
Security News
upm Launches as a Fast, Tiny Package Manager Written in TypeScript
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.
form0-core
Advanced tools
The schema-driven form engine behind form0, the open-source form ecosystem by paqu.io. Framework-agnostic: conditional visibility, validation and calculations from a JSON schema, in Node.js, browsers and React Native.
[!WARNING] form0 is in active, very early development. Do not use in production. Expect breaking changes and unstable behavior.
form0-core is the schema-driven engine that powers form0 open-source ecosystem. It is framework-agnostic and runs in any JavaScript runtime (Node.js, browsers, React Native, etc.)
The entry point for most users is form0-cli. Follow the quickstart to create a project and preview your schema.
If you are integrating the engine directly:
npm install form0-core
form0-core owns behavioral schema concerns such as fields, conditions, calculations,
events, and AI metadata. Applications may still attach optional top-level metadata such as
id (unique form identifier), status (publication state), version (schema version),
scope fields like main_org_id, and media or location settings. Operational counters like
record_count and record_last_change_at should stay platform-owned and be injected at
application or API boundaries, not treated as engine-authored schema. A top-level
form.version may still exist, but the engine does not bump or consume it.
form0-core intentionally uses two different choice-value shapes:
{ choice, other }{ choices, other }{ choice_value, other_value }{ choices_value, other_value }Record-side utilities follow this contract:
createStructuredRecord() outputs canonical stored recordsnormalizeStructuredRecord() consumes and returns canonical stored recordsbuildFormRecordSnapshot() consumes canonical stored records and returns renderer snapshot valuesprojectDatasetRowValues() consumes canonical stored rowsFIELD_SPECS keep separate validators by context:
valueValidator validates live engine / renderer valuesrecordValueValidator validates canonical stored record valuesRecord status remains top-level as @status; it is not stored inside form_values.
See SECURITY.md for security modes and configuration.
Contributions are welcome! Please feel free to submit issues and pull requests.
FAQs
The schema-driven form engine behind form0, the open-source form ecosystem by paqu.io. Framework-agnostic: conditional visibility, validation and calculations from a JSON schema, in Node.js, browsers and React Native.
The npm package form0-core receives a total of 51 weekly downloads. As such, form0-core popularity was classified as not popular.
We found that form0-core demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.

Company News
Socket is joining the OpenJS Security Stewardship Program to fund Node.js vulnerability research, maintainer remediation, and security releases.

Security News
Two compromised GitHub Actions were re-enabled with malicious tags intact, exposing thousands of downstream repositories to Mini Shai-Hulud.