+1 (415) 779-8456

GatsbyJS Tutorials

Helpful GatsbyJS Tutorials

Security Headers and a Real CSP for a Gatsby Site

September 9, 2026 · StaticCraft Team

Static does not mean safe: how to ship security headers on a Gatsby 5 site, generate a Content-Security-Policy with inline-script hashes at build time, and roll it out report-only without breaking the deploy.

Read more

Hardening a Gatsby Build Against npm Supply-Chain Attacks

September 9, 2026 · StaticCraft Team

Gatsby ships no server, so the attack surface is the build. A practical hardening pass: lockfile-only installs, disabled lifecycle scripts with an allow-list, release-age cooldowns, npm provenance, minimal build secrets, and SBOMs.

Read more
Looking For More GatsbyJS Help?
Contact Us Today