@ag-ui/mastra
Supply chain provenance
Status for the latest visible version.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/mastra-Dozbr1Ex.js | AI (source-diff): Bundled minified output (tsdown); code is readable and benign, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/mastra-BQO6BVT_.mjs | AI (source-diff): Bundled minified output (tsdown); code is readable and benign, not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/a2ui-tool-CD0w1hhG.mjs | AI (source-diff): Bundled build output (tsdown); readable identifiers, no true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/mastra-L4s4cSPp.mjs | AI (source-diff): Bundled build output (tsdown); readable identifiers, no true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/a2ui-tool-w-ZB0CY6.js | AI (source-diff): Bundled build output (tsdown); readable identifiers, no true obfuscation. | ai | |
| phantom-deps | phantom-dep:fast-json-patch | AI (phantom-deps): Used in bundled dist output; phantom-dep heuristic misses bundled imports. | ai | |
| phantom-deps | phantom-dep:@ai-sdk/ui-utils | AI (phantom-deps): Used in bundled dist output; phantom-dep heuristic misses bundled imports. | ai | |
| phantom-deps | phantom-dep:zod | AI (phantom-deps): Used in bundled dist output; phantom-dep heuristic misses bundled imports. | ai | |
| source-diff | obfuscated-file:dist/mastra-CW7Gt4su.js | AI (source-diff): Bundled build output (tsdown); readable identifiers, no true obfuscation. | ai |
Versions (showing 7 of 7)
| Version | Deps | Published |
|---|---|---|
| 1.1.0 | 5 / 13 | |
| 1.0.3 | 2 / 13 | |
| 1.0.2 | 2 / 13 | |
| 1.0.1 | 2 / 13 | |
| 1.0.0 | 2 / 10 | |
| 0.2.4 | 3 / 9 | |
| 0.2.3 | 3 / 9 |
v1.1.0
6 findingsThis version was published by a different npm account than previous versions on 2026-07-02. This could indicate a legitimate maintainer transition or an account compromise.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.