NewYour coding agent can read the release notes before it upgrades.Set up the MCP server →
npm · #4764 most downloaded on npm
Fast, lightweight JSON Schema validator for Node.js and browsers — full support for draft-04, draft-06, draft-07, draft-2019-09, and draft-2020-12 (latest)
Last release 17 days ago
17 Sep 2026
Ships fairly regularly
a new release about every 3 weeks
Nearly every release is documented
notes for 58 of the last 60 stable releases
7 versions withdrawn
withdrawn after publishing
13 years old
164 releases · first in 2013
format: validate uri-template against the complete RFC 6570 ABNF
One column per quarter.
format: validate uri/uri-reference/iri/iri-reference per RFC 3986/3987 ABNF
format: reject control characters in uri-template literals
deps: bump postcss, nanoid and brace-expansion to patched releases
deps: bump brace-expansion to 5.0.8 ( GHSA-3jxr-9vmj-r5cp )
format: implement IDNA2008 idn-hostname/idn-email validation (RFC 5890-5893)
run copy:schemas before check in release-please workflow
cli: show JSON filename in output instead of "json #N"
allow consecutive hyphens in ASCII hostname labels per RFC 1123
switch bundler from rollup to tsdown
switch bundler from rollup to tsdown (a9245fd)
WARNING: minor breaking change if you imported files from /dist folder directly, they now have correct .mjs extension instead of .js
add safe-regex2 ReDoS guard and strengthen prototype pollution protection
correctly set sideEffects for file that needs it
update 'uri' and 'duration' format validators to comply with json-schema-test-suite
address CodeQL security alerts (CWE-1321, CWE-95, CWE-400)
clamp asyncTimeout to prevent resource exhaustion (CWE-400)
implement maxRecursionDepth safeguard
draft-07 to draft2020-12. If your schemas rely on draft-04/06/07 behavior, set version explicitly or declare $schema in every schema. See MIGRATION.md for details.formatAssertions: null to restore the legacy always-assert behavior.maxRecursionDepth safeguard (default: 100). Deeply nested schemas or data that previously validated may now fail with MAX_RECURSION_DEPTH_EXCEEDED. Increase the value if needed.draft2020-12 as the new default version (#355) (c0c3a30)
$anchor, $recursiveRef/$recursiveAnchor, $defs, $vocabulary, dependentRequired, dependentSchemas, maxContains, minContains, unevaluatedItems, unevaluatedProperties$dynamicRef/$dynamicAnchor, prefixItems, refined items (applies to remaining items after prefixItems)unevaluatedProperties/unevaluatedItems with applicator traversal through allOf, anyOf, oneOf, if/then/else, dependentSchemas, contains, $ref, $recursiveRef, $dynamicRefformatAssertions option to control format assertion behavior per draft (c0c3a30)JsonSchemaDraft201909, JsonSchemaDraft202012 with layered inheritance (ba1bd69)ARRAY_UNEVALUATED_ITEMS, OBJECT_UNEVALUATED_PROPERTIES, COLLECT_EVALUATED_DEPTH_EXCEEDED, MAX_RECURSION_DEPTH_EXCEEDEDid for draft-04 and $id for newer drafts (c7ec640)___$visited schema mutation with WeakSet in getResolvedSchema (161430c)## 11.0.1 (2026-02-25) ### Bug Fixes * refresh docs
implement draft-06, draft-06 version is the new default
add optional schemaPath to errors to suggest which part of schema triggered the error, fixes #198
new api and new cache algorithms, see docs for changes
new ZSchema() replaced by ZSchema.create() factory. The constructor is no longer the public API. Use ZSchema.create(options) to get a typed validator instance. (#336)validate() now throws by default. Returns true on success, throws ValidateError on failure. Use { safe: true } for a non-throwing API that returns { valid, err? }.ZSchema.create() returns ZSchema, ZSchemaSafe, ZSchemaAsync, or ZSchemaAsyncSafe based on { async, safe } options.getLastError() / getLastErrors() removed. Errors are now returned directly from validate() — thrown as ValidateError (default) or in { err } field (safe mode).isValid(), compileSchema(), getMissingReferences(), getMissingRemoteReferences(), getResolvedSchema() removed.setRemoteReference() is now static only. The instance method was removed; use ZSchema.setRemoteReference().validateAsyncSafe() return type changed. Returns { valid, err? } instead of { valid, errs? }.SchemaCache algorithms changed; custom code relying on cache internals will break.add promise api and document how to perform async validation in README
add keyword in error objects, fixes #232
