2022-08-16) provenance

[Accepted risk] This version was published by a different npm account than previous versions on 2022-08-16. This could indicate a legitimate maintainer transition or an account compromise.