@mastra/core
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/chunk-XGNME7PA.cjs | AI (source-diff): Bundled tsup chunk with std-lib require; no hostile fetch/exec target. Stable build artifact for this package. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/otlp-exporter-base | AI (phantom-deps): OTel package referenced via config, stable false positive. | ai | |
| phantom-deps | phantom-dep:@opentelemetry/sdk-metrics | AI (phantom-deps): OTel package referenced via config, stable false positive. | ai | |
| phantom-deps | phantom-dep:zod-to-json-schema | AI (phantom-deps): Referenced indirectly, stable false positive. | ai | |
| phantom-deps | phantom-dep:pino-pretty | AI (phantom-deps): Optional logging transport referenced in config. | ai | |
| phantom-deps | phantom-dep:date-fns | AI (phantom-deps): Referenced in config, not a real omission. | ai | |
| phantom-deps | phantom-dep:pino | AI (phantom-deps): Used via config/dynamic logging setup, stable false positive. | ai | |
| dependencies | unvetted-dep:@openrouter/ai-sdk-provider-v5 | AI (dependencies): Official OpenRouter AI SDK provider, aliased for v5 migration. | ai | |
| dependencies | unvetted-dep:@ai-sdk/openai-compatible-v5 | AI (dependencies): Official Vercel AI SDK provider, aliased for v5 migration. | ai | |
| dependencies | unvetted-dep:@ai-sdk/anthropic-v5 | AI (dependencies): Official Vercel AI SDK provider, aliased for v5 migration. | ai | |
| dependencies | unvetted-dep:@ai-sdk/mistral-v5 | AI (dependencies): Official Vercel AI SDK provider, aliased for v5 migration. | ai | |
| dependencies | unvetted-dep:@ai-sdk/openai-v5 | AI (dependencies): Official Vercel AI SDK provider, aliased for v5 migration. | ai | |
| dependencies | unvetted-dep:@ai-sdk/google-v5 | AI (dependencies): Official Vercel AI SDK provider, aliased for v5 migration. | ai | |
| dependencies | unvetted-dep:ai-v5 | AI (dependencies): Official ai-sdk alias package, well-known and widely used. | ai | |
| dependencies | unvetted-dep:@ai-sdk/xai-v5 | AI (dependencies): Official Vercel AI SDK provider, aliased for v5 migration. | ai | |
| phantom-deps | phantom-dep:fastq | AI (phantom-deps): Bundled dep referenced transitively; stable FP for this package. | ai | |
| source-diff | net-exec-file:dist/chunk-OAN2CNR7.cjs | AI (source-diff): Bundled framework storage/MCP code; net+require are normal internals, per-hash filename won't recur. | ai | |
| dependencies | unvetted-dep:@ai-sdk/provider-v7 | AI (dependencies): Aliased official @ai-sdk/provider; established ecosystem package. | ai | |
| source-diff | net-exec-file:dist/chunk-GEMF5BYY.js | AI (source-diff): Bundled ESM framework dist chunk; MCP/storage code, benign. | ai | |
| source-diff | net-exec-file:dist/chunk-QOHX7UZQ.cjs | AI (source-diff): Bundled framework dist chunk; net+fs are legitimate storage/agent code, no exfil target. | ai | |
| dependencies | unvetted-dep:@ai-sdk/provider-utils-v7 | AI (dependencies): Aliased official @ai-sdk/provider-utils; established ecosystem package. | ai | |
| source-diff | net-exec-file:dist/chunk-YLFDILPM.cjs | AI (source-diff): Bundled build output with standard node APIs (crypto, fs, path); no malicious behavior in sample. | ai | |
| source-diff | net-exec-file:dist/chunk-TYT5FLEU.cjs | AI (source-diff): Build-output chunk with standard Node APIs (crypto, fs, path); no malicious behavior in sample. | ai | |
| source-diff | net-exec-file:dist/chunk-7JOITI7K.cjs | AI (source-diff): Chunked CJS build output with standard requires; no malicious payload in sample. | ai | |
| phantom-deps | phantom-dep:@modelcontextprotocol/sdk | AI (phantom-deps): Peer/optional dep referenced in config; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@ai-sdk/provider-utils-v7 | AI (phantom-deps): npm-aliased dep used via config; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@ai-sdk/ui-utils-v5 | AI (phantom-deps): npm-aliased dep used via config; stable pattern for this package. | ai | |
| phantom-deps | phantom-dep:@ai-sdk/provider-v7 | AI (phantom-deps): npm-aliased dep used via config; stable pattern for this package. | ai | |
