Zod

Frameworks & LibrariesMIT

TypeScript-first schema validation with static type inference.

Latest v4.6.2 · by Colin McDonnellWritten in TypeScriptWebsitecolinhacks/zodRSS

Release activity

Release activity — 18 releases across 10 days since Dec 31, 2025. Each cell is one day; darker means more releases that day. Nothing is recorded before Dec 31, 2025. Older weeks are hidden at this screen width.
JunJulAugSep
SundayNo releases on May 24, 2026No releases on May 31, 2026No releases on Jun 7, 2026No releases on Jun 14, 2026No releases on Jun 21, 2026No releases on Jun 28, 2026No releases on Jul 5, 2026No releases on Jul 12, 2026No releases on Jul 19, 2026No releases on Jul 26, 2026No releases on Aug 2, 2026No releases on Aug 9, 2026No releases on Aug 16, 2026No releases on Aug 23, 2026No releases on Aug 30, 2026No releases on Sep 6, 2026
MondayNo releases on May 25, 2026No releases on Jun 1, 2026No releases on Jun 8, 2026No releases on Jun 15, 2026No releases on Jun 22, 2026No releases on Jun 29, 2026No releases on Jul 6, 2026No releases on Jul 13, 2026No releases on Jul 20, 2026No releases on Jul 27, 2026No releases on Aug 3, 2026No releases on Aug 10, 2026No releases on Aug 17, 2026No releases on Aug 24, 2026No releases on Aug 31, 2026No releases on Sep 7, 2026
TuesdayNo releases on May 26, 2026No releases on Jun 2, 2026No releases on Jun 9, 2026No releases on Jun 16, 2026No releases on Jun 23, 2026No releases on Jun 30, 2026No releases on Jul 7, 2026No releases on Jul 14, 2026No releases on Jul 21, 2026No releases on Jul 28, 2026No releases on Aug 4, 2026No releases on Aug 11, 2026No releases on Aug 18, 2026No releases on Aug 25, 2026No releases on Sep 1, 2026No releases on Sep 8, 2026
WednesdayNo releases on May 27, 2026No releases on Jun 3, 2026No releases on Jun 10, 2026No releases on Jun 17, 2026No releases on Jun 24, 2026No releases on Jul 1, 2026No releases on Jul 8, 2026No releases on Jul 15, 2026No releases on Jul 22, 2026No releases on Jul 29, 2026No releases on Aug 5, 2026No releases on Aug 12, 2026No releases on Aug 19, 2026No releases on Aug 26, 2026No releases on Sep 2, 20262 releases on Sep 9, 2026
ThursdayNo releases on May 28, 2026No releases on Jun 4, 2026No releases on Jun 11, 2026No releases on Jun 18, 2026No releases on Jun 25, 2026No releases on Jul 2, 2026No releases on Jul 9, 2026No releases on Jul 16, 2026No releases on Jul 23, 2026No releases on Jul 30, 2026No releases on Aug 6, 2026No releases on Aug 13, 2026No releases on Aug 20, 2026No releases on Aug 27, 2026No releases on Sep 3, 20261 release on Sep 10, 2026
FridayNo releases on May 29, 2026No releases on Jun 5, 2026No releases on Jun 12, 2026No releases on Jun 19, 2026No releases on Jun 26, 2026No releases on Jul 3, 2026No releases on Jul 10, 2026No releases on Jul 17, 2026No releases on Jul 24, 2026No releases on Jul 31, 2026No releases on Aug 7, 2026No releases on Aug 14, 2026No releases on Aug 21, 20262 releases on Aug 28, 2026No releases on Sep 4, 2026No releases on Sep 11, 2026
SaturdayNo releases on May 30, 2026No releases on Jun 6, 2026No releases on Jun 13, 2026No releases on Jun 20, 2026No releases on Jun 27, 2026No releases on Jul 4, 2026No releases on Jul 11, 2026No releases on Jul 18, 2026No releases on Jul 25, 2026No releases on Aug 1, 2026No releases on Aug 8, 2026No releases on Aug 15, 2026No releases on Aug 22, 20263 releases on Aug 29, 2026No releases on Sep 5, 2026

18 releases since Dec 31, 2025, busiest day 4

Changelog

v4.6.2

Latest
Fixed 1
  • preserve undefined prefault outputs and object keys

From Zod

Commits:
  • a00c3f348abb8b56ccb6281ac4c946141e2728d5 docs: use Trigger.dev's brand-kit lockups for the platinum card
  • 0c483c58849fdb6445aea4f54b1bac6b57ab3d22 docs: Zod 4.6 announcement post (#6546)
  • 9446b5cc14c5bf137790f1f66abf602044871223 fix: preserve undefined prefault outputs and object keys (#6587)
  • e359f7378fe56d695134701cda1e9055a08892dc 4.6.2
View originalPermalink
How v4.6.2 went

v4.6.1

Added 1
  • Add Tajik (tg) locale
Fixed 2
  • Preserve unique tags with defaulted discriminators
  • Defer recursive object index inference

From Zod

A patch on top of 4.6.0.

View originalPermalink
How v4.6.1 went

v4.6.0

Added 7
  • Add `.validate()` method for standalone boolean validation without constructing a ZodError, up to 35x faster than `.safeParse().success` on compiled schemas
  • Add `z.properties()` API for validating specific properties of an object in-place, compatible with class instances
  • Add `.properties()` method to `ZodInstanceOf` for validating instance properties
  • Add `z.iban()` validator for electronic-format IBAN with mod-97 checksum
  • Add `z.withParser()` to install a parser generated elsewhere, for environments without `new Function`
  • Add support for `minProperties`, `maxProperties`, `uniqueItems`, `contains`, `minContains`, and `maxContains` keywords in `z.fromJSONSchema()`
  • Release `@zod/mini` as a standalone package versioned in lockstep with `zod`
Changed 1
  • Improve CommonJS performance by removing getters on exports, approximately 3x faster `z.validate()` under `require`
Fixed 1
  • Fix memory retention issue in recursive schemas that caused an out-of-memory regression in version 4.5

From Zod

Zod 4.6 is now available.

npm install zod@latest

At a glance:

  • .validate() — checks input validity without building a result (up to 35x faster than .safeParse().success on a compiled schema)
  • z.instanceof().properties() — validates properties of an instance
  • fromJSONSchema() — enforces six validation keywords it used to ignore
  • z.iban() — electronic-format IBAN plus mod-97 checksum
  • z.withParser() — installs a parser generated elsewhere, for environments without new Function
  • Faster CommonJS — drops the getter on every export (~3x faster z.validate() under require)
  • Memory retention in recursive schemas — releases the parsed input, fixing a 4.5 out-of-memory regression
  • @zod/mini — Zod Mini as a standalone package, versioned in lockstep with zod since 4.5
.validate()

Standalone boolean validation, in Zod, Zod Mini, and Zod Core. It answers "is this input valid?" without constructing a ZodError, which makes rejection cheap. The return type is a guard on the schema's input type.

z.validate(z.string(), "hi"); // true
z.validate(z.string(), 42);   // false

It is a method on Zod Classic schemas too. (#6547)

const Player = z.object({
  username: z.string(),
  xp: z.number(),
});

if (Player.validate(data)) {
  data.username; // narrowed
}

In conjunction with z.compile(), this can be up to 35x faster than .safeParse().success on invalid input.

Time per call on invalid input, schemas compiled with z.compile(), safeParse().success as a gray bar with .validate() as a blue bar inside it: a union of 3 objects 28 ns (34.9x faster), an array of 10 strings 23 ns (24.6x), a 3-element tuple 28 ns (16.1x), a 5-key object 21 ns (16.3x), a discriminated union of 3 21 ns (15.7x), z.number() 19 ns (13.8x), z.string() 19 ns (13.2x), z.boolean() 19 ns (13.7x); up to 34.9x faster

Time per call on invalid input, compiled with z.compile() — lower is better (benchmark)

Without compilation it is up to 5.9x faster. The saving is the result object: .safeParse() allocates one with an accessor pair on every call, and .validate() allocates nothing.

