Skip to content

Releases: dev-ik/safe_shape

SafeShape v3.5.1

Choose a tag to compare

@github-actions github-actions released this 06 Oct 15:57

Full Changelog: v3.5.0...v3.5.1

SafeShape v3.5.0

Choose a tag to compare

@github-actions github-actions released this 06 Oct 14:11

Full Changelog: v3.4.1...v3.5.0

SafeShape v3.4.1

Choose a tag to compare

@github-actions github-actions released this 02 Oct 10:09

SafeShape 3.4.1 improves npm documentation and package discovery. Runtime code, public APIs and snapshot formats are unchanged from 3.4.0.

  • Expanded EN/RU README for safe-shape and @safe-shape/api: endpoint catalogs, validated fetch clients, OpenAPI 3.1, snapshots, CLI commands and transport limitations.
  • Catalog and client examples are separate modules so importing a catalog through the CLI does not send HTTP requests.
  • Explicit GitHub documentation and language links in all nine package READMEs, pinned to v3.4.1.
  • Keywords added to all nine npm packages.
  • Release checks now validate keywords, npm-safe links and linked repository files; translation checks accept the explicit package language links.
npm install safe-shape@3.4.1

No migration is required. All nine packages and internal dependencies use 3.4.1. Validation: 307 workspace tests, build, typecheck, examples, README client and CLI workflows, consumer installation, quality checks, dependency audits with zero vulnerabilities, and CI on Node 20.10.0 and 24. Independent developer walkthrough was not performed.

English README · Русский README · Release evidence

SafeShape v3.4.0

Choose a tag to compare

@github-actions github-actions released this 02 Oct 09:03

SafeShape 3.4.0 adds an API contract workflow without breaking existing 3.3.x APIs or snapshot defaults.

  • Endpoint catalogs: immutable httpEndpoint and apiContract describe methods, paths, request sections and status-specific responses.
  • Validated fetch clients: createApiClient validates requests and responses, preserves warnings, supports AbortSignal, and returns typed results by HTTP status. Use @safe-shape/api/client for browsers.
  • OpenAPI 3.1: toOpenApi and safeToOpenApi export JSON Schema components and recursive references. Unsupported semantics produce structured errors without partial documents.
  • API compatibility: snapshots check request and response compatibility, route changes and response status changes against existing clients.
  • CLI: api export, api snapshot and api check, with stable JSON results and explicit exit codes.
  • All nine packages use version 3.4.0; EN/RU documentation and examples include the new workflow.
npm install safe-shape@3.4.0

The transport supports JSON and explicit wire schemas. Cookies, multipart, automatic retries and server routing are outside this release. Existing core, HTTP and tooling calls require no migration. Node >=20.10 and ESM remain required.

Validation: 307 workspace tests; build, typecheck, documentation, examples, installed consumers, quality and migration checks; dependency audits with zero vulnerabilities; CI on Node 20.10.0 and 24. An independent developer walkthrough was not performed.

API reference · Русская документация · Release evidence

SafeShape v3.3.0

Choose a tag to compare

@github-actions github-actions released this 30 Sep 10:03

SafeShape 3.3.0

Checked output contracts, runtime improvements and English/Russian documentation across all eight packages.

What's new

  • describeOutputBound(schema) exposes a conservative upper bound on successful outputs.
  • checkSchemaConnection(producer, consumer) checks live-schema connections against that bound. Unproven containment requires manual review; it does not invent a produced counterexample.
  • Explicit JSON Schema export with { side: "output", mode: "output-bound" }. Exact export remains the default.
  • Cached completed async discovery and immutable result reuse reduce runtime overhead while preserving diagnostics and Error behavior.
  • Current guides, API references and package READMEs have Russian counterparts, with translation coverage and drift checks.

Upgrade

npm install safe-shape@3.3.0

Update scoped SafeShape packages to 3.3.0 together. Node.js >=20.10 and ESM are required. No breaking public API, snapshot format or default behavior changes are intended.

English release notes · Русское описание релиза

Verification

286 package tests, type checks, build, examples, benchmarks, installed consumers, quality and migration checks passed. Both dependency audits reported zero known vulnerabilities. Final-commit CI passed on Node 20.10.0 and Node 24; both jobs' archives matched the locally qualified archives byte for byte.

The owner authorized publication with the disclosed incomplete independent developer walkthrough. Automated checks do not count as that human review. Performance improved in measured workloads; this release does not claim general performance parity with Zod.

CI · Publishing workflow


По-русски

В 3.3.0 добавлены проверяемые границы выходных значений, проверка связей живых схем и явный экспорт верхней границы в JSON Schema. Оптимизирован runtime с сохранением диагностики; актуальные руководства и README всех пакетов доступны на русском.

При обновлении синхронизируйте версии всех используемых пакетов SafeShape. Существующие схемы и точные экспортёры не требуют миграции. Если включение выходной границы во вход потребителя не доказано, результат требует ручной проверки — это не доказательство несовместимого выхода.

