CodeSampleX

Sample

zod 4.4.3: Identify constructor coercion traps in z.coerce and verify that .refine() discards return values without mutating parsed output

Verified sample for npm zod 4.4.3: Identify constructor coercion traps in z.coerce and verify that .refine() discards return values without mutating parsed…

sha256:d3a9cc5fa6af1de9c4bd13813f2a670ad60d7afe148dadb0bcc4dc95133a9eb4

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
2
Signing keys that built it
2
Declared environment node linux x64 node node npm

Verification-run environments

Environment Contract Stages Run
node 22 · linux alpine/x64 · docker ed25519:ac1544ece1e22594 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-15
node 22 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-18

Case

HOW
Goal
Identify constructor coercion traps in z.coerce and verify that .refine() discards return values without mutating parsed output
Packages
Symbols
  • z.coerce.boolean
  • z.coerce.number
  • z.coerce.string
  • z.coerce.date
  • z.coerce.bigint
  • z.ZodType.refine
Environment
node
Created
2026-08-15T04:21:08Z

Contract

  1. assert z.coerce.boolean() evaluates Boolean(val), coercing 'false', '0', 'off', 'no', [], and {} to true
  2. assert z.coerce.boolean() coerces only empty string, 0, null, undefined, and false to false
  3. assert z.coerce.number() coerces empty string, whitespace, null, false, and [] to 0 rather than failing
  4. assert z.coerce.number() rejects undefined as invalid_type with received NaN
  5. assert z.coerce.string() turns null and undefined into literal strings 'null' and 'undefined'
  6. assert z.coerce.date() coerces null and false to Unix epoch 1970-01-01 but rejects empty string
  7. assert z.coerce.bigint() coerces empty string and booleans to bigint but rejects null and undefined
  8. assert refine() discards returned transformed values and preserves raw parsed inputs
  9. assert chained coercion and refinement coerces empty string and null to 0 before refinement fails with custom issue

Files

  • NOTES.md
  • csx.json
  • package-lock.json
  • package.json
  • src/schema.mjs
  • test/contract.mjs

Download the source artifact (tar.gz)

Origin Seeder

anonymous