@mastra/slack
Slack integration for Mastra agents with app factory, OAuth, and slash commands
Supply chain provenance
Status for the latest visible version.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file:dist/slack/src/client/services.gen.d.ts | AI (source-diff): Auto-generated OpenAPI client typings, not obfuscation. | ai | |
| phantom-deps | phantom-dep:ts-to-zod | AI (phantom-deps): Used via codegen script gen:zod:schema, not a direct import. | ai | |
| source-diff | obfuscated-file:src/client/services.gen.ts | AI (source-diff): Auto-generated OpenAPI client code, long import lines only. | ai | |
| phantom-deps | phantom-dep:easy-day-js | AI (phantom-deps): Phantom-dep heuristic; easy-day-js may be used indirectly. Not independently disqualifying. | ai | |
| provenance | missing-githead | AI (provenance): SLSA provenance attestation compensates; GitHub Actions CI/CD publish flow for this package doesn't consistently set gitHead. | ai | |
| npm-metadata | suspicious-initial-version | AI (npm-metadata): Mastra monorepo uses 0.0.0 as initial version for new packages; not a malware indicator. | ai | |
| phantom-deps | phantom-dep:@chat-adapter/slack | AI (phantom-deps): @chat-adapter/slack is a declared runtime dependency; phantom-dep heuristic is a false positive here. | ai |
Versions (showing 13 of 13)
| Version | Deps | Published |
|---|---|---|
| 1.5.1 | 1 / 6 | |
| 1.5.0 | 1 / 6 | |
| 1.4.0 | 1 / 6 | |
| 1.3.2 | 1 / 6 | |
| 1.3.0 | 1 / 6 | |
| 1.2.1 | 1 / 6 | |
| 1.2.0 | 1 / 6 | |
| 1.1.1 | 1 / 6 | |
| 1.1.0 | 1 / 6 | |
| 1.0.2 | 4 / 14 | |
| 1.0.1 | 4 / 14 | |
| 1.0.0 | 2 / 15 | |
| 0.0.0 | 1 / 6 |
v1.5.1
1 findingPublished via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.
v1.0.2
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.1
3 findingsNewly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Newly added source file contains lines over 3000 chars, suggesting minified or obfuscated code. New obfuscated files are a strong attack indicator.
Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v1.0.0
1 findingPackage was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.