SafeShape v3.2.1

Choose a tag to compare

@github-actions github-actions released this 25 Sep 13:44

SafeShape 3.2.1 publishes the corrected package READMEs to npm and synchronizes all eight packages to 3.2.1.

npm install safe-shape@3.2.1

Documentation fixes

  • Mark composition, checked pipelines, recursive TypeScript declarations and producer/consumer connection checks as available since 3.2.0.
  • Correct async validation and diagnostic descriptions; expand the core, compatibility, CLI and umbrella package guides.
  • Fix the English/Russian quick starts: exported schema modules, clean CLI JSON output and snapshot directory creation.
  • Update release metrics, quality baseline and benchmark policy while retaining historical measurements as historical evidence.

Runtime implementation and public API are unchanged from 3.2.0. No application or snapshot migration is required. Upgrade installed safe-shape and @safe-shape/* packages together.

Quick start · Быстрый старт · Composition · Connections

Verification

The full local prepare:release gate and exact-candidate CI on Node 20.10.0 and Node 24 passed, including 274 package tests, type checks, examples, installed consumers, quality budgets and clean dependency audits. All eight archives from both CI jobs match the qualified local archives.

Comparison with published 3.2.0 confirms identical JavaScript, type declarations, source maps and file modes. Only package version/internal-dependency metadata and five package READMEs differ.

The publishing workflow passed. All eight npm packages now have latest: 3.2.1; each registry README exactly matches the corrected repository file. Registry integrity, downloaded npm tarballs and GitHub release assets match the qualified archives. A clean-cache registry installation passed public imports, CLI, type compilation, connection checks and HTTP failure/recovery scenarios.

SafeShape v3.2.0

Choose a tag to compare

@github-actions github-actions released this 25 Sep 12:51

SafeShape 3.2.0 adds composable schemas and explicit producer/consumer contract checks while preserving immutable schemas, rich diagnostics and explicit conversion.

npm install safe-shape@3.2.0

What changed

  • Compose object schemas with shape, pick, omit, partial, required and add-only extend, preserving field rules and unknown-property policies.
  • Validate transformation outputs with pipe, retaining input/output inference and explicit async behavior.
  • Generate recursive TypeScript declarations and select schema types --side input|output.
  • Check producer output against consumer input with checkContractConnection and contract check-connections, including migration diagnostics and supported, independently verified JSON counterexamples.
  • Construct native errors at the public boundary while retaining complete diagnostics. Invalid-input workloads improved in the paired candidate measurements; no general performance parity with Zod is claimed.
  • Use production boundary examples that reject invalid operations, contain logger failures and keep serving subsequent requests.
  • Migrate the documented Zod subset with a restricted source tool that does not execute schemas or overwrite files.

Compatibility and limits

This is an additive release. Existing parsing APIs, snapshot formats and existing CLI envelopes/exit codes remain stable. parse still throws on validation failure; safeParse returns a result. Production recovery is explicit at the application boundary.

Object extend rejects field replacement; compose before adding object-level checks. Tooling reports uncertainty for unsupported opaque behavior. Missing counterexamples do not prove compatibility. The Zod migration tool handles only its documented subset.

Verification

Exact-candidate CI passed on Node 20.10.0 and Node 24. All eight archives from both jobs matched the qualified local archives. Qualification includes 274 package tests, compiler and installed-consumer checks, production failure/logging tests, browser checks, unchanged quality budgets and dependency audits.

Publication workflow passed. All eight packages are published with npm latest set to 3.2.0. Downloaded npm tarballs and GitHub release assets match the qualified archives. A clean-cache registry installation passed public imports, CLI, connection checks, generated type compilation and five real HTTP requests, including successful processing after validation, service and logger failures.

The owner explicitly authorized release after disclosure that the independent human walkthrough remained incomplete. This is an owner-approved exception to that gate; the agent walkthrough is not recorded as a human pass.

Composition guide · Connection checks · Production boundaries · Migrating from Zod

SafeShape v3.1.0

Choose a tag to compare

@github-actions github-actions released this 11 Sep 09:26

SafeShape 3.1.0 expands the workflow for reviewing runtime contract changes across a TypeScript project.

  • Project checks: contract check-many evaluates a manifest and aggregates compatibility, migration, manual-review and operational-error results.
  • Concrete counterexamples: createContractCounterexamples() and --counterexamples generate bounded input witnesses for supported scalar and finite composite contracts, including objects, arrays and ordinary unions.
  • Review artifacts: --markdown presents findings, migration suggestions, optional witnesses and batch HTTP roles in a shareable report.
  • Correctness fixes: equal literals compare correctly in graph contracts; prototype-sensitive properties and definition ids are preserved across descriptions, snapshots and JSON Schema.

Default CLI reports and snapshot formats remain unchanged. Counterexample values are deeply immutable, and an unavailable witness never implies compatibility. Recursive references, opaque behavior and output-side synthesis remain outside the supported construction domain.

Review the 3.0 → 3.1 migration notes before replacing affected prototype-sensitive baselines. See counterexample limits and Markdown review usage.

All eight packages share version 3.1.0. Install the umbrella package with npm install safe-shape@3.1.0, or use the scoped packages individually.

SafeShape v3.0.0

Choose a tag to compare

@github-actions github-actions released this 04 Sep 10:22

Full Changelog: v2.0.2...v3.0.0

SafeShape v2.0.2

Choose a tag to compare

@github-actions github-actions released this 19 Aug 09:21

Full Changelog: v2.0.1...v2.0.2