CodeSampleX

Sample

zod 3.24.0: z

Verified sample for npm zod 3.24.0: z. The contract ran on node 22 · linux debian/x64 · docker and passed: z.object validates structured schema with nested…

sha256:7c06e5bdea078c23d53d07c7ad217ab298e3a3bdbe7a0f9d5e6284b3c5c49a5e

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
1
Signing keys that built it
1
Declared environment linux 24 · ubuntu · glibc 2.39 x64 npm

Verification-run environments

Environment Contract Stages Run
node 22 · linux debian/x64 · docker ed25519:c1973797be207ac4 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1node:22@sha256:8a34c4ab3ea2…
2026-09-10

Case

HOW
Goal
verify zod.z in pkg:npm/zod@3.24.0
Packages
Symbols
  • zod.z
Created
2026-09-10T17:22:20Z

Contract

  1. z.object validates structured schema with nested primitive validators and defaults
  2. z.string validates constraints including email and min length
  3. z.number validates integer and non-negative constraints
  4. z.enum validates allowed string literal choices and defaults
  5. z.coerce converts string input to typed numbers and booleans
  6. z.array and z.record validate collection structures
  7. safeParse returns structured validation issues on invalid payload
  8. refine and transform apply custom predicate validations and data transformations
  9. direct access to zod.z schema constructor functions

Files

  • PROMPT.md
  • csx.json
  • index.js
  • package-lock.json
  • package.json
  • spec.json
  • test/contract.js

Download the source artifact (tar.gz)

Source

PROMPT.md
Clean-room public code sample — generation instructions

Write a brand-new, minimal, self-contained code sample in this clean-room directory.
Do not copy, paraphrase, or reference any existing project source. Work only from this spec.

A csx.json manifest scaffold already exists. Do not recreate it from memory. Preserve its case.goal, packages and symbols; fill its empty case.contract with exact assertions and correct its environment, commands and verifierAdapter for the files you generate.

Goal: verify zod.z in pkg:npm/zod@3.24.0
Kind: HOW

Use EXACTLY these public packages and versions:
  - pkg:npm/zod@3.24.0
Demonstrate these symbols/APIs:
  - zod.z

Rules:
  - One focused purpose; the smallest project that proves the goal.
  - Include a contract test (test/contract.*) that runs OFFLINE and exits 0 exactly when the goal behavior works.
  - Pin every dependency with a lockfile so resolution is reproducible.
  - No secrets, credentials, or tokens. No real URLs (only example.com or localhost). No absolute paths.
  - No personal names, emails, company names, or project identifiers of any kind.
  - No binaries and no generated output (node_modules, dist, target, venv, .git, .env).
  - Keep it under 200 files and 256KB packed.
csx.json
{"case":{"caseId":"case:sha256:22ca6560ae7d37a382e784c6dd44d94001ade3ac33fc0ab86deed48d7e3d6985","contract":["z.object validates structured schema with nested primitive validators and defaults","z.string validates constraints including email and min length","z.number validates integer and non-negative constraints","z.enum validates allowed string literal choices and defaults","z.coerce converts string input to typed numbers and booleans","z.array and z.record validate collection structures","safeParse returns structured validation issues on invalid payload","refine and transform apply custom predicate validations and data transformations","direct access to zod.z schema constructor functions"],"goal":"verify zod.z in pkg:npm/zod@3.24.0","kind":"HOW","packages":["pkg:npm/zod@3.24.0"],"schemaVersion":1,"symbols":["zod.z"]},"contractCommand":["node","test/contract.js"],"environment":{"arch":"x64","distro":"ubuntu","ecosystem":"npm","libc":"glibc","libcVersion":"2.39","os":"linux","osVersionBucket":"24","packageManager":"npm","schemaVersion":1},"license":"MIT-0","packages":["pkg:npm/zod@3.24.0"],"schemaVersion":1,"subject":"pkg:npm/zod@3.24.0","symbols":["zod.z"],"verifierAdapter":"node-typescript@1"}
index.js
const { z } = require('zod');

// User schema demonstrating object, primitives, constraints, enums, arrays, and defaults
const userSchema = z.object({
  id: z.string().min(1),
  name: z.string().min(1).max(50),
  age: z.number().int().nonnegative(),
  email: z.string().email(),
  role: z.enum(['admin', 'member', 'guest']).default('guest'),
  isActive: z.boolean().default(true),
  tags: z.array(z.string()).default([]),
  metadata: z.record(z.string(), z.string()).optional(),
});

// Config schema demonstrating coercion, ranges, and transformations
const configSchema = z.object({
  port: z.coerce.number().int().min(1).max(65535),
  host: z.string().min(1),
  debug: z.coerce.boolean().default(false),
  timeoutMs: z.coerce.number().positive().default(5000),
});

