@mastra/server
Typed HTTP handlers and utilities for exposing a `Mastra` instance over HTTP. This package powers `mastra dev` and can be added to your own server to provide REST and streaming endpoints for agents, workflows, telemetry and more.
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | net-exec-file:dist/chunk-WOQFR6J7.cjs | AI (source-diff): Bundled tsup output (zod/schema-compat); network+eval pattern is build artifact, not malicious behavior. | ai | |
| source-diff | net-exec-file:dist/chunk-4QX6ZNKX.cjs | AI (source-diff): Bundled schema/zod code in tsup dist output; per-file rule id won't recur but net+exec pattern is benign build artifact. | ai | |
| source-diff | obfuscated-file:dist/observational-memory-SR6G4HN5-G66HNVG4.cjs | AI (source-diff): Minified tsup bundle output (base64-js vendored), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-TXC7QU6O.cjs | AI (source-diff): Bundled tsup dist chunk with normal require of child_process/fs; no fetched-payload execution. | ai | |
| source-diff | net-exec-file:dist/chunk-EFSXF23C.cjs | AI (source-diff): Bundled tsup output with zod/schema interop; no malicious network+exec behavior, stable FP for this build. | ai | |
| source-diff | obfuscated-file:dist/observational-memory-QFQUF5EY-5VPKVXKI.cjs | AI (source-diff): Minified bundler output (readable base64-js), not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-E5I4COAV.cjs | AI (source-diff): tsup-bundled dist chunk aggregating core modules; not a dropper. | ai | |
| source-diff | net-exec-file:dist/chunk-3BKGGOC6.cjs | AI (source-diff): Bundled tsup chunk; child_process/fs are normal server deps, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/observational-memory-AJWSMZVP-HI6EWRCH.cjs | AI (source-diff): Minified bundle output (base64-js polyfill), not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-EZCRZUSZ.cjs | AI (source-diff): Bundled schema/openapi utils; net+exec heuristic FP in tsup output, stable across releases. | ai | |
| source-diff | net-exec-file:dist/chunk-6P7P7Y5U.cjs | AI (source-diff): Bundled schema-compat code (inlined removed dep); benign require/zod, no dropper behavior. | ai | |
| source-diff | obfuscated-file:dist/observational-memory-53AFLLSH-PNWZJNLZ.cjs | AI (source-diff): Minified bundler output (base64-js vendored), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-O36HRJ75.cjs | AI (source-diff): tsup-bundled dist chunk; dual-use child_process in an established, SLSA-attested official package. | ai | |
| source-diff | net-exec-file:dist/chunk-EGSCXVMR.cjs | AI (source-diff): Bundled tsup output with schema/validation code; benign build artifact, not a loader. | ai | |
| source-diff | net-exec-file:dist/chunk-3D3V6DJZ.cjs | AI (source-diff): tsup-bundled server chunk; standard node builtins, no fetched/hostile target. | ai | |
| source-diff | net-exec-file:dist/chunk-34ZUTBG5.js | AI (source-diff): Bundled workflow/route handlers; net+exec are framework functionality. | ai | |
| source-diff | obfuscated-file:dist/observational-memory-LI6QFTRE-OJTY4B6Y.cjs | AI (source-diff): Minified bundle output (base64-js), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/observational-memory-LI6QFTRE-QRWTE6CR.js | AI (source-diff): Minified ESM bundle, same benign content as cjs sibling. | ai | |
| source-diff | obfuscated-file:dist/observational-memory-KAFD4QZK-UEZ333UM.cjs | AI (source-diff): Minified tsup bundle (base64-js/CommonJS wrapper), not true obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-PLW5CELE.cjs | AI (source-diff): tsup-bundled dist chunk; child_process/require are framework internals, not a dropper. | ai | |
| source-diff | source-size-tripled | AI (source-diff): Growth from added bundled dist chunks + sourcemaps; expected for this build. | ai | |
| source-diff | net-exec-file:dist/chunk-P4O7OBGH.cjs | AI (source-diff): Bundled tsup output of a server SDK; child_process+network usage is legitimate, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/observational-memory-ZNTAIUGT-565A3END.cjs | AI (source-diff): Minified/bundled dist chunk (base64-js vendored), not true obfuscation. | ai | |
| source-diff | obfuscated-file:dist/observational-memory-3DA7KJIH-IZ4WMHFJ.cjs | AI (source-diff): Minified bundle (base64-js vendored), not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-HKIHEE45.js | AI (source-diff): tsup ESM bundle; workflow route handlers, benign. | ai | |
