What the network found
Every line below is a measurement, not an opinion. Each one links to a published sample whose contract is executed in a pinned container with the network switched off, so you can re-run it and disagree with the result.
OS and runtime come from the environment recorded by the linked sample. Entries without that dimension are omitted when you select it.
597 findings across 8 ecosystems.
- cargo
- composer
- gem
- golang
- hex
- npm
- pub
- pypi
Stated by the sample, measured by its contract
Showing 1–25 of 568 measured by published samples.
-
pypiSample contractpython · linux 24/x64cffi@2.1.1
BelievedCalling ffi.string with maxlen reads the full byte length regardless of null bytes, and ffi.buffer on a pointer defaults to the full allocated buffer length.
MeasuredCalling ffi.string(cdata, maxlen) truncates at the first null byte rather than reading maxlen bytes, while ffi.unpack extracts the exact byte count across embedded nulls.
-
npmSample contractnode · linux 24/x64browserslist@4.28.7
BelievedModifying .browserslistrc on disk causes browserslist to automatically pick up the updated target configuration on subsequent queries in a long-running process.
MeasuredWhen .browserslistrc is modified on disk during a process lifetime, browserslist continues to return stale cached configurations until browserslist.clearCaches() is explicitly invoked.
-
npmSample contractnode 22.23 · linux 24/x64@babel/preset-env@7.26.9
BelievedModern compilation targets automatically negate all transforms regardless of configuration options like forceAllTransforms, and preset-level settings like bugfixes or loose are not systematically passed to configured plugins.
MeasuredpresetEnv with forceAllTransforms: true forces all 49 syntax transform plugins to activate even when targeting modern Chrome 120 (which normally requires 17).
-
npmSample contractnode 22.23 · linux 24/x64@rollup/plugin-commonjs@28.0.2
BelievedWhen bundling CommonJS modules that require external dependencies into ESM, @rollup/plugin-commonjs automatically imports them as ES module namespaces or detects external module formats to preserve named exports.
MeasuredBy default, @rollup/plugin-commonjs renders external dependencies required in CommonJS modules as default ESM imports rather than namespace imports.
-
npmSample contractnode 22.23 · linux 24/x64@rollup/plugin-commonjs@28.0.2
BelievedWhen bundling CommonJS modules that wrap external require calls inside try-catch blocks into ESM, @rollup/plugin-commonjs always hoists the requires to top-level static imports or always preserves runtime try-catch error handling.
MeasuredBy default, @rollup/plugin-commonjs leaves external require calls inside try-catch blocks untransformed as dynamic require() calls, preventing top-level static ESM imports.
-
npmSample contractnode · linux 24/x64@rollup/plugin-commonjs@28.0.2
BelievedWhen bundling CommonJS modules containing dynamic require calls, @rollup/plugin-commonjs resolves dynamic calls automatically or leaves them untouched without requiring explicit configuration.
MeasuredBy default, @rollup/plugin-commonjs transforms dynamic require calls into commonjsRequire helper calls that throw an error instructing the user to configure dynamicRequireTargets or ignoreDynamicRequires.
-
npmSample contractnode 22.23 · linux 24/x64@rollup/plugin-commonjs@29.0.3
BelievedWhen bundling CommonJS modules with dynamic require expressions, @rollup/plugin-commonjs either automatically resolves dynamic calls at runtime or silently ignores them without error.
MeasuredBy default, @rollup/plugin-commonjs transforms dynamic require calls into commonjsRequire helper calls that throw an error instructing the user to configure dynamicRequireTargets or ignoreDynamicRequires.
-
npmSample contractnode 22.23 · linux 24/x64@rollup/plugin-commonjs@29.0.3
BelievedWhen bundling CommonJS modules that wrap external require calls inside try-catch blocks into ESM, @rollup/plugin-commonjs always hoists the requires to top-level static imports or always preserves runtime try-catch error handling.
MeasuredBy default, @rollup/plugin-commonjs leaves external require calls inside try-catch blocks untransformed as dynamic require() calls, preventing top-level static ESM imports.
-
npmSample contractnode 22.23 · linux 24/x64@rollup/plugin-commonjs@29.0.3
BelievedWhen bundling CommonJS modules that require external dependencies into ESM, @rollup/plugin-commonjs automatically imports them as ES module namespaces or detects external module formats to preserve named exports.
MeasuredBy default, @rollup/plugin-commonjs renders external dependencies required in CommonJS modules as default ESM imports rather than namespace imports.
-
npmSample contractnode · linux 24/x64@babel/preset-env@7.26.9
BelievedDevelopers expect specifying useBuiltIns alone without corejs to automatically configure polyfill plugins, or expect getPolyfillPlugins to return non-empty default plugins even when useBuiltIns is false or unset.
MeasuredgetPolyfillPlugins returns an empty array when useBuiltIns is unset, false, or not usage/entry, or when corejs is missing.
-
npmSample contractlinux 24/x64@rollup/plugin-commonjs@28.0.7
BelievedBundling CommonJS code with Rollup leaves dynamic require calls as native runtime require invocations in the output bundle.
Measuredassert @rollup/plugin-commonjs with default ignoreDynamicRequires (false) rewrites dynamic require calls into commonjsRequire helper that throws a runtime error
-
npmSample contractnode 22.23 · linux 24/x64@babel/preset-env@7.26.9
BelievedModern compilation targets automatically negate all transforms regardless of configuration options like forceAllTransforms, and preset-level settings like bugfixes or shippedProposals do not alter plugin resolution counts for modern environments.
MeasuredpresetEnv with forceAllTransforms: true forces all 49 syntax transform plugins to activate even when targeting modern Chrome 120 (which normally requires 17).
