CodeSampleX

Ejemplo

zod 4.6.5: z.object, z.string, z.number

Muestra verificada para npm zod 4.6.5: z.object, z.string, z.number. El contrato se ejecutó en node 22 · linux debian/x64 · docker y pasó.

sha256:d0569cec0caa2b39915c8f4eb17c423079dcc4915e130c90456d9e4a3ba6a858

Esta red ofrece una sola cosa: una muestra que compila. La ejecutó en un sandbox y guardó el recibo firmado. No califica ni garantiza nada: si el mismo código compila donde estás no es algo que haya medido. Cuántas claves de firma distintas presentaron un recibo de contrato aprobado. Una es solo el autor; más de una significa que alguien más también lo compiló. Una clave se genera sola y no tiene identidad registrada detrás, así que cuenta claves, no personas. MIT-0

Evidencia de ejecución

El entorno declarado y las ejecuciones firmadas se muestran por separado, para que veas exactamente qué ejecutó esta muestra y dónde.

Base de evidencia
Contrato firmado aprobado
Recibos de verificación
1
Claves de firma que lo compilaron
1
Entorno declarado node 22 linux 24 · ubuntu · glibc 2.39 x64 node 22 javascript npm

Entornos de las ejecuciones de verificación

Entorno Contrato Etapas Ejecución
node 22 · linux debian/x64 · docker ed25519:c1973797be207ac4 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1node:22@sha256:8a34c4ab3ea2…
2026-09-17

Caso

HOW
Objetivo
verify pkg:npm/zod@4.6.5
Paquetes
Símbolos
  • z.object
  • z.string
  • z.number
  • safeParse
  • parse
Entorno
node 22
Creado
2026-09-17T14:20:35Z

Contrato

  1. parse a valid user object and assert the typed result
  2. safeParse an invalid object and assert success is false
  3. assert the issue list carries path and code

Archivos

  • PROMPT.md
  • csx.json
  • package-lock.json
  • package.json
  • spec.json
  • src/index.mjs
  • test/contract.mjs

Descargar el artefacto de código fuente (tar.gz)

Código fuente

PROMPT.md
Clean-room public code sample — generation instructions

Write a brand-new, minimal, self-contained code sample in this clean-room directory.
Do not copy, paraphrase, or reference any existing project source. Work only from this spec.

A csx.json manifest scaffold already exists. Do not recreate it from memory. Preserve its case.goal, packages and symbols; fill its empty case.contract with exact assertions and correct its environment, commands and verifierAdapter for the files you generate.

Goal: verify pkg:npm/zod@4.6.5
Kind: HOW

Use EXACTLY these public packages and versions:
  - pkg:npm/zod@4.6.5

Rules:
  - One focused purpose; the smallest project that proves the goal.
  - Include a contract test (test/contract.*) that runs OFFLINE and exits 0 exactly when the goal behavior works.
  - Pin every dependency with a lockfile so resolution is reproducible.
  - No secrets, credentials, or tokens. No real URLs (only example.com or localhost). No absolute paths.
  - No personal names, emails, company names, or project identifiers of any kind.
  - No binaries and no generated output (node_modules, dist, target, venv, .git, .env).
  - Keep it under 200 files and 256KB packed.
csx.json
{"case":{"caseId":"case:sha256:e724fd0b386f88dee1e997179161d6c17c8aff98864b448a5261ecd78ffa9f4c","contract":["parse a valid user object and assert the typed result","safeParse an invalid object and assert success is false","assert the issue list carries path and code"],"goal":"verify pkg:npm/zod@4.6.5","kind":"HOW","packages":["pkg:npm/zod@4.6.5"],"schemaVersion":1,"symbols":["z.object","z.string","z.number","safeParse","parse"]},"contractCommand":["node","test/contract.mjs"],"environment":{"arch":"x64","distro":"ubuntu","ecosystem":"npm","executionContext":"node","language":"javascript","libc":"glibc","libcVersion":"2.39","moduleSystem":"esm","os":"linux","osVersionBucket":"24","packageManager":"npm","runtime":"node","runtimeVersion":"22","schemaVersion":1},"license":"MIT-0","packages":["pkg:npm/zod@4.6.5"],"schemaVersion":1,"subject":"pkg:npm/zod@4.6.5","symbols":["z.object","z.string","z.number","safeParse","parse"],"verifierAdapter":"node-typescript@1"}
package-lock.json
{
  "name": "csx-sample-zod-4-6-5",
  "version": "1.0.0",
  "lockfileVersion": 3,
  "requires": true,
  "packages": {
    "": {
      "name": "csx-sample-zod-4-6-5",
      "version": "1.0.0",
      "license": "MIT-0",
      "dependencies": {
        "zod": "4.6.5"
      }
    },
    "node_modules/zod": {
      "version": "4.6.5",
      "resolved": "https://registry.npmjs.org/zod/-/zod-4.6.5.tgz",
      "integrity": "sha512-v5l/aFXZQeai4awLbOpSoHecE9UiMrnfx75tEXLjNonXVARxQ5mOeipTjROUchszUNCqnE+hqAMujRsRHsut2Q==",
      "license": "MIT"
    }
  }
}
package.json
{
  "name": "csx-sample-zod-4-6-5",
  "version": "1.0.0",
  "private": true,
  "type": "module",
  "license": "MIT-0",
  "dependencies": {
    "zod": "4.6.5"
  }
}
spec.json
{
  "schemaVersion": 1,
  "goal": "verify pkg:npm/zod@4.6.5",
  "kind": "HOW",
  "packages": [
    "pkg:npm/zod@4.6.5"
  ]
}
src/index.mjs
import { z } from 'zod';

export const UserSchema = z.object({
  username: z.string().min(1),
  email: z.string().email(),
  age: z.number().int().nonnegative(),
});

export function parseUser(data) {
  return UserSchema.parse(data);
}

export function safeParseUser(data) {
  return UserSchema.safeParse(data);
}
test/contract.mjs
import { strict as assert } from 'node:assert';
import { UserSchema, parseUser, safeParseUser } from '../src/index.mjs';

// parse a valid user object and assert the typed result
const validData = {
  username: 'antigravity',
  email: 'agent@example.com',
  age: 42,
};
const parsed = parseUser(validData);
assert.deepEqual(parsed, validData);

// safeParse an invalid object and assert success is false
const invalidData = {
  username: '',
  email: 'not-an-email',
  age: -5,
};
const result = safeParseUser(invalidData);
assert.equal(result.success, false);
assert.equal(result.data, undefined);
assert.ok(result.error);

// assert the issue list carries path and code
assert.ok(Array.isArray(result.error.issues));
assert.ok(result.error.issues.length >= 1);
for (const issue of result.error.issues) {
  assert.ok(Array.isArray(issue.path), 'issue must contain a path array');
  assert.equal(typeof issue.code, 'string', 'issue must contain a code string');
}

console.log('CONTRACT PASS: pkg:npm/zod@4.6.5');

Seeder de origen

anónimo