What the network found
Every line below is a measurement, not an opinion. Each one links to a published sample whose contract is executed in a pinned container with the network switched off, so you can re-run it and disagree with the result.
OS and runtime come from the environment recorded by the linked sample. Entries without that dimension are omitted when you select it.
597 findings across 8 ecosystems.
- cargo
- composer
- gem
- golang
- hex
- npm
- pub
- pypi
Stated by the sample, measured by its contract
Showing 251–275 of 568 measured by published samples.
-
npmSample contractnode · linux/x64happy-dom@20.11.2
BelievedA competent reader expects that omitting script-evaluation settings in happy-dom still evaluates inline `<script>` blocks like a browser would.
MeasuredIn happy-dom 20.11.2, constructing `Window` without `settings.enableJavaScriptEvaluation` means inline script execution is disabled, so a script that sets `window.__ran = true` leaves `window.__ran` undefined.
-
npmSample contractnode · linux/x64jest@30.4.2
BelievedA strong implementation instinct is that `jest.setSystemTime` accepts any date-like input, including ISO strings, when using fake timers.
MeasuredCalling `jest.setSystemTime` with an ISO string under fake timers throws; it only accepts a `Date` object or a numeric epoch timestamp.
-
npmSample contractnode · linux/x64express@4.19.1
BelievedA seasoned developer expects `app.configure(...)` to remain available in Express 4 as it did in v3.
MeasuredIn Express 4.19.1, `app.configure` is undefined and calling `app.configure(...)` throws `TypeError`, showing the v3-style helper no longer exists.
-
npmSample contractnode · linux/x64es-toolkit@1.49.0
BelievedMost callers assume the second argument of `chunk` defaults to 1 when omitted.
MeasuredCalling `chunk([1, 2, 3])` must throw a runtime error because `size` is required.
-
npmSample contractnode · linux/x64express@4.19.1
BelievedForwarded client IP headers should always be reflected in `req.ip` even when `trust proxy` is disabled.
MeasuredA request to `/ip` without `trust proxy` ignores `X-Forwarded-For` and `req.ip` is not the forwarded client value.
-
npmSample contractnode · linux/x64commander@10.0.0
BelievedA leading space before a positional signature is ignored by Commander, so `program.arguments(' <name>')` is equivalent to `program.arguments('<name>')`.
MeasuredIn Commander 10, a leading-space argument signature is not ignored, so parsing `['node', 'app', 'only']` with `new Command().arguments(' <required> [optional]')` throws `commander.missingArgument` and does not accept a single positional argument.
-
npmSample contractnode · linux/x64commander@15.0.0
BelievedWhen both `--cache` and `--no-cache` are defined, omitting both options should leave `cache` as `true` because the negated form implies a true default.
MeasuredWith both `--cache` and `--no-cache`, parsing without either flag leaves `program.opts().cache` as `undefined`, even though the negated option alone would default to true.
-
npmSample contractnode · linux/x64bun@1.3.14
BelievedCalling server.stop() on a Bun.serve HTTP server terminates all active client connections and immediately frees server resources.
Measuredassert server.pendingRequests is 1 while an in-flight request is being processed by the fetch handler
-
npmSample contractnode · linux/x64chalk@6.0.0
BelievedA caller should get the same kind of rejection for all obviously malformed `chalk.hex(...)` inputs.
Measured`chalk.hex('')('x')` also returns black 24-bit ANSI output instead of an error.
-
npmSample contractnode · linux/x64bun@1.3.14
BelievedBun.password.verify returns false whenever a candidate password fails to verify against an unparseable, legacy, or corrupted hash string.
MeasuredBun.password.verify throws an Error with code PASSWORD_UNSUPPORTED_ALGORITHM for arbitrary non-empty hash strings and PASSWORD_INVALID_ENCODING for malformed prefixes rather than returning false, while an empty string hash returns false.
-
npmSample contractnode · linux/x64@babel/preset-env@8.0.2
BelievedA shared preset-env tuple can be safely mutated between runs so each transform picks up the latest target value.
MeasuredCalling transformAsync twice with the same preset tuple and then changing `targets` in between does not recompute the tuple for the second run.
-
npmSample contractnode 22.18 · linux/x64@babel/core@8.0.1
BelievedBecause @babel/core 8 ships as ESM, `require('@babel/core')` must always throw ERR_REQUIRE_ESM.
MeasuredCommonJS require and ESM import expose the same transformSync function.
-
golangSample contractgo 1.26 · linux/x64github.com/gin-gonic/gin@v1.12.0
BelievedAbortWithStatusJSON immediately returns from the current handler, so code after it cannot run and an explicit return is unnecessary.
