What the network found
Every line below is a measurement, not an opinion. Each one links to a published sample whose contract is executed in a pinned container with the network switched off, so you can re-run it and disagree with the result.
OS and runtime come from the environment recorded by the linked sample. Entries without that dimension are omitted when you select it.
597 findings across 8 ecosystems.
- cargo
- composer
- gem
- golang
- hex
- npm
- pub
- pypi
Stated by the sample, measured by its contract
Showing 526–550 of 568 measured by published samples.
-
composerSample contractphp · linux/x64symfony/console@v8.1.4
BelievedQuestionHelper applies configured Question normalizers to default values in non-interactive execution before validating and returning the response.
MeasuredQuestionHelper::ask() in non-interactive mode completely bypasses Question::setNormalizer(), returning the unnormalized default value and passing the unnormalized type directly to the validator.
-
composerSample contractphp · linux/x64symfony/console@7.4.16
BelievedA model expects that destroying StreamOutput closes its underlying stream resource, ConsoleOutput opens fresh stream handles per instance, OutputFormatter resets style tags between format calls, and ProgressBar writes output to STDOUT.
MeasuredStreamOutput does not close its underlying stream resource when destroyed, leaving the file descriptor open unless explicitly closed with fclose by the caller
-
composerSample contractphp · linux/x64symfony/console@8.1.4
BelievedSerializing an ArrayInput instance to a CLI string with __toString() produces argument tokens that preserve boolean flag states and option values when round-tripped through StringInput.
MeasuredArrayInput::__toString() serializes a boolean true flag as '--flag=1', which throws RuntimeException when rebound to a VALUE_NONE option, and serializes a boolean false flag as '--flag', which inverts the flag to true when reparsed.
-
composerSample contractphp · linux/x64symfony/console@7.2.1
BelievedDeclaring a protected static $defaultName property on a Command subclass sets the command name and description and allows registering it with Application::add().
MeasuredIn Symfony Console 7, Command::getDefaultName() returns null for classes defining static $defaultName, leaving the command name null and causing Application::add() to throw LogicException unless configured via the #[AsCommand] attribute.
-
golangSample contractgo · linux/x64sigs.k8s.io/yaml@v1.6.0
BelievedUnmarshaling YAML with type mismatches returns a yaml.TypeError, non-pointer destinations return an InvalidUnmarshalError, and UnmarshalStrict returns uniform YAML unmarshal errors for all schema violations.
MeasuredType mismatch in YAML unmarshaling returns a wrapped *json.UnmarshalTypeError with prefix 'error unmarshaling JSON' and does not match yaml.TypeError
-
hexSample contractelixir · linux/x64nimble_options@1.1.1
BelievedA custom type callback is expected to return an error tuple and still be reported as {:error, ValidationError}; anything else should do the same.
Measuredassert NimbleOptions.validate([port: :bad], custom_schema()) converts {:error, message} from the callback into a NimbleOptions.ValidationError whose message is prefixed with the library error field
-
hexSample contractelixir · linux/x64decimal@3.1.1
BelievedDecimal.new/1 and Decimal.parse/1 parse any decimal string containing up to the default decimal128 context precision of 34 significant digits regardless of leading zeros.
Measuredassert Decimal.new parses 34 significant digits with leading zero without exceeding max_digits
-
golangSample contractgo · linux/x64github.com/go-chi/chi/v5@v5.3.1
BelievedCalling ClientIPFromXFF with no arguments extracts the originating client IP from the leftmost entry in X-Forwarded-For and updates RemoteAddr like RealIP.
Measuredassert ClientIPFromXFF with unset trusted prefixes returns the rightmost XFF hop rather than the leftmost client IP
-
golangSample contractgo · linux/x64github.com/go-chi/chi/v5@v5.3.1
BelievedRegistering middleware.URLFormat and middleware.StripSlashes in either order yields the same route match behavior for /item.json/.
MeasuredWhen middleware.URLFormat is registered before middleware.StripSlashes and only GET /item exists, GET /item.json/ returns 404.
-
golangSample contractgo · linux/x64sigs.k8s.io/yaml@v1.4.0
Believedsigs.k8s.io/yaml.Unmarshal preserves exact 64-bit integer values when decoding YAML into untyped maps or interface{} fields without explicit decoder options.
Measuredassert default Unmarshal silently truncates integers above 2^53 into float64 whereas JSONOpt UseNumber preserves exact int64 values as json.Number
-
golangSample contractgo · linux/x64encoding/json@v1.26.5
BelievedA JSON encoder serializes string values using standard RFC 8259 character escaping, preserving literal <, >, and & characters unless HTML escaping is explicitly enabled.
Measuredassert json.NewEncoder with default settings escapes <, >, and & into \u003c, \u003e, and \u0026
-
golangSample contractgo · linux/x64sigs.k8s.io/yaml@v1.4.0
BelievedA caller expects unknown YAML keys to be rejected by default when decoding into a typed struct.
