← Home

@zod-to-form/cli

Build-time code generator for Zod v4 form components

32
Versions
MIT
License
No
Install Scripts
Verified
Provenance

Supply chain provenance

Status for the latest visible version.

SLSA provenance attestation npm registry signatures No source commit

Maintainers

pmouli

Keywords

zodzod-v4codegenformsform-generationreact-hook-formschema-drivencligeneratorcomponent-codegenschema-to-tsx

Accepted risks

Findings the reviewer chose to accept rather than block on.

SourceRuleReasonAccepted byWhen
source-diff source-size-tripled AI (source-diff): Size growth reflects active feature development (Zod v4 support); no malicious indicators found alongside it. ai
provenance publisher-changed AI (provenance): Transition to GitHub Actions publisher is a legitimate CI/CD automation change; SLSA attestation confirms integrity. ai
phantom-deps phantom-dep:chokidar AI (phantom-deps): File watcher for dev mode; used indirectly in CLI flow. ai
phantom-deps phantom-dep:@zod-to-form/core AI (phantom-deps): Same-org scoped sibling; core library for this CLI package. ai
phantom-deps phantom-dep:commander AI (phantom-deps): CLI argument parser; used indirectly in bin entry point. ai
phantom-deps phantom-dep:jiti AI (phantom-deps): Build-time code generator; jiti used indirectly via config loading. ai
typosquat typosquat.levenshtein:joi AI (typosquat): Scoped package for Zod form codegen; edit-distance match to 'joi' is coincidental, not a squatting attempt. ai

Versions (showing 32 of 32)

Version Deps Published
0.8.4 4 / 1
0.8.3 4 / 1
0.8.2 4 / 1
0.8.1 4 / 1
0.8.0 4 / 1
0.7.4 4 / 1
0.7.3 4 / 1
0.7.2 4 / 1
0.7.1 4 / 1
0.7.0 4 / 1
0.6.8 4 / 1
0.6.7 4 / 1
0.6.6 4 / 1
0.6.5 5 / 1
0.6.4 5 / 1
0.6.3 5 / 1
0.6.2 5 / 1
0.6.1 4 / 1
0.6.0 4 / 1
0.5.0 4 / 1
0.4.2 4 / 1
0.4.1 4 / 1
0.4.0 4 / 1
0.3.0 4 / 1
0.2.7 4 / 1
0.2.6 4 / 1
0.2.5 4 / 1
0.2.4 5 / 1
0.2.3 4 / 1
0.2.2 4 / 1
0.2.1 4 / 1
0.2.0 4 / 1

v0.8.4

1 finding
INFO Has SLSA provenance attestation provenance

Published via CI/CD with Sigstore attestation (predicate: https://slsa.dev/provenance/v1). This is the strongest supply chain integrity signal.