Time per call on invalid input, plain schemas, safeParse().success as a gray bar with .validate() as a blue bar inside it: a union of 3 objects 659 ns (1.5x faster), an array of 10 strings 211 ns (2.3x), a 3-element tuple 166 ns (2.5x), a discriminated union of 3 93 ns (3.3x), a 5-key object 75 ns (3.9x), z.number() 47 ns (5.3x), z.string() 42 ns (5.8x), z.boolean() 42 ns (5.9x); up to 5.9x faster

Time per call on invalid input, plain schemas — lower is better (benchmark)

Both charts measure the failure path. The key feature of .validate() is that it can short-circuit on the first issue it encounters, instead of aggregating a full ZodIssue[] array.

[!NOTE] Async refinements are covered by .validateAsync().

z.properties()

A new API for validating specific properties of an object. Unlike z.object() it validates in-place, so it plays nice with class instances. (#6536)

const responseLike = z.properties({ status: z.number().min(200).max(299) });

responseLike.parse(new Response("ok", { status: 200 }));  // ✅ a real Response
responseLike.parse({ status: 204 });                      // ✅ a plain object

A corresponding .properties() method has been added to ZodInstanceOf.

Zod

const okResponse = z.instanceof(Response).properties({
  ok: z.literal(true),
  status: z.number().min(200).max(299),
});

Zod Mini

const okResponse = z.instanceof(Response).check(...z.properties({
  ok: z.literal(true),
  status: z.number().check(z.minimum(200), z.maximum(299)),
}));

The input comes back untouched, so the prototype survives and the methods still work. That is the part z.object() cannot do: it would hand back a plain object and the Response would be gone.

const res = await fetch("/api/user");

okResponse.parse(res) === res; // ✅ true
fromJSONSchema()

Six additional JSON Schema keywords are now supported in z.fromJSONSchema(). (#6535)

const schema = z.fromJSONSchema({
  type: "object",
  minProperties: 2,      // also maxProperties
});

schema.parse({ a: 1 });        // ❌ too few properties
schema.parse({ a: 1, b: 2 });  // ✅

Both property bounds count the input's own keys. Array uniqueness is structural, so [{ a: 1 }, { a: 1 }] is a duplicate.

z.fromJSONSchema({ type: "array", uniqueItems: true }).parse([{ a: 1 }, { a: 1 }]); // ❌

z.fromJSONSchema({
  type: "array",
  contains: { type: "number" },   // also minContains and maxContains
  minContains: 2,
}).parse(["a", 2]);               // ❌ only one number
z.iban()

A new string format: an IBAN in electronic format, with a valid ISO 7064 MOD 97-10 checksum. (#6571)

z.iban().parse("DE89370400440532013000"); // ✅
z.iban().parse("DE89370400440532013001"); // ❌ bad checksum
z.withParser()

z.compile() builds its parser with new Function, which a strict Content Security Policy blocks. z.withParser() is that installer on its own: it takes a parser generated somewhere else, at build time or by a native compiler, and installs it under the same contract. (#6575)

const Player = z.object({ username: z.string(), xp: z.number() });

// isPlayer is a type guard your build step generated
const Fast = z.withParser(Player, (input) =>
  isPlayer(input) ? { username: input.username, xp: input.xp } : z.INVALID
);

The supplied parser owns the whole result, so it has to return what the schema would have returned. This one rebuilds the object rather than handing back its input, because z.object() strips unknown keys. Returning z.INVALID hands the input to the runtime, which stays the only source of ZodErrors.

Faster CommonJS

TypeScript compiles a re-export to a getter, and 252 of the 255 exports on Zod 4.5's CommonJS entrypoint were getters. V8 could not see a constant callee behind one, so it could not inline the call. The 4.6 build emits plain properties and freezes the exports object. On a compiled schema, z.validate() under require is about 3x faster than it was in Zod 4.5. (#6564)

const { z } = require("zod");
const CompiledPlayer = z.compile(Player);

z.validate(CompiledPlayer, data); // ~3x faster than Zod 4.5

Only calls through the namespace were affected. A method call like Player.safeParse(data) never reads the exports object, and the ESM build is unchanged.

Memory retention in recursive schemas

A recursive schema held the input and output of its last parse until the next parse replaced it, so one long-lived schema pinned every object it had touched. Zod 4.4 released that input and Zod 4.5 did not, which surfaced as an out-of-memory failure on a repository-wide lint run. The parse state is weak throughout now: one parse of a 29k-node tree retains 2.2 MB where it used to retain 10.1 MB, and recursive parses give up about 6% for it. (#6572)

const Category = z.object({
  name: z.string(),
  get children() {
    return z.array(Category);
  },
});
Bug fixes
⚠️ Error maps run on the first read of error

Because safeParse() now builds its error lazily, error maps — global, locale, and per-schema error — run when result.error is first read, not at parse time. Code that swaps z.config() between the parse and the read gets the newer configuration. (#6519)

const result = schema.safeParse(12);
z.config(z.locales.fr());
result.error.issues[0].message; // French in 4.6, English in 4.5

An error map with a side effect never runs if nothing reads the error. Throwing parses are unaffected — .parse() builds and throws its error immediately, never takes the lazy path, and its stack still points at your call site.

⚠️ z.emoji() rejects component-only strings

Unicode's Emoji_Component property covers the pieces that attach to an emoji, so z.emoji() accepted "123", "#", "*", and a lone zero-width joiner, variation selector, or skin tone modifier. The pattern now requires at least one pictograph, regional indicator, or keycap. (#6532)

z.emoji().parse("😀");   // ✅
z.emoji().parse("1️⃣");   // ✅ the keycap is the anchor
z.emoji().parse("123");  // ❌ was accepted in 4.5

Flags, subdivision flags, skin-tone-modified emoji, and ZWJ sequences are unchanged. Closes #6515.

⚠️ Numeric enum options no longer include the reverse mappings

A numeric TypeScript enum also carries its reverse mapping (0 to "UK") at runtime. The parser already ignored those keys, but .options was read straight off the enum object, so a three-member enum listed six values and three of them failed to parse. (#6542)

enum Country { UK, Germany, France }

z.enum(Country).options; // 4.5: ["UK", "Germany", "France", 0, 1, 2] — 4.6: [0, 1, 2]
⚠️ base64 patterns

The runtime patterns for z.base64() and z.base64url() are the character sets, with length and padding enforced in code, so a multi-megabyte string can no longer overflow the regex stack through a composed schema. The JSON Schema output still emits the exact block forms, so z.toJSONSchema() is unchanged. (#6534, #6527)

Composing z.base64() into a template literal now checks the alphabet but not the length, which is how z.creditCard() already behaves there. The exported z.regexes.base64url is now the length-aware form, so it overflows on a multi-megabyte input the same way z.regexes.base64 does.

⚠️ The email pattern dropped its lookaheads

z.email() opened with two lookaheads, and the second scanned the whole string before the match began. Both are gone, and the rule they enforced — no empty segment in the local part — is expressed structurally instead, so z.email() accepts and rejects exactly what it did before. Valid addresses validate roughly twice as fast. (#6573)

The pattern string is user-visible, and every copy of it changes: z.regexes.email, which has no capture groups now — neither of the two it used to expose held a usable value; issue.pattern on a failed z.email(); and the pattern that z.toJSONSchema() emits, which no longer carries a lookahead, so validators outside ECMAScript can compile it.

Composing an email into a template literal also stops applying its no-consecutive-dots rule to the rest of the string.

z.templateLiteral([z.email(), "|", z.string()]).parse("a@b.cc|a..b");
// 4.5: ❌ — the lookahead reached past the email segment — 4.6: ✅
⚠️ Chained checks no longer overwrite each other in JSON Schema

Each check used to write its own bounds into the schema as it attached, in chain order, so a format check applied after .min() and .max() replaced the tighter values with its own range. The converter folds the checks as a conjunction now. The order they are chained in no longer changes the output. (#6554, #6553)

z.toJSONSchema(z.number().min(0).max(23).int());
// 4.5: { minimum: -9007199254740991, maximum: 9007199254740991 }
// 4.6: { minimum: 0, maximum: 23 }

Runtime parsing enforced the bounds in every version. Only the emitted schema was wrong. The same fold fixes two more cases: a repeated multipleOf kept the first divisor and dropped the rest, so z.number().multipleOf(2).multipleOf(3) emitted a schema that accepts 4, and z.string().min(8).length(5) emitted minLength: 5, widening a bound the runtime still rejected. Closes #6550.