-
npmSample contractnode 22.23 · linux 24/x64@babel/preset-env@8.0.2
BelievedCompilation targets strictly dictate plugin selection, requiring full package names if manually overridden, and include and exclude silently resolve collisions by precedence rather than throwing an error.
MeasuredConfiguring the include option with transform-arrow-functions forces transpilation of arrow functions to function expressions even when targeting modern runtimes (such as Chrome 120) that natively support them, while preserving non-included syntax like template literals.
-
npmSample contractnode 22.23 · linux 24/x64@babel/preset-env@8.0.2
BelievedModern compilation targets like Chrome 120 prevent all syntax transformations, forceAllTransforms converts ES module syntax into CommonJS require calls, and exclude is ignored when forceAllTransforms is true.
MeasuredWhen forceAllTransforms is omitted or false, @babel/preset-env preserves native modern syntax (arrow functions, template literals, optional chaining) for targets that natively support them.
-
npmSample contractnode 22.23 · linux 24/x64@rollup/plugin-commonjs@28.0.7
BelievedBy default @rollup/plugin-commonjs hoists all CommonJS require calls including those inside try-catch blocks into top-level static imports.
Measuredassert @rollup/plugin-commonjs by default (ignoreTryCatch: true) leaves external require calls inside try-catch blocks unconverted as runtime require statements without hoisting static imports
-
npmSample contractnode 22.23 · linux 24/x64@babel/preset-env@7.26.0
BelievedConfiguring polyfill injection with useBuiltIns 'usage' or 'entry' generates identical plugin lists, and legacy polyfill handling is only applied when corejs version 2 is specified.
Measuredassert useBuiltIns 'usage' with corejs 3 selects pluginCoreJS3 with method 'usage-global' and legacyBabelPolyfillPlugin marked as deprecated
-
npmSample contractnode · linux 24/x64@babel/preset-env@7.26.0
BelievedDisabling module transforms in @babel/preset-env removes all module-related plugins entirely, and requesting dynamic import transformation enables transform-dynamic-import across all formats including UMD.
Measuredassert modules: 'commonjs' with shouldTransformESM maps the module format to its transformation plugin alongside dynamic import and export-namespace transforms
-
npmSample contractnode · linux 24/x64@rollup/plugin-commonjs@28.0.7
BelievedBy default @rollup/plugin-commonjs allows CommonJS modules requiring external ES modules to access both default and named exports.
Measuredassert @rollup/plugin-commonjs with default esmExternals: false emits default imports for external dependencies, causing named exports to be inaccessible (undefined) when required from CommonJS
-
npmSample contractnode 22.23 · linux 24/x64@babel/preset-env@7.29.7
BelievedModern compilation targets automatically negate all transforms regardless of configuration options like forceAllTransforms, and preset-level settings like bugfixes or loose are not systematically passed to configured plugins.
MeasuredpresetEnv with forceAllTransforms: true forces all 50 syntax transform plugins to activate even when targeting modern Chrome 120 (which normally requires 18).
-
npmSample contractnode · linux 24/x64@babel/preset-env@7.26.0
BelievedTargeting a modern environment like Node 20 prevents syntax transforms like arrow functions from running, and targeting older environments compiles all modern syntax without granular options to selectively force or skip specific transforms.
Measuredassert include with shorthand 'transform-arrow-functions' forces arrow function compilation on targets that natively support them such as node 20
-
npmSample contractnode 22 · linux 24/x64@babel/preset-env@7.29.7
BelievedTarget-based compilation dynamically configures the plugin pipeline, and preset helper utilities resolve feature requirements and partition syntax transforms.
MeasuredisPluginRequired returns true when target version is below support requirement, and false when target meets or exceeds requirement.
-
npmSample contractnode 22 · linux 24/x64@babel/preset-env@7.24.7
BelievedTarget-based compilation dynamically configures the plugin pipeline, and preset helper utilities resolve feature requirements and partition syntax transforms.
MeasuredisPluginRequired returns true when target version is below support requirement, and false when target meets or exceeds requirement.
-
golangSample contractgo · linux/x64google.golang.org/protobuf@v1.35.1
Believedreflect.DeepEqual safely compares protobuf messages while proto.Equal behaves identically to standard struct comparisons.
Measuredproto.Equal returns true when comparing two nil proto.Message values, and returns false when comparing a non-nil message with nil.
-
pypiSample contractpython · linux/x64pydantic@2.13.4
BelievedPydantic field_validators always receive raw uncoerced input by default and can access all sibling fields in ValidationInfo.data regardless of field definition order.
MeasuredLeaving field_validator mode unset defaults to 'after', running after core type coercion; inputs that fail core type coercion raise ValidationError before the after-validator executes.
-
npmSample contractnode 22.23 · linux 24/x64socket.io-client@4.8.1
BelievedEmitted events are always intercepted immediately by onAnyOutgoing regardless of connection state, volatile.emit queues offline packets like standard emit, and emitWithAck resolves directly without handling socket.io error-first ack protocol or timeout errors.
Measuredassert volatile emit while disconnected discards event immediately without queuing in sendBuffer whereas regular emit is queued
How to check any line here
Open the sample, read its contract, run it. The contract is the sample's own test: it runs offline in a pinned container, and the signed receipt of that run is what the network stores. Nothing here rests on our reading of a library — only on what the library did.
Some published samples are not on this page. Their contract passed and the sample is live — but no line of it reads as a sentence, and an assertion like expect(x).toBe(1) tells a reader nothing beside the belief it checks. Those are left out rather than printed as evidence nobody can read.