@umpire/zod
Availability-aware Zod validation for [@umpire/core](https://www.npmjs.com/package/@umpire/core)-powered state. Disabled fields produce no validation errors. Required/optional follows Umpire's availability map.
3
Versions
MIT
License
No
Install Scripts
Verified
Provenance
Supply chain provenance
Status for the latest visible version.
SLSA provenance attestation
npm registry signatures
No source commit
Maintainers
sdougbrown
Accepted risks
Findings the reviewer chose to accept rather than block on.
| Source | Rule | Reason | Accepted by | When |
|---|---|---|---|---|
| provenance | publisher-changed | AI (provenance): Transition from sdougbrown to GitHub Actions is a CI automation handoff within the same @umpire monorepo; SLSA attestation confirms integrity. | ai | |
| publish-pattern | new-deps-added | AI (publish-pattern): @umpire/write is a sibling package in the same monorepo (github.com/sdougbrown/umpire); not a third-party dependency. | ai | |
| typosquat | typosquat.levenshtein:koa | AI (typosquat): Scoped @umpire/zod package; Levenshtein match to 'koa' is coincidental, not a squatting attempt. | ai | |
| typosquat | typosquat.levenshtein:got | AI (typosquat): Scoped @umpire/zod package; Levenshtein match to 'got' is coincidental, not a squatting attempt. | ai | |
| typosquat | typosquat.levenshtein:joi | AI (typosquat): Scoped @umpire/zod package; Levenshtein match to 'joi' is coincidental, not a squatting attempt. | ai |