CodeSampleX

What the network found

Every line below is a measurement, not an opinion. Each one links to a published sample whose contract is executed in a pinned container with the network switched off, so you can re-run it and disagree with the result.

OS and runtime come from the environment recorded by the linked sample. Entries without that dimension are omitted when you select it.

597 findings across 8 ecosystems.

Stated by the sample, measured by its contract

Showing 351–375 of 568 measured by published samples.

  1. npmSample contractnode · linux/x64marked@17.0.3

    BelievedMarkdown image alt text containing double quotes is rendered with HTML entity escaping so the attribute value does not break out of quotes.

    Measuredmarked.parse escapes double quotes inside image alt text as " rather than emitting raw unescaped double quotes inside alt attributes

  2. npmSample contractnode · linux/x64luxon@3.7.2

    BelievedConfiguring Settings.defaultZone causes DateTime zone specifiers and setZone calls specifying 'system' to resolve to that configured default zone.

    MeasuredWhen Settings.defaultZone is overridden, Info.normalizeZone('system') and DateTime.fromISO(str, { zone: 'system' }) resolve to the host environment's SystemZone rather than Settings.defaultZone, while 'default' resolves to Settings.defaultZone instead of creating an invalid DateTime.

  3. npmSample contractnode · linux/x64luxon@3.5.0

    BelievedSetting Settings.defaultZone overrides the zone for DateTime instances created or converted with the system zone specifier.

    MeasuredDateTime setZone('system') returns a SystemZone instance with type system rather than inheriting Settings.defaultZone.

  4. npmSample contractnode · linux/x64luxon@3.6.1

    BelievedLooking up an invalid IANA timezone string such as 'constructor' in Luxon returns an invalid IANAZone object rather than the native Object constructor function.

    MeasuredIANAZone.create('constructor') returns an invalid IANAZone instance with isValid equal to false rather than returning the native Object constructor function.

  5. npmSample contractnode · linux/x64luxon@3.5.0

    BelievedWhen throwOnInvalid is enabled, Luxon throws public custom error classes whose name property matches their constructor name.

    MeasuredLuxon's custom error classes (InvalidDateTimeError, InvalidDurationError, and InvalidIntervalError) are not exported, and their thrown instances have their name property set to 'Error' rather than their constructor names.

  6. npmSample contractnode · linux/x64luxon@3.7.2

    BelievedDateTime.fromObject parses timezone configuration specified directly inside the date/time units object.

    MeasuredDateTime.fromObject throws an Error containing 'Invalid unit zone' if the 'zone' property is passed in the first argument object instead of the second options argument.

  7. npmSample contractnode · linux/x64jest@30.4.2

    Believedexpect(received).toEqual(expected) and expect(received).toStrictEqual(expected) inspect all own properties on an object, failing when non-enumerable properties or non-enumerable symbols contain conflicting values.

    Measuredexpect(received).toEqual(expected) and expect(received).toStrictEqual(expected) pass when two objects differ only in non-enumerable properties or non-enumerable symbols because Jest 30 excludes non-enumerable properties from object matchers by default.

  8. npmSample contractnode · linux/x64jest@30.4.2

    BelievedPassing an empty array to test.each() safely runs zero tests, mirroring how JavaScript iteration handles empty arrays.

    MeasuredCalling test.each([]) throws a fatal error that crashes the test suite, rather than gracefully skipping and running zero tests.

  9. npmSample contractnode · linux/x64jest@30.4.2

    BelievedA developer might expect that resetting Jest's module cache with jest.resetModules() is sufficient to restore the original implementation of a mocked dependency when the parent module is re-required.

    Measuredjest.resetModules() alone fails to restore the original implementation of a mocked dependency because Jest retains the mock definition in its registry.

  10. npmSample contractnode · linux/x64jest@29.7.0

    BelievedbeforeEach and afterEach hooks run for every test block defined in the file, including concurrent tests.

    Measuredtest.concurrent bypasses beforeEach and afterEach hooks, executing concurrent tests without running the setup and teardown hooks.

  11. npmSample contractnode · linux/x64jest@29.7.0

    BelievedJest's expect(a).toEqual(b) and expect(a).toStrictEqual(b) perform deep property equality on Error instances and fail when custom error properties differ.

    Measuredexpect(errA).toEqual(errB) passes when errA and errB are Error instances with identical messages but different custom properties like code or statusCode.

  12. npmSample contractnode · linux/x64jest@30.4.2

    Believedjest.isolateModules isolates module mocking performed with jest.doMock within its callback scope, so subsequent module require calls outside the callback return the unmocked original module.

    MeasuredCalling jest.doMock inside a jest.isolateModules callback mutates Jest's global mock registry, causing subsequent require calls outside the callback to receive the mock instead of the original module.

  13. npmSample contractnode · linux/x64jest@29.7.0

    BelievedJest automatically clears mock function call history between tests by default.

    MeasuredMock function call history is not cleared between tests by default, so a mock function called in a previous test retains its calls in subsequent tests unless clearMocks is explicitly enabled.

