← Home

@hookform/resolvers

React Hook Form validation resolvers: Yup, Joi, Superstruct, Zod, Vest, Class Validator, io-ts, Nope, computed-types, TypeBox, arktype, Typanion, Effect-TS and VineJS

5
Versions
MIT
License
No
Install Scripts
Missing
Provenance

Supply chain provenance

Status for the latest visible version.

No SLSA provenance npm registry signatures gitHead linked

Without SLSA provenance there is no cryptographic link between this tarball and the public source, so a manually published version cannot be tied back to a reviewed commit.

Maintainers

bluebill1049kotarella1110jorisre

Keywords

schemevalidationscheme-validationhookformreact-hook-formyupjoisuperstructtypescriptzodvestclass-validatorio-tseffect-tsnopecomputed-typestypanionajvTypeBoxarktypetypeschemavinefluentvalidation-tsstandard-schemaata-validator

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff obfuscated-file-transition:zod/dist/zod.js AI (source-diff): Microbundle minified build output, not true obfuscation; no malicious behavior present. ai
source-diff obfuscated-file:ajv/dist/ajv.js AI (source-diff): Minified build output of AJV resolver bundle; standard for @hookform/resolvers which ships bundled dist files per resolver. ai
source-diff obfuscated-file:ajv/dist/ajv.modern.js AI (source-diff): Minified build output of AJV resolver bundle; modern ESM variant of the same resolver. ai
source-diff obfuscated-file:ajv/dist/ajv.module.js AI (source-diff): Minified build output of AJV resolver bundle; module variant of the same resolver. ai
source-diff obfuscated-file:ajv/dist/ajv.mjs AI (source-diff): Minified build output of AJV resolver bundle; .mjs variant of the same resolver. ai
source-diff net-exec-file:ajv/dist/ajv.js AI (source-diff): AJV uses new Function() for schema compilation; no actual network calls. False positive on bundled validator. ai
source-diff net-exec-file:ajv/dist/ajv.modern.js AI (source-diff): AJV uses new Function() for schema compilation; no actual network calls. False positive on bundled validator. ai
source-diff net-exec-file:ajv/dist/ajv.module.js AI (source-diff): AJV uses new Function() for schema compilation; no actual network calls. False positive on bundled validator. ai
source-diff net-exec-file:ajv/dist/ajv.umd.js AI (source-diff): AJV uses new Function() for schema compilation; no actual network calls. False positive on bundled validator. ai
source-diff net-exec-file:ajv/dist/ajv.mjs AI (source-diff): AJV uses new Function() for schema compilation; no actual network calls. False positive on bundled validator. ai
source-diff large-new-source-files AI (source-diff): Package bundles multiple validation resolvers (Yup, Joi, Superstruct, Zod); new source files reflect legitimate feature expansion, not injected code. Stable for this well-known package. ai
source-diff obfuscated-file:class-validator/dist/class-validator.mjs AI (source-diff): Standard minified build output (mjs variant); source maps included. ai
source-diff obfuscated-file:class-validator/dist/class-validator.js AI (source-diff): Standard minified build output for class-validator resolver; source maps included. Legitimate bundled code for this package. ai
source-diff obfuscated-file:class-validator/dist/class-validator.modern.js AI (source-diff): Standard minified build output (modern ESM variant); source maps included. ai
source-diff obfuscated-file:class-validator/dist/class-validator.module.js AI (source-diff): Standard minified build output (module variant); source maps included. ai
maintainer-change maintainer-added AI (maintainer-change): kotarella1110 is a long-standing contributor to react-hook-form; legitimate team expansion. ai
provenance publisher-changed AI (provenance): kotarella1110 is a known react-hook-form org collaborator; legitimate maintainer addition within the official @hookform scope. ai
phantom-deps phantom-dep:@types/lodash.set AI (phantom-deps): Type-only package loaded by convention, not direct import; expected pattern for @types/* packages. ai
dependencies unvetted-dep:lodash.set AI (dependencies): lodash.set is a well-known, widely-used lodash sub-package with no security concerns; stable false positive for this package. ai
dependencies unvetted-dep:@types/lodash.set AI (dependencies): @types/lodash.set is a standard TypeScript type definition package; no security risk, stable false positive for this package. ai
dependencies unvetted-dep:@standard-schema/utils AI (dependencies): @standard-schema/utils is a legitimate utility from the standard-schema interoperability project; its use in a form validation resolver is expected and appropriate. ai
provenance no-provenance AI (provenance): Lack of Sigstore provenance is common (~88% of packages) and not a meaningful risk signal for this well-established package. ai

Versions (showing 5 of 105)

Version Deps Published
0.0.5 0 / 28
0.0.4 0 / 28
0.0.3 1 / 16
0.0.2 1 / 16
0.0.1 1 / 16