@gatsbyjs/reach-router
Gatsby's fork to modernize reach-router
7
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
smcgaritykathmbecknodebotanistj0sh77mcolelittletyhoppkgarbayamarvinjudehkkylemathewsdschaupiehwardpeettylerbarnesfksmthomaslekoartsdmccrawjulienprachelbahldaniellewgatsbymlgualtieri-gatsbygatsby_integrations
Keywords
reactreach routergatsby
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| typosquat | typosquat.levenshtein:react-router | AI (typosquat): Scoped under @gatsbyjs org — a legitimate Gatsby-maintained fork of @reach/router. Not a typosquat of react-router; the Levenshtein match is a mechanical false positive for this well-known package. | ai | |
| bogus-package | bogus-package | AI (bogus-package): Inflated semver reflects intentional version alignment with upstream @reach/router fork. README link dump is consistent with a documentation-heavy router library. Not a spam/phishing package. | ai | |
| source-diff | obfuscated-file:dist/index.js | AI (source-diff): Standard microbundle minified output. Code samples show recognizable React router logic (history API, pushState, URL parsing). Not malicious obfuscation. | ai | |
| source-diff | source-size-dropped | AI (source-diff): Size drop explained by removal of react-lifecycles-compat runtime dep and modernization to React 18. Legitimate refactor, not code replacement with a stub. | ai | |
| source-diff | obfuscated-file:dist/index.modern.mjs | AI (source-diff): Standard microbundle minified ESM output. Code samples show recognizable React router logic. Not malicious obfuscation. | ai | |
| install-scripts | install-script:postinstall | AI (install-scripts): Script is named '_postinstall' (underscore prefix) so npm does not execute it. It's a husky dev-tool pattern to prevent consumer execution; stable false positive for this package. | ai | |
| provenance | publisher-changed | AI (provenance): Publisher change from lekoarts to pieh reflects an internal Gatsby team transition; both are known Gatsby contributors. This is stable for this package. | ai | |
| maintainer-change | maintainer-removed | AI (maintainer-change): Removal of abhiaiyer is consistent with routine Gatsby org team changes; no indication of hostile takeover given publisher's strong track record. | ai |