⚠️ Metadata members materialize on first read

Eight members on a Zod Classic schema — .format, .minLength, .maxLength, .minValue, .maxValue, .isInt, .minDate and .maxDate — are computed from the checks now instead of being written onto every instance at construction. Each one is a prototype getter that becomes an own property on first read. (#6554)

const s = z.string().min(3).max(9);

Object.keys(s); // 4.5: ["def", "type", "format", "minLength", "maxLength"] — 4.6: ["def", "type"]
s.minLength;    // 3 in both
Object.keys(s); // 4.6: ["def", "type", "minLength"]

A key is absent until something reads it, and Object.assign({}, schema) copies only the members that have been read. Deleting one restores the getter, and the next read recomputes it.

The values can move too, because the getters read the same fold the JSON Schema converter does. An order-dependent chain reports the tighter bound now instead of whichever check wrote last.

z.string().min(8).length(5).minLength; // 4.5: 5 — 4.6: 8
Commits

Zod 4.6 rolls up 72 commits.

View originalPermalink
How v4.6.0 went

v4.5.4

Fixed 1
  • Stop the cycle walk from firing a default factory

From Zod

Commits:
  • 84e416fbf4740527bbc8f319634f4e1b065bb42c fix(v4): stop the cycle walk from firing a default factory (#6500)
  • e8e206fa33ac5fe7ce20a2beb12d57b1cb3df653 4.5.4
View originalPermalink
How v4.5.4 went

v4.5.3

Fixed 1
  • emit record numeric keys as strings in toJSONSchema

From Zod

Commits:
  • e6b6ab347675cd2bd54b1bdbed16f98c59be82a9 docs(blog): widen the z.compile example to a 20-property schema
  • 87d6464418582bb96fc665a01f852ca6da324ad0 fix(docs): drop the OG description when the title wraps past two lines
  • 99fce394a026823e602b9c30d8d5d9f5f1932ce7 bench(v4): z.compile() against zod-compiler (#6499)
  • e3a695b6bf3f0d591ea682816e3cdaea04b0f967 docs(v4): record the email regex and container output-shape findings under Open
  • 7e24a24288183ce02554f1ded7775d0650a7b7e6 docs(blog): drop the reading time and put a GitHub link in the navbar
  • eab51ff3592b2d11d863f4ee4d5452f31a3de1b6 fix(v4): emit record numeric keys as strings in toJSONSchema (#6497)
View originalPermalink
How v4.5.3 went

v4.5.2

Fixed 3
  • Let a prototype method getter answer a bare call so vi.spyOn works
  • Drop ISR on the docs route so the home page hydrates
  • Render blog tabs with the stock fumadocs tab card

From Zod

Commits:
  • a354314ac04fdd5484aa62dd5c3a4b553211a0e4 fix(docs): keep blog posts out of the docs collection (#6484)
  • d378c42aff6869f0929058a7923cd775880f5c4c ci: drop canary publishing from the release workflow (#6487)
  • 212b941791e7faae078e17645eb612824fd8f79a fix(v4): let a prototype method getter answer a bare call so vi.spyOn works (#6488)
  • e7576f542a7bc7ef3cc5eeec237714fd0e6b6e98 docs(blog): let the page show through the navbar in dark mode (#6489)
  • fedb06fafe33a66ce0b5c236ad2557e0a5a170fe fix(docs): match the blog TOC hover bar to the 2px active indicator
  • 6c932fcb2eea6eb671710ea058ca9fdc382ada89 chore: bump devcontainer image to Node 24 (#6470)
  • 6635d9dd367a664109de83c021995821f48efa29 docs(blog): soften the "method memoization" attribution
  • 019ae299cc75daa132bf1acf59086a520abf6b85 fix(docs): drop ISR on the docs route so the home page hydrates
  • 652bb438aa4c626c1cd7948c6849c4691239fca7 chore(docs): drop the scroll log from the route-change scroller
  • 571c8e8a3d73b4305f4abfdd6977773cc12f2bf5 fix(docs): render blog tabs with the stock fumadocs tab card
  • 9a193aa24b4efa3b315b91d4c56c8bc385b8513f 4.5.2
View originalPermalink
How v4.5.2 went

v4.5.1

Commits:
  • 2e862dbf89da2835e5206a8fd3d3be61afe3cf7f ci: gate the GitHub release and JSR publish on the version being live on npm
  • 8e03380510db36fa6fda979fc78a375fdea8021c 4.5.1
View originalPermalink
How v4.5.1 went

v4.5.0

Added 6
  • Add z.compile() function to pre-compile schemas for dramatically faster parsing performance, with 3-9x speedup on objects, arrays, and unions
  • Add z.creditCard() validator for 12-19 digit credit card numbers with Luhn checksum verification
  • Add z.properties() as a multi-property counterpart to z.property()
  • Add z.deepPartial() and .exactPartial() schema modifiers
  • Add z.validate() function to verify input validity as a boolean without full parse, up to 16x faster on invalid data
  • Add new locales: Bengali (bn), Central Kurdish (ckb), Hindi (hi), Kannada (kn), Norwegian Nynorsk (nn), Brazilian Portuguese (pt-BR), Slovak (sk), and Turkmen (tk)
Changed 1
  • Reduce schema memory footprint by 9x

From Zod

Zod 4.5 is now available.

npm install zod@latest

At a glance:

z.compile()

You can now pre-compile any Zod schema using z.compile(schema). This dramatically speeds up parsing performance.

import * as z from "zod";

const Player = z.object({
  username: z.string(),
  bio: z.string(),
  xp: z.number(),
  // ...20 more properties...
});

const CompiledPlayer = z.compile(Player);

A compiled schema can be used exactly like an uncompiled one. There are no special rules around compiled schemas. They're just faster.

Player.parse({ ... });
CompiledPlayer.parse({ ... }); // ~9x faster

On objects, arrays, and unions, this speeds up parsing by a factor of ~3–9. More complex schemas stand to benefit more than simpler ones.

Time per parse by schema type, standard parser vs compiled — lower is better (benchmark)

Below are the Moltar benchmark results comparing Zod (compiled and uncompiled) against the Moltar ParseSafe bench.

Throughput on the moltar benchmark fixture (parseSafe: returns a new object with unknown keys stripped) — higher is better (benchmark)

And the equivalent results for the Moltar AssertLoose bench. Tested against the new z.validate(schema, input) function (detailed later in the post).

Throughput on the moltar benchmark fixture (assertLoose: returns a boolean, unknown keys allowed) — higher is better (benchmark)

Zod's entire test suite runs twice—once normally and again with auto-compilation enabled globally—to ensure perfect fidelity.

Under the hood, z.compile() walks the entire schema once and produces a hyperoptimized snippet of flat, loop-free JavaScript that can validate inputs far faster than a standard runtime validator. This snippet can be executed via new Function() (effectively a more powerful eval) to serve as a fast-path validator. Schemas use this to "fast check" validity, falling back to the regular runtime logic on validation failure to provide granular error information.

Take this simple Point schema:

const Point = z.object({
  x: z.number(),
  y: z.number()
});

Here is the generated snippet for it:

const isPoint = new Function("input", `
  if (typeof input !== "object" || input === null) return false;
  if (typeof input.x !== "number") return false;
  if (typeof input.y !== "number") return false;
  return true;
`);

isPoint({ x: 1, y: 2 }); // true
isPoint({ x: "1" });     // false

For the large majority of inputs, the generated function validates the data with the fastest logic JavaScript can express: straight-line typeof checks and property reads, with no interpreter in between. When it can't handle an input, Zod falls back to the standard parser.