added an option to exclude errors from being reported, fixes #263
## 8.1.0 (2026-02-05) ### Features * export global format functions
treat all schemas without $schema specified as draft-04
$schema are now treated as draft-04. Previously, schemas missing $schema were validated without strict draft semantics. Now $schema is automatically set to http://json-schema.org/draft-04/schema#. Use { version: 'none' } to opt out. (#325)version option on ZSchemaOptions. Defaults to 'draft-04'. Set to 'none' to disable automatic $schema injection.ZSchema.setRemoteReference() at module load time instead of per-instance in the constructor.version option to ZSchemaOptions for selecting the JSON Schema draft (#325) (15d2855)getDefaultSchemaId() methoddependensices → dependencies)error in collectReferences where scope was not reset when traversing inside an element with id
support for unicode properties, fixes #298
drop dependency on lodash.get, fixes #303
## 7.0.8 (2026-02-02) ### Bug Fixes * schema caching (0886ec4) * validate type signatures (1c85ef7) * validateSchema type signatures (f6a5617) ### Mis
## 7.0.7 (2026-02-02) ### Bug Fixes * limit exported typings (a9c775e) * validate input typings (09c656a) ### Miscellaneous Chores * release 7.0.7
improved typings and converted project to use TypeScript strict mode
## 7.0.5 (2026-01-31) ### Bug Fixes * add verbose arg to npm publish (16228d2) ### Miscellaneous Chores * release 7.0.5
TypeScript / ESM rewrite — Source converted from plain JavaScript to TypeScript. The library is now published as ES modules with CJS and UMD bundles.
engines field now requires Node.js 22 or later.main field replaced by exports map. Import z-schema (ESM), z-schema/cjs (CJS), or z-schema/umd/ZSchema.js (UMD). Direct deep imports like z-schema/src/ZSchema no longer work.ZSchema.js, FormatValidators.js) to kebab-case (z-schema.ts, format-validators.ts). Any direct submodule imports will break.z-schema/cjs) and UMD bundle (z-schema/umd/ZSchema.js)Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
Nothing published for this version
remove deprecated david-dm dependency badges from README
commander from 10.0.0 to 11.0.0word-wrap from 1.2.3 to 1.2.5### Miscellaneous Chores * version bump
Drop support for Node.js < 16. CI now tests on Node.js 16 and 18 only.
ensure git submodules are fetched in CI
mainbrowserify to package.json dependenciescommander to 10.0.0grunt to 1.6.1grunt-contrib-jasmine to 4.0.0grunt-browserify to 6.0.0bump decode-uri-component from 0.2.0 to 0.2.2 (security fix)
decode-uri-component from 0.2.0 to 0.2.2 (security fix)Nothing published for this version
bump minimist from 1.2.5 to 1.2.6 (security fix)
minimist from 1.2.5 to 1.2.6 (security fix)cached-path-relative from 1.0.2 to 1.1.0bump path-parse from 1.0.6 to 1.0.7 (security fix)
validator from 13.6.0 to 13.7.0path-parse from 1.0.6 to 1.0.7 (security fix)bump validator from 12.2.0 to 13.6.0 to fix ReDoS vulnerabilities
validator from 12.2.0 to 13.6.0 to fix ReDoS vulnerabilitiesengines.node fieldbreakOnFirstError now defaults to false (was true). All validation errors are reported by default. Set breakOnFirstError: true to restore previous beh
breakOnFirstError now defaults to false (was true). All validation errors are reported by default. Set breakOnFirstError: true to restore previous behavior.validator to ^12.0.0### Miscellaneous Chores * version bump
pass null instead of undefined when no error is present
null instead of undefined when no error is presentvalidator to version 12.0.0pedanticCheck option handlingfix multipleOf validation for floating-point numbers by using integer-scaled arithmetic
multipleOf validation for floating-point numbers by using integer-scaled arithmeticpass validation context to CustomValidatorFn callback
CustomValidatorFn callbackdrop core-js polyfill for Symbol
core-js polyfill for Symboloptimize Utils.cloneDeep performance
core-js to 3.2.1validator to 11.0.0Utils.cloneDeep performanceallow integer array indices in report path (push index as number instead of string)
version bump, rebuild distribution files
fix infinite loop with circular $ref schemas by introducing ancestor report traversal
$ref schemas by introducing ancestor report traversalDrop support for Node.js < 10. CI now tests on Node.js 10, 12, and 14.
Your coding agent can read these notes before it upgrades. Set up the MCP server →