@hookform/resolvers
React Hook Form validation resolvers: Yup, Joi, Superstruct, Zod, Vest, Class Validator, io-ts, Nope, computed-types, TypeBox, arktype, Typanion, Effect-TS and VineJS
Supply chain provenance
Status for the latest visible version.
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
Keywords
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file-transition:zod/dist/zod.js | AI (source-diff): Microbundle minified build output, not true obfuscation; no malicious behavior present. | ai | |
| source-diff | obfuscated-file:ajv/dist/ajv.js | AI (source-diff): Minified build output of AJV resolver bundle; standard for @hookform/resolvers which ships bundled dist files per resolver. | ai | |
| source-diff | obfuscated-file:ajv/dist/ajv.modern.js | AI (source-diff): Minified build output of AJV resolver bundle; modern ESM variant of the same resolver. | ai | |
| source-diff | obfuscated-file:ajv/dist/ajv.module.js | AI (source-diff): Minified build output of AJV resolver bundle; module variant of the same resolver. | ai | |
| source-diff | obfuscated-file:ajv/dist/ajv.mjs | AI (source-diff): Minified build output of AJV resolver bundle; .mjs variant of the same resolver. | ai | |
| source-diff | net-exec-file:ajv/dist/ajv.js | AI (source-diff): AJV uses new Function() for schema compilation; no actual network calls. False positive on bundled validator. | ai | |
| source-diff | net-exec-file:ajv/dist/ajv.modern.js | AI (source-diff): AJV uses new Function() for schema compilation; no actual network calls. False positive on bundled validator. | ai | |
| source-diff | net-exec-file:ajv/dist/ajv.module.js | AI (source-diff): AJV uses new Function() for schema compilation; no actual network calls. False positive on bundled validator. | ai | |
| source-diff | net-exec-file:ajv/dist/ajv.umd.js | AI (source-diff): AJV uses new Function() for schema compilation; no actual network calls. False positive on bundled validator. | ai | |
| source-diff | net-exec-file:ajv/dist/ajv.mjs | AI (source-diff): AJV uses new Function() for schema compilation; no actual network calls. False positive on bundled validator. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Package bundles multiple validation resolvers (Yup, Joi, Superstruct, Zod); new source files reflect legitimate feature expansion, not injected code. Stable for this well-known package. | ai | |
| source-diff | obfuscated-file:class-validator/dist/class-validator.mjs | AI (source-diff): Standard minified build output (mjs variant); source maps included. | ai | |
| source-diff | obfuscated-file:class-validator/dist/class-validator.js | AI (source-diff): Standard minified build output for class-validator resolver; source maps included. Legitimate bundled code for this package. | ai | |
| source-diff | obfuscated-file:class-validator/dist/class-validator.modern.js | AI (source-diff): Standard minified build output (modern ESM variant); source maps included. | ai | |
| source-diff | obfuscated-file:class-validator/dist/class-validator.module.js | AI (source-diff): Standard minified build output (module variant); source maps included. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): kotarella1110 is a long-standing contributor to react-hook-form; legitimate team expansion. | ai | |
| provenance | publisher-changed | AI (provenance): kotarella1110 is a known react-hook-form org collaborator; legitimate maintainer addition within the official @hookform scope. | ai | |
| phantom-deps | phantom-dep:@types/lodash.set | AI (phantom-deps): Type-only package loaded by convention, not direct import; expected pattern for @types/* packages. | ai | |
