← Home

@mastra/voice-murf

Mastra Murf voice integration

45
Versions
Apache-2.0
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

abhiaiyersmthomasrase-calcsamnikaiyertylerbarnes

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
provenance publisher-changed AI (provenance): Transition to GitHub Actions CI publisher with SLSA attestation; consistent with mastra-ai monorepo CI/CD migration. ai
bogus-package bogus-package AI (bogus-package): Mass-production signal reflects a large legitimate monorepo; no spam or malicious indicators. ai
source-diff obfuscated-file:dist/_types/@internal_voice/dist/_types/@internal_ai-sdk-v5/dist/index.d.ts AI (source-diff): TypeScript declaration file with long lines from bundled type definitions; not obfuscated code. ai
source-diff source-size-tripled AI (source-diff): Size increase driven by bundled .d.ts type declarations from internal packages, not injected payloads. ai
source-diff large-new-source-files AI (source-diff): New files are bundled type declaration files from internal dependencies, consistent with build tooling changes. ai
phantom-deps phantom-dep:easy-day-js AI (phantom-deps): Phantom-dep rule cannot auto-block per policy; flagged in rationale instead. ai

Versions (showing 45 of 45)

Version Deps Published
0.13.0 0 / 11
0.12.4 0 / 11
0.12.2 0 / 10
0.12.1 0 / 10
0.12.0 1 / 10
0.11.12 1 / 9
0.11.11 1 / 9
0.11.10 1 / 9
0.11.9 1 / 9
0.11.8 1 / 9
0.11.7 1 / 9
0.11.6 1 / 9
0.11.5 1 / 9
0.11.4 1 / 9
0.11.3 1 / 9
0.11.2 1 / 9
0.10.9 2 / 9
0.10.8 2 / 9
0.10.7 2 / 8
0.10.6 2 / 8
0.10.5 2 / 8
0.10.4 2 / 8
0.10.3 2 / 8
0.10.2 2 / 8
0.10.1 2 / 8
0.10.0 2 / 8
0.1.18 3 / 7
0.1.17 3 / 7
0.1.16 3 / 7
0.1.15 3 / 7
0.1.14 3 / 7
0.1.13 3 / 7
0.1.12 3 / 7
0.1.11 3 / 7
0.1.10 3 / 7
0.1.9 3 / 7
0.1.8 3 / 7
0.1.7 3 / 7
0.1.6 3 / 7
0.1.5 3 / 7
0.1.4 3 / 7
0.1.3 3 / 7
0.1.2 3 / 7
0.1.1 3 / 7
0.1.0 3 / 7

v0.1.14

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.13

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.12

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.11

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.10

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.9

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.8

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.7

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.6

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.5

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.4

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.3

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.2

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.1

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.

v0.1.0

1 finding
LOW No provenance attestation provenance

Package was published without Sigstore provenance. Only ~12% of npm packages have provenance, so this is common but not ideal.