← Home

@mastra/voice-cloudflare

Mastra Cloudflare AI voice integration

36
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

abhiaiyersmthomasrase-calcsamnikaiyertylerbarnes

Keywords

mastracloudflarettssttopen-sourcespeech-to-texttext-to-speechspeech-recognition

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI/CD publishing with SLSA attestation; consistent with monorepo automation for mastra-ai org. ai
maintainer-change maintainer-removed AI (maintainer-change): Large mastra-ai monorepo with CI/CD publishing and SLSA provenance; team churn is expected, not a takeover signal. ai
phantom-deps phantom-dep:easy-day-js AI (phantom-deps): Phantom-dep rule cannot auto-block per policy; flagged in rationale for human review. ai
source-diff source-size-tripled AI (source-diff): Explained by inclusion of bundled .d.ts type files from internal monorepo dependencies. ai
source-diff obfuscated-file:dist/_types/@internal_voice/dist/_types/@internal_ai-sdk-v5/dist/index.d.ts AI (source-diff): Generated TypeScript declaration bundle; long lines are normal for bundled .d.ts files, not obfuscation. ai
source-diff large-new-source-files AI (source-diff): Size increase driven by bundled internal type declarations from monorepo packages, not injected payloads. ai
phantom-deps phantom-dep:zod AI (phantom-deps): zod is declared and used in validation; false positive for TypeScript packages. ai
dependencies unvetted-dep:cloudflare AI (dependencies): cloudflare SDK is the expected runtime dep for a Cloudflare AI voice integration package. ai

Versions (showing 36 of 36)

Version Deps Published
0.13.0 2 / 12
0.12.4 2 / 12
0.12.2 2 / 11
0.12.1 1 / 12
0.12.0 1 / 12
0.11.12 1 / 11
0.11.11 1 / 11
0.11.10 1 / 11
0.11.9 1 / 11
0.11.8 1 / 11
0.11.7 1 / 11
0.11.6 1 / 11
0.11.5 1 / 11
0.11.4 1 / 11
0.11.3 1 / 11
0.11.2 1 / 11
0.10.8 2 / 10
0.10.7 2 / 10
0.10.6 2 / 9
0.10.5 2 / 9
0.10.4 2 / 9
0.10.3 2 / 9
0.10.2 2 / 9
0.10.1 2 / 9
0.10.0 2 / 9
0.1.11 3 / 8
0.1.10 3 / 8
0.1.9 3 / 8
0.1.8 3 / 8
0.1.7 3 / 8
0.1.6 3 / 8
0.1.5 3 / 8
0.1.4 3 / 8
0.1.3 3 / 8
0.1.2 3 / 8
0.1.1 3 / 8

v0.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.

v0.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.