| dependencies | unvetted-dep:lodash.set | AI (dependencies): lodash.set is a well-known, widely-used lodash sub-package with no security concerns; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@types/lodash.set | AI (dependencies): @types/lodash.set is a standard TypeScript type definition package; no security risk, stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@standard-schema/utils | AI (dependencies): @standard-schema/utils is a legitimate utility from the standard-schema interoperability project; its use in a form validation resolver is expected and appropriate. | ai | |
| provenance | no-provenance | AI (provenance): Lack of Sigstore provenance is common (~88% of packages) and not a meaningful risk signal for this well-established package. | ai |
Versions (showing 100 of 105)
| Version | Deps | Published |
|---|---|---|
| 5.5.7 | 1 / 51 | |
| 5.5.6 | 1 / 51 | |
| 5.5.5 | 1 / 51 | |
| 5.5.4 | 1 / 51 | |
| 5.5.3 | 1 / 51 | |
| 5.5.2 | 1 / 51 | |
| 5.5.1 | 1 / 51 | |
| 5.5.0 | 1 / 51 | |
| 5.4.3 | 1 / 51 | |
| 5.4.2 | 1 / 51 | |
| 5.4.1 | 1 / 51 | |
| 5.4.0 | 1 / 51 | |
| 5.2.2 | 1 / 50 | |
| 5.2.1 | 1 / 50 | |
| 5.2.0 | 1 / 50 | |
| 5.1.1 | 1 / 48 | |
| 5.1.0 | 1 / 48 | |
| 5.0.1 | 1 / 48 | |
| 5.0.0 | 1 / 48 | |
| 4.1.3 | 1 / 48 | |
| 4.1.2 | 1 / 48 | |
| 4.1.1 | 1 / 49 | |
| 4.1.0 | 1 / 48 | |
| 4.0.0 | 0 / 48 | |
| 3.10.0 | 0 / 47 | |
| 3.9.1 | 0 / 48 | |
| 3.9.0 | 0 / 48 | |
| 3.8.0 | 0 / 47 | |
| 3.7.0 | 0 / 50 | |
| 3.6.0 | 0 / 49 | |
| 3.5.0 | 0 / 49 | |
| 3.4.2 | 0 / 49 | |
| 3.4.1 | 2 / 49 | |
| 3.4.0 | 0 / 49 | |
| 3.3.4 | 0 / 47 | |
| 3.3.3 | 0 / 47 | |
| 3.3.2 | 0 / 47 | |
| 3.3.1 | 0 / 47 | |
| 3.3.0 | 0 / 47 | |
| 3.2.0 | 0 / 48 | |
| 3.1.1 | 0 / 47 | |
| 3.1.0 | 0 / 47 | |
| 3.0.1 | 0 / 46 | |
| 3.0.0 | 0 / 46 | |
| 2.9.11 | 0 / 39 | |
| 2.9.10 | 0 / 39 | |
| 2.9.9 | 0 / 39 | |
| 2.9.8 | 0 / 39 | |
| 2.9.7 | 0 / 39 | |
| 2.9.6 | 0 / 39 | |
| 2.9.5 | 0 / 39 | |
| 2.9.4 | 0 / 39 | |
| 2.9.3 | 0 / 39 | |
| 2.9.2 | 0 / 39 | |
| 2.9.1 | 0 / 39 | |
| 2.9.0 | 0 / 39 | |
| 2.8.10 | 0 / 37 | |
| 2.8.9 | 0 / 37 | |
| 2.8.8 | 0 / 37 | |
| 2.8.7 | 0 / 37 | |
| 2.8.6 | 0 / 37 | |
| 2.8.5 | 0 / 37 | |
| 2.8.4 | 0 / 37 | |
| 2.8.3 | 0 / 37 | |
| 2.8.2 | 0 / 37 | |
| 2.8.1 | 0 / 37 | |
| 2.8.0 | 0 / 37 | |
| 2.7.1 | 0 / 37 | |
| 2.7.0 | 0 / 37 | |
| 2.6.1 | 0 / 36 | |
| 2.6.0 | 0 / 36 | |
| 2.5.2 | 0 / 36 | |
| 2.5.1 | 0 / 36 | |
| 2.5.0 | 0 / 37 | |
| 2.4.0 | 0 / 36 | |
| 2.3.2 | 0 / 35 | |
| 2.3.1 | 0 / 35 | |
| 2.3.0 | 0 / 35 | |
| 2.2.0 | 0 / 30 | |
| 2.1.0 | 0 / 30 | |
| 2.0.1 | 0 / 28 | |
| 2.0.0 | 0 / 28 | |
| 1.3.8 | 0 / 24 | |
| 1.3.7 | 0 / 25 | |
| 1.3.6 | 0 / 24 | |
| 1.3.5 | 0 / 29 | |
| 1.3.4 | 0 / 29 | |
| 1.3.3 | 0 / 29 | |
| 1.3.2 | 0 / 29 | |
| 1.3.1 | 0 / 30 | |
| 1.3.0 | 0 / 28 | |
| 1.2.0 | 0 / 28 | |
| 1.1.2 | 0 / 27 | |
| 1.1.1 | 0 / 27 | |
| 1.1.0 | 0 / 27 | |
| 1.0.1 | 0 / 28 | |
| 1.0.0 | 0 / 27 | |
| 0.1.1 | 0 / 29 | |
| 0.1.0 | 0 / 29 | |
| 0.0.6 | 0 / 28 |
v5.5.7
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.5.6
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.5.5
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.5.4
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.5.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.5.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.5.1
2 findingsThis file was readable in the previously greenflagged version and is now minified or obfuscated (lines over 3000 chars). A file that gains obfuscation between releases is a strong payload-swap indicator.
[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.5.0
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.4.3
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.4.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.4.1
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.
v5.2.2
1 finding[Accepted risk] Package was published without Sigstore provenance. Consider requesting the maintainer enable provenance via CI/CD.