← Home

@mastra/memory

51
Versions
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

abhiaiyersmthomasrase-calcsamnikaiyertylerbarneswardpeet

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file:dist/_types/@internal_ai-sdk-v4/dist/index.d.ts AI (source-diff): Bundled AI SDK type declarations; long lines from interface definitions, not obfuscation. ai
source-diff obfuscated-file:dist/processors/observational-memory/observer-agent.d.ts AI (source-diff): Long string literal in .d.ts for prompt template; not obfuscated. ai
source-diff source-size-tripled AI (source-diff): Major version jump (0.x→1.x) internalized types and added processors; expected growth. ai
source-diff obfuscated-file:dist/processors/observational-memory/constants.d.ts AI (source-diff): TypeScript .d.ts with long readonly config objects; not obfuscated. ai
phantom-deps phantom-dep:@upstash/redis AI (phantom-deps): Optional adapter dependency declared for peer use; not directly imported in main bundle. ai
phantom-deps phantom-dep:zod-to-json-schema AI (phantom-deps): Utility dependency used conditionally; stable false positive for this package. ai
phantom-deps phantom-dep:postgres AI (phantom-deps): Optional adapter dependency declared for peer use; not directly imported in main bundle. ai
phantom-deps phantom-dep:pg AI (phantom-deps): Optional adapter dependency declared for peer use; not directly imported in main bundle. ai
phantom-deps phantom-dep:redis AI (phantom-deps): Optional adapter dependency declared for peer use; not directly imported in main bundle. ai
phantom-deps phantom-dep:pg-pool AI (phantom-deps): Optional adapter dependency declared for peer use; not directly imported in main bundle. ai
phantom-deps phantom-dep:lru-cache AI (phantom-deps): lru-cache is a declared runtime dep used transitively; phantom-dep is a false positive for this package. ai
bogus-package bogus-package AI (bogus-package): Mastra monorepo package; sparse README is a known pattern across all @mastra/* packages, not a spam indicator. ai
phantom-deps phantom-dep:json-schema AI (phantom-deps): json-schema declared as runtime dep; types-only usage pattern is stable for this package. ai

Versions (showing 51 of 54)

View all versions
Version Deps Published
1.23.1 10 / 19
1.23.0 10 / 19
1.22.2 10 / 19
1.22.1 10 / 19
1.22.0 10 / 19
1.21.2 9 / 20
1.21.1 9 / 20
1.21.0 9 / 20
1.20.5 9 / 20
1.20.3 9 / 20
1.20.2 9 / 19
1.20.1 8 / 19
1.20.0 8 / 19
1.19.0 8 / 19
1.18.2 8 / 19
1.18.1 8 / 19
1.18.0 8 / 19
1.17.5 8 / 19
1.17.4 8 / 19
1.17.3 8 / 19
1.17.2 8 / 19
1.17.1 8 / 19
1.17.0 8 / 19
1.16.0 8 / 19
1.15.1 8 / 19
1.15.0 8 / 19
1.14.0 8 / 19
1.13.1 8 / 19
1.13.0 8 / 19
1.12.1 8 / 19
1.12.0 8 / 19
1.11.0 8 / 19
1.10.0 8 / 19
1.9.0 8 / 19
1.8.3 8 / 19
1.8.2 8 / 19
1.8.1 8 / 19
1.8.0 8 / 19
1.7.0 8 / 19
1.6.2 8 / 19
1.6.1 6 / 18
1.6.0 6 / 18
1.5.2 6 / 18
1.5.1 6 / 18
1.5.0 6 / 18
1.4.0 6 / 18
1.3.0 6 / 18
1.2.0 6 / 18
1.1.0 6 / 18
1.0.1 6 / 18
1.0.0 6 / 18

v1.23.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.23.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.22.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.22.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.22.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.10.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.9.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.3

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.8.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.7.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.6.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.2

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.5.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.4.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.3.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.2.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.1.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.1

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.

v1.0.0

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.