This is the function Zod generates for the Player schema above:

if (typeof input !== "object" || input === null || Array.isArray(input)) return INVALID;
const v0 = input["username"];
if (typeof v0 !== "string") return INVALID;
const v1 = input["bio"];
if (typeof v1 !== "string") return INVALID;
const v2 = input["xp"];
if (typeof v2 !== "number" || !Number.isFinite(v2)) return INVALID;
const v3 = { "username": v0, "bio": v1, "xp": v2 };
return v3;

Armed with the power of new Function(), this happens in-process at runtime. There is no need to integrate with your build system.

The compiled schema is purely additive on top of the existing schema. It tacks on the pre-compiled fast path for checking valid inputs. When invalid data is detected, it returns the INVALID symbol to signal that parsing should fall back to the uncompiled parser. This structurally prevents subtle deviations in error reporting between compiled and uncompiled variants.

import "zod/compile"

To compile every schema in an application, import zod/compile once at the top of your entry point. Every schema constructed after that import is automatically compiled the first time it's used to parse data.

import "zod/compile"; // must come before modules that define schemas
import * as z from "zod";

const schema = z.object({ name: z.string() });
schema.parse({ name: "ok" }); // compiled on first parse

It also works as a Node.js CLI flag, which guarantees it runs before any module defines a schema:

node --import zod/compile app.js

Or set preload in bunfig.toml or nub.jsonc.

{
  "preload": ["zod/compile"]
}

All schemas benefit to varying degrees, though complex object/tuple/array schemas benefit more than simple scalar validators.

Read the docs, or the full technical writeup: Introducing z.compile()

z.creditCard()

A new string format: 12–19 digits, optionally separated by single spaces or hyphens, with a valid Luhn checksum. (#5931)

z.creditCard().parse("4111 1111 1111 1111"); // ✅
z.creditCard().parse("4111 1111 1111 1112"); // ❌ bad checksum
z.properties()

The multi-property counterpart to z.property(). (#5912)

const httpsUrl = z.instanceof(URL).check(
  ...z.properties({
    protocol: z.literal("https:" as string),
    hostname: z.string().regex(z.regexes.domain),
  })
);

httpsUrl.parse(new URL("https://example.com")); // ✅
httpsUrl.parse(new URL("http://localhost")); // ❌ protocol
z.deepPartial()

Back in functional form after being removed as a method in Zod 4. (#5928)

const Post = z.object({
  title: z.string(),
  author: z.object({ name: z.string(), email: z.string() }),
});

const PartialPost = z.deepPartial(Post);
type PartialPost = z.output<typeof PartialPost>;
// => { title?: string; author?: { name?: string; email?: string } }

PartialPost.parse({ author: {} }); // ✅

The result is still a ZodObject, so .shape and .extend() keep working.

.exactPartial()

Like .partial(), but wraps each field in z.exactOptional() instead of z.optional(): keys may be omitted, but an explicit undefined is rejected. This matches TypeScript's Partial<> under exactOptionalPropertyTypes. (#6065)

const Recipe = z.object({ title: z.string(), servings: z.number() });

const PartialRecipe = Recipe.exactPartial();
PartialRecipe.parse({});                    // ✅
PartialRecipe.parse({ title: undefined });  // ❌

In Zod Mini it's a top-level function: z.exactPartial(Recipe).

z.validate()

Standalone boolean validation, in Zod, Zod Mini, and Zod Core. It answers "is this input valid?" without constructing a ZodError, which makes rejection cheap: on invalid input it is up to 16x faster than .safeParse().success. The return type is a guard on the schema's input type, and z.validateAsync() covers schemas with async refinements. (#6471)

z.validate(z.string(), "hi"); // true
z.validate(z.string(), 42);   // false
z.input() / z.output()

Project a schema onto its input or output side. Useful for validating the two halves of a codec independently. (#5928)

const isoDate = z.codec(z.iso.datetime(), z.date(), {
  decode: (s) => new Date(s),
  encode: (d) => d.toISOString(),
});

const Event = z.object({ name: z.string(), at: isoDate });

z.input(Event).parse({ name: "launch", at: "2024-01-01T00:00:00Z" }); // ✅
z.output(Event).parse({ name: "launch", at: new Date() });            // ✅

This is a no-op on schemas not containing codecs/pipes.

z.toZod<T>()

A utility to define a Zod schema that agrees exactly with a static type, often one that is handwritten or externally defined. (#5913)

type Player = { username: string; xp: number };

const Player = z.toZod<Player>()(
  z.object({
    username: z.string(),
    xp: z.number(),
  })
);

Player.shape.username; // ZodString — the schema is returned unchanged
z.getDiscriminatedOption()

Extract a discriminated union member by discriminator value. (#5947)

const Fruit = z.object({ type: z.literal("fruit"), seeds: z.boolean() });
const Veg = z.object({ type: z.literal("vegetable"), leafy: z.boolean() });
const Produce = z.discriminatedUnion("type", [Fruit, Veg]);

z.getDiscriminatedOption(Produce, "fruit"); // typeof Fruit
z.getDiscriminatedOption(Produce, "meat");  // ❌ TypeScript error
Cyclical inputs

Zod recursive schemas now support cyclical data. For bundle size reasons, Zod Mini requires you to register a memoizer explicitly. (#6387, #6482)

Zod

const Category = z.object({
  name: z.string(),
  get subcategories() {
    return z.array(Category);
  },
});

const input: any = { name: "root", subcategories: [] };
input.subcategories.push(input);

const result = Category.parse(input);
result.subcategories[0] === result; // true

Zod Mini

// register a memoizer before defining any schemas
z.config({ memoizer: z.memoizer() });

const result = Category.parse(input);
result.subcategories[0] === result; // true
9x reduction in schema memory footprint

In Zod 4.4 a bare z.string() retained 7.5kb of heap. In Zod 4.5 it retains 784 bytes.

Retained heap per schema instance, Zod 4.4.3 vs 4.5 (benchmark)

In Zod 4.4 and earlier, all schema methods were automatically bound to the instance itself. This allowed users to pluck methods from schemas without causing issues due to this-binding.

const { parse } = z.string();

parse("some data");

A consequence of this is that each bound method allocates space on the heap; method implementations are not shared across all instances via prototype, as you'd expect. Zod 4.5 implements a method memoization pattern that avoids allocating bound methods until they are actually accessed.

Read the deep dive: Reducing Zod's memory footprint by an order of magnitude

Faster failures

Zod .parse()/.safeParse() instantiates a JavaScript Error, which captures a stack trace. In the case of validation failures, this is often much slower than the parsing logic itself. When using .safeParse(), Zod no longer captures this stack trace, speeding up failure-path parses by a factor of ~7.5x. (#6316, #6450)

const result = Player.safeParse({ username: 42, bio: "hello", xp: 12 });
result.success; // false — ~7.5x faster than Zod 4.4

Player schema (benchmark)

Symbol keys in z.object()

A shape can now declare a symbol key. TypeScript tracks it: a const symbol infers as unique symbol, so z.infer makes the key required and checks its value type. Undeclared symbol keys are still ignored. (#6448)

const TAG = Symbol("tag");
const schema = z.object({ name: z.string(), [TAG]: z.number() });

schema.parse({ name: "alice", [TAG]: 42 }); // ✅ { name: "alice", [TAG]: 42 }
schema.safeParse({ name: "alice" });        // ❌ the symbol key is required
Bug fixes

All of these fix soundness issues, so a schema that relied on the old behavior may now reject input it used to accept.

⚠️ z.iso.datetime() requires seconds

RFC 3339 mandates seconds. z.iso.datetime() and z.iso.datetime({ offset: true }) no longer accept minute-precision input like 2020-01-01T06:15Z. local: true still admits 2020-01-01T06:15, since an unqualified datetime is outside RFC 3339 either way. (#6457)

z.iso.datetime().parse("2020-01-01T06:15:00Z"); // ✅
z.iso.datetime().parse("2020-01-01T06:15Z");    // ❌ was accepted in 4.4

To accept both forms, union the two precisions:

z.union([z.iso.datetime(), z.iso.datetime({ precision: -1 })]);
⚠️ String length counts code points

.min(), .max(), and .length() counted UTF-16 code units, so z.string().max(5) rejected five emoji. They now count Unicode code points, which is what every non-JS consumer of a length bound does (Postgres, MySQL, Go, Python, and the maxLength that z.toJSONSchema() emits). .max() only loosens; .min() and .length() tighten for astral input. Graphemes are unchanged — a ZWJ sequence is still several code points. (#6441)

z.string().max(5).parse("😀😀😀😀😀"); // was too_big, now passes
z.string().min(5).parse("😀😀😀");     // was fine, now too_small

Closes #3355.

