What the network found
Every line below is a measurement, not an opinion. Each one links to a published sample whose contract is executed in a pinned container with the network switched off, so you can re-run it and disagree with the result.
OS and runtime come from the environment recorded by the linked sample. Entries without that dimension are omitted when you select it.
597 findings across 8 ecosystems.
- cargo
- composer
- gem
- golang
- hex
- npm
- pub
- pypi
Stated by the sample, measured by its contract
Showing 76–100 of 568 measured by published samples.
-
gemSample contractruby · linux/x64activesupport@8.1.3.1
BelievedActiveSupport::TimeZone#parse retains the parsed string's offset or assigns wall-clock time directly without zone conversion, and raises ArgumentError on invalid date strings like standard Time.parse.
MeasuredActiveSupport::TimeZone#parse with an explicit UTC offset converts the instant into the receiver's time zone representation rather than retaining the string's offset or treating the wall-clock time as local.
-
pypiSample contractpython · linux/x64greenlet@3.5.4
BelievedA newly created greenlet automatically inherits the active contextvars context of the parent greenlet that spawned it, and setting context variables inside the greenlet alters the ambient context seen by the parent upon returning.
MeasuredA newly created greenlet starts with gr_context as None and executes within a fresh isolated contextvars Context that does not inherit the caller greenlet's ContextVar values, unless a Context is explicitly assigned to gr_context prior to switching.
-
golangSample contractgo · linux/x64gopkg.in/yaml.v3@v3.0.1
BelievedUnmarshaling a YAML mapping directly into *yaml.Node produces a MappingNode whose Content slice holds child values.
Measuredyaml.Unmarshal into *yaml.Node produces a root DocumentNode with Kind 1 whose Content slice wraps the top-level MappingNode (Kind 4) at index 0 rather than returning a MappingNode directly.
-
npmSample contractnode · linux/x64ajv@8.20.0
BelievedSetting removeAdditional true in Ajv options strips all undeclared properties from validated objects regardless of whether additionalProperties false is present in the schema
MeasuredAjv with removeAdditional true removes undeclared properties from validated objects only when additionalProperties false is explicitly specified in the schema, retaining undeclared properties when additionalProperties is omitted.
-
npmSample contractnode · linux/x64uuid@14.0.1
BelievedUUIDv1 strings sort chronologically by generation time, or converting between UUID versions requires manually decoding and recalculating timestamp fields
MeasuredUUIDv7 with identical timestamps sorts strictly by sequence number
-
cargoSample contractrust · linux/x64once_cell@1.21.4
BelievedA common belief is that OnceCell initialization failure permanently poisons the cell preventing subsequent retry, or that unsync::OnceCell allows recursive initialization without panicking.
Measuredget_or_try_init leaves the OnceCell uninitialized upon receiving Err, enabling subsequent initialization attempts to retry and succeed without cell poisoning
-
npmSample contractnode · linux/x64yoga-layout@3.2.1
BelievedSetting explicit dimensions with padding and border calculates content-box size like web CSS, and container overflow automatically shrinks child items without configuring web defaults.
MeasuredYoga 3 defaults node box-sizing to BoxSizing.BorderBox (0) where fixed dimensions include padding and border, expanding computed bounds only when switched to BoxSizing.ContentBox (1)
-
golangSample contractgo · linux/x64golang.org/x/sync@v0.22.0
Believedsingleflight.Group.DoChan returns a shared broadcast channel that closes after sending, blocks the worker if an abandoned caller stops receiving, and does not deduplicate against synchronous Do.
Measuredassert singleflight.Group.DoChan allocates a distinct buffered channel of capacity 1 for each caller so concurrent readers do not compete or consume each other's results
-
pypiSample contractpython · linux/x64pytest@9.0.3
Believedpytest.approx(0.0) matches small floating point numbers like 1e-7 using the default 1e-6 relative tolerance
Measuredpytest.approx(0.0) compares against zero using exclusively the absolute tolerance (defaulting to 1e-12) because relative tolerance scales to zero, causing 1e-7 == approx(0.0) to evaluate to False unless abs is explicitly set
-
npmSample contractnode · linux/x64lodash-es@4.18.1
BelieveddefaultsDeep returns a new cloned object without mutating the destination and concatenates or overwrites entire arrays when applying nested defaults.
MeasureddefaultsDeep mutates the destination object in-place and merges array elements index-by-index rather than replacing or concatenating them
-
golangSample contractgo · linux/x64github.com/jackc/pgx/v5@v5.10.0
BelievedCollectOneRow errors when multiple rows match, empty PostgreSQL ranges scan as Valid=false like SQL NULL, and PostgreSQL infinity timestamps scan into time.Time
MeasuredCollectOneRow consumes the first row without error on multi-row results whereas CollectExactlyOneRow rejects multiple rows with ErrTooManyRows
-
golangSample contractgo · linux/x64github.com/google/go-cmp@v0.7.0
BelievedStandard library error values can be compared directly with cmp.Equal or cmp.Diff like other basic Go types.
MeasuredComparing standard error values without cmpopts.EquateErrors panics at runtime because standard errors contain unexported struct fields
-
npmSample contractnode · linux/x64nanoid@6.0.1
BelievedNegative size arguments passed to nanoid/non-secure functions are expected to throw a RangeError matching cryptographic nanoid behavior.
