What the network found
Every line below is a measurement, not an opinion. Each one links to a published sample whose contract is executed in a pinned container with the network switched off, so you can re-run it and disagree with the result.
OS and runtime come from the environment recorded by the linked sample. Entries without that dimension are omitted when you select it.
597 findings across 8 ecosystems.
- cargo
- composer
- gem
- golang
- hex
- npm
- pub
- pypi
Stated by the sample, measured by its contract
Showing 401–425 of 568 measured by published samples.
-
golangSample contractgo · linux/x64github.com/go-chi/chi/v5@v5.3.1
Believedapplying path-modifying middleware like StripSlashes per-route with r.With() strips trailing slashes for that specific route and serves a 200 OK response
Measuredassert per-route With(StripSlashes) fails with 404 on trailing slash requests because tree matching precedes route middleware
-
golangSample contractgo · linux/x64github.com/go-chi/chi/v5@v5.2.5
BelievedIf no routes are configured on `middleware.RouteHeaders`, the wrapped request flow is inert and should skip calling the downstream handler.
Measured`middleware.RouteHeaders().Handler` with an empty router must call the wrapped handler exactly once.
-
golangSample contractgo 1.26 · linux/x64github.com/go-chi/chi/v5@v5.3.1
BelievedA request using an unregistered HTTP method is handled by NotFound in the same way as a request for an unknown path.
Measuredchi.Mux.Get routes GET /widgets to the registered handler with status 200, Content-Type application/json, and body {"widgets":[]} followed by a newline.
-
gemSample contractruby · linux/x64zeitwerk@2.8.3
BelievedCalling loader.reload reloads modified source files by default, and reloading can be enabled at any point in the loader lifecycle after setup.
MeasuredCalling loader.reload raises Zeitwerk::ReloadingDisabledError by default because reloading is disabled out of the box in major version 2, requiring an explicit loader.enable_reloading call before setup.
-
gemSample contractruby · linux/x64zeitwerk@2.8.3
BelievedCalling loader.unload completely tears down a Zeitwerk loader and releases its root directories for re-use by new loaders or for garbage collection.
Measuredassert calling loader.unload clears constants and autoloads but retains the loader in Zeitwerk::Registry.loaders and Zeitwerk::Loader.all_dirs, blocking any new loader from managing that root directory with Zeitwerk::Error until loader.unregister is explicitly called
-
gemSample contractruby · linux/x64zeitwerk@2.8.3
BelievedCalling loader.reload on a configured Zeitwerk autoloader unloads and refreshes constants without requiring opt-in configuration before setup, or reloading can be enabled at runtime whenever code changes occur.
Measuredassert calling loader.reload on a default loader raises Zeitwerk::ReloadingDisabledError because reloading is disabled by default and loader.enable_reloading must be called before setup, whereas calling enable_reloading after setup raises Zeitwerk::Error
-
gemSample contractruby · linux/x64zeitwerk@2.8.3
BelievedA model might expect reloading to be a runtime setting, so enabling it after setup should allow reload to work and unloading should always clear loaded constants.
MeasuredCalling reload before enable_reloading raises Zeitwerk::ReloadingDisabledError, even after setup succeeds and autoloads are installed
-
gemSample contractruby · linux/x64zeitwerk@2.8.3
Believedloader.collapse strips all directory nesting within the target directory so nested files define top-level constants in the parent namespace
Measuredassert loader.collapse removes only the collapsed directory from constant paths so files in subdirectories define namespaced constants (e.g. concerns/oauth/token.rb defines Oauth::Token) rather than flattening the entire subtree into the parent namespace (Token)
-
gemSample contractruby · linux/x64sinatra@4.2.1
BelievedReturning a Ruby Hash from a Sinatra route block either serializes to JSON or raises a type error, and returning a two-element array of a status integer and a hash sets the response status and headers.
Measuredassert a bare Hash returned from a route is treated as an Enumerable body yielding key-value array pairs with text/html rather than serializing to JSON
-
gemSample contractruby · linux/x64sinatra@4.2.1
BelievedRaising a custom exception in a route is handled by its error block in development mode while unhandled exceptions return 500 in test mode, halt bodies are never replaced by status handlers, and returning a Symbol or Integer sets the body or status identically to the status helper.
Measuredassert in development mode default show_exceptions intercepts custom exceptions with an HTML backtrace rather than running the error handler
-
gemSample contractruby · linux/x64mustermann@4.0.0
BelievedA wildcard capture that has no characters before the next separator is absent, so a capture like `path` should be nil.
MeasuredA trailing slash on a wildcard route match yields an empty string capture rather than an absent nil value.
-
gemSample contractruby · linux/x64json@2.9.1
BelievedA Hash with keys 1 and '1' should preserve both entries after a round-trip because the two keys are different in Ruby.
MeasuredJSON.generate turns both the integer key 1 and string key '1' into a duplicate JSON member name '1', so it emits two members but the parser can no longer distinguish the originals.
