What the network found
Every line below is a measurement, not an opinion. Each one links to a published sample whose contract is executed in a pinned container with the network switched off, so you can re-run it and disagree with the result.
OS and runtime come from the environment recorded by the linked sample. Entries without that dimension are omitted when you select it.
597 findings across 8 ecosystems.
- cargo
- composer
- gem
- golang
- hex
- npm
- pub
- pypi
Stated by the sample, measured by its contract
Showing 51–75 of 568 measured by published samples.
-
npmSample contractnode · linux/x64core-js@3.42.0
BelievedConfiguring core-js with useNative prevents polyfills from being installed even when the target feature is completely missing from the environment.
MeasuredCalling core-js/configurator with usePolyfill forces replacement of compliant native methods upon module import, whereas useNative preserves native implementations but still installs polyfills when the target property is undefined.
-
npmSample contractnode · linux/x64three@0.185.1
BelievedCloning an InterleavedBufferAttribute preserves its interleaved layout and BufferAttribute.needsUpdate is a readable boolean flag.
MeasuredBufferGeometry.clone preserves shared InterleavedBuffer instances across attributes while standalone InterleavedBufferAttribute.clone de-interleaves into standard BufferAttribute, and BufferAttribute.needsUpdate is a write-only setter that increments version rather than exposing a readable boolean property.
-
npmSample contractnode · linux/x64es-toolkit@1.50.0
BelievedInstantiating or catching AbortError yields an error object whose name property is 'AbortError' and code is 20 (DOMException.ABORT_ERR).
MeasuredAbortError instances have name set to 'Error' and code set to 0 rather than 'AbortError' and 20 because its constructor extends DOMException and invokes super(message) without the name argument
-
npmSample contractnode · linux/x64@babel/core@7.22.5
Believeda naive model expects transformFromAstSync can transform arbitrary AST nodes like statements or expressions in-place, but it strictly requires a Program or File root node and clones the input by default
MeasuredtransformFromAstSync throws if the AST root is not a Program or File node, refusing to transform individual statements.
-
npmSample contractnode · linux/x64@babel/core@7.24.0
Believedbabel.parseSync returns a standard ESTree Program AST node whose top-level body property directly contains statements, and defaults non-module code to script sourceType.
Measuredbabel.parseSync returns a File AST node where statements are nested under ast.program.body while root ast.body is undefined, and defaults ast.program.sourceType to module.
-
npmSample contractnode · linux/x64@babel/core@7.22.5
BelievedtransformFromAst accepts options as its second parameter in transformFromAst(ast, options) like transform(code, options), applying plugins directly
MeasuredtransformFromAst(ast, options) treats the options object as the raw code string and leaves options undefined, generating code without applying plugins
-
npmSample contractnode · linux/x64fast-glob@3.3.3
BelievedA slashless pattern like *.txt matches nested files across subdirectories by default, and a negative-only pattern array discovers all unmatched files.
Measuredfg with baseNameMatch expands slashless patterns like *.txt to match nested files at any depth while default matching is restricted to the search root.
-
npmSample contractnode · linux/x64minimatch@10.1.1
Believedpatterns starting with a hash character match literal hash-prefixed filenames by default
Measuredassert minimatch treats leading hash characters as comments that match nothing by default, requiring nocomment or backslash escaping to match literal hashes
-
pypiSample contractpython · linux/x64polars-runtime-32@1.43.2
BelievedMutating the POLARS_ENGINE_AFFINITY environment variable at runtime immediately updates the engine affinity of the polars runtime, and setting an unrecognized engine name raises an exception.
MeasuredIn-process mutations to POLARS_ENGINE_AFFINITY do not take effect until config_reload_env_var is explicitly invoked, and unrecognized engine names fall back to auto rather than raising an exception.
-
golangSample contractgo · linux/x64golang.org/x/sync@v0.22.0
BelievedCalling CompareAndSwap with an old value of nil acts as an insert-if-absent operation by treating unassigned keys as having a nil value.
MeasuredCompareAndSwap on an absent key returns false when old is nil, but succeeds and returns true when the key was explicitly stored with nil
-
golangSample contractgo · linux/x64go.opentelemetry.io/otel@v1.35.0
Believedattribute.NewSet copies the provided slice to avoid mutating the caller's arguments, leaving the original variadic slice unchanged.
Measuredattribute.NewSet mutates the provided slice in place to sort it and deduplicate, leaving discarded duplicates at the beginning and the unique set at the end.
-
golangSample contractgo · linux/x64go.opentelemetry.io/otel/sdk@v1.35.0
BelievedA model assumes passing a zero-valued SpanLimits struct or partially specified limits to WithRawSpanLimits applies default limits for unmentioned fields or allows unlimited telemetry, whereas WithRawSpanLimits applies zero values verbatim, truncating string attributes to empty strings and dropping all events and links.
MeasuredSpanLimits passed with uninitialized zero values to WithRawSpanLimits truncates all string attribute values to empty strings and drops all events and links because zero values are applied verbatim rather than falling back to defaults
-
golangSample contractgo · linux/x64go.opentelemetry.io/otel/sdk@v1.35.0
BelievedA model expects span limits to apply a uniform eviction strategy across all collections, truncate string attributes by byte count, and enforce AttributeValueLengthLimit across span, event, and link attributes identically.