// Refined schema demonstrating custom validation rules
const passwordResetSchema = z
  .object({
    newPassword: z.string().min(8),
    confirmPassword: z.string().min(8),
  })
  .refine((data) => data.newPassword === data.confirmPassword, {
    message: 'Passwords must match',
    path: ['confirmPassword'],
  });

// Transformed schema demonstrating data pipeline
const trimmedLowercaseSchema = z
  .string()
  .trim()
  .toLowerCase()
  .transform((val) => `user_${val}`);

function parseUser(input) {
  return userSchema.parse(input);
}

function safeParseUser(input) {
  return userSchema.safeParse(input);
}

function parseConfig(input) {
  return configSchema.parse(input);
}

function safeParseConfig(input) {
  return configSchema.safeParse(input);
}

function validatePasswordReset(input) {
  return passwordResetSchema.safeParse(input);
}

function transformUsername(input) {
  return trimmedLowercaseSchema.parse(input);
}

module.exports = {
  z,
  userSchema,
  configSchema,
  passwordResetSchema,
  trimmedLowercaseSchema,
  parseUser,
  safeParseUser,
  parseConfig,
  safeParseConfig,
  validatePasswordReset,
  transformUsername,
};
package-lock.json
{
  "name": "sample-zod",
  "version": "1.0.0",
  "lockfileVersion": 3,
  "requires": true,
  "packages": {
    "": {
      "name": "sample-zod",
      "version": "1.0.0",
      "license": "MIT-0",
      "dependencies": {
        "zod": "3.24.0"
      }
    },
    "node_modules/zod": {
      "version": "3.24.0",
      "resolved": "https://registry.npmjs.org/zod/-/zod-3.24.0.tgz",
      "integrity": "sha512-Hz+wiY8yD0VLA2k/+nsg2Abez674dDGTai33SwNvMPuf9uIrBC9eFgIMQxBBbHFxVXi8W+5nX9DcAh9YNSQm/w==",
      "license": "MIT",
      "funding": {
        "url": "https://github.com/sponsors/colinhacks"
      }
    }
  }
}
package.json
{
  "name": "sample-zod",
  "version": "1.0.0",
  "private": true,
  "description": "Clean-room verification sample for zod.z in zod",
  "main": "index.js",
  "scripts": {
    "test": "node test/contract.js"
  },
  "license": "MIT-0",
  "dependencies": {
    "zod": "3.24.0"
  }
}
spec.json
{
  "schemaVersion": 1,
  "goal": "verify zod.z in pkg:npm/zod@3.24.0",
  "kind": "HOW",
  "packages": [
    "pkg:npm/zod@3.24.0"
  ],
  "symbols": [
    "zod.z"
  ]
}
test/contract.js
const assert = require('assert');
const {
  z,
  userSchema,
  configSchema,
  passwordResetSchema,
  trimmedLowercaseSchema,
  parseUser,
  safeParseUser,
  parseConfig,
  safeParseConfig,
  validatePasswordReset,
  transformUsername,
} = require('../index.js');

function runTests() {
  // 1. z.object validates structured schema with nested primitive validators and defaults
  {
    const input = {
      id: 'usr_1001',
      name: 'Alice Smith',
      age: 30,
      email: 'alice@example.com',
    };
    const user = parseUser(input);
    assert.strictEqual(user.id, 'usr_1001');
    assert.strictEqual(user.name, 'Alice Smith');
    assert.strictEqual(user.age, 30);
    assert.strictEqual(user.email, 'alice@example.com');
    assert.strictEqual(user.role, 'guest', 'applies default role');
    assert.strictEqual(user.isActive, true, 'applies default isActive');
    assert.deepStrictEqual(user.tags, [], 'applies default tags');
  }

  // 2. z.string validates constraints including email and min length
  {
    const invalidEmail = safeParseUser({
      id: 'usr_1002',
      name: 'Bob',
      age: 25,
      email: 'not-an-email',
    });
    assert.strictEqual(invalidEmail.success, false);
    assert.ok(
      invalidEmail.error.issues.some((issue) => issue.path.includes('email')),
      'reports invalid email issue'
    );

    const emptyName = safeParseUser({
      id: 'usr_1002',
      name: '',
      age: 25,
      email: 'bob@example.com',
    });
    assert.strictEqual(emptyName.success, false);
    assert.ok(
      emptyName.error.issues.some((issue) => issue.path.includes('name')),
      'reports empty name issue'
    );
  }

