Manifests have been superseded by binary caches for years. This also gets rid of nix-pull, nix-generate-patches and bsdiff/bspatch.
specially-crafted derivations that produce output paths belonging to other derivations. This could be used to inject malware into the store.