Measuredsdktrace.WithSpanLimits applies tail-drop to span attributes while applying FIFO eviction to span events and links when count limits are exceeded.
-
golangSample contractgo · linux/x64github.com/jackc/pgx/v5@v5.10.0
Believedtx.Exec returns standard sql.Result types, allows execution after transaction commit or rollback, and leaves transactions permanently broken upon query failure without savepoint recovery
Measuredpgx.Tx.Exec returns a structured pgconn.CommandTag with RowsAffected and command predicates rather than sql.Result, and immediately rejects execution on committed or rolled back transactions with ErrTxClosed
-
golangSample contractgo · linux/x64github.com/gin-gonic/gin@v1.12.0
BelievedShouldBindJSON caches the request body to allow multiple binds on the same context, and requires an application/json Content-Type header before parsing.
MeasuredShouldBindJSON consumes the request body stream directly without caching, causing any subsequent ShouldBindJSON call on the same context to return io.EOF.
-
npmSample contractnode · linux/x64minimatch@10.1.1
Believedminimatch.unescape strips backslash escape sequences under windowsPathsNoEscape mode and preserves brace escapes by default
Measuredminimatch.unescape preserves backslash sequences under windowsPathsNoEscape mode because backslashes are treated as path separators rather than escape characters
-
npmSample contractnode · linux/x64@babel/core@7.24.0
Believedbabel.transformFromAstSync includes the processed AST in its return object by default, since it is an AST-focused API.
Measuredbabel.transformFromAstSync returns a null ast property by default to save memory, rather than returning the processed AST
-
golangSample contractgo · linux/x64github.com/caddyserver/caddy/v2@v2.11.4
BelievedThe filter log encoder requires an explicit wrapped encoder format and uses dot notation for nested log field paths.
MeasuredCaddy's filter log encoder module (caddy.logging.encoders.filter) intercepts zap log fields and filters nested object paths delimited by '>' before delegating encoding to a wrapped encoder, defaulting to JSON when wrap is unconfigured.
-
golangSample contractgo · linux/x64github.com/jackc/pgx/v5@v5.10.0
Believedpgconn.PgError.Error() includes diagnostic details such as Detail, Hint, and ConstraintName in its formatted error string.
Measuredpgconn.PgError.Error() formats only the severity, message, and SQLSTATE code, leaving Detail, Hint, and constraint metadata accessible exclusively through struct fields
-
pypiSample contractpython · linux/x64numpy@2.5.2
Believednumpy.asarray with copy=False creates an ndarray from any sequence without raising an exception
Measurednumpy.asarray with copy=False raises ValueError when a copy cannot be avoided for Python sequences or incompatible dtypes
-
golangSample contractgo · linux/x64github.com/caddyserver/caddy/v2@v2.11.4
BelievedEvaluating ReplaceKnown on an unset http.vars placeholder leaves the placeholder token unreplaced in the string because the variable was never defined.
MeasuredThe caddyhttp replacer recognizes all {http.vars.*} placeholders as known and replaces unset variables with the fallback string in ReplaceKnown rather than leaving them unreplaced.
-
npmSample contractnode · linux/x64three@0.185.1
BelievedACESFilmicToneMapping is an object or tone mapping pass class rather than an integer mode constant (4) consumed by WebGL and WebGPU pipelines.
MeasuredACESFilmicToneMapping is exported as the integer constant 4 across root and webgpu entrypoints, identifying the ACES Filmic curve in ShaderChunk and ToneMappingNode pipelines.
-
npmSample contractnode · linux/x64marked@18.0.5
Believedmarked.parse automatically returns a Promise and awaits token transformations whenever an asynchronous walkTokens handler or async hook is provided.
Measuredmarked.parse with an asynchronous walkTokens handler returns a rendered HTML string synchronously without awaiting token transformations unless the async: true option is explicitly provided.
-
golangSample contractgo · linux/x64github.com/caddyserver/caddy/v2@v2.10.0
BelievedCaddyfile log output file blocks accept roll_interval to schedule time-based log rotation.
MeasuredParsing a Caddyfile log output file block containing roll_interval fails with an unrecognized subdirective error.
-
golangSample contractgo · linux/x64github.com/caddyserver/caddy/v2@v2.11.4
BelievedThe filter.hash log filter replaces field values with a full 64-character SHA-256 hexadecimal hash string.
MeasuredCaddy's filter.hash log filter module (caddy.logging.encoders.filter.hash) replaces string log field values with an 8-character hexadecimal string representing the first 4 bytes of their SHA-256 hash.
How to check any line here
Open the sample, read its contract, run it. The contract is the sample's own test: it runs offline in a pinned container, and the signed receipt of that run is what the network stores. Nothing here rests on our reading of a library — only on what the library did.
Some published samples are not on this page. Their contract passed and the sample is live — but no line of it reads as a sentence, and an assertion like expect(x).toBe(1) tells a reader nothing beside the belief it checks. Those are left out rather than printed as evidence nobody can read.