  // 3. z.number validates integer and non-negative constraints
  {
    const negativeAge = safeParseUser({
      id: 'usr_1003',
      name: 'Charlie',
      age: -5,
      email: 'charlie@example.com',
    });
    assert.strictEqual(negativeAge.success, false);
    assert.ok(
      negativeAge.error.issues.some((issue) => issue.path.includes('age')),
      'reports negative age issue'
    );

    const floatAge = safeParseUser({
      id: 'usr_1003',
      name: 'Charlie',
      age: 25.4,
      email: 'charlie@example.com',
    });
    assert.strictEqual(floatAge.success, false);
    assert.ok(
      floatAge.error.issues.some((issue) => issue.path.includes('age')),
      'reports float age issue'
    );
  }

  // 4. z.enum validates allowed string literal choices and defaults
  {
    const adminUser = parseUser({
      id: 'usr_1004',
      name: 'Dana',
      age: 40,
      email: 'dana@example.com',
      role: 'admin',
    });
    assert.strictEqual(adminUser.role, 'admin');

    const invalidRole = safeParseUser({
      id: 'usr_1004',
      name: 'Dana',
      age: 40,
      email: 'dana@example.com',
      role: 'superadmin',
    });
    assert.strictEqual(invalidRole.success, false);
    assert.ok(
      invalidRole.error.issues.some((issue) => issue.path.includes('role')),
      'reports invalid enum issue'
    );
  }

  // 5. z.coerce converts string input to typed numbers and booleans
  {
    const config = parseConfig({
      port: '8080',
      host: 'localhost',
      debug: 'true',
      timeoutMs: '3000',
    });
    assert.strictEqual(config.port, 8080);
    assert.strictEqual(typeof config.port, 'number');
    assert.strictEqual(config.host, 'localhost');
    assert.strictEqual(config.debug, true);
    assert.strictEqual(typeof config.debug, 'boolean');
    assert.strictEqual(config.timeoutMs, 3000);

    const outOfRange = safeParseConfig({
      port: '70000',
      host: 'localhost',
    });
    assert.strictEqual(outOfRange.success, false);
    assert.ok(
      outOfRange.error.issues.some((issue) => issue.path.includes('port')),
      'reports port out of range'
    );
  }

  // 6. z.array and z.record validate collection structures
  {
    const userWithCollections = parseUser({
      id: 'usr_1005',
      name: 'Eve',
      age: 22,
      email: 'eve@example.com',
      tags: ['developer', 'nodejs'],
      metadata: { env: 'production', tier: 'gold' },
    });
    assert.deepStrictEqual(userWithCollections.tags, ['developer', 'nodejs']);
    assert.deepStrictEqual(userWithCollections.metadata, { env: 'production', tier: 'gold' });

    const invalidTags = safeParseUser({
      id: 'usr_1005',
      name: 'Eve',
      age: 22,
      email: 'eve@example.com',
      tags: ['valid', 999],
    });
    assert.strictEqual(invalidTags.success, false);
  }

  // 7. safeParse returns structured validation issues on invalid payload
  {
    const res = safeParseUser({});
    assert.strictEqual(res.success, false);
    assert.ok(Array.isArray(res.error.issues));
    assert.ok(res.error.issues.length >= 3, 'reports multiple missing field issues');
    assert.strictEqual(res.error.name, 'ZodError');
  }

  // 8. refine and transform apply custom predicate validations and data transformations
  {
    const matchingPasswords = validatePasswordReset({
      newPassword: 'secretpassword123',
      confirmPassword: 'secretpassword123',
    });
    assert.strictEqual(matchingPasswords.success, true);

    const mismatchingPasswords = validatePasswordReset({
      newPassword: 'secretpassword123',
      confirmPassword: 'differentpassword123',
    });
    assert.strictEqual(mismatchingPasswords.success, false);
    assert.ok(
      mismatchingPasswords.error.issues.some((issue) => issue.path.includes('confirmPassword')),
      'reports refine validation failure on confirmPassword'
    );

    const transformed = transformUsername('  Alice_Wonder  ');
    assert.strictEqual(transformed, 'user_alice_wonder');
  }

  // 9. direct access to zod.z schema constructor functions
  {
    assert.strictEqual(typeof z.object, 'function');
    assert.strictEqual(typeof z.string, 'function');
    assert.strictEqual(typeof z.number, 'function');
    assert.strictEqual(typeof z.boolean, 'function');
    assert.strictEqual(typeof z.array, 'function');
    assert.strictEqual(typeof z.record, 'function');
    assert.strictEqual(typeof z.enum, 'function');
    assert.strictEqual(typeof z.coerce, 'object');
  }

  console.log('Contract tests passed successfully.');
}

runTests();

Origin Seeder

anonymous