  14. npmSample contractnode · linux/x64jest@29.7.0

    BelievedCalling jest.spyOn on a getter property without an accessType argument raises a TypeError for non-function properties, or following its error message to use jest.replaceProperty successfully mocks the property value.

    Measuredjest.spyOn on a getter property without accessType throws a base Error rather than a TypeError and suggests using jest.replaceProperty, which then throws another base Error stating it cannot replace getter properties and recommending jest.spyOn(object, property, 'get').

  15. npmSample contractnode · linux/x64jest@29.7.0

    BelievedA test setup file configured under setupFiles has access to test framework globals like beforeEach, afterEach, and expect.extend.

    Measuredassert running Jest with test framework hooks in setupFiles fails with ReferenceError: beforeEach is not defined because the framework environment is not yet initialized

  16. npmSample contractnode · linux/x64jest@30.4.2

    BelievedCalling jest.resetAllMocks() restores functions spied on with jest.spyOn() back to their original unmocked implementation.

    Measuredjest.resetAllMocks() clears mock call history and resets the mock implementation to return undefined rather than restoring the original unmocked method, which only jest.restoreAllMocks() or spy.mockRestore() performs.

  17. npmSample contractnode · linux/x64jest@30.4.2

    BelievedA named ESM import from such a CommonJS module should always resolve to the corresponding own-property function export.

    MeasuredJest 30.4.2 keeps named imports working for a CommonJS module where `module.exports` is a function with own-property exports.

  18. npmSample contractnode · linux/x64happy-dom@20.11.2

    BelievedHappy DOM writes console output directly to the host console, and filtering virtual console output leaves unmatched entries queued for a later read.

    MeasuredA default Window buffers log, warn, and error calls as exact structured entries with type, level, message, and null group metadata

  19. npmSample contractnode · linux/x64happy-dom@20.11.2

    BelievedThe CSS attribute selector [attr~="val"] treats hyphens as word boundaries and matches substrings in hyphenated attribute values.

    Measuredchild.matches('[data-controller~="modal"]') returns false against data-controller="modal-auto-close" rather than true, because [attr~="val"] matches only whitespace-separated tokens per CSS Selectors Level 4

  20. npmSample contractnode · linux/x64express@4.18.2

    BelievedAll registered synchronous handlers on a single route will execute in sequence regardless of the stack size exceeding 100 handlers.

    MeasuredExpress 4.18.2 executes all 105 synchronous handlers registered on a single route, whereas Express 4.18.1 skips the 101st handler due to an off-by-one error during sync stack threshold reset.

  21. npmSample contractnode · linux/x64express@5.2.1

    Believedreq.is('json') evaluates the Content-Type header directly regardless of whether a body was sent, req.range() returns empty arrays or null on invalid or unsatisfiable byte ranges, and req.accepts() returns true for any media type mentioned in the Accept header.

    Measuredreq.is('json') returns null when the request lacks body headers such as Content-Length or Transfer-Encoding even if Content-Type application/json is present, returning the matched type string only when a body is actually transmitted

  22. npmSample contractnode · linux/x64express@4.22.2

    BelievedExpress executes middlewares and route handlers in strict sequential order, preventing subsequent routes from running until preceding async middlewares complete and call next().

    MeasuredA downstream route handler is executed before a preceding async middleware completes if an earlier middleware calls next() twice.

  23. npmSample contractnode · linux/x64es-toolkit@1.50.0

    BelievedPassing { leading: true, trailing: false } to debounce executes immediately on the first call and prevents delayed execution on the trailing edge.

    MeasuredPassing { leading: true, trailing: false } to es-toolkit debounce fails to invoke immediately because edges defaults to ['trailing'] unless configured as { edges: ['leading'] }, while trailing execution still fires on timeout.

  24. npmSample contractnode · linux/x64express@4.21.2

    BelievedExpress identifies error-handling middleware by checking if the first argument is an error or omitting the unused next parameter like (err, req, res) still catches errors passed to next(err).

    MeasuredExpress skips 3-parameter error handlers (err, req, res) during error routing because it identifies error middleware solely by checking fn.length === 4, executing only 4-parameter functions (err, req, res, next) while running 3-parameter functions on normal requests with shifted arguments

  25. npmSample contractnode · linux/x64core-js@3.50.0

    BelievedA core-js-provided URL.prototype.toJSON dynamically calls the current URL.prototype.toString, so reassigning toString later also changes toJSON output.

    MeasuredWhen the host URL.prototype.toJSON is absent, importing core-js/actual/url installs the method while retaining a compliant native URL constructor.

How to check any line here

Open the sample, read its contract, run it. The contract is the sample's own test: it runs offline in a pinned container, and the signed receipt of that run is what the network stores. Nothing here rests on our reading of a library — only on what the library did.

Some published samples are not on this page. Their contract passed and the sample is live — but no line of it reads as a sentence, and an assertion like expect(x).toBe(1) tells a reader nothing beside the belief it checks. Those are left out rather than printed as evidence nobody can read.