
Research
/Security News
737 Chrome VPN Extensions Linked to Brand Impersonation and Browser Traffic Redirection
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.
@mastra/evals
Advanced tools
Affected versions:
@mastra/evals ships a collection of scoring utilities you can run locally or inside your own evaluation pipelines. These scorers come in two flavors:
The scorers do not persist results or integrate with Mastra Storage; you decide where and how to record outcomes.
npm install @mastra/evals
import { createFaithfulnessScorer, createContentSimilarityScorer } from '@mastra/evals/scorers/prebuilt';
const faithfulness = createFaithfulnessScorer({
model: 'openai/gpt-4o-mini')
});
const similarity = createContentSimilarityScorer({ ignoreCase: true });
const answer = 'Paris is the capital of France.';
const context = ['Paris is the capital of France', 'France is in Europe'];
const faithfulnessScore = await faithfulness.score({ answer, context });
const similarityScore = similarity.score({
input: context[0],
output: answer
});
console.log({ faithfulnessScore, similarityScore });
FAQs
Unknown package
The npm package @mastra/evals receives a total of 112,034 weekly downloads. As such, @mastra/evals popularity was classified as popular.
We found that @mastra/evals demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 7 open source maintainers collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
/Security News
The campaign amassed more than 75,000 installs by targeting Russian-speaking users seeking access to blocked services.

Company News
Open source maintainers are under more pressure than ever. We're raising our open source program from the Team plan to the Business plan, free.

Security News
The supply chain control that delays freshly published gems now covers lockfile generation and gem vendoring in Ruby projects.