Measurednanoid/non-secure functions return an empty string for negative or non-positive sizes rather than throwing RangeError like root nanoid
-
npmSample contractnode · linux/x64fs-extra@11.3.0
Believedfs.move overwrites existing destination files by default like fs.copy and Node's fs.rename, and requires destination parent directories to already exist
Measuredfs.move rejects with 'dest already exists.' when destination exists unless overwrite: true is explicitly passed, while fs.copy defaults overwrite to true
-
pypiSample contractpython · linux/x64markupsafe@3.0.3
Believedescape() decodes UTF-8 byte sequences before HTML-escaping them, and str.join() escapes raw strings when concatenating with Markup elements.
Measuredescape() converts bytes objects via str() to their literal repr 'b\'...\'' and escapes the resulting quotes rather than decoding UTF-8 bytes, requiring Markup(data, encoding) for explicit byte decoding.
-
pypiSample contractpython · linux/x64structlog@26.1.0
BelievedCalling bind_contextvars automatically propagates context variables to all structlog loggers without requiring merge_contextvars in the processor chain.
MeasuredCalling bind_contextvars has no effect on log output unless merge_contextvars is explicitly present in the processor chain, and bound logger fields override conflicting context variables.
-
pypiSample contractpython · linux/x64packaging@24.2
Believedparse_wheel_filename preserves unnormalized distribution names and parses build tags as plain strings or leaves compressed wheel tags unexpanded
Measuredparse_wheel_filename returns a 4-tuple of canonicalized name, parsed Version, integer-prefixed build tag tuple, and Cartesian-product expanded Tag frozenset, rejecting build tags without a leading digit.
-
golangSample contractgo · linux/x64google.golang.org/protobuf@v1.36.12
Believedproto.Merge replaces repeated slice fields with the source list and ignores explicit zero values for optional fields, while reflect.DeepEqual can safely compare protobuf messages.
Measuredproto.Merge appends repeated slice elements rather than replacing them, leaves destination scalars untouched when source holds implicit zero values, overwrites destination when source explicitly sets proto3 optional zero values, and recursively merges nested message fields.
-
pypiSample contractpython · linux/x64python-dotenv@1.2.2
BelievedA model would expect single quotes to expand escape sequences identically to double quotes, and for inline comments to consistently require or not require preceding whitespace.
Measureddotenv_values expands \n to an actual newline only inside double quotes, and treats # as a comment only if it follows a space (when unquoted) or immediately follows a closing quote.
-
pypiSample contractpython · linux/x64pycparser@2.22
Believedpycparser can automatically skip or handle standard preprocessor directives like #include when parsing C source.
MeasuredCParser().parse() raises ParseError with 'Directives not supported yet' when given C code containing #include <stdio.h>, rather than successfully ignoring or processing it.
-
golangSample contractgo · linux/x64github.com/lmittmann/tint@v1.2.0
Believedtint formats AddSource as a standard key-value attribute at the end of the log line matching slog.TextHandler conventions.
Measuredtint.NewTextHandler formats source code locations directly between the level badge and log message as a faint prefix instead of a trailing key-value pair, and allows complete suppression or replacement via ReplaceAttr
-
pypiSample contractpython · linux/x64markupsafe@3.0.3
BelievedMarkup.format() treats objects returning str from __html__() as pre-escaped HTML identically to escape() and % interpolation.
MeasuredMarkup.format() escapes plain str returns from __html__() into HTML entities because EscapeFormatter wraps format_field results in escape(), requiring __html__() to return Markup or define __html_format__ for unescaped formatting
-
cargoSample contractrust · linux/x64rustls@0.23.43
BelievedResolvesServerCertUsingSni accepts wildcard domain patterns or IP literals as registration keys and serves any mapped certificate without validating its Subject Alternative Names against the domain key
Measuredrustls ResolvesServerCertUsingSni::add strictly rejects wildcard patterns and IP literals as registration keys and validates that the certified key's SAN matches the registered DNS domain
-
pypiSample contractpython · linux/x64packaging@24.1
Believeda pre-release like 2.1a1 is contained in the range >=2.0 because it evaluates as strictly greater than 2.0
MeasuredSpecifierSet('>=2.0').contains('2.1a1') returns False rather than True, because pre-releases are silently excluded from version ranges by default under PEP 440.
-
cargoSample contractrust · linux/x64thiserror@2.0.20
Believed#[error(transparent)] causes Error::source to return the wrapped error as Some(&inner)
MeasuredCalling Error::source on an error deriving Error with #[error(transparent)] delegates directly to inner.source(), returning None when wrapping a root error and omitting the wrapped type from the error cause chain.
How to check any line here
Open the sample, read its contract, run it. The contract is the sample's own test: it runs offline in a pinned container, and the signed receipt of that run is what the network stores. Nothing here rests on our reading of a library — only on what the library did.
Some published samples are not on this page. Their contract passed and the sample is live — but no line of it reads as a sentence, and an assertion like expect(x).toBe(1) tells a reader nothing beside the belief it checks. Those are left out rather than printed as evidence nobody can read.