Repository navigation
SafeShape v3.2.0
SafeShape 3.2.0 adds composable schemas and explicit producer/consumer contract checks while preserving immutable schemas, rich diagnostics and explicit conversion.
npm install safe-shape@3.2.0What changed
- Compose object schemas with
shape,pick,omit,partial,requiredand add-onlyextend, preserving field rules and unknown-property policies. - Validate transformation outputs with
pipe, retaining input/output inference and explicit async behavior. - Generate recursive TypeScript declarations and select
schema types --side input|output. - Check producer output against consumer input with
checkContractConnectionandcontract check-connections, including migration diagnostics and supported, independently verified JSON counterexamples. - Construct native errors at the public boundary while retaining complete diagnostics. Invalid-input workloads improved in the paired candidate measurements; no general performance parity with Zod is claimed.
- Use production boundary examples that reject invalid operations, contain logger failures and keep serving subsequent requests.
- Migrate the documented Zod subset with a restricted source tool that does not execute schemas or overwrite files.
Compatibility and limits
This is an additive release. Existing parsing APIs, snapshot formats and existing CLI envelopes/exit codes remain stable. parse still throws on validation failure; safeParse returns a result. Production recovery is explicit at the application boundary.
Object extend rejects field replacement; compose before adding object-level checks. Tooling reports uncertainty for unsupported opaque behavior. Missing counterexamples do not prove compatibility. The Zod migration tool handles only its documented subset.
Verification
Exact-candidate CI passed on Node 20.10.0 and Node 24. All eight archives from both jobs matched the qualified local archives. Qualification includes 274 package tests, compiler and installed-consumer checks, production failure/logging tests, browser checks, unchanged quality budgets and dependency audits.
Publication workflow passed. All eight packages are published with npm latest set to 3.2.0. Downloaded npm tarballs and GitHub release assets match the qualified archives. A clean-cache registry installation passed public imports, CLI, connection checks, generated type compilation and five real HTTP requests, including successful processing after validation, service and logger failures.
The owner explicitly authorized release after disclosure that the independent human walkthrough remained incomplete. This is an owner-approved exception to that gate; the agent walkthrough is not recorded as a human pass.
Composition guide · Connection checks · Production boundaries · Migrating from Zod