⚠️ Record keys and intersections match TypeScript

A record's key schema now governs only the keys that match it, the way TypeScript treats an index signature. Intersecting an object with a pattern-keyed record no longer rejects the object's own keys. (#6412)

z.object({ name: z.string() })
  .and(z.record(z.string().regex(/^S_/), z.string()))
  .parse({ name: "a", S_a: "s" });
// 4.4: throws invalid_key on "name"
// 4.5: { name: "a", S_a: "s" }

Separately, an unrecognized_keys issue no longer aborts the schema it came from, so a strict object with an extra key and a bad value now reports both issues instead of just the first. Closes #2200, #2573, #4017, #5663.

⚠️ __proto__ is always stripped

Object and record parsers now drop a __proto__ key whether it comes from the input, is declared by the schema, or is produced by a record key transform. A key that a record's key schema normalizes to __proto__ is dropped too. .strict() reports an own __proto__ input key as unrecognized_keys instead of silently swallowing it. Error formatters and both JSON Schema converters use own-property writes so a toString or constructor path segment can't walk onto Object.prototype (#6213, #6367, #6346). (#6386, #6354, #6355, #6221)

⚠️ Stricter string formats
  • z.ipv6() validated by handing the string to new URL(), which let ::@1\ and ::1\n through. It now checks the address alphabet directly (#6442).
  • z.ulid() restricts the first character to 07; anything higher overflows the 48-bit timestamp. A fixture that doesn't start with a real timestamp, such as one with a leading letter, is now rejected (#6095).
  • z.httpUrl() enforces the RFC 1035 length limits on the host, matching z.hostname() (#6035).
  • z.emoji() no longer backtracks exponentially on a failed match (#6347).
  • z.string().includes(sub, { position: N }) emits a JSON Schema pattern that allows at least N leading characters, matching String.prototype.includes (#6024).
Commits

Zod 4.5 rolls up 155 commits. Thanks to everyone who contributed: @dokson, @deepshekhardas, @zirkelc, @francisjohnjohnston-web, @MerlijnW70, @codinsonn, @oimo23, @JSap0914, @zelinewang, @abhishek-chaudhary2003, @spokodev, @Mohammad-Faiz-Cloud-Engineer, @hamed-bavar, @MGPOCKY, @ChiChuRita, @dinwwwh, @thristhart, @tsmartin9, @vedanshshetti, @belicam, @frastefanini, @andersk, @musaddiq-rafi, @tachmyratsaparmyradov, @arvindfroi, @KUMachine, @spidersouris, @catdalfonso, @mneetika, @gwagjiug, @MahinAnowar, @MaksZhukov, @emmayusufu, @agcty, @devareddy05, @Vish05, @yamcodes, @mattiasahlsen, @samchungy, @ozzyfromspace, @udohjeremiah, @patrickwehbe, @gajus, @Harm-Nullix, @thwbh, @IdanGonen, @irfanfandi, @JuerGenie, @marcalexiei, @itsahmedbilal, @DucMinhNe, @meliharik.

View originalPermalink
How v4.5.0 went

v4.4.3

Fixed 2
  • Restore catch handling for absent object keys
  • Generalize optin/fallback to transform and restore preprocess on absent keys

From Zod

Commits:
  • 4c2fa95ce3f3390fbc522324e406b4e9e89b88f9 docs: use Zernio primary wordmark for gold sponsor logo
  • 2aeec83eb135e3a83756e973ef44845fc5a455d2 docs: prune lapsed gold sponsors and rebalance logo sizing
  • 7391be88ac1ee5cd02057f5ccc012a1f5df4efd0 docs: prune lapsed silver/bronze sponsors and add active ones
  • 2c703322a21b4e2b12f33f49ea8430c451a68b4f docs: normalize bronze sponsor logos to github avatar pattern
  • 9195250cab0e7950efe39c3926d6c203b4b0a170 docs: remove Mintlify from bronze sponsors (churned)
  • b8dffe9e62f17e6571e6249d05cc5102b54d94e4 docs: remove Numeric and Speakeasy (2+ missed monthly cycles)
  • 1cab69383fcdeae2a366d5e2a2fc4d8fc765d168 fix(v4): restore catch handling for absent object keys (#5937) (#5939)
  • c2be4f819064eed62c7c350a2d399b5faecd15f8 fix(v4): generalize optin/fallback to transform; restore preprocess on absent keys (#5941)
  • f3c9ec03ba7a28ae72d25cc295f38674bee0f559 4.4.3
  • 1fb56a5c18c27102dbc92260a4007c7732a0ccca docs: document release procedure in AGENTS.md
View originalPermalink
How v4.4.3 went

v4.4.2

Added 2
  • Document codec inversion
  • Document preprocess input type narrowing
Changed 2
  • Tighten discriminated union option typing
  • Make z.preprocess defer optionality to inner schema
Fixed 1
  • Heading anchor links now include the hash so it doesn't scroll all the way up, follows navbar logic

From Zod

Commits:
  • 0c62df0ea19fd05abdf90473e9eef7eea530fab2 Clean up docs navigation and stale labels (#5901)
  • 20cc794895cc8604fe0c87d83a5d1c3f89fad0ac chore: add security policy and refresh tooling deps
  • 6fbe07b0177efdd1bf1c0b05160e70d7a0702337 fix(docs): heading anchor links now include the hash so it doesnt scoll all the way up, follows navbar logic (#5791)
  • 4bbed1b1c73eca4ce9e59b1189ed236aa6c8b5bd Tighten discriminated union option typing
  • bbac3e567e7fccfaaf7cdc97f1ce30c295e2c908 Update PR guidance for agents
  • cf0dc942a32805c292fff59ade20a7ace980735a Merge remote-tracking branch 'origin/main' into fix-discriminated-union-key-constraint
  • 292c894a5fd2aa42e527900b83d8d7a3009a709c docs: add Zernio gold sponsor
  • 1fc9f311c28dcf80d0bb5a36b177086cbc3d8eca docs: document codec inversion
  • 1373c85da9aeff704a9762d27bc58699618aefb7 docs: remove AI disclosure guidance
  • e20d02b473c08e3a4e557bc610b1b5fac079b649 chore: ignore triage notes
  • e58ea4d91b1dfe8194b73508203213cbc7e9c936 docs: test Zod Mini tab code heights
  • 905761a5d127e8d5dd2ebb3bc88c75cb0b8149ff docs: document preprocess input type narrowing
  • bf64bac850d4dee2b7dde7e64909d5d796d32043 chore: tighten test guidance in AGENTS.md
  • 8ec4e73f4c4693b6361ad591be40fb41eb8a9f95 chore: update play.ts scratch
  • 02c2baf7d0d615872fa4528a8020603b71211702 Make z.preprocess defer optionality to inner schema (#5929)
  • 88015df8e25c44fb5385eb3ef28935119cd5edea fix(docs): drop deprecated baseUrl from tsconfig
  • c59d4474e3b4cad1b323462186cf607178ce8267 4.4.2
View originalPermalink
How v4.4.2 went

v4.4.1

Fixed 1
  • Reject tuple holes before required defaults

From Zod

Commits:
  • 481f7be4238c83ed58183f921b2646f340a91c6a ci: gate release publishing on full test workflow
  • 95ccab423aec720b2523c3a64cdc7e3204537cc7 test(v3): restore optional undefined expectations
  • cede2c63739a5823d6aa5093d291e9a111da943d fix(v4): reject tuple holes before required defaults (#5900)
  • edd0bf0f5ada4a8dc581c259407d7bbad0a71ea7 release: 4.4.1
  • 180d83d1dbe6a59260710cc8637a3dea2281ee56 docs: remove Jazz featured sponsor
View originalPermalink
How v4.4.1 went

v4.4.0

Changed 3
  • Object properties with z.undefined() schema are now treated as required, with the key needing to be present but value allowed to be undefined
  • CUID validation has been tightened and CUID v1 is now deprecated
  • HTTP URL validation now rejects malformed HTTP(S) URLs with a missing slash after the protocol
Fixed 10
  • Tuple parsing now correctly materializes default values in the output, optional tails, and handles explicit undefined values
  • The merge() method now throws when the receiver has refinements instead of silently producing ambiguous refinement behavior
  • JSON Schema $defs entries no longer include redundant id fields to ensure correct reference resolution
  • Base64 validation now rejects whitespace instead of allowing atob()-style whitespace stripping
  • Nested union paths are now preserved correctly in z.treeifyError() and z.formatError() output
  • Invalid discriminated union errors now include discriminator options and improved messages