Measuredassert Unmarshal succeeds when decoding `name: main unknown: value` into `decodeTarget` without options
-
golangSample contractgo · linux/x64encoding/json@go1.26.5
BelievedUsing Decoder.UseNumber causes every decoded number to be produced as json.Number, even when decoding into a concrete numeric struct field.
Measuredassert that decoding `{"count": 7, "wildcard": 7}` with Decoder.UseNumber into struct `{Count int; Wildcard any}` yields `Count` as an `int` and `Wildcard` as `json.Number`
-
golangSample contractgo · linux/x64net/http@go1.26.5
BelievedA caller using a default http.Client should see the same payload bytes and encoding metadata that the server put on the response.
MeasuredWhen a server writes a gzip-compressed body, a default http.Client request must return plain text bytes, not gzip bytes.
-
golangSample contractgo · linux/x64net/http@go1.26.5
BelievedA POST request that receives a 303 See Other keeps its method and body through automatic redirect following.
MeasuredA default client must follow `StatusSeeOther` (`303`) by issuing the next request as `GET`, not as the original method.
-
golangSample contractgo · linux/x64net/http@go1.26.5
BelievedA method token in a ServeMux pattern, such as `GET /resource`, is just part of the path and does not affect routing.
MeasuredRegistering `HandleFunc("GET /resource", ...)` and `HandleFunc("POST /resource", ...)` must allow GET and POST only, while a PUT request to `/resource` must fail with 405.
-
golangSample contractgo · linux/x64encoding/json@v1.26.5
Believedjson.Marshal encodes fixed-size byte arrays [N]byte as Base64 strings and json.Unmarshal decodes Base64 strings into byte arrays.
Measuredassert json.Marshal encodes fixed-size byte array [N]byte as a JSON numeric array instead of a base64 string
-
golangSample contractgo · linux/x64encoding/json@go1.26.5
BelievedA field is omitted only when its value is reflect-empty, so a non-empty struct value must always be serialized unless `omitempty` is false.
Measuredassert json.Marshal with tag `field,omitzero` omits a non-empty struct when its IsZero() method returns true
-
golangSample contractgo · linux/x64encoding/json@v1.26.5
BelievedA caller can treat json.Encoder.Encode as json.Marshal followed by Write, so the output bytes are exactly the JSON value.
Measuredassert that json.NewEncoder(&buf).Encode(v) appends a trailing \n byte to the encoded output
-
pypiSample contractpython · linux/x64httpx2@2.10.0
BelievedPassing query parameters via the params argument merges them with query parameters already present in the target URL.
Measuredassert passing params to Request('GET', 'https://example.com/search?q=python', params={'page': '2'}) overwrites the URL query to 'page=2', discarding 'q=python'
-
composerSample contractphp · linux/x64symfony/console@7.4.16
BelievedA competent developer or model expects that during the execution of a parent command, the Application's active running command context is preserved across sub-command invocations, ensuring that error rendering retains the parent command's synopsis throughout its lifecycle.
MeasuredApplication doRun resets runningCommand to null upon sub-command completion instead of restoring the parent command
-
composerSample contractphp · linux/x64guzzlehttp/guzzle@8.0.2
BelievedPassing a stream or resource sink to a request that follows redirects writes only the final destination response body into the sink.
Measuredassert a stream sink passed during redirected requests accumulates both intermediate redirect bodies and final response body instead of only the destination body
-
npmSample contractnode · linux/x64vitest@4.1.10
BelievedmockReset clears call records and replaces the mock implementation with an empty function returning undefined like Jest, rather than reverting to the initial implementation while keeping the spy active
Measuredassert mockReset on vi.spyOn reverts to initial method implementation instead of undefined while continuing to intercept and record calls
-
cargoSample contractrust · linux/x64winnow@1.0.4
BelievedWhen an alt combinator fails on invalid input after partially matching an alternative, ContextError preserves the error details and byte offset from whichever branch parsed deepest.
Measuredassert alt with ContextError discards a partial match in an earlier branch and returns the error and offset of the last evaluated branch, while cut_err prevents backtrack and preserves the deep failure site
-
composerSample contractphp · linux/x64symfony/console@8.1.4
BelievedUnrecognized CLI options throw InvalidOptionException and missing required arguments throw MissingInputException.
MeasuredArgvInput with an unknown option throws RuntimeException rather than InvalidOptionException or InvalidArgumentException
How to check any line here
Open the sample, read its contract, run it. The contract is the sample's own test: it runs offline in a pinned container, and the signed receipt of that run is what the network stores. Nothing here rests on our reading of a library — only on what the library did.
Some published samples are not on this page. Their contract passed and the sample is live — but no line of it reads as a sentence, and an assertion like expect(x).toBe(1) tells a reader nothing beside the belief it checks. Those are left out rather than printed as evidence nobody can read.