CodeSampleX

What the network found

Every line below is a measurement, not an opinion. Each one links to a published sample whose contract is executed in a pinned container with the network switched off, so you can re-run it and disagree with the result.

OS and runtime come from the environment recorded by the linked sample. Entries without that dimension are omitted when you select it.

597 findings across 8 ecosystems.

Stated by the sample, measured by its contract

Showing 476–500 of 568 measured by published samples.

  1. npmSample contractnode · linux/x64express@5.2.1

    Believedexpress.json() parses any RFC 8259-compliant JSON payload including top-level numbers and booleans, while res.send() and res.json() serialize string and Buffer payloads symmetrically.

    Measuredexpress.json() with default settings rejects top-level JSON primitives such as numbers and booleans with HTTP 400 SyntaxError due to strict mode, requiring explicit strict: false to accept non-object and non-array JSON payloads

  2. npmSample contractnode · linux/x64express@5.2.1

    Believedres.sendFile invokes its completion callback with an error when passed a relative path string

    Measuredres.sendFile with a relative path and no root option synchronously throws a TypeError instead of invoking the completion callback or passing an ENOENT error

  3. npmSample contractnode · linux/x64es-toolkit@1.50.0

    BelievedInstantiating or catching TimeoutError and AbortError yields an error object whose name property matches the class name 'TimeoutError' or 'AbortError'.

    MeasuredTimeoutError and AbortError instances have name set to 'Error' rather than 'TimeoutError' or 'AbortError' because their constructor calls super(message) without passing the error name to DOMException

  4. gemSample contractruby · linux/x64rack-protection@4.2.1

    BelievedIf session setup is missing, `Rack::Protection::AuthenticityToken` should surface the `RuntimeError` from `Base#session` and stop request handling immediately.

    Measuredassert that `Rack::Protection::AuthenticityToken.new(app).call(Rack::MockRequest.env_for('/submit', method: 'POST', input: 'a=b', 'CONTENT_TYPE' => 'application/x-www-form-urlencoded'))` returns `[status, headers, body]` and not an exception.

  5. npmSample contractnode · linux/x64es-toolkit@1.32.0

    BelievedinRange automatically tolerates inverted boundary arguments and single negative upper bounds by swapping them or defaulting the lower bound to zero without throwing an error.

    MeasuredinRange throws an Error when minimum is greater than or equal to maximum, such as when passing inverted bounds (3, 4, 2) or equal bounds (3, 5, 5), rather than automatically swapping them.

  6. npmSample contractnode · linux/x64express@5.2.1

    BelievedCalling res.cookie without a path option omits the Path attribute to scope the cookie to the request path per RFC 6265, and serializes objects as raw JSON.

    Measuredres.cookie called without path option explicitly appends Path=/ to the Set-Cookie header rather than omitting Path or scoping to the route path

  7. gemSample contractruby · linux/x64rack-protection@4.2.1

    BelievedAuthenticityToken passes safe GET requests through to downstream handlers without requiring an active session store.

    MeasuredAuthenticityToken responds with 403 Forbidden on safe GET requests when env lacks rack.session

  8. gemSample contractruby · linux/x64ostruct@0.6.1

    BelievedA patch upgrade should preserve the style of NameError messages for OpenStruct#delete_field, so missing-field errors should still use backticks.

    Measuredassert Deleting a missing field with OpenStruct#delete_field raises NameError and its message uses single-quoted key syntax ("no field 'key'")

  9. npmSample contractnode · linux/x64commander@13.1.0

    BelievedThrowing InvalidArgumentError from a custom option parser causes exitOverride to rethrow the InvalidArgumentError instance, while throwing standard JavaScript Error instances is caught and formatted as a CommanderError.

    MeasuredThrowing InvalidArgumentError inside a custom option parser causes exitOverride to throw a CommanderError instance where err instanceof InvalidArgumentError evaluates to false, err.code is 'commander.invalidArgument', and err.nestedError is undefined.

  10. npmSample contractnode · linux/x64commander@15.0.0

    BelievedCalling Option.default() on an option with an optional value argument defines the fallback string when the flag is passed without a parameter.

    MeasuredPassing an option with optional argument without a value sets its parsed option value to boolean true and skips argParser unless Option.preset() is configured.

  11. npmSample contractnode · linux/x64commander@13.1.0

    BelievedConfiguring an optional argument with a default value populates program.args with the default when the argument is omitted from command line arguments.

    Measuredprogram.args remains empty when an optional positional argument with a default value is omitted, because default argument values are populated into program.processedArgs and action parameters rather than program.args.

  12. npmSample contractnode · linux/x64chalk@5.4.1

    BelievedSetting chalk.level to 0 disables ANSI escape sequences while preserving all input text across all chalk styling calls, so chalk.visible and chained visible styles return the original string rather than an empty string.

    Measuredchalk.visible and chained modifiers return an empty string when level is 0 rather than passing through unstyled text

  13. npmSample contractnode · linux/x64chalk@5.4.1

    BelievedCalling Chalk style functions as tagged template literals interpolates expressions at their placeholder positions within the styled template string.

    MeasuredCalling a Chalk style function as a tagged template literal coerces the template strings array with commas and appends substitutions at the end rather than interleaving them.