From Zod

4.4.0

This is a minor release with a wide set of correctness and soundness fixes. Some fixes intentionally make Zod stricter, so code that depended on previously accepted invalid or ambiguous inputs may need small updates.

Potentially breaking bug fixes
Tuple defaults now materialize output values correctly

Fixed in #5661. Tuple parsing now more accurately reflects defaults, optional tails, explicit undefined, and under-filled inputs. The headline behavior is that defaults in tuple positions now properly appear in parsed output.

const schema = z.tuple([
  z.string(),
  z.string().default("fallback"),
]);

schema.parse(["a"]);
// ["a", "fallback"]

Trailing optional elements that are absent still stay absent; they are not filled with undefined.

const schema = z.tuple([
  z.string(),
  z.string().optional(),
]);

schema.parse(["a"]);
// ["a"]

But explicit undefined values supplied by the caller are preserved.

schema.parse(["a", undefined]);
// ["a", undefined]

When optional elements appear before later defaults, the parsed tuple is now dense so array operations behave predictably.

const schema = z.tuple([
  z.string(),
  z.string().optional(),
  z.string().default("fallback"),
]);

schema.parse(["a"]);
// ["a", undefined, "fallback"]

Tuple length errors are also more consistent now. Since z.function() arguments are tuple-shaped, function input errors may look different.

Required object properties with z.undefined()

Fixed in #5661, with follow-up coverage in 57d80a82. A property whose schema is z.undefined() is now treated as required. The key must be present, but its value may be undefined.

const schema = z.object({
  value: z.undefined(),
});

schema.safeParse({}).success;
// false

schema.safeParse({ value: undefined }).success;
// true

Use .optional() when the key itself may be absent.

const schema = z.object({
  value: z.undefined().optional(),
});

schema.safeParse({}).success;
// true

This also affects related .catch(), .partial(), .default(), and .prefault() combinations that previously relied on missing z.undefined() keys being treated as optional.

Safer .merge() behavior with refinements

Fixed in #5856. The .merge() method now throws when the receiver has refinements, rather than silently producing ambiguous refinement behavior. Refinements from the second schema are preserved.

const a = z.object({ a: z.string() }).refine((val) => val.a.length > 0);
const b = z.object({ b: z.string() });

a.merge(b);
// throws

Prefer .extend() or .safeExtend() for object composition. The .merge() method is still supported for compatibility, but it is discouraged for new code because its semantics around overlapping keys and refinements are easier to misread.

JSON Schema $defs entries no longer include redundant id

Fixed in #5759. JSON Schema conversion through z.toJSONSchema() now strips redundant id fields from $defs entries. This is required for correctness in older JSON Schema dialects from before $id was introduced: in those dialects, id changes the resolution scope, so leaving it inside an extracted definition can make references resolve incorrectly. The removed value was redundant because the schema had already been extracted into $defs, so the definition key itself is the identifier. This may affect consumers that were reading those internal id fields directly.

Other JSON Schema fixes in this release:

  • Draft-04/OpenAPI 3.0 min/max intersections: #5700
  • Recursive lazy schemas with .describe(): #5797
  • Falsy prefault values emitted as defaults: #5893
  • CUID pattern output tightened: #5880
String validators are stricter

Base64 validation now rejects whitespace instead of allowing atob()-style whitespace stripping. Fixed in #5888.

z.base64().safeParse("Zm9v").success;
// true

z.base64().safeParse("Zm 9v").success;
// false

Other string validator changes:

  • CUID validation through z.cuid() has been tightened, and CUID v1 is now deprecated. Fixed in #5880.
  • HTTP URL validation through z.httpUrl() now rejects malformed HTTP(S) URLs with a missing slash after the protocol. The underlying URL constructor normalizes inputs like https:/example.com, but Zod now rejects them instead of accepting the repaired URL. Fixed in #5672, related to #5284.
z.httpUrl().safeParse("https://example.com").success;
// true

z.httpUrl().safeParse("https:/example.com").success;
// false

z.httpUrl().safeParse("http:/www.apple.com").success;
// false
Union paths are fixed in formatted errors

Two union-related error fixes landed:

  • Nested union paths are now preserved correctly in the output of z.treeifyError() and z.formatError(). Fixed in #5708 and 60ff3987.
  • Invalid discriminated union errors now include discriminator options and improved messages. Fixed in #5723. This may affect users snapshotting ZodError output.
Other fixes
Record key transforms now run

Fixed in #5891. Record schemas now run transforms on record keys.

const schema = z.record(
  z.string().transform((key) => key.toUpperCase()),
  z.number()
);

schema.parse({ foo: 1 });
// { FOO: 1 }

Related record fixes:

  • Key refinement failures now surface as structured invalid_key issues. Fixed in #5719.
  • Non-enumerable properties are skipped more consistently. Fixed in #5719.
  • The v3-style single-argument z.record(valueType) form works again. Fixed in 0e960108.
Metadata and input handling in fromJSONSchema()

Schema generation from JSON Schema now applies metadata more consistently across enum, const, not, anyOf, and multi-type schemas. Fixed in #5758. It also rejects or normalizes more non-JSON-like inputs, including cyclic objects and BigInt. Fixed in 87cf0f93.

Codecs

Codec changes:

  • Encoding through z.discriminatedUnion().encode() now works when the discriminator uses a codec. Fixed in #5769.
  • Codec inversion was added in #5770.
const stringToNumber = z.codec(
  z.string(),
  z.number(),
  {
    decode: Number,
    encode: String,
  }
);

const numberToString = z.invertCodec(stringToNumber);
Transform context

Transform callbacks now support ctx.addIssue(). Fixed in #5699.

Conditional .superRefine() with when

The when option was added for .superRefine(). Added in #5741, with related abort behavior fixed in #5681.

Defaults for Map and Set

Defaults for Map and Set are now cloned instead of shared across parses. Fixed in #5855.

const schema = z.map(z.string(), z.number()).default(new Map());

const a = schema.parse(undefined);
const b = schema.parse(undefined);

a === b;
// false
Empty unions

Empty z.union([]), z.xor([]), and discriminated unions no longer crash at construction time. They construct and fail at parse time. Fixed in #5869.

Floating-point multiples

Number multipleOf() / step() validation is more accurate for decimal and exponent edge cases. Fixed in #5687 and #5793.

Global config and jitless

Configuration fixes:

  • Global configuration is now shared through globalThis, improving behavior across mixed CJS/ESM module instances. Fixed in #5889.
  • Jitless mode now avoids eval probing when set before first access. Fixed in #5864.
Prototype pollution hardening

Object catchall paths now skip __proto__ keys. Fixed in #5898.

Performance improvements
Reduced memory usage from lazy-bound methods

Fixed in #5897. Classic builder methods are now lazy-bound through a shared internal prototype instead of eagerly attached per schema instance. This significantly reduces per-schema method allocation overhead, especially in codebases that construct many schemas. Detached methods continue to work:

const schema = z.string();
const optional = schema.optional;

optional.call(schema);
// still works
Improved tree-shaking

Implemented in 195e8696 and #5689. Top-level factory calls are annotated as pure, and generated stub package manifests now include sideEffects: false. This gives bundlers more room to remove unused Zod code.

