colinhacks/zod
53.4
Adequate · 28 September 2026
46.5k
lines of production code
TypeScript
primary language
4
measurements over time
What this system is
This system is the Zod validation library, providing a TypeScript-first schema validation engine with support for both classic and lightweight (Mini) APIs. It features a new v4 core with ahead-of-time compilation for performance, extensive internationalization, and strict type safety. The repository also includes comprehensive tooling for benchmarking, tree-shaking verification, and automated triage of issues and security advisories.
How it got here
2020–2025 — Zod v4 development and tooling overhaul
29 changes.
This period focused on the comprehensive development of Zod v4, introducing a new core architecture with ahead-of-time compilation, a lightweight Mini API, and a Classic compatibility layer. The work included extensive benchmarking for performance and bundle size, alongside a complete migration to the Nub package manager and standardized repository tooling.
2026 — memory benchmarking and tooling expansion
4 changes.
This period focused on establishing comprehensive memory profiling for schema instances through a new benchmark suite in the packages/bench/memory directory. It also expanded the project's development tooling by introducing automated triage and security-advisory skills for issue investigation, alongside the release of the standalone @zod/mini npm package.
Features
Added English locale error messages for Zod v3
The \packages/zod/src/v3/locales\ directory now includes an English locale file (\en.ts\) that defines the default error messages for validation failures. This file exports an error map that translates internal Zod issue codes (such as \invalid\_type\, \too\_small\, \invalid\_string\, etc.) into human-readable English strings, allowing users to see standardized error messages when validation fails in Zod v3.
packages/zod/src/v3/locales · high confidence
Added TypeScript compiler performance benchmarking suite
A new benchmarking package has been added to measure and compare TypeScript compilation performance across different schema validation libraries. The suite includes scripts to generate random schemas for Zod v3, Zod v4, Valibot, and ArkType, and runs \tsc\ with extended diagnostics to capture compilation time, memory usage, and type instantiations. This allows developers to track the impact of schema complexity and library choices on build times.
packages/tsc · high confidence
Added new logo asset variants
The repository now includes three new Adobe Illustrator source files for the brand logo: a black version, a white version, and an outer glow variant. These assets provide designers with ready-to-edit vector files for different background contexts.
logo · high confidence
Ahead-of-time schema compilation and improved tree-shaking
Zod now supports ahead-of-time schema compilation via \z.compile()\ and a global post-processor mode (activated by importing \zod/compile\) that automatically compiles schemas on first parse for improved performance, with automatic fallback to the runtime parser if a schema cannot be compiled. Additionally, the default export has been refactored to ensure bundlers can properly tree-shake unused locale files, reducing bundle size.
packages/zod/src · high confidence
Initial release of the v3 documentation site
The v3 documentation site is now available, providing comprehensive guides, API references, and migration instructions for upgrading to Zod 3. This includes a new changelog, error handling details, and a migration guide from Zod 1 and 2.
packages/docs-v3 · high confidence
Introduces a new mini entry point for Zod v4
A new entry point at packages/zod/src/mini/index.ts has been added to expose the Zod v4 mini build. This file re-exports all symbols from the internal v4 mini external module and also exports the 'z' namespace object, providing a consolidated access point for users of the mini variant.
packages/zod/src/mini · high confidence
New CI and development tooling scripts for Zod v4
The repository now includes a suite of new scripts in the \scripts/\ directory to support the v4 release and improve development workflows. These include \check-comments.ts\ to enforce single-line prose comments, \check-lockstep.ts\ to verify that \zod\ and \@zod/mini\ packages remain synchronized on npm and JSR, and \check-versions.ts\ to ensure version consistency across \package.json\, \jsr.json\, and internal version files. Additional scripts like \compile-fuzz.ts\ and \enable-compile.ts\ support the new \z.compile()\ feature, while \triage-signal.ts\ assists in prioritizing issues and PRs based on engagement and security signals. The \update-iso-4217.ts\ script automates the maintenance of the currency code list, and \write-stub-package-jsons.ts\ generates stub manifests to resolve TypeScript assignability issues.
scripts · high confidence
New build configuration files for Rollup and TypeScript
Added new configuration files to the \.configs\ directory: a Rollup build script (\rollup.config.js\) that sets up an ES module build pipeline with TypeScript compilation and tree-shaking, and a base TypeScript configuration (\tsconfig.base.json\) that enforces strict type checking, targets ES2020, and uses NodeNext module resolution.