| source-diff | net-exec-file:dist/chunk-J5F3CZD7.cjs | AI (source-diff): Bundled CJS chunk with normal require() calls; no malicious network+exec behavior. | ai | |
| source-diff | net-exec-file:dist/chunk-HXSNKC2B.js | AI (source-diff): ESM counterpart of same bundled build output; standard imports, not malicious. | ai | |
| source-diff | net-exec-file:dist/chunk-TMPKR5YT.cjs | AI (source-diff): Bundled build output with standard imports (crypto, fs, path); not malicious. | ai | |
| source-diff | net-exec-file:dist/chunk-6GGWCR2E.js | AI (source-diff): ESM counterpart of same bundled chunk; same false-positive pattern. | ai | |
| source-diff | net-exec-file:dist/chunk-O3IPVE45.cjs | AI (source-diff): Bundled build output for server-side AI framework; network+exec from crypto/fs/path imports is expected. | ai | |
| source-diff | net-exec-file:dist/chunk-MOHL74NI.cjs | AI (source-diff): Bundled CJS output for AI framework; network+exec pattern is normal application logic, not a dropper. | ai | |
| phantom-deps | phantom-dep:@ai-sdk/provider-v6 | AI (phantom-deps): npm-aliased dependency (npm:@ai-sdk/[email protected]); import resolves under alias. | ai | |
| phantom-deps | phantom-dep:@ai-sdk/provider-v5 | AI (phantom-deps): npm-aliased dependency (npm:@ai-sdk/[email protected]); import resolves under alias. | ai | |
| source-diff | net-exec-file:dist/chunk-IPBUKOUR.js | AI (source-diff): ESM counterpart of same storage domain code; legitimate network+fs usage. | ai | |
| source-diff | net-exec-file:dist/chunk-2P5NL6Q2.cjs | AI (source-diff): Bundled CJS chunk with legitimate fs/path/crypto usage for storage domains; not malware. | ai | |
| source-diff | net-exec-file:dist/chunk-U3AK7BS3.cjs | AI (source-diff): Build output of AI agent framework; network+fs calls are core functionality, not malware. | ai | |
| source-diff | net-exec-file:dist/chunk-RJK2C4PL.cjs | AI (source-diff): Build-chunked output importing crypto for AI framework functionality; not malicious. | ai | |
| source-diff | net-exec-file:dist/chunk-IZCBYIU3.cjs | AI (source-diff): Build-chunked output importing crypto/fs/net for AI framework functionality; not malicious. | ai | |
| source-diff | net-exec-file:dist/chunk-RVVLQNKU.cjs | AI (source-diff): Normal CJS build chunk with fs/crypto/path imports; expected for this AI framework package. | ai | |
| source-diff | net-exec-file:dist/chunk-3MN5BPJC.js | AI (source-diff): ESM counterpart of same storage/observability code; legitimate usage. | ai | |
| source-diff | net-exec-file:dist/chunk-PCV2UDOR.cjs | AI (source-diff): Bundled chunk with legitimate fs/crypto/network usage for AI framework core; not malware. | ai | |
| npm-metadata | no-description | AI (npm-metadata): Scoped package under @mastra org; missing description is cosmetic, not a malware signal. | ai | |
| source-diff | net-exec-file:dist/chunk-EVUNY5SD.cjs | AI (source-diff): Bundled CJS chunk with normal require() calls; network+exec pattern is inherent to this AI framework. | ai | |
| source-diff | net-exec-file:dist/chunk-J3E47CMA.cjs | AI (source-diff): AI framework core naturally combines network (LLM APIs) and code execution; build chunks rotate names each version. | ai | |
| source-diff | net-exec-file:dist/chunk-B7CR6B45.cjs | AI (source-diff): Bundled build output with standard require calls; not malicious network+exec. | ai | |
| source-diff | net-exec-file:dist/chunk-GM7WJ3F7.cjs | AI (source-diff): Bundled CJS chunk using standard Node built-ins (fs, crypto, path); expected for this framework. | ai | |
| source-diff | net-exec-file:dist/chunk-OWAWKGJ4.cjs | AI (source-diff): Build output of an AI/server framework; network + fs/crypto co-occurrence is expected, not malicious. | ai | |
| source-diff | net-exec-file:dist/chunk-QJB2YTBM.cjs | AI (source-diff): Bundled CJS output with standard requires; network+exec pattern is normal for an AI framework core. | ai | |
| source-diff | net-exec-file:dist/chunk-YNE3ZCU5.cjs | AI (source-diff): Build output chunk with tool-builder code; network+exec pattern is framework functionality. | ai | |
| source-diff | net-exec-file:dist/chunk-TUZTUFQO.cjs | AI (source-diff): Build output chunk with standard framework code (storage, observability); not malware. | ai | |