This is intended as the conclusive fix for a long-standing class of tree-shaking and bundle-size issues, especially in Next.js and Turbopack projects. The most visible symptom was that unused validators and locales could survive bundling even when importing from zod/mini or from a narrow subpath.

Related reports include:

{
  "sideEffects": false
}
Locales

Added or updated locale support:

  • Croatian: #5610
  • Greek: #5840
  • Romanian: #5657
  • Uzbek map support: #5599
  • Georgian translation fix: #5655
  • French issue origin translations: #5845
  • Italian validation message updates: #5852

Locale message text changed in some cases, which may affect snapshots.

Closed issues

The following issues were closed by PRs included in this release:

  • Closed #5466 via #5632: preserve context immutability in parse functions.
  • Closed #5617 via #5655: correct Georgian translation for string.
  • Closed #5619 via #5657: add Romanian locale.
  • Closed #5229 via #5661: align object and tuple optionality handling.
  • Closed #5680 via #5681: respect abort: true in .refine() checks with when.
  • Closed #5678 via #5699: add missing addIssue to transform context.
  • Closed #5717 via #5718: avoid delete in finalizeIssue.
  • Closed #5714 via #5719: skip non-enumerable properties in record validation.
  • Closed #5670 via #5723: add discriminator options to invalid discriminator errors.
  • Closed #5743 via #5744: increase timeout for the datetime ReDoS checker test.
  • Closed #5732 via #5758: apply description and default metadata in fromJSONSchema().
  • Closed #5731 via #5759: strip redundant id from $defs entries in JSON Schema output.
  • Closed #5605 via #5763: update z.custom() docs for v4 compatibility.
  • Closed #5593 via #5769: support discriminatedUnion().encode() with codec discriminators.
  • Closed #5625 via #5770: add codec inversion.
  • Closed #5778 via #5779: add custom docs 404 page.
  • Closed #5792 via #5793: correct floating-point multipleOf() validation.
  • Closed #5777 via #5797: resolve recursive lazy JSON Schema stack overflow.
  • Closed #5805 via #5812: fix self-referencing schema docs.
  • Closed #5826 via #5855: clone Map and Set defaults.
  • Closed #5842 via #5856: align .merge() refinement semantics with .extend().
  • Closed #4461 and #5414 via #5864: honor jitless config in the eval probe.
  • Closed #5868 via #5869: handle empty z.union([]) and z.xor([]).
  • Closed #5296 via #5891: apply key schema transforms in z.record().
  • Closed #5824 via #5893: emit falsy prefault values in JSON Schema output.
Commits
  • Commit 44f6a03e fix(locales): correct Georgian translation for 'string' to 'ველი' (#5655) by @tushargr0ver
  • Commit 7b43bc64 docs(ecosystem): add Hono Takibi (#5651) by @nakita628
  • Commit 119376b9 feat: add map support to Uzbek locale (#5599) by @uchkunr
  • Commit 8fbf701e test: add edge case tests for boundary values (#5601) by @uchkunr
  • Commit f1f93c2b Fix order of brand method examples in api.mdx (#5604) by @onurtemiz
  • Commit 10105ee4 docs: Fix typos in json-schema documentation (#5608) by @SaKaNa-Y
  • Commit 2d367139 feat: add hr translation (#5610) by @vuki656
  • Commit 54902cb7 chore: update pullfrog.yml workflow
  • Commit 89ba70f2 chore: add sideEffects false to stub package.json for tree-shaking (#5689) by @jesse-holden
  • Commit eaa3c2c3 Update positive checks to use alias .gt(0) in the docs (#5671) by @Fredkiss3
  • Commit 65f1f404 fix typo (#5676) by @Nikita0x
  • Commit 5b574501 fix: respect abort: true in .refine() for checks with when function (#5681)
  • Commit 539de140 docs: fix README links for async refinements/transforms (#5682) by @pavan-sh
  • Commit 46cd10e7 docs: fix README anchor links for async APIs (#5683) by @pavan-sh
  • Commit 55747b3c Remove deprecated downlevelIteration option (#5684) by @RyanCavanaugh
  • Commit 3a818de1 fix(v4): handle multi-digit exponents in floatSafeRemainder (#5687) by @shakecodeslikecray
  • Commit 3cd45ebc fix(v4): add strict validation to httpUrl() (#5672) by @LuckySilver0021
  • Commit 7d98c909 add Sanity as silver sponsor and Mintlify as bronze sponsor
  • Commit c7805073 move Sanity and Mintlify to top of sponsor lists
  • Commit bee2dc8d docs: move z.iso.time() from format to pattern section (#5696)
  • Commit 2f8414bc fix: add missing addIssue to transform context (#5699) by @F-A-N-D-E
  • Commit d3c0ec87 docs: add note about removed .errors alias in v4 changelog (#5705) by @togami2864
  • Commit fa338a3b fix(v4): JSON schema min/max intersection for draft-04 and openapi-3.0 (#5700) by @ebroder
  • Commit 3473b288 chore: bump zshy to ^0.7.1
  • Commit cc8f9b7c docs: improve README wording and fix typos (#5736) by @vedanshshetti
  • Commit f5336717 feat: add json-up to ecosystem (#5740) by @mrspence
  • Commit 60ff3987 fix(v4): preserve parent path when treeifying nested union/key/element issues
  • Commit 08b14b51 perf: avoid delete in finalizeIssue to keep V8 fast mode (#5718)
  • Commit 9cf868d2 fix(v4): treeify error nested union bug (#5708) by @dstashevskyi
  • Commit 28f39a6d Add JSONType export (#5709) by @RobinVdBroeck
  • Commit 65fab33e feat: allow when parameter in .superRefine() (#5741) by @vilvai
  • Commit 7f87df1e refactor(v4): remove unnecessary type assertions (#5720) by @chisaki66
  • Commit 518f15dd Preprocess is not deprecated (#5721) by @mxdvl
  • Commit 2e5b23dc fix: add options to invalid discriminator errors (#5723) by @Danielchinasa
  • Commit 7f789def fix: skip non-enumerable properties in record validation (#5719) by @veeceey
  • Commit ee15fa19 docs: add AGENTS notes for JSDoc, PR comments, and PR worktree workflow
  • Commit f52b4d28 Revert "docs: improve README wording and fix typos (#5736)"
  • Commit ddb41391 test: increase timeout for redos checker in datetime.test.ts (#5744) by @rishadaufa
  • Commit bc07e459 docs: fix doc (#5745) by @xgaia
  • Commit e06af5de Update Hey API description (#5748) by @mrlubos
  • Commit 28c156e2 fix: apply description and default metadata to enum, const, and not schemas in fromJSONSchema (#5758) by @mibragimov
  • Commit f457edf1 Fix grammar in CONTRIBUTING.md (#5765) by @siekmang
  • Commit 411f6c64 fix(v4): resolve stack overflow in toJSONSchema for recursive lazy with describe (#5797) by @Hassad674
  • Commit 45dd421e docs: add tone guidelines for issue and PR comments to AGENTS.md
  • Commit ddd20a30 test: align optional property assertions with actual inferred types
  • Commit a1cf8a93 docs: update z.custom example for v4 compatibility (#5763) by @andrewdamelio
  • Commit b6a3b336 fix: strip redundant id from $defs entries in toJSONSchema (#5759) by @mibragimov
  • Commit c7a8ccc0 fix: discriminatedUnion encode() with codec discriminator (#5769) by @mahmoodhamdi
  • Commit 87cf0f93 fix(fromJSONSchema): normalize input via JSON round-trip
  • Commit 7163e6f2 feat: add .invert() method to ZodCodec (#5770) by @mahmoodhamdi
  • Commit b59b9b13 fix: replace .default with .prefault (#5776) by @alanskovrlj
  • Commit 93bba686 docs: add Zod AOT to ecosystem page (#5806) by @wakita181009
  • Commit 2564caa4 fix(docs): add custom 404 page with proper theme support (#5779) by @WolfieLeader
  • Commit 5b7ed214 fix: correct multipleOf float validation using tolerance-based comparison (#5793) by @cyphercodes
  • Commit cc9139d2 docs: fix self-referencing schema in refine when() example (#5812) by @claygeo
  • Commit 0e960108 fix(v4): support v3-style single-arg z.record(valueType)
  • Commit 41b25af9 docs(agents): refine PR comment tone guidance
  • Commit 4c03c20d Update Italian locale error messages for validation (#5852) by @pastorello
  • Commit 37ac1ba0 fix(fr): translate issue.origin in too_big/too_small errors (#5845) by @Ouaziz-chedli
  • Commit 345be203 docs: add validex to ecosystem (#5848) by @chiptoma
  • Commit 3c1f32bd feat(locales/en): handle instanceof and add comprehensive locale tests
  • Commit 888e52bb feat(locales): add Greek (el) locale (#5840) by @saileshbro
  • Commit bf6d99ed Revert "feat(locales/en): handle instanceof and add comprehensive locale tests"
  • Commit e8196a8d fix(resolution): align expected fr message with translated locale
  • Commit b6b12882 correct logic for validating length (#5843) by @nameearly
  • Commit 34f60159 fix(v4): clone Map and Set in shallowClone to prevent shared state across .default() parses (#5855) by @artur-seppa
  • Commit 91a7d0d1 fix(v4): reject whitespace in z.base64() to close atob bypass
  • Commit 23edf484 Revert "fix(v4): reject whitespace in z.base64() to close atob bypass"
  • Commit 15cafa13 fix(v4): throw on .merge() receiver with refinements; preserve refinements from second schema (#5856) by @solssak
  • Commit 584b1089 fix(v4): reject whitespace in z.base64() to close atob bypass (#5888) by @colinhacks
  • Commit b9b62c65 fix(core): honour jitless config in allowsEval probe (#5864) by @dokson
  • Commit fffe99bd fix(v4): construct empty unions instead of crashing (#5869) by @tjenkinson
  • Commit 285bde7f feat(core): share globalConfig across module systems via globalThis (#5889) by @colinhacks
  • Commit 195e8696 perf(v4): mark top-level factory calls as /*@__PURE__*/ for tree-shaking
  • Commit 61d7bedb fix(v4): apply key schema transforms in z.record() (#5891) by @colinhacks
  • Commit 45acd2ad ci(release): switch to npm trusted publishing via OIDC (#5890) by @colinhacks
  • Commit 476ae243 Tighten cuid() regex and deprecate CUID v1 (#5880) by @colinhacks
  • Commit 6217527e docs(agents): document push-to-main footgun and version-bump rule (#5883) by @colinhacks
  • Commit 757f0b0f fix(v4): apply util.Writeable in strictObject/looseObject for shape display parity (#5882) by @colinhacks
  • Commit fa4a3740 fix(v4): apply util.Writeable in mini object constructors and extend/safeExtend/partial/required (#5895) by @colinhacks
  • Commit ebc8287c fix(v4): emit falsy prefault values in toJSONSchema (#5893) by @mixelburg
  • Commit 8fcb71a5 perf(v4): lazy-bind builder methods to shared internal prototype (#5897) by @colinhacks
  • Commit 76e8f706 fix(v4): skip __proto__ key in object catchall (#5898) by @colinhacks
  • Commit f0b0608e ecosystem: eslint-plugin-zod-x is eslint-plugin-zod now (#5637) by @marcalexiei
  • Commit 0b5c3bc2 docs: fix refinements examples in api.mdx (#5649) by @playoffthecuff
  • Commit 327e152e docs(agents): refine PR comment tone guidance further
  • Commit 57d80a82 test(v4): pin object/tuple key optionality through optout propagation
  • Commit f19860f1 fix: preserve context immutability in parse functions (#5632) by @bgk614
  • Commit ec979ad7 feat: add Romanian (ro) locale (#5657) by @tushargr0ver
  • Commit b6066b3e fix(v4): align object and tuple optionality handling (#5661) by @Cyjin-jani
  • Commit ad0b8271 ci: update release workflow for trusted publishing
  • Commit 6db607be fix(release): keep JSR manifest publishable
  • Commit f778e02a build: bump zshy for JSR wildcard exports
View originalPermalink
How v4.4.0 went

