Skip to content
Code Recycle

Component · for humans & their agents

dlt Schema Contract Verdict

verified · first-partyactively maintained$0 during beta (was $39)

SUM(amount) returns the same wrong number under three of dlt's four schema contracts, from three different silent losses -- and the lossy default is the one you get.

by datawright · Code Recycle maintainer

Get it free — beta

Every claim on this page is refundable if it is untrue — refund policy.

Verified: 20 tests

Decides what your dlt schema_contract will SILENTLY LOSE when an upstream changes shape. Pure function: no I/O, no warehouse connection, no dependency on dlt.

Decides what your dlt schema_contract will SILENTLY LOSE when an upstream changes shape. Pure function: no I/O, no warehouse connection, no dependency on dlt.

Built for dlt 1.29.1 (Apache-2.0). Not affiliated with or endorsed by the dltHub project.

THE MEASUREMENT. A source that had been sending {id, amount} starts sending a string in amount and adds a field nobody asked for:

  evolve         2 rows. amount is NULL for row 2 -- the value went to amount__v_text. new_col and secret_ssn auto-created.
  freeze         RAISES. The only loud option.
  discard_row    1 row. Row 2 vanished. Load reported success.
  discard_value  2 rows. amount NULL. The value vanished.

SELECT SUM(amount) RETURNS 100 UNDER ALL THREE NON-FREEZE OPTIONS. Three different losses producing one identical wrong answer, with the load reporting success every time -- and evolve is dlt's DEFAULT.

WHAT EACH ONE DOES. Under evolve a type change does not fail: dlt creates a second column and leaves the original NULL for those rows, so every aggregate over it silently covers only the rows that kept the old type. Under discard_row the offending row is dropped in full -- and the rows most likely to be dropped are the anomalous ones somebody needed to see. Under discard_value the row survives with a NULL, which is indistinguishable from a value that was legitimately absent, so nothing downstream can tell a discarded measurement from one that was never taken.

THE COMPLIANCE CASE. Because evolve creates columns automatically, an upstream that begins sending personal or regulated data gets it written to the warehouse and into every backup taken afterwards. Measured: a secret_ssn field the pipeline had never seen was created and stored on the first run that contained it. That arrives as a SUCCESSFUL PIPELINE RUN, not as an incident.

IT REFUSES RATHER THAN GUESSES. An unknown contract returns NOT_DETERMINABLE and says why it matters. Same for a source whose drift capability is unknown, which is the normal state for an API you do not control. And it stays quiet where it should: a source that genuinely cannot add columns or change types never exercises the contract, and it says so specifically so you can stop reviewing the choice.

RECONCILIATION IS WHAT MAKES ANY OF IT DETECTABLE, and is reported alongside a real loss rather than on its own. Without a row-count reconciliation against the source or an alert on the null rate of a column you aggregate, every failure above is permanent and invisible: the pipeline is green, the dashboard is plausible, and the number is wrong.

VERIFIED: 20 tests, measured by running the suite, every mutation observed FAILING before restore -- including one that caught a gap in the TESTS rather than the code.

DELIVERY: signed download of a hash-verified tarball, immediately on purchase. Permissive licence: unlimited products, unlimited clients, unlimited seats, no attribution, perpetual and irrevocable. One restriction, do not republish the source as source.

Interface

What you call, and what comes back. Types and signatures only — the implementation ships with the source.

  export function evaluateSchemaContract(config: PipelineConfig): Verdict;
  export type SchemaContract = "evolve" | "freeze" | "discard_row" | "discard_value" | "unknown";
  export type Verdict = | { status: "SAFE";

01Capabilities

Does

  • + Data engineering
  • + Compliance audit
  • + Schema contract enforcement

Doesn’t

  • No exclusions declared

02Requirements & stack

Depends on

No declared dependencies

Credentials needed

None declared

Stack

typescript

03Community

No endorsements yet

No verified confirmations yet — be the first.

Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.

Open an issue

Sign in to confirm — weight comes from verified usage, not vote count.

0 open · 0 answered · 0 fixed · 1 said it worked

04Trust Passport

Full passport →
–/100

0/0 automated components pass. An automated score is never a security guarantee.

✓ Verified · first-partyreviewed Sep 20, 2026 · re-verification due Dec 19, 2026
  • publisher identity Publisher status verified; 1 verification(s) on file
  • malicious pattern scan No known malicious-behavior patterns across 58 source file(s) plus listing text
  • capability contract All 0 observed capability reference(s) match the declared manifest
  • agent safety scan No injection patterns in agent-readable content
  • provenance No release signature or provenance attestation
  • behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.

Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.

VersionChannelReleasedNotes
1.0.0stableAug 6, 2026First public release.