| source-diff | net-exec-file:dist/chunk-GDEXRBE2.cjs | AI (source-diff): Bundled app code using fs/crypto/path + network for AI framework functionality; not a dropper. | ai | |
| source-diff | net-exec-file:dist/chunk-FFMMLKXC.cjs | AI (source-diff): Bundled CJS chunk with standard imports (crypto, fs, path, zod); not malicious code execution. | ai | |
| source-diff | net-exec-file:dist/chunk-NNRGAKKH.cjs | AI (source-diff): Bundled CJS chunk combining AI-provider HTTP calls with require(); expected for this package. | ai | |
| source-diff | net-exec-file:dist/chunk-GCVSTCZ7.cjs | AI (source-diff): Bundled CJS chunk combining AI-provider HTTP calls with require(); expected for this package. | ai | |
| dependencies | unvetted-dep:@ai-sdk/provider-v6 | AI (dependencies): Aliased @ai-sdk/provider version; legitimate multi-version pinning pattern for this package. | ai | |
| dependencies | unvetted-dep:@ai-sdk/provider-v5 | AI (dependencies): Aliased @ai-sdk/provider version; legitimate multi-version pinning pattern for this package. | ai | |
| dependencies | unvetted-dep:@ai-sdk/provider-utils-v6 | AI (dependencies): Aliased @ai-sdk/provider-utils version; legitimate multi-version pinning pattern for this package. | ai | |
| dependencies | unvetted-dep:@ai-sdk/provider-utils-v5 | AI (dependencies): Aliased @ai-sdk/provider-utils version; legitimate multi-version pinning pattern for this package. | ai | |
| dependencies | unvetted-dep:@ai-sdk/ui-utils-v5 | AI (dependencies): Aliased @ai-sdk/ui-utils version; legitimate multi-version pinning pattern for this package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Chunk-split build output changes hash-named files each release; expected for this package. | ai | |
| source-diff | net-exec-file:dist/chunk-HK4BBFHR.cjs | AI (source-diff): Build-output chunk with normal framework code (storage, observability); not malicious. | ai | |
| source-diff | net-exec-file:dist/chunk-HZYM4F5A.cjs | AI (source-diff): Build-output chunk with normal tool-builder code; not malicious. | ai | |
| phantom-deps | phantom-dep:ajv | AI (phantom-deps): ajv is a declared runtime dep used via config/schema validation; phantom-dep heuristic false positive for this package. | ai | |
| phantom-deps | phantom-dep:@ai-sdk/provider-utils-v6 | AI (phantom-deps): npm-alias versioned dep; phantom-dep heuristic fires on aliased package names, stable false positive. | ai | |
| typosquat | typosquat.levenshtein:cors | AI (typosquat): @mastra/core is a scoped AI framework package; Levenshtein match to 'cors' is coincidental and not a typosquat. | ai |
Versions (showing 45 of 45)
| Version | Deps | Published |
|---|---|---|
| 1.51.0 | 32 / 66 | |
| 1.50.1 | 32 / 64 | |
| 1.50.0 | 32 / 64 | |
| 1.49.0 | 32 / 64 | |
| 1.48.0 | 32 / 64 | |
| 1.47.0 | 32 / 64 | |
| 1.46.0 | 29 / 59 | |
| 1.45.0 | 29 / 58 | |
| 1.43.0 | 29 / 58 | |
| 1.42.0 | 28 / 58 | |
| 1.41.0 | 28 / 57 | |
| 1.40.0 | 28 / 57 | |
| 1.39.0 | 28 / 57 | |
| 1.38.0 | 30 / 55 | |
| 1.37.1 | 31 / 53 | |
| 1.37.0 | 31 / 53 | |
| 1.36.0 | 31 / 53 | |
| 1.35.0 | 30 / 53 | |
| 1.34.0 | 30 / 53 | |
| 1.33.1 | 30 / 53 | |
| 1.33.0 | 30 / 53 | |
| 1.32.1 | 31 / 53 | |
| 1.32.0 | 31 / 53 | |
| 1.31.0 | 30 / 53 | |
| 1.30.0 | 30 / 53 | |
| 1.29.1 | 30 / 53 | |
| 1.29.0 | 30 / 53 | |
| 1.28.0 | 30 / 53 | |
| 1.27.0 | 30 / 53 | |
| 1.26.0 | 30 / 53 | |
| 1.25.0 | 30 / 53 | |
| 1.24.1 | 30 / 48 | |
| 1.24.0 | 30 / 48 | |
| 1.23.0 | 30 / 48 | |
| 1.22.0 | 30 / 48 | |
| 1.21.0 | 29 / 48 | |
| 1.20.0 | 29 / 48 | |
| 1.19.0 | 29 / 48 | |
| 1.18.0 | 29 / 48 | |
| 1.13.1 | 28 / 47 | |
| 1.8.0 | 23 / 44 | |
| 1.5.0 | 23 / 41 | |
| 1.1.0 | 22 / 39 | |
| 0.24.4 | 46 / 24 | |
| 0.24.1 | 46 / 24 |
v1.51.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.50.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.50.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.49.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.48.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.13.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.8.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.