v4.3.6

Changed 3
  • avoid non null assertion
  • avoid re-exported star modules
  • generalize numeric key handling
Fixed 2
  • add missing User-agent to robots.txt and allow all
  • typo in codec.test.ts file

From Zod

Commits:
  • 9977fb0868432461de265a773319e80a90ba3e37 Add brand.dev to sponsors
  • f4b7bae3468f6188b8f004e007d722148fc91d77 Update pullfrog.yml (#5634)
  • 251d7163a0ac7740fee741428d913e3c55702ace Clean up workflow_call
  • edd4132466da0f5065a8e051b599d01fdd1081d8 fix: add missing User-agent to robots.txt and allow all (#5646)
  • 85db85e9091d0706910d60c7eb2e9c181edd87bd fix: typo in codec.test.ts file (#5628)
  • cbf77bb12bdfda2e054818e79001f5cb3798ce76 Avoid non null assertion (#5638)
  • dfbbf1c1ae0c224b8131d80ddf0a264262144086 Avoid re-exported star modules (#5656)
  • 762e911e5773f949452fd6dd4e360f2362110e8e Generalize numeric key handling
  • ca3c8629c0c2715571f70b44c2433cad3db7fe4e v4.3.6
View originalPermalink
How v4.3.6 went

v4.3.5

Changed 2
  • Improve mini treeshaking
  • Update migration guide documentation for deprecation of message

From Zod

Commits:
  • 21afffdb42ccab554036312e33fed0ea3cb8f982 [Docs] Update migration guide docs for deprecation of message (#5595)
  • e36743e513aadb307b29949a80d6eb0dcc8fc278 Improve mini treeshaking
  • 0cdc0b8597999fd9ca99767b912c1e82c1ff2d6c 4.3.5
View originalPermalink
How v4.3.5 went

v4.3.4

Added 1
  • Support patternProperties for looserecord
Fixed 1
  • Drop iso time in fromJSONSchema
Removed 1
  • Remove .refine() from ZodMiniType

From Zod

Commits:
  • 1a8bea3b474eada6f219c163d0d3ad09fadabe72 Add integration tests
  • e01cd02b2f23d7e9078d3813830b146f8a2258b4 Support patternProperties for looserecord (#5592)
  • 089e5fbb0f58ce96d2c4fb34cd91724c78df4af5 Improve looseRecord docs
  • decef9c418d9a598c3f1bada06891ba5d922c5cd Fix lint
  • 9443aab00d44d5d5f4a7eada65fc0fc851781042 Drop iso time in fromJSONSchema
  • 66bda7491a1b9eab83bdeec0c12f4efc7290bd48 Remove .refine() from ZodMiniType
  • b4ab94ca608cd5b581bfc12b20dd8d95b35b3009 4.3.4
View originalPermalink
How v4.3.4 went

v4.3.3

Commits:
  • f3b2151959d215d405f54dff3c7ab3bf1fd887ca v4.3.3
View originalPermalink
How v4.3.3 went

v4.3.2

Changed 1
  • Loosen strictObject inside intersection
Removed 1
  • Remove Juno

From Zod

Commits:
  • bf96635d243118de6e4f260077aa137453790bf6 Loosen strictObjectinside intersection (#5587)
  • f71dc0182ab0f0f9a6be6295b07faca269e10179 Remove Juno (#5590)
  • 0f41e5a12a43e6913c9dcb501b2b5136ea86500d 4.3.2
View originalPermalink
How v4.3.2 went

v4.3.1

Fixed 1
  • allow non-overwriting extends with refinements

From Zod

Commits:
  • 0fe88407a4149c907929b757dc6618d8afe998fc allow non-overwriting extends with refinements. 4.3.1
View originalPermalink
How v4.3.1 went
View all

Discussion

If you publish Zod, you can claim this product by proving you administer its repository.