@mastra/server
Typed HTTP handlers and utilities for exposing a `Mastra` instance over HTTP. This package powers `mastra dev` and can be added to your own server to provide REST and streaming endpoints for agents, workflows, telemetry and more.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source — the axios compromise (March 2026) relied on exactly this gap.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| npm-metadata | no-description | AI (npm-metadata): @mastra/server has always had empty description; stable FP. | ai | |
| source-diff | net-exec-file:dist/chunk-KGMN6MLX.cjs | AI (source-diff): Bundled server framework code with zod validation; network+exec pattern is normal for a server package. | ai | |
| source-diff | net-exec-file:dist/chunk-YI3WMF2D.cjs | AI (source-diff): Bundled AI SDK schema validation code; network+exec pattern is a false positive for this legitimate framework package. | ai | |
| source-diff | net-exec-file:dist/chunk-3WBBCKFS.cjs | AI (source-diff): Bundled chunk contains zod/AI SDK schema code; network+exec pattern is from legitimate library bundling, not malware. | ai | |
| source-diff | net-exec-file:dist/chunk-Q7GNNLCY.cjs | AI (source-diff): Bundled schema/zod validation code; no actual dropper behavior in sample. Stable false positive for this package. | ai | |
| source-diff | net-exec-file:dist/chunk-YDO5OPEU.cjs | AI (source-diff): Schema validation/zod interop bundle; no actual dropper behavior in sampled code. | ai | |
| source-diff | net-exec-file:dist/chunk-2HPMUAMW.js | AI (source-diff): ESM equivalent of the same schema-compat bundle; no malicious network/exec pattern. | ai | |
| source-diff | net-exec-file:dist/chunk-7LAFXMXB.cjs | AI (source-diff): Bundled schema/zod validation code; no actual network+exec dropper pattern in the sample. | ai | |
| source-diff | net-exec-file:dist/probe-image-size-H2PYJKCK.cjs | AI (source-diff): Bundled probe-image-size library with ms utility; standard build artifact, not dropper malware. | ai | |
| source-diff | net-exec-file:dist/chunk-5UKYK7YK.cjs | AI (source-diff): Bundled schema/utility code from @mastra/schema-compat and zod; not malicious network+exec pattern. | ai | |
| typosquat | typosquat.levenshtein:semver | AI (typosquat): Scoped package @mastra/server is part of the Mastra AI framework, not a typosquat of semver. | ai |
Versions (showing 29 of 29)
| Version | Deps | Published |
|---|---|---|
| 1.41.0 | 1 / 22 | |
| 1.40.0 | 1 / 22 | |
| 1.39.0 | 1 / 22 | |
| 1.38.0 | 1 / 22 | |
| 1.37.1 | 1 / 21 | |
| 1.37.0 | 1 / 21 | |
| 1.36.0 | 1 / 21 | |
| 1.35.0 | 1 / 21 | |
| 1.34.0 | 1 / 21 | |
| 1.33.1 | 1 / 21 | |
| 1.33.0 | 1 / 21 | |
| 1.32.1 | 1 / 20 | |
| 1.32.0 | 1 / 20 | |
| 1.31.0 | 1 / 19 | |
| 1.30.0 | 1 / 19 | |
| 1.29.1 | 1 / 19 | |
| 1.29.0 | 1 / 19 | |
| 1.28.0 | 1 / 19 | |
| 1.27.0 | 1 / 19 | |
| 1.26.0 | 1 / 19 | |
| 1.25.0 | 1 / 19 | |
| 1.24.1 | 1 / 19 | |
| 1.24.0 | 1 / 19 | |
| 1.23.0 | 1 / 19 | |
| 1.22.0 | 1 / 19 | |
| 1.21.0 | 1 / 19 | |
| 1.20.0 | 1 / 19 | |
| 1.19.0 | 1 / 19 | |
| 1.18.0 | 1 / 19 |
v1.41.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.40.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.39.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.38.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.37.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.37.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.36.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.35.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.34.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.33.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.33.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.32.1
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.32.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.31.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.30.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.29.1
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.28.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.27.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.26.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.25.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.24.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.23.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.22.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.21.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.20.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.19.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.18.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.