Runtime evidence / smoke tested
zod4.6.5
Observed 2026-10-09 10:10 UTC · Linux amd64 / glibc
Version summary · Observation 0 · Report history · Maintainer tools (coming soon)
Coverage is limited. Inspect the groups and omissions below.
This is loading evidence. It does not establish functional correctness or package safety.
Runtime matrix
4 pinned runtimes · production_ce416e976d3b4c51b252859d31c1fa7c| Runtime | Root import | Root require | Subpath imports | Subpath requires |
|---|---|---|---|---|
| Node.js24.21.0 | Passed | Passed | Passed9 passed · 0 failed | Passed9 passed · 0 failed |
| Node.js26.10.0 | Passed | Passed | Passed9 passed · 0 failed | Passed9 passed · 0 failed |
| Bun1.4.2 | Passed | Passed | Passed9 passed · 0 failed | Passed9 passed · 0 failed |
| Deno2.9.7 | Passed | Passed | Passed9 passed · 0 failed | Passed9 passed · 0 failed |
Node.js 26.10.0
Bun 1.4.2
Deno 2.9.7
Import uses ESM; require uses CommonJS. Root modes use fresh sandboxes. Subpath batches share module caches and globals. Select a result to inspect its evidence.
Does zod work in Node.js, Bun and Deno?
Coverage is limited: some exports or checks were omitted, incomplete or unavailable. A passing runtime row does not remove those gaps. The runtimes used the same installed dependency snapshot. Test environment: Linux amd64 / glibc, with install scripts and execution networking disabled. Successful import or require does not prove that package functions, native features or your application work.
Does zod work with Node.js?
zod@4.6.5 passed the applicable loading checks in Node.js 24.21.0. 20 passed · 0 failed.
zod@4.6.5 passed the applicable loading checks in Node.js 26.10.0. 20 passed · 0 failed.
Does zod work with Bun?
zod@4.6.5 passed the applicable loading checks in Bun 1.4.2. 20 passed · 0 failed.
Does zod work with Deno?
zod@4.6.5 passed the applicable loading checks in Deno 2.9.7. 20 passed · 0 failed.
Compare npm package compatibility across Node.js, Bun and Deno · Browse observed runtime loading failures
Shared preparation
1 installed packages · 0 optional dependencies omitted · lifecycle scripts disabled
The omitted count covers locked optional dependencies. Optional peers are separate and are not automatically installed.
Static manifest, native and script observations
Static indicators are context; their presence alone does not establish a prerequisite or failure.
Coverage and evidence
Node.js 24.21.0 · Root · ESM importPassed
1 passed · 0 failed · 1 observed of 1 planned
Node.js 24.21.0 · Root · CommonJS requirePassed
1 passed · 0 failed · 1 observed of 1 planned
Node.js 24.21.0 · Subpaths · ESM importPassed
9 passed · 0 failed · 9 observed of 9 planned
Node.js 24.21.0 · Subpaths · CommonJS requirePassed
9 passed · 0 failed · 9 observed of 9 planned
Node.js 26.10.0 · Root · ESM importPassed
1 passed · 0 failed · 1 observed of 1 planned
Node.js 26.10.0 · Root · CommonJS requirePassed
1 passed · 0 failed · 1 observed of 1 planned
Node.js 26.10.0 · Subpaths · ESM importPassed
9 passed · 0 failed · 9 observed of 9 planned
Node.js 26.10.0 · Subpaths · CommonJS requirePassed
9 passed · 0 failed · 9 observed of 9 planned
Bun 1.4.2 · Root · ESM importPassed
1 passed · 0 failed · 1 observed of 1 planned
Bun 1.4.2 · Root · CommonJS requirePassed
1 passed · 0 failed · 1 observed of 1 planned
Bun 1.4.2 · Subpaths · ESM importPassed
9 passed · 0 failed · 9 observed of 9 planned
Bun 1.4.2 · Subpaths · CommonJS requirePassed
9 passed · 0 failed · 9 observed of 9 planned
Deno 2.9.7 · Root · ESM importPassed
1 passed · 0 failed · 1 observed of 1 planned
Deno 2.9.7 · Root · CommonJS requirePassed
1 passed · 0 failed · 1 observed of 1 planned
Deno 2.9.7 · Subpaths · ESM importPassed
9 passed · 0 failed · 9 observed of 9 planned
Deno 2.9.7 · Subpaths · CommonJS requirePassed
9 passed · 0 failed · 9 observed of 9 planned
Planner omissions
- pattern
- 1
- non executable
- 1
- not exported
- 0
- invalid subpath
- 0
- coverage limit
- 0
./package.json— non executable./v4/locales/*— pattern
Reproduce these inputs
Download the recorded inputs and exact dependency lock. These files do not include the CLI, runtime images or installed packages.
