gatsby-source-filesystem
Gatsby source plugin for building websites from local data. Markdown, JSON, images, YAML, CSV, and dozens of other data types supported.
84
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
piehkathmbeckserhalp-netlifymlgualtieri-gatsbyfktylerbarnesdaniellewgatsby
Keywords
gatsbygatsby-plugin
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Publisher change reflects Netlify's acquisition of Gatsby; serhalp-netlify is a verified Netlify employee with 5570 approved packages. This transition is organizational, not a takeover. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): New maintainers mlgualtieri-gatsby and serhalp-netlify are Netlify employees taking over Gatsby maintenance post-acquisition. Legitimate organizational transition. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removal of original Gatsby founders (kylemathews, dschau) is consistent with Netlify acquisition transition. Not indicative of malicious takeover. | ai | |
| phantom-deps | phantom-dep:mime | AI (phantom-deps): Declared runtime dependency; phantom detection likely due to compiled Babel output being distributed rather than source files. | ai | |
| phantom-deps | phantom-dep:xstate | AI (phantom-deps): Declared runtime dependency; phantom detection likely due to compiled Babel output being distributed rather than source files. | ai | |
| phantom-deps | phantom-dep:chokidar | AI (phantom-deps): Declared runtime dependency; phantom detection likely due to compiled Babel output being distributed rather than source files. | ai | |
| phantom-deps | phantom-dep:fs-extra | AI (phantom-deps): Declared runtime dependency; phantom detection likely due to compiled Babel output being distributed rather than source files. | ai | |
| phantom-deps | phantom-dep:file-type | AI (phantom-deps): Declared runtime dependency; phantom detection likely due to compiled Babel output being distributed rather than source files. | ai | |
| phantom-deps | phantom-dep:valid-url | AI (phantom-deps): Declared runtime dependency; phantom detection likely due to compiled Babel output being distributed rather than source files. | ai | |
| phantom-deps | phantom-dep:pretty-bytes | AI (phantom-deps): Declared runtime dependency; phantom detection likely due to compiled Babel output being distributed rather than source files. | ai | |
| phantom-deps | phantom-dep:@babel/runtime | AI (phantom-deps): Framework-scoped Babel runtime dependency; standard for Gatsby packages compiled with babel-preset-gatsby-package. | ai | |
| phantom-deps | phantom-dep:gatsby-core-utils | AI (phantom-deps): Declared runtime dependency; phantom detection likely due to compiled Babel output being distributed rather than source files. | ai |
Versions (showing 84 of 284)
| Version | Deps | Published |
|---|---|---|
| 2.0.26 | 15 / 4 | |
| 2.0.25 | 15 / 4 | |
| 2.0.24 | 15 / 4 | |
| 2.0.23 | 15 / 4 | |
| 2.0.22 | 15 / 4 | |
| 2.0.21 | 15 / 4 | |
| 2.0.20 | 15 / 4 | |
| 2.0.19 | 15 / 4 | |
| 2.0.18 | 15 / 4 | |
| 2.0.17 | 15 / 4 | |
| 2.0.16 | 15 / 4 | |
| 2.0.14 | 15 / 4 | |
| 2.0.13 | 14 / 4 | |
| 2.0.12 | 14 / 4 | |
| 2.0.11 | 14 / 4 | |
| 2.0.10 | 14 / 4 | |
| 2.0.9 | 14 / 4 | |
| 2.0.8 | 14 / 4 | |
| 2.0.7 | 14 / 4 | |
| 2.0.6 | 12 / 4 | |
| 2.0.5 | 12 / 3 | |
| 2.0.4 | 12 / 3 | |
| 2.0.3 | 12 / 3 | |
| 2.0.2 | 12 / 3 | |
| 2.0.1 | 12 / 3 | |
| 1.5.39 | 12 / 1 | |
| 1.5.38 | 12 / 1 | |
| 1.5.37 | 12 / 1 | |
| 1.5.36 | 12 / 1 | |
| 1.5.35 | 12 / 1 | |
| 1.5.34 | 12 / 1 | |
| 1.5.33 | 11 / 1 | |
| 1.5.32 | 11 / 1 | |
| 1.5.31 | 11 / 1 | |
| 1.5.30 | 11 / 1 | |
| 1.5.29 | 11 / 1 | |
| 1.5.28 | 11 / 1 | |
| 1.5.27 | 11 / 1 | |
| 1.5.26 | 11 / 1 | |
| 1.5.25 | 11 / 1 | |
| 1.5.24 | 11 / 1 | |
| 1.5.23 | 11 / 1 | |
| 1.5.22 | 11 / 1 | |
| 1.5.21 | 11 / 1 | |
| 1.5.20 | 11 / 1 | |
| 1.5.19 | 11 / 1 | |
| 1.5.18 | 11 / 1 | |
| 1.5.17 | 11 / 1 | |
| 1.5.16 | 11 / 1 | |
| 1.5.15 | 11 / 1 | |
| 1.5.14 | 11 / 1 | |
| 1.5.13 | 11 / 1 | |
| 1.5.12 | 11 / 1 | |
| 1.5.11 | 11 / 1 | |
| 1.5.10 | 11 / 1 | |
| 1.5.9 | 11 / 1 | |
| 1.5.8 | 11 / 1 | |
| 1.5.7 | 11 / 1 | |
| 1.5.6 | 10 / 1 | |
| 1.5.5 | 10 / 1 | |
| 1.5.4 | 10 / 1 | |
| 1.5.3 | 10 / 1 | |
| 1.5.2 | 10 / 1 | |
| 1.5.1 | 10 / 1 | |
| 1.5.0 | 10 / 1 | |
| 1.4.12 | 10 / 1 | |
| 1.4.11 | 10 / 1 | |
| 1.4.10 | 10 / 1 | |
| 1.4.9 | 10 / 0 | |
| 1.4.8 | 8 / 0 | |
| 1.4.7 | 8 / 0 | |
| 1.4.6 | 8 / 0 | |
| 1.4.5 | 8 / 0 | |
| 1.4.4 | 8 / 0 | |
| 1.4.3 | 8 / 0 | |
| 1.4.2 | 7 / 0 | |
| 1.4.1 | 7 / 0 | |
| 1.4.0 | 7 / 0 | |
| 1.0.1 | 5 / 0 | |
| 1.0.0 | 5 / 0 | |
| 5.17.0-react19.1 | 9 / 4 | |
| 5.17.0-react19.0 | 9 / 4 | |
| 5.17.0-next.0 | 9 / 4 | |
| 5.16.0-next.0 | 9 / 4 |