.configs · high confidence
New triage and security-advisory skills for issue and PR investigation
Added \.claude/skills/triage\ and \.claude/skills/security-advisory\ to guide the automated investigation of GitHub issues, pull requests, and private security advisories. The triage skill defines a structured workflow for evaluating tickets, including reproducible code blocks, verdicts, and drafted close comments, while the security-advisory skill adapts this process for private GHSA reports with specific rules for privacy, fix-before-comment, and publish-or-decline decisions. A supporting \reindex.mjs\ script automatically generates sortable index tables from the YAML frontmatter of investigation write-ups stored in \.triage/\.
.claude · high confidence
Repository development environment and tooling setup
The repository now includes a standardized development environment configuration. This introduces \.editorconfig\ for consistent file formatting (2-space indentation, LF line endings), a \.gitignore\ to exclude build artifacts and local state, and a \.nvmrc\ pinning the Node.js version to 24. It also adds \AGENTS.md\ to provide detailed guidance for AI coding assistants (like Claude Code) on development commands, performance benchmarking, and code style, alongside \biome.jsonc\ for linting and formatting rules. Additionally, a \.mcp.json\ file configures a Chrome DevTools MCP server via the Nub tool, and standard documentation files like \CODE\_OF\_CONDUCT.md\, \CONTRIBUTING.md\, \SECURITY.md\, and \FUNDING.yml\ are established.
(repo-wide) · high confidence
Standalone @zod/mini package available
Zod Mini is now available as a standalone npm package (@zod/mini). This package re-exports the zod/mini functionality from the zod peer dependency, allowing users to import Zod Mini schemas directly via @zod/mini while ensuring they remain instances of the main zod schema types. The package version tracks the main zod version (e.g., @zod/mini@4.x.y requires zod@^4.x.0) and is also published to JSR.
packages/mini · high confidence
Zod Mini v4: New lightweight validation API
Zod Mini v4 introduces a new, lightweight validation API designed for smaller bundle sizes and faster initialization. This release adds a complete set of mini-specific schema types (such as ZodMiniString, ZodMiniObject, and ZodMiniUnion) and exposes them through a dedicated entry point. The new API includes mini-optimized coercion helpers (coerce.string, coerce.number, etc.), a deepPartial utility for recursively making schema fields optional, and input/output type extraction helpers. It also provides a full suite of validation checks (lt, gt, maxLength, regex, etc.) and ISO date/time formats, all re-exported from the core engine but structured for the mini footprint.
packages/zod/src/v4/mini · high confidence
Zod v4 core library initialization
The \packages/zod/src/v4/core\ directory has been introduced, establishing the foundational runtime and type definitions for Zod v4. This includes the core schema constructors (\core.ts\), the check system (\checks.ts\), error definitions (\errors.ts\), and the public API factory functions (\api.ts\). A significant addition is the ahead-of-time (AOT) compilation engine (\compile.ts\), which allows schemas to be compiled into fast-path JavaScript functions for improved validation performance, with a fallback to the standard runtime parser for unsupported features. The directory also contains the JSON Schema generation logic (\json-schema-generator.ts\, \json-schema-processors.ts\) and utility modules, effectively replacing the previous v3 core implementation with a new, modular architecture.
packages/zod/src/v4/core · high confidence
Behavioural changes
Re-introduce v4-mini entry point with explicit re-exports
The \packages/zod/src/v4-mini/index.ts\ file has been added to serve as the entry point for the v4-mini package. It re-exports all symbols from the underlying \../v4/mini/external.js\ module and explicitly exports the \z\ namespace object, ensuring that consumers of the v4-mini package have access to both named exports and the default \z\ binding.
packages/zod/src/v4-mini · high confidence
Symlinked skills directory for issue and PR investigation
The .codex/skills directory is now a symbolic link pointing to ../.claude/skills, enabling the system to access existing skill definitions for triage and investigation tasks without duplicating files.
.codex · high confidence
Updated pre-commit and pre-push hooks to use Nub and enforce clean working trees
The .husky directory now contains explicit pre-commit and pre-push scripts that reject commits or pushes if untracked files are present. The pre-commit hook runs semver and comment checks via Nub before executing lint-staged, while the pre-push hook additionally runs the test suite via Nub. This replaces the previous Husky v7 configuration with a v9 setup that delegates execution to the Nub tooling.