| source-diff | net-exec-file:dist/chunk-DVYTF2FH.cjs | AI (source-diff): tsup bundle of server framework; standard node builtins, no hostile target. | ai | |
| source-diff | obfuscated-file:dist/observational-memory-VXLHOSDZ-H2TJ6BI4.js | AI (source-diff): tsup-bundled base64-js, minified not obfuscated. | ai | |
| source-diff | net-exec-file:dist/chunk-2ABZICAN.cjs | AI (source-diff): Bundled server framework output; child_process/net normal for @mastra/server. | ai | |
| source-diff | obfuscated-file:dist/observational-memory-VXLHOSDZ-YUXHRMDP.cjs | AI (source-diff): tsup-bundled base64-js, long lines are minification not obfuscation. | ai | |
| source-diff | net-exec-file:dist/chunk-Z3ZWANXZ.js | AI (source-diff): Bundled ESM server routes; benign build artifact. | ai | |
| source-diff | net-exec-file:dist/probe-image-size-B7W34DN2.cjs | AI (source-diff): Bundled probe-image-size dependency in tsup dist output; SLSA-attested official build. | ai | |
| source-diff | net-exec-file:dist/chunk-22EM2GBH.cjs | AI (source-diff): Bundled tsup output for zod schema-compat; no malicious behavior or destination. | ai | |
| source-diff | net-exec-file:dist/chunk-3YQ7NWF6.cjs | AI (source-diff): Bundled schema-compat chunk with zod validation; standard build output for this server package. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Rebuilt dist output with source maps; normal for this package's build cycle. | ai | |
| source-diff | net-exec-file:dist/chunk-KGMN6MLX.cjs | AI (source-diff): Bundled server framework code with zod validation; network+exec pattern is normal for a server package. | ai | |
| npm-metadata | no-description | AI (npm-metadata): @mastra/server has always had empty description; stable FP. | ai | |
| source-diff | net-exec-file:dist/chunk-YI3WMF2D.cjs | AI (source-diff): Bundled AI SDK schema validation code; network+exec pattern is a false positive for this legitimate framework package. | ai | |
| source-diff | net-exec-file:dist/chunk-3WBBCKFS.cjs | AI (source-diff): Bundled chunk contains zod/AI SDK schema code; network+exec pattern is from legitimate library bundling, not malware. | ai | |
| source-diff | net-exec-file:dist/chunk-Q7GNNLCY.cjs | AI (source-diff): Bundled schema/zod validation code; no actual dropper behavior in sample. Stable false positive for this package. | ai | |
| source-diff | net-exec-file:dist/chunk-2HPMUAMW.js | AI (source-diff): ESM equivalent of the same schema-compat bundle; no malicious network/exec pattern. | ai | |
| source-diff | net-exec-file:dist/chunk-YDO5OPEU.cjs | AI (source-diff): Schema validation/zod interop bundle; no actual dropper behavior in sampled code. | ai | |
| source-diff | net-exec-file:dist/chunk-7LAFXMXB.cjs | AI (source-diff): Bundled schema/zod validation code; no actual network+exec dropper pattern in the sample. | ai | |
| source-diff | net-exec-file:dist/chunk-5UKYK7YK.cjs | AI (source-diff): Bundled schema/utility code from @mastra/schema-compat and zod; not malicious network+exec pattern. | ai | |
| source-diff | net-exec-file:dist/probe-image-size-H2PYJKCK.cjs | AI (source-diff): Bundled probe-image-size library with ms utility; standard build artifact, not dropper malware. | ai | |
| typosquat | typosquat.levenshtein:semver | AI (typosquat): Scoped package @mastra/server is part of the Mastra AI framework, not a typosquat of semver. | ai |
Versions (showing 73 of 73)
| Version | Deps | Published |
|---|---|---|
| 1.51.0 | 1 / 23 | |
| 1.50.1 | 1 / 23 | |
| 1.50.0 | 1 / 23 | |
| 1.49.0 | 1 / 23 | |
| 1.48.0 | 1 / 23 | |
| 1.47.0 | 1 / 23 | |
| 1.46.0 | 1 / 23 | |
| 1.45.0 | 1 / 23 | |
| 1.43.0 | 1 / 23 | |
| 1.42.0 | 1 / 23 | |
| 1.41.0 | 1 / 22 | |
| 1.40.0 | 1 / 22 | |
| 1.39.0 | 1 / 22 | |
| 1.38.0 | 1 / 22 | |
| 1.37.1 | 1 / 21 | |
| 1.37.0 | 1 / 21 | |
| 1.36.0 | 1 / 21 | |
| 1.35.0 | 1 / 21 | |
| 1.34.0 | 1 / 21 | |
| 1.33.1 | 1 / 21 | |
| 1.33.0 | 1 / 21 | |
| 1.32.1 | 1 / 20 | |
| 1.32.0 | 1 / 20 | |
| 1.31.0 | 1 / 19 | |
| 1.30.0 | 1 / 19 | |
| 1.29.1 | 1 / 19 | |
| 1.29.0 | 1 / 19 | |
| 1.28.0 | 1 / 19 | |
| 1.27.0 | 1 / 19 | |
| 1.26.0 | 1 / 19 | |
| 1.25.0 | 1 / 19 | |
| 1.24.1 | 1 / 19 | |
| 1.24.0 | 1 / 19 | |
