@hookform/resolvers
React Hook Form validation resolvers: Yup, Joi, Superstruct, Zod, Vest, Class Validator, io-ts, Nope, computed-types, TypeBox, arktype, Typanion, Effect-TS and VineJS
5
Versions
MIT
License
No
Install Scripts
Missing
Provenance
Supply chain provenance
Status for the latest visible version.
No SLSA provenance
npm registry signatures
gitHead linked
Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.
Maintainers
bluebill1049kotarella1110jorisre
Keywords
schemevalidationscheme-validationhookformreact-hook-formyupjoisuperstructtypescriptzodvestclass-validatorio-tseffect-tsnopecomputed-typestypanionajvTypeBoxarktypetypeschemavinefluentvalidation-tsstandard-schemaata-validator
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| source-diff | obfuscated-file-transition:zod/dist/zod.js | AI (source-diff): Microbundle minified build output, not true obfuscation; no malicious behavior present. | ai | |
| source-diff | obfuscated-file:ajv/dist/ajv.js | AI (source-diff): Minified build output of AJV resolver bundle; standard for @hookform/resolvers which ships bundled dist files per resolver. | ai | |
| source-diff | obfuscated-file:ajv/dist/ajv.modern.js | AI (source-diff): Minified build output of AJV resolver bundle; modern ESM variant of the same resolver. | ai | |
| source-diff | obfuscated-file:ajv/dist/ajv.module.js | AI (source-diff): Minified build output of AJV resolver bundle; module variant of the same resolver. | ai | |
| source-diff | obfuscated-file:ajv/dist/ajv.mjs | AI (source-diff): Minified build output of AJV resolver bundle; .mjs variant of the same resolver. | ai | |
| source-diff | net-exec-file:ajv/dist/ajv.js | AI (source-diff): AJV uses new Function() for schema compilation; no actual network calls. False positive on bundled validator. | ai | |
| source-diff | net-exec-file:ajv/dist/ajv.modern.js | AI (source-diff): AJV uses new Function() for schema compilation; no actual network calls. False positive on bundled validator. | ai | |
| source-diff | net-exec-file:ajv/dist/ajv.module.js | AI (source-diff): AJV uses new Function() for schema compilation; no actual network calls. False positive on bundled validator. | ai | |
| source-diff | net-exec-file:ajv/dist/ajv.umd.js | AI (source-diff): AJV uses new Function() for schema compilation; no actual network calls. False positive on bundled validator. | ai | |
| source-diff | net-exec-file:ajv/dist/ajv.mjs | AI (source-diff): AJV uses new Function() for schema compilation; no actual network calls. False positive on bundled validator. | ai | |
| source-diff | large-new-source-files | AI (source-diff): Package bundles multiple validation resolvers (Yup, Joi, Superstruct, Zod); new source files reflect legitimate feature expansion, not injected code. Stable for this well-known package. | ai | |
| source-diff | obfuscated-file:class-validator/dist/class-validator.mjs | AI (source-diff): Standard minified build output (mjs variant); source maps included. | ai | |
| source-diff | obfuscated-file:class-validator/dist/class-validator.js | AI (source-diff): Standard minified build output for class-validator resolver; source maps included. Legitimate bundled code for this package. | ai | |
| source-diff | obfuscated-file:class-validator/dist/class-validator.modern.js | AI (source-diff): Standard minified build output (modern ESM variant); source maps included. | ai | |
| source-diff | obfuscated-file:class-validator/dist/class-validator.module.js | AI (source-diff): Standard minified build output (module variant); source maps included. | ai | |
| maintainer-change | maintainer-added | AI (maintainer-change): kotarella1110 is a long-standing contributor to react-hook-form; legitimate team expansion. | ai | |
| provenance | publisher-changed | AI (provenance): kotarella1110 is a known react-hook-form org collaborator; legitimate maintainer addition within the official @hookform scope. | ai | |
| phantom-deps | phantom-dep:@types/lodash.set | AI (phantom-deps): Type-only package loaded by convention, not direct import; expected pattern for @types/* packages. | ai | |
| dependencies | unvetted-dep:lodash.set | AI (dependencies): lodash.set is a well-known, widely-used lodash sub-package with no security concerns; stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@types/lodash.set | AI (dependencies): @types/lodash.set is a standard TypeScript type definition package; no security risk, stable false positive for this package. | ai | |
| dependencies | unvetted-dep:@standard-schema/utils | AI (dependencies): @standard-schema/utils is a legitimate utility from the standard-schema interoperability project; its use in a form validation resolver is expected and appropriate. | ai | |
| provenance | no-provenance | AI (provenance): Lack of Sigstore provenance is common (~88% of packages) and not a meaningful risk signal for this well-established package. | ai |