@mastra/ai-sdk
Adds custom API routes to be compatible with the AI SDK UI parts
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/_types/@internal_ai-v6/dist/index.d.ts | AI (source-diff): Long lines in generated .d.ts type bundles are expected; not obfuscation. | ai | |
| source-diff | obfuscated-file:dist/_types/@internal_ai-sdk-v5/dist/index.d.ts | AI (source-diff): Long lines in a .d.ts file are bundled TypeScript type declarations, not obfuscated executable code. | ai | |
| provenance | publisher-changed | AI (provenance): Transition to GitHub Actions CI publisher with SLSA attestation; consistent with org-wide CI migration for mastra-ai monorepo. | ai | |
| typosquat | typosquat.levenshtein:aws-sdk | AI (typosquat): Legitimate @mastra scoped package; name reflects 'ai-sdk' integration, not aws-sdk impersonation. | ai |
Versions (showing 35 of 35)
| Version | Deps | Published |
|---|---|---|
| 1.6.3 | 0 / 19 | |
| 1.6.2 | 0 / 17 | |
| 1.6.1 | 0 / 17 | |
| 1.6.0 | 0 / 17 | |
| 1.5.1 | 0 / 17 | |
| 1.5.0 | 0 / 17 | |
| 1.4.7 | 0 / 17 | |
| 1.4.5 | 0 / 17 | |
| 1.4.4 | 0 / 17 | |
| 1.4.3 | 0 / 17 | |
| 1.4.2 | 0 / 17 | |
| 1.4.1 | 0 / 17 | |
| 1.4.0 | 0 / 17 | |
| 1.3.3 | 0 / 17 | |
| 1.3.2 | 0 / 17 | |
| 1.3.1 | 0 / 17 | |
| 1.3.0 | 0 / 17 | |
| 1.2.1 | 0 / 17 | |
| 1.2.0 | 0 / 17 | |
| 1.1.4 | 0 / 16 | |
| 1.1.3 | 0 / 16 | |
| 1.1.2 | 0 / 16 | |
| 1.1.1 | 0 / 15 | |
| 1.1.0 | 0 / 14 | |
| 1.0.5 | 0 / 14 | |
| 1.0.4 | 0 / 14 | |
| 1.0.3 | 0 / 14 | |
| 1.0.2 | 0 / 14 | |
| 1.0.1 | 1 / 9 | |
| 1.0.0 | 1 / 9 | |
| 0.3.3 | 1 / 9 | |
| 0.3.2 | 1 / 9 | |
| 0.3.1 | 1 / 9 | |
| 0.2.7 | 1 / 9 | |
| 0.2.6 | 1 / 9 |
v1.6.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.2.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.2.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.