Repository navigation
softschema 0.4.0
softschema v0.4.0 makes YAML date- and timestamp-shaped scalars portable strings in
both the Python/Pydantic and TypeScript/Zod implementations. The paired release also
aligns canonical schemas compiled from corresponding temporal fields.
Upgrade
-
Upgrade every softschema implementation your project uses to
0.4.0, then refresh
its lockfiles. Projects using both implementations should update them together.
Python should resolvefrontmatter-format>=0.4.0; TypeScript should resolve
fast-uri>=3.1.4through Ajv. -
Validate the full artifact corpus. No artifact rewrite is required: existing quoted
date values stay strings, and bare date-shaped values rejected by v0.3.0 are now
accepted as strings. -
Regenerate committed schemas compiled from Zod ISO date, datetime, time, or duration
helpers. Their digest may change once because compiler-intrinsic temporal patterns
are removed; review and commit that generated diff. -
If a workflow relied on one of those generated patterns for structural rejection,
add an explicit portable JSON Schemapattern. JSON Schemaformatis
annotation-only in softschema. -
Test the application's Pydantic and Zod temporal validators with its accepted and
rejected values. Canonical structural parity does not make the two model libraries'
semantic accept sets identical. -
Treat
ArtifactValidationResult.valuestemporal values as strings. Construct Python
date/datetimeor JavaScriptDateobjects explicitly after validation when host
code needs them. -
If the bundled project skill is installed, refresh its managed mirrors:
softschema skill --install --scope project --agent portable --agent claude
The Dates and Timestamps Are Strings
guide section gives the complete rationale and migration guidance.
What Changed
- Bare and quoted YAML dates and timestamps decode to portable string content in both
runtimes. Explicit YAML tags remain rejected. - Corresponding Pydantic temporal fields and Zod ISO string helpers compile to the same
format-only canonical schema and digest. Explicitly authored regex constraints remain
structural. - The guide, language-neutral spec, language design references, changelog, and bundled
agent skill consistently document the parsing, structural-validation, and
semantic-validation boundaries.
Dependencies and Security
- Python now requires
frontmatter-format>=0.4.0. Its generic readers retain YAML-native
timestamp behavior; softschema does not use them for artifacts and continues to own
its portable-string parsing boundary. - The checked-in TypeScript graph resolves Ajv's URI parser to reviewed
fast-uri
3.1.4, removing CVE-2026-13676 and CVE-2026-16221. Applications must refresh and
verify their own lockfiles at the same safe floor.
Release Safety
The final merge commit passed Python 3.11-3.14, TypeScript, three golden corpora, direct
cross-implementation parity, candidate checksum/smoke checks, and six clean artifact
smokes across Ubuntu, macOS, and Windows. The senior engineering review found no
remaining issues.