Measuredassert binding an empty required name with ShouldBindJSON lets the handler choose HTTP 422 and a JSON error response
-
npmSample contractnode · linux/x64@babel/core@8.0.1
BelievedBecause Babel 8 presents an ES module API, `require('@babel/core')` throws `ERR_REQUIRE_ESM` and only dynamic `import()` can reach `transformSync`.
MeasuredIn @babel/core 8.0.1, `require('@babel/core')` returns an API object whose `transformSync` member is a function.
-
npmSample contractnode · linux/x64@babel/core@7.29.6
BelievedA model would likely expect Babel to treat `new super()` like a standard callable super-expression form and return transpiled output instead of throwing.
Measured`transformSync` does not return transformed code for `class A extends class {} { constructor() { new super() } }`; it throws a syntax error for this invalid `new super()` form.
-
pubSample contractdart · linux/x64collection@1.18.0
BelievedIterableExtension.sample provides a randomly ordered subset of elements, meaning that requesting a sample equal to the collection's size will return a shuffled permutation.
MeasuredBefore 1.19.0, calling sample() on an iterable requesting its full length returns the elements in their exact original order, rather than a randomly shuffled permutation.
-
gemSample contractruby · linux/x64zeitwerk@2.6.0
BelievedZeitwerk silently skips a file that defines a different constant than its path implies
MeasuredAccessing Foo when lib/foo.rb defines Bar raises Zeitwerk::NameError and the error identifies the missing expected constant Foo.
-
gemSample contractruby · linux/x64zeitwerk@2.8.3
BelievedCalling Zeitwerk::Loader.setup multiple times on the same loader raises a Zeitwerk::Error
MeasuredSecond call to loader.setup does NOT raise an error
-
gemSample contractruby · linux/x64zeitwerk@2.8.3
BelievedCalling loader.reload refreshes the source code for a constant while keeping the same Class object bound to that name, so existing instances continue to satisfy is_a?(Widget) and case/when Widget after reload.
MeasuredAfter loader.reload, Widget is a different Class object than it was before reload — klass_before.equal?(klass_after) is false — meaning reload undefines the constant and installs a new autoload rather than patching the existing class in place.
-
gemSample contractruby · linux/x64zeitwerk@2.8.3
BelievedCalling reload and unload-like operations is enough to refresh or remove constants, so explicit pre-setup reloading configuration should not matter.
Measuredassert a loader without `enable_reloading` raises `Zeitwerk::ReloadingDisabledError` on `reload` after `setup`, and then `unload` keeps a previously loaded constant in place
-
gemSample contractruby · linux/x64zeitwerk@2.8.3
Believedpush_dir without an explicit namespace parameter scopes autoloaded constants under a module matching the directory name.
Measuredassert push_dir with namespace left unset defaults the root namespace to Object rather than inferring a namespace from the directory name, mapping the directory to Object in all_expected_cpaths and expecting unprefixed top-level constants
-
gemSample contractruby · linux/x64zeitwerk@2.8.2
BelievedLoader callback APIs are expected to accept only bare constant names, so `::User` should be rejected as an invalid path.
Measuredassert `Zeitwerk::Loader#on_load` accepts a leading double-colon constant path and does not raise at registration (`::User`)
-
gemSample contractruby · linux/x64sorbet-runtime@0.6.13427
BelievedThe legacy `pii:` property option is still accepted as a backward-compatible alias for `sensitivity:` in sorbet-runtime v0.x.
Measureddefining a `T::Struct` prop with `pii:` raises ArgumentError and the message says `pii:` was renamed to `sensitivity:`
-
gemSample contractruby · linux/x64sorbet-runtime@0.6.13427
BelievedBecause T::Struct declares prop types and the .new constructor raises TypeError when a value does not match, from_hash — the documented deserialization path — applies the same check and raises on mismatched types.
MeasuredT::Struct.from_hash accepts a String value for a prop declared Integer and returns it unchanged without raising TypeError, while T::Struct.new raises TypeError for the identical input — proving that the deserialization path skips the sig-based check the constructor applies
-
gemSample contractruby · linux/x64sorbet-runtime@0.6.13427
BelievedReplacing a `sig`-annotated method with a plain method definition should discard the prior runtime signature metadata so internal signature lookup returns no stale declaration for that method key.
MeasuredAfter redefining a typed method without adding a new `sig`, `T::Private::Methods.signature_for_method` still returns a `T::Private::Methods::Signature` for that method key instead of clearing it.
How to check any line here
Open the sample, read its contract, run it. The contract is the sample's own test: it runs offline in a pinned container, and the signed receipt of that run is what the network stores. Nothing here rests on our reading of a library — only on what the library did.
Some published samples are not on this page. Their contract passed and the sample is live — but no line of it reads as a sentence, and an assertion like expect(x).toBe(1) tells a reader nothing beside the belief it checks. Those are left out rather than printed as evidence nobody can read.