.husky · high confidence
Zod v3 internal parsing and utility helpers introduced
The v3 helpers directory now contains the core internal utilities for the Zod v3 validation library. This includes \parseUtil.ts\, which defines the \ParseStatus\ class, issue creation logic (\makeIssue\, \addIssueToContext\), and result types (\OK\, \DIRTY\, \INVALID\) used during schema validation. It also adds \enumUtil.ts\ for union-to-tuple type transformations, \errorUtil.ts\ for normalizing error messages, \partialUtil.ts\ for deep-partial type inference, \typeAliases.ts\ for primitive/scalar definitions, and \util.ts\ for common runtime helpers (like \getValidEnumValues\, \objectKeys\) and the \ZodParsedType\ enum. These files form the foundational support layer for v3 schema parsing and type inference.
packages/zod/src/v3/helpers · high confidence
Zod v3 source code reorganization and Standard Schema support
The Zod v3 library has been restructured with source files moved into a dedicated \v3\ directory, improving internal organization. This update also introduces support for the Standard Schema V1 specification, allowing Zod schemas to be used with tools that adhere to this standard, and includes various internal fixes to error handling and validation logic.
packages/zod/src/v3 · medium confidence
Zod v4 Classic API surface and validation behavior
This change introduces the Zod v4 Classic API, providing a new validation engine with updated schema definitions, coercion utilities, and error handling. Users gain access to new string formats (credit card, IBAN, MAC address, hostname), a \deepPartial\ utility for recursively making object properties optional, and explicit \input\/\output\ schema transformations. The release also includes a compatibility layer for Zod v3 patterns, stricter JSON Schema conversion logic, and performance optimizations such as lazy error construction and prototype-based method sharing.
packages/zod/src/v4/classic · high confidence
Zod v4: New locale files and updated English error messages
The \packages/zod/src/v4/locales\ directory now includes new locale files for Arabic (ar), Azerbaijani (az), Belarusian (be), Bulgarian (bg), Bengali (bn), Catalan (ca), Central Kurdish (ckb), Czech (cs), Danish (da), German (de), and Greek (el). Additionally, the English (en) locale has been updated to support the \exact\ flag for size validation messages and includes a \getTypeName\ helper for improved type name handling.
packages/zod/src/v4/locales · high confidence
Test coverage
Added automated bundle-size and tree-shaking regression tests; Added comprehensive test coverage for Zod v4 locale error messages; Added comprehensive test suite for Zod v3; Added integration test fixtures for Zod v4 compatibility; Added package resolution verification tests; Added resolution tests for Zod v4 module imports and French locale validation; Added test coverage for Zod Mini v4; Added test coverage for Zod v4 Classic schema types and behaviors; Added test coverage for Zod v4 core utilities and schema compilation; Added v3 benchmark suite for performance validation; Expanded benchmark suite for Zod v4 compilation and runtime performance; New memory benchmark suite for schema instances.
Dependencies
Migrate to Nub package manager and update core dependencies
The project has switched its package manager to Nub (v0.8.3), replacing the previous tooling. This migration includes updating the root \package.json\ to use Nub for all scripts (build, test, lint) and configuring workspaces for the monorepo. Key dependency updates visible in the manifests include upgrading TypeScript to \~5.5.4, Vitest to ^4.1.5, Vite to ^7.3.6, and Biome to ^1.9.4. The documentation package now uses Next.js 15.5.25 with React 19, and the benchmarking package has been updated to compare against Zod 4.0.8 and other libraries like Arktype 2.1.19 and Valibot 1.3.1.
(dependencies) · high confidence
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
How this codebase got here
Score
- CAI 37 → 53 (+16.6)
- Rubric changed (rubric-2026.08.15 → rubric-2026.09.16) — scores are not directly comparable.
