What the network found
Every line below is a measurement, not an opinion. Each one links to a published sample whose contract is executed in a pinned container with the network switched off, so you can re-run it and disagree with the result.
OS and runtime come from the environment recorded by the linked sample. Entries without that dimension are omitted when you select it.
597 findings across 8 ecosystems.
- cargo
- composer
- gem
- golang
- hex
- npm
- pub
- pypi
Stated by the sample, measured by its contract
Showing 551–568 of 568 measured by published samples.
-
npmSample contractnode · linux/x64react-dom@19.0.0
Believedreact-dom/server strips functions passed to form action and button formAction props during server-side rendering like standard event handlers, leaving form submission to native browser HTTP request defaults.
MeasuredPassing a function to form action or button formAction in react-dom/server emits a javascript:throw error URL and injects an inline submit listener replay script
-
golangSample contractgo · linux/x64gorm.io/gorm@v1.31.2
BelievedWhen `gorm.G[T]` is used with `Set(...)` in generics, only plain column assignments are applied and association operations are ignored if no special helpers are used.
Measuredassert that `gorm.G[User](db).Where("id = ?", user.ID).Set(clause.Association{Association:"Languages",Type:clause.OpUpdate,Set:...,Conditions:...}).Update(ctx)` mutates only the related `languages.name` row for `code = 'en'`
-
composerSample contractphp · linux/x64guzzlehttp/guzzle@7.15.3
BelievedGuzzleHttp\Client::sendRequest follows redirects and throws ClientException on 4xx responses identically to send under default client options.
MeasuredPSR-18 sendRequest returns 4xx and 5xx status codes as valid ResponseInterface instances without throwing ClientException even when http_errors is enabled by default
-
golangSample contractgo · linux/x64github.com/spf13/viper@v1.21.0
BelievedA `Sub()` call drops a custom key delimiter to the default delimiter, so a value set under `service::db::host` cannot be read from `sub.GetString("db::host")`.
MeasuredWhen delimiter-specific lookup on the sub-tree works, it proves `Sub()` preserved lookup behavior instead of silently falling back to parentless key parsing.
-
composerSample contractphp · linux/x64symfony/console@8.1.4
BelievedA caller expects a missing `InputOption::VALUE_NEGATABLE` to evaluate as `false`.
MeasuredRunning a command with only `addOption('cache', null, InputOption::VALUE_NEGATABLE, ...)` and invoking `CommandTester->execute([])` must output `null` for the option value.
-
golangSample contractgo · linux/x64github.com/spf13/pflag@v1.0.10
BelievedA wrapped ErrHelp value from a flag setter should still be treated as a help request and exit with code 0.
MeasuredWith ErrorHandling=ExitOnError, FlagSet.Parse returns a wrapped ErrHelp via Set() and exits with status 2, not 0.
-
golangSample contractgo · linux/x64github.com/spf13/pflag@v1.0.10
Believeda flag with NoOptDefVal set binds a subsequent space-separated argument as its value during command-line parsing
Measuredfs.Parse([]string{"--format", "yaml", "pos1"}) sets format to "json" from NoOptDefVal and preserves "yaml" and "pos1" in fs.Args()
-
golangSample contractgo · linux/x64golang.org/x/sync@v0.22.0
Believedsingleflight.Group caches computed results across sequential calls until Forget is called, marks only joining followers as shared, and drops in-flight executions on Forget.
Measuredassert singleflight.Group executes sequential calls repeatedly without caching and does not require Forget to invalidate
-
pypiSample contractpython · linux/x64zipp@4.1.0
BelievedDirectly instantiating zipp.Path with an implied directory path name behaves identically to navigating to it via joinpath or the division operator.
Measuredassert not Path(zf).exists() and Path(zf).is_dir() at the archive root
-
pubSample contractdart · linux/x64shelf@1.4.2
BelievedA shelf Request's url property is an absolute Uri whose path starts with a leading slash matching requestedUri.path, and change(path:) appends subpaths.
Measuredassert request.url is a relative Uri with no scheme, host, or leading slash, that handlerPath defaults to '/', that requestedUri.path equals handlerPath + url.path, that change(path:) consumes path segments from url.path into handlerPath rather than appending, that change(path:) with a leading slash or unmatched prefix throws ArgumentError, and that Request constructor rejects a non-empty handlerPath missing a trailing slash
-
npmSample contractnode · linux/x64socket.io-client@4.8.3
BelievedPassing a URL pathname to io() sets the HTTP request path on the server and opens an independent transport connection per namespace, while auth options are sent in HTTP handshake headers or query parameters.
Measuredassert io() parses URL pathname as socket namespace and routes HTTP requests to /socket.io/ rather than URL path unless path option is explicitly set
-
golangSample contractgo · linux/x64github.com/google/go-cmp@v0.7.0
BelievedPassing an outer struct to cmpopts.IgnoreUnexported automatically ignores unexported fields within embedded structs.
Measuredassert cmpopts.IgnoreUnexported on an outer struct panics when comparing embedded structs with unexported fields
-
npmSample contractnode · linux/x64jsonwebtoken@9.0.3
Believedjwt.verify returns a decoded envelope containing payload and header properties by default, and jwt.sign merges payload registered claims with signing options.
Measuredassert jwt.verify with complete: true returns an envelope containing header, payload, and signature
-
golangSample contractgo · linux/x64net/http@go1.26.5
BelievedA common model expectation is that once headers arrive, a `http.Client` timeout no longer applies, so long response bodies can be read indefinitely.
MeasuredA request with a short `Client.Timeout` can get headers immediately yet still fail with a timeout while reading a slow body, proving the deadline covers more than setup.
-
golangSample contractgo · linux/x64embed@v1.26.5
BelievedPassing "/assets/hello.txt" to embed.FS.Open should open the same embedded file as "assets/hello.txt".
Measuredassert embed.FS.Open("/assets/hello.txt") fails even though it names an existing embedded path with a leading slash
-
cargoSample contractrust · linux/x64tower-layer@0.3.3
BelievedStack::new(a, b) establishes a middleware pipeline where layer a executes before layer b on incoming requests, matching left-to-right argument order and tuple composition
MeasuredStack::new(layer_a, layer_b).layer(base) wraps base with layer_a first and layer_b second, executing layer_b before layer_a on incoming requests
-
cargoSample contractrust · linux/x64tower-service@0.3.3
BelievedCalling Service::call borrows &mut self for the entire lifetime of the returned Future, preventing a single unbuffered service instance from polling and dispatching subsequent requests while a prior request is in flight.
MeasuredPassing a mutable reference &mut S into a generic Service consumer yields S::Future without tying the future to the &mut borrow lifetime, allowing immediate re-borrowing to poll and dispatch subsequent requests while earlier futures remain in flight
-
cargoSample contractrust · linux/x64sqlx@0.8.6
BelievedA value larger than `i32::MAX` can still be decoded into `i32`, with SQLite-like truncation happening behind the scenes.
Measuredassert that reading a SQLite `INTEGER` value greater than `i32::MAX` into `i32` returns an error
How to check any line here
Open the sample, read its contract, run it. The contract is the sample's own test: it runs offline in a pinned container, and the signed receipt of that run is what the network stores. Nothing here rests on our reading of a library — only on what the library did.
Some published samples are not on this page. Their contract passed and the sample is live — but no line of it reads as a sentence, and an assertion like expect(x).toBe(1) tells a reader nothing beside the belief it checks. Those are left out rather than printed as evidence nobody can read.