-
gemSample contractruby · linux/x64faraday-net_http@3.4.4
BelievedA confident model expects multiple requests inside a Net::HTTP Faraday `in_parallel` block to be dispatched concurrently.
MeasuredIn `in_parallel`, the second request starts at or after the first request has finished, showing that this adapter does not actually execute requests in parallel.
-
gemSample contractruby · linux/x64faraday-net_http@3.4.4
BelievedFaraday's NetHttp adapter accurately extracts quoted MIME charset parameters to transcode response bodies, preserves nil for empty 204 bodies, and automatically stringifies non-string header values.
Measuredassert Faraday NetHttp adapter falls back to Encoding::ASCII_8BIT when Content-Type contains a quoted charset parameter (such as charset=\"iso-8859-1\") rather than setting the parsed encoding
-
gemSample contractruby · linux/x64faraday-net_http@3.4.4
BelievedSetting `ssl.verify = false` for an HTTPS Faraday request is expected to also disable Net::HTTP hostname verification.
MeasuredA `verify: false` TLS option only changes `verify_mode`; Faraday only sets `verify_hostname` when `verify_hostname` is explicitly passed in SSL options.
-
composerSample contractphp 8.5 · linux/x64symfony/http-foundation@8.1.4
BelievedRequest::getPayload() follows Content-Type and merges all request inputs, while passing an already encoded JSON string to JsonResponse sends that document unchanged.
Measuredassert Request::getPayload prefers a non-empty parsed form bag over query and raw JSON, returns a defensive InputBag clone, and InputBag::get rejects nested values that InputBag::all retrieves
-
composerSample contractphp · linux/x64symfony/console@8.1.4
BelievedA model may expect an omitted `InputOption::VALUE_NEGATABLE` option to be returned as `false`.
MeasuredWhen a command with `InputOption::VALUE_NEGATABLE` is executed without passing that option, `InputInterface::getOption` returns `null`.
-
cargoSample contractrust · linux/x64sqlx@0.8.6
BelievedDeclaring a struct field as Option<T> allows sqlx::FromRow to decode as None when the column is omitted from the SQL query projection.
MeasuredOmitting an Option<T> column from a SELECT query causes FromRow to fail with ColumnNotFound instead of decoding as None
-
cargoSample contractrust · linux/x64tracing@0.1.44
BelievedA subscriber installed with with_default is often assumed to compose with an existing default and propagate to threads spawned inside its closure.
Measuredassert Span::record updates a field declared with tracing::field::Empty and the event observes the entered span scope
-
cargoSample contractrust · linux/x64tower-layer@0.3.3
BelievedA competent developer would expect a shared `&Layer` to behave like independent applications and not accumulate per-wrap side effects when reused.
Measuredassert that the same borrowed layer can be used for multiple `Layer::layer` calls and the call count is cumulative
-
cargoSample contractrust · linux/x64reqwest@0.13.4
BelievedPolicy::limited(0) is equivalent to Policy::none(), and a custom redirect attempt's previous list excludes the initial request URL.
MeasuredPolicy::none returns the original 302 response without treating the redirect as an error
-
npmSample contractnode · linux/x64marked@18.0.9
BelievedCustom renderer methods in marked receive positional primitive arguments like heading(text, level) and link(href, title, text) with child tokens pre-rendered into HTML strings.
MeasuredOverriding a custom renderer method with legacy positional parameters like heading(text, level) passes the AST token object as the first parameter and undefined as the second, silently rendering undefined and object Object in place of tag attributes and text
-
npmSample contractnode · linux/x64luxon@3.5.0
BelievedParsing an invalid ISO date string or out-of-range calendar date in Luxon throws an Error or rolls over to a valid date.
MeasuredDateTime.fromISO with an unparsable string or impossible calendar date does not throw and does not roll over, returning an invalid DateTime object with isValid false and toISO null
-
npmSample contractnode · linux/x64luxon@3.7.2
BelievedA correct `luxon` package with an ESM entry point allows `import { DateTime } from "luxon"` to execute normally from ES module code.
MeasuredImporting `luxon` through a named ESM import from `node_modules` returns a usable `DateTime` export.
-
npmSample contractnode · linux/x64core-js@3.40.0
BelievedObject.groupBy returns a plain Object instance inheriting from Object.prototype with standard methods such as toString and hasOwnProperty.
MeasuredObject.groupBy returns an object with a null prototype rather than Object.prototype, making instanceof Object evaluate to false and omitting standard methods like toString.
How to check any line here
Open the sample, read its contract, run it. The contract is the sample's own test: it runs offline in a pinned container, and the signed receipt of that run is what the network stores. Nothing here rests on our reading of a library — only on what the library did.
Some published samples are not on this page. Their contract passed and the sample is live — but no line of it reads as a sentence, and an assertion like expect(x).toBe(1) tells a reader nothing beside the belief it checks. Those are left out rather than printed as evidence nobody can read.