← Home

gatsby

Blazing fast modern site generator for React

100
Versions
MIT
License
Yes
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.

Maintainers

piehkathmbeckserhalp-netlifymlgualtieri-gatsbyfktylerbarnesdaniellewgatsby

Keywords

bloggeneratorjekyllmarkdownreactssgwebsite

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
phantom-deps phantom-dep:@sigmacomputing/babel-plugin-lodash AI (phantom-deps): Babel plugin loaded by convention in Gatsby's build pipeline; not a direct import by design. ai
phantom-deps phantom-dep:style-to-object AI (phantom-deps): Framework-level convention loading; stable false positive for Gatsby. ai
phantom-deps phantom-dep:body-parser AI (phantom-deps): Gatsby is a framework that loads many deps by convention; phantom dep findings are structural false positives for this package. ai
maintainer-change maintainer-added AI (maintainer-change): Netlify acquired Gatsby; new maintainers with -netlify and -gatsby suffixes reflect legitimate organizational team changes, not a takeover. ai
maintainer-change maintainer-removed AI (maintainer-change): Removal of legacy maintainers is consistent with Netlify's acquisition and team restructuring of the Gatsby project. ai
dependencies unvetted-dep:webpack-merge AI (dependencies): webpack-merge is a mainstream, well-known webpack utility; standard dependency for a framework like Gatsby. ai
phantom-deps phantom-dep:core-js AI (phantom-deps): Gatsby uses core-js as a runtime polyfill loaded by convention via babel-preset-gatsby; not directly imported but legitimately used. ai
phantom-deps phantom-dep:css-loader AI (phantom-deps): Gatsby loads webpack loaders like css-loader dynamically via webpack config; phantom detection is a stable false positive for this framework. ai
phantom-deps phantom-dep:babel-preset-gatsby AI (phantom-deps): Loaded by convention as part of Gatsby's babel configuration; not directly imported but legitimately used. ai
phantom-deps phantom-dep:react-refresh AI (phantom-deps): Used by Gatsby's HMR infrastructure via webpack plugin; loaded by convention, not direct import. ai
dependencies unvetted-dep:babel-loader AI (dependencies): babel-loader is a mainstream, well-known webpack ecosystem package; standard dependency for a framework like Gatsby. ai
semgrep semgrep:dynamic-require AI (semgrep): Dynamic require in SSR module tracking wrapper is intentional framework infrastructure for Gatsby's build system. ai
provenance publisher-changed AI (provenance): pieh and serhalp-netlify are both Gatsby/Netlify team members; legitimate maintainer transition within the same org. ai
install-scripts install-script:postinstall AI (install-scripts): Gatsby's postinstall (node scripts/postinstall.js) is a long-standing part of the framework's install flow; stable across versions. ai

Versions (showing 100 of 1220)

Show 7 prereleases
Version Deps Published
2.0.4 114 / 6
2.0.3 114 / 6
2.0.2 114 / 6
2.0.1 114 / 6
2.0.0 114 / 6
1.9.279 110 / 4
1.9.278 110 / 4
1.9.277 110 / 4
1.9.276 110 / 4
1.9.275 110 / 4
1.9.274 110 / 4
1.9.273 110 / 4
1.9.272 110 / 4
1.9.271 110 / 4
1.9.270 109 / 4
1.9.269 109 / 4
1.9.267 109 / 4
1.9.266 109 / 4
1.9.265 109 / 4
1.9.264 109 / 4
1.9.263 109 / 4
1.9.262 109 / 4
1.9.261 109 / 4
1.9.260 109 / 4
1.9.259 109 / 4
1.9.256 109 / 4
1.9.255 109 / 4
1.9.254 109 / 4
1.9.253 109 / 4
1.9.252 109 / 4
1.9.251 109 / 4
1.9.250 109 / 4
1.9.249 109 / 4
1.9.248 109 / 4
1.9.247 109 / 4
1.9.246 109 / 4
1.9.245 109 / 4
1.9.244 109 / 4
1.9.243 109 / 4
1.9.242 109 / 4
1.9.241 109 / 4
1.9.240 109 / 4
1.9.239 109 / 4
1.9.238 109 / 4
1.9.237 109 / 4
1.9.236 109 / 4
1.9.235 108 / 5
1.9.234 108 / 5
1.9.233 109 / 4
1.9.232 108 / 4
1.9.231 108 / 4
1.9.229 108 / 4
1.9.228 108 / 4
1.9.227 108 / 4
1.9.225 108 / 4
1.9.224 108 / 4
1.9.223 108 / 4
1.9.222 108 / 4
1.9.221 108 / 4
1.9.220 108 / 4
1.9.219 108 / 4
1.9.218 108 / 4
1.9.217 108 / 4
1.9.216 108 / 4
1.9.215 108 / 4
1.9.214 108 / 4
1.9.213 108 / 4
1.9.212 108 / 4
1.9.211 108 / 4
1.9.210 108 / 4
1.9.209 108 / 4
1.9.208 108 / 4
1.9.207 108 / 4
1.9.206 108 / 4
1.9.205 108 / 4
1.9.204 108 / 4
1.9.203 108 / 4
1.9.202 108 / 4
1.9.201 108 / 4
1.9.200 108 / 4
1.9.199 108 / 4
1.9.198 108 / 4
1.9.197 108 / 4
1.9.196 107 / 4
1.9.195 107 / 4
1.9.194 107 / 4
1.9.193 107 / 4
1.9.192 107 / 4
1.9.191 107 / 4
1.9.190 107 / 4
1.9.189 107 / 4
1.9.188 107 / 4
1.9.187 107 / 4
1.9.186 107 / 4
1.9.185 107 / 4
1.9.184 107 / 4
1.9.183 107 / 4
1.9.182 107 / 4
1.9.181 107 / 4
1.9.180 107 / 4
Showing 100 of 1220 Next page →