| 1.23.0 | 1 / 19 | |
| 1.22.0 | 1 / 19 | |
| 1.21.0 | 1 / 19 | |
| 1.20.0 | 1 / 19 | |
| 1.19.0 | 1 / 19 | |
| 1.18.0 | 1 / 19 | |
| 1.17.0 | 1 / 19 | |
| 1.16.0 | 1 / 19 | |
| 1.15.0 | 1 / 19 | |
| 1.14.0 | 1 / 19 | |
| 1.13.2 | 1 / 18 | |
| 1.13.1 | 1 / 18 | |
| 1.13.0 | 1 / 18 | |
| 1.12.0 | 2 / 17 | |
| 1.11.0 | 2 / 17 | |
| 1.10.0 | 1 / 16 | |
| 1.9.0 | 1 / 16 | |
| 1.8.0 | 1 / 16 | |
| 1.7.0 | 1 / 16 | |
| 1.6.0 | 1 / 16 | |
| 1.5.0 | 1 / 16 | |
| 1.4.0 | 1 / 16 | |
| 1.3.0 | 1 / 16 | |
| 1.2.0 | 1 / 16 | |
| 1.1.0 | 1 / 16 | |
| 1.0.4 | 1 / 16 | |
| 1.0.3 | 0 / 11 | |
| 1.0.2 | 0 / 11 | |
| 1.0.1 | 0 / 11 | |
| 1.0.0 | 0 / 11 | |
| 0.24.9 | 0 / 15 | |
| 0.24.8 | 0 / 15 | |
| 0.24.7 | 0 / 15 | |
| 0.24.6 | 0 / 15 | |
| 0.24.5 | 0 / 15 | |
| 0.24.4 | 0 / 15 | |
| 0.24.3 | 0 / 15 | |
| 0.24.2 | 0 / 15 | |
| 0.24.1 | 0 / 15 | |
| 0.24.0 | 0 / 15 |
v1.51.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.50.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.50.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.49.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.48.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.17.0
3 findingsThis version was published without provenance, but prior versions were published via CI/CD with attestations. This is a strong signal of a potential account compromise or unauthorized publish. Multiple high-profile registry compromises have exhibited exactly this pattern.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
This version was published by a different npm account (wardpeet) than the most recent previously approved version (GitHub Actions) on 2026-03-26, but wardpeet is listed as a maintainer on prior approved versions (matched on name). This looks like a manual publish by a known maintainer rather than a publisher change. Recorded as INFO for audit trail.
v1.16.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.15.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.14.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.13.2
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.13.1
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.13.0
2 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.12.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.11.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.10.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.9.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.8.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.7.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.6.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.5.0
3 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.4.0
4 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.3.0
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.2.0
5 findingsNewly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added file contains both network calls and dynamic code execution. This is a hallmark of dropper/loader malware.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.1.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.3
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.2
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1
1 findingPackage was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.
v0.24.9
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.8
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (wardpeet) on 2025-12-10, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.24.7
2 findingsPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
This version was published by a different npm account (GitHub Actions) than the most recent previously approved version (wardpeet) on 2025-12-09, but it carries Sigstore provenance attestation. This means the package moved to a trusted publisher (CI/CD with OIDC, e.g. GitHub Actions) — a supply-chain integrity improvement, not a compromise, since a stolen npm token cannot forge provenance bound to the source repository. Recorded as INFO for audit trail.
v0.24.6
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.5
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.4
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.3
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.2
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v0.24.0
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.