Lenses
- Code Health 65 → 67 (+1.5)
- Architecture 91 (new)
- Maturity 51 → 57 (+5.7)
- Readiness 19 → 45 (+25.8)
- Security 53 → 60 (+7.6)
- Accessibility 71 (new)
- Performance 60 (new)
Resolved (92)
- Change coupling: api.ts ↔ play.ts (packages/zod/src/v4/core/api.ts)
- Change coupling: api.ts ↔ schemas.ts (packages/zod/src/v4/core/api.ts)
- Change coupling: errors.ts ↔ play.ts (packages/zod/src/v4/core/errors.ts)
- Change coupling: schemas.ts ↔ play.ts (packages/zod/src/v4/classic/schemas.ts)
- Change coupling: schemas.ts ↔ play.ts (packages/zod/src/v4/core/schemas.ts)
- Change coupling: schemas.ts ↔ play.ts (packages/zod/src/v4/mini/schemas.ts)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Dimension evaluation failed
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- High CVE: [GHSA redacted] (pnpm-lock.yaml)
- …and 72 more
New (679)
- Change coupling: index.ts ↔ types.ts (packages/zod/src/v3/benchmarks/index.ts)
- Coverage not measured — JavaScript/TypeScript suite
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- Critical CVE: [GHSA redacted] (pnpm-lock.yaml)
- FileTooLong: classic/from-json-schema.ts (packages/zod/src/v4/classic/from-json-schema.ts)
- FileTooLong: classic/schemas.ts (packages/zod/src/v4/classic/schemas.ts)
- FileTooLong: core/api.ts (packages/zod/src/v4/core/api.ts)
- FileTooLong: core/checks.ts (packages/zod/src/v4/core/checks.ts)
- FileTooLong: core/compile.ts (packages/zod/src/v4/core/compile.ts)
- FileTooLong: core/json-schema-processors.ts (packages/zod/src/v4/core/json-schema-processors.ts)
- FileTooLong: core/schemas.ts (packages/zod/src/v4/core/schemas.ts)
- FileTooLong: core/util.ts (packages/zod/src/v4/core/util.ts)
- FileTooLong: mini/schemas.ts (packages/zod/src/v4/mini/schemas.ts)
- FileTooLong: v3/types.ts (packages/zod/src/v3/types.ts)
- FunctionTooLong: be.error (packages/zod/src/v4/locales/be.ts)
- FunctionTooLong: ckb.error (packages/zod/src/v4/locales/ckb.ts)
- FunctionTooLong: compile-fuzz.build (scripts/compile-fuzz.ts)
- FunctionTooLong: compile.generateCheck (packages/zod/src/v4/core/compile.ts)
- FunctionTooLong: compile.generateObjectCheck (packages/zod/src/v4/core/compile.ts)
- FunctionTooLong: en.errorMap (packages/zod/src/v3/locales/en.ts)
- …and 659 more
Changes since last survey
- 300 commits — 204 feature/other, 96 fixes
By area
- packages/zod — 182 commits
- packages/docs — 68 commits
- (root) — 17 commits
- .github/workflows — 9 commits
- packages/bench — 8 commits
- .claude/skills — 3 commits
- packages/mini — 3 commits
- packages/docs-v3 — 2 commits
- packages/resolution — 2 commits
- packages/treeshake — 2 commits
- .devcontainer/devcontainer.json — 1 commit
- .github/scripts — 1 commit
- wiki/compile.md — 1 commit
- wiki/compiled-constructor-graph.md — 1 commit
Notable commits
- fix: Fix bugs and improve performance
- fix: Fix bugs and improve performance
- fix: Revert "Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)""
- fix: Revert "feat: add z.currencyCode() over a vendored ISO 4217 list, refreshed weekly by CI (#6595)"
- fix: chore: drop dead code in core and fix a stale deprecation message (#6012)
- fix: fix(ci): read zod's latest version with npm view when picking the backfill dist-tag
- fix: fix(compile): unwind the doc indent when a child generator throws (#6570)
- fix: fix(core): an omittable discriminator claims undefined (#6432)
- fix: fix(core): restore defineLazy semantics lost in the internals move (#6429)
- fix: fix(docs): drop ISR on the docs route so the home page hydrates
- fix: fix(docs): drop the OG description when the title wraps past two lines
- fix: fix(docs): keep blog posts out of the docs collection (#6484)
- fix: fix(docs): match the blog TOC hover bar to the 2px active indicator
- fix: fix(docs): render blog tabs with the stock fumadocs tab card
- fix: fix(docs): render the docs 404 page inside the (doc) layout once
- fix: fix(docs): retry the GitHub stars fetch and log the real status
- fix: fix(docs-v3): serve the docsify SPA fallback on Vercel (#6378)
- fix: fix(fr): remove hyphen in "non-optionnel" (#5999)
- fix: fix(from-json-schema): drop redundant inclusive bound for draft-04 exclusive ranges (#6022)
- fix: fix(json-schema): accept RFC 3339 numeric offsets in date-time format (#6298)
- …and 280 more
Written by watchdog.canine.dev from the codebase's own history, inside the signed delivery this page is composed from.
Survey your own repository
colinhacks/zod was measured the same way every project in this corpus was: the same rubric, at a pinned commit, with the result published in full. Point a surveyor at a repository you know and see whether you agree with it.
About this page
- The score is its most recent published measurement, taken on 28 September 2026 at a pinned commit. It is not a live figure and does not change until the project is measured again.
- Measured at commit 2bf7b0630d5378033e90bcee82cb32b0fe04628e — the exact code this score is about.
- Scored under rubric-2026.09.16 — the same rubric and the same method as every other entry in this index.
- Measured by watchdog.canine.dev using codehealth-analyzer preprod-eb9197011364.