Local replay requires setup. The CLI currently runs from the CompatLab source repository on a qualified Linux amd64/runsc host. Hosted runtime images are not yet distributed for public download; an operator must supply the exact images named in this report. A fresh image build does not substitute for them. CLI setup and replay requirements
Command for a configured host
Run from the built CompatLab repository with both downloads in that directory and the exact runtime images loaded. Rebuilding creates a new snapshot generation.
sudo "$(command -v node)" apps/cli/dist/bin.js reproduce ./4cd31f95-7f85-4e52-8f09-3a75df7f8f04-reproduction.json --rebuild --lockfile ./package-lock.json --jsonThe original worker last reported its sealed snapshot as available. Verified reuse requires those actual bytes in your local state directory.
Exact provenance
- artifact
zod@4.6.5- integrity
sha512-v5l/aFXZQeai4awLbOpSoHecE9UiMrnfx75tEXLjNonXVARxQ5mOeipTjROUchszUNCqnE+hqAMujRsRHsut2Q==- tarball
https://registry.npmjs.org/zod/-/zod-4.6.5.tgz- snapshot
33c43b31-6bc0-4cf4-becf-d3a69ffd1abe- generation
88febbe5-0485-4b23-a2cd-ab6b91a057d1- lockDigest
49658ad882071e789ebc65c45d80c759c8045f8371a8a219b5b6be30ea56c49f- treeDigest
bdf00d81bbb9b365dbb59caa8e142535f10f9f93e5e5c1f9e2ffc35a7c8c7780- installerImage
node:24.21.0-bookworm-slim@sha256:5cbc7caba8c2c0f0bca675d1b61b9f2857e1cf1853c6164ee9dd409501a936e7- preparationProfile
npm_11_19_0_linux_amd64_v2- harness
load_v2- planner
explicit_exports_v1- policy
runtime_limits_v2- classifier
classifier_v2- classifiedAt
2026-10-09T10:10:08.515Z
node_24_21_0
sha256:e3a5a41a242a766e69f326b91f9ed9280c5719ad3e9ab54f0ac28bfc71d77794
Built 2026-10-04 15:20 UTC · runtime_image_v1
node_26_10_0
sha256:5d2fa297021c7db25494856bb25e2cddecbb020722ce1e0f2101385a063c0611
Built 2026-10-04 15:20 UTC · runtime_image_v1
bun_1_4_2
sha256:fd67412f5baad0c2b1038367df9cf2d4b33237d3815e16eedae16cfd94ab3182
Built 2026-10-04 15:21 UTC · runtime_image_v1
deno_2_9_7
sha256:3b0f993e5ec0b1d4e8e09bc50ae53f142f7347d0baf96cefe7a8cfe7a00f7958
Built 2026-10-04 15:21 UTC · runtime_image_v1
Evidence limitations
- Only installation and loading were observed; functional correctness and package safety are not established.
- Subpath batches share module caches and globals; root modes use separate fresh sandboxes.
- Package-visible harness observations can be tampered with. They are not adversarial attestation.
- Evidence applies to these exact artifacts, dependency snapshot, runtime images and Linux amd64/glibc policy.
- Runtime error codes are captured observations and can also be thrown by package code.