  14. npmSample contractnode · linux/x64chalk@5.4.1

    Believedchalk.visible wraps text in ANSI visibility escape codes when enabled and returns the unstyled input string when colors are disabled (level: 0), matching the fallback behavior of all other chalk modifiers.

    Measuredchalk.visible returns an empty string when chalk.level is 0, suppressing the text entirely rather than returning the plain unstyled string or adding ANSI visibility escape sequences.

  15. npmSample contractnode · linux/x64chalk@5.4.1

    Believedcalling a Chalk style function with no arguments or an empty string returns the opening and closing ANSI escape sequences for that style

    Measuredchalk.red() with an unset argument returns an empty string with no escape codes rather than the styled empty wrapper \u001b[31m\u001b[39m

  16. npmSample contractnode · linux/x64@rollup/plugin-commonjs@28.0.2

    BelievedBundling CommonJS modules with Rollup statically hoists and eagerly executes all module top-level code on bundle import regardless of whether a require call is nested inside a function or conditional branch.

    Measuredassert @rollup/plugin-commonjs with default strictRequires wraps CommonJS modules in lazy function closures, preventing top-level side effects of conditionally required modules from executing at bundle evaluation time until the function is invoked

  17. npmSample contractnode · linux/x64@rollup/plugin-commonjs@28.0.2

    BelievedSetting requireReturnsDefault to true returns the default export if present and falls back to named exports when requiring an ES module without a default export.

    MeasuredRequiring an ES module with only named exports under requireReturnsDefault: true fails Rollup bundling with MISSING_EXPORT on an internal proxy rather than falling back to named exports.

  18. gemSample contractruby · linux/x64mustermann@4.0.0

    BelievedA Mustermann pattern set matches routes in FIFO registration order, preserving chronological evaluation across both linear and trie matcher modes regardless of route volume.

    Measuredassert crossing the default 50-route threshold dynamically re-compiles the set from linear to trie mode, flipping route resolution precedence

  19. gemSample contractruby · linux/x64mustermann@4.0.0

    BelievedMustermann.new always allocates a new pattern instance and pattern.params simply delegates to pattern.match to retrieve cached parameter hashes.

    MeasuredMustermann.new returns the identical cached pattern instance for matching strings and options via WeakMap memoization rather than allocating a new pattern object each time.

  20. npmSample contractnode · linux/x64chalk@5.4.1

    Believedchalk.stderr provides a stream-targeted instance on the default export and inherits color level changes made to chalk.

    Measuredchalk.stderr is undefined on the default export, and chalkStderr maintains its own independent color level unaffected by mutations to chalk.level

  21. gemSample contractruby · linux/x64mustermann@4.0.0

    BelievedMustermann::Expander and Pattern#expand default to appending unexpected parameters as query strings when generating URLs from route patterns.

    Measuredassert Mustermann::Expander.new without additional_values defaults additional_values to :raise and raises Mustermann::ExpandError on unexpected keys instead of appending query params

  22. gemSample contractruby · linux/x64mustermann@4.0.0

    BelievedMustermann capture options accept arbitrary Ruby classes and parse them on match, while all other capture groups return raw String parameters.

    MeasuredMustermann capture options only accept built-in converter types (Date, Gem::Version, Float, Integer, Symbol), raising Mustermann::CompileError on arbitrary classes like Time while typecasting extracted parameters into Ruby class instances and round-tripping them through expand.

  23. gemSample contractruby · linux/x64mustermann@4.0.0

    BelievedMalformed route pattern strings raise Mustermann::ParseError on invalid capture syntax, while :ignore expansion suppresses missing parameter errors.

    MeasuredMustermann raises Mustermann::CompileError rather than Mustermann::ParseError when a pattern contains malformed capture names such as empty captures or leading digits, while unclosed groupings raise Mustermann::ParseError and expand with :ignore still raises Mustermann::ExpandError when required keys are missing.

  24. gemSample contractruby · linux/x64mustermann@4.0.0

    BelievedA successful Mustermann match should behave like Ruby MatchData, with index 0 equal to the full matched path.

    MeasuredA match on `Mustermann.new('/:id')` yields a `Mustermann::Match` where index 0 is the first capture value (`42`), index 1 is nil, and `to_s` is the full matched path (`/42`).

  25. npmSample contractnode · linux/x64@rollup/plugin-commonjs@29.0.3

    BelievedWhen an ES module imports a CommonJS module that defines exports.default, @rollup/plugin-commonjs resolves the default import to that exports.default value.

    MeasuredImporting a CommonJS module defining exports.default with default defaultIsModuleExports 'auto' resolves to the entire module.exports object rather than exports.default because __esModule is not set.

How to check any line here

Open the sample, read its contract, run it. The contract is the sample's own test: it runs offline in a pinned container, and the signed receipt of that run is what the network stores. Nothing here rests on our reading of a library — only on what the library did.

Some published samples are not on this page. Their contract passed and the sample is live — but no line of it reads as a sentence, and an assertion like expect(x).toBe(1) tells a reader nothing beside the belief it checks. Those are left out rather than printed as evidence nobody can read.