What the network found
Every line below is a measurement, not an opinion. Each one links to a published sample whose contract is executed in a pinned container with the network switched off, so you can re-run it and disagree with the result.
OS and runtime come from the environment recorded by the linked sample. Entries without that dimension are omitted when you select it.
597 findings across 8 ecosystems.
- cargo
- composer
- gem
- golang
- hex
- npm
- pub
- pypi
Stated by the sample, measured by its contract
Showing 126–150 of 568 measured by published samples.
-
pubSample contractdart · linux/x64json_annotation@4.9.0
BelievedA model expects JsonSerializable.fromJson to accept camelCase Dart option names, unknownEnumValue to serve as a fallback when an enum field is null, and disallowNullValues to reject missing keys.
MeasuredJsonSerializable.fromJson enforces snake_case option keys and disallowUnrecognizedKeys, throwing a CheckedFromJsonException with badKey true on camelCase Dart property names
-
golangSample contractgo · linux/x64github.com/goccy/go-yaml@v1.19.2
Believedyaml.Unmarshal silently accepts duplicate mapping keys and overwrites earlier occurrences with later ones.
Measuredassert yaml.Unmarshal rejects duplicate mapping keys with a SyntaxError by default, leaving destination values empty
-
pypiSample contractpython · linux/x64cffi@2.0.0
BelievedCalling ffi.string with maxlen reads the full byte length regardless of null bytes, and ffi.buffer on a pointer defaults to the full allocated buffer length.
MeasuredCalling ffi.string(cdata, maxlen) truncates at the first null byte rather than reading maxlen bytes, while ffi.unpack extracts the exact byte count across embedded nulls.
-
pubSample contractdart · linux/x64http@1.6.0
BelievedTop-level HTTP convenience functions executed inside runWithClient reuse a shared ambient client instance without closing it after each request.
MeasuredTop-level HTTP convenience functions inside runWithClient instantiate a client via the client factory and close it upon completion, causing subsequent requests on a singleton client factory to fail with ClientException.
-
npmSample contractnode · linux/x64typescript@5.9.3
BelievedTypeScript automatically elides type-only named imports and unused value imports during ECMAScript emit regardless of whether type keywords or verbatimModuleSyntax are configured.
MeasuredWhen compilerOptions.verbatimModuleSyntax is enabled, importing a type without the type modifier fails type-checking with TS1484, and re-exporting a type without export type fails with TS1205, whereas type-only imports and inline type specifiers compile cleanly and are elided during emit.
-
npmSample contractnode · linux/x64vitest@3.2.7
BelievedmergeConfig replaces array options like test.include and test.reporters with override values and supports function config factories.
MeasuredmergeConfig concatenates array options like test.include, test.exclude, and test.reporters rather than replacing them, appending override test filters to base patterns.
-
pubSample contractdart · linux/x64convert@3.1.2
BelievedCodePage.encode and CodePage.decode silently replace unmapped characters or undefined bytes with fallback tokens rather than throwing FormatException.
MeasuredCodePage.encode throws FormatException on unmapped characters unless configured with an in-range invalidCharacter byte, and CodePage.decode throws FormatException on undefined byte entries unless allowInvalid is set to true.
-
npmSample contractnode · linux/x64browserslist@4.28.8
Believedpassing custom usage statistics via opts.stats causes standard popularity queries like '> 10%' to automatically evaluate against the provided custom statistics
Measuredbrowserslist('> 10% in my stats') throws a BrowserslistError when opts.stats is omitted
-
golangSample contractgo · linux/x64github.com/go-playground/validator/v10@v10.30.3
BelievedTagging a non-pointer struct field with validate:"required" causes validator.New().Struct() to reject an uninitialized zero-value struct.
Measuredvalidator.New() ignores validate:"required" on non-pointer struct fields and returns nil for zero-value structs, while validator.WithRequiredStructEnabled() causes validation to fail with a required tag error on the struct field.
-
pubSample contractdart · linux/x64shelf@1.4.2
BelievedA mounted sub-router configured with a custom notFoundHandler only handles its own 404s when no other parent routes match, allowing sibling or fallback routes in the parent Router to catch unhandled paths.
MeasuredA parent Router falls through unmatched sub-paths to subsequent sibling routes when the mounted sub-router uses the default notFoundHandler, but halts and returns 404 when configured with a custom notFoundHandler.
-
golangSample contractgo · linux/x64github.com/spf13/pflag@v1.0.10
BelievedEnabling ParseErrorsWhitelist.UnknownFlags allows unrecognized flags to pass through without error while preserving all subsequent positional arguments in FlagSet.Args().
MeasuredWhen ParseErrorsWhitelist.UnknownFlags is true, FlagSet.Parse on unknown flags without an equals sign silently consumes the following non-flag argument as the flag value, leaving Args empty rather than preserving the positional argument.
-
golangSample contractgo 1.26 · linux/x64google.golang.org/grpc@v1.83.0
BelievedA client can receive responses larger than 4MB without additional configuration because the default 4MB limit applies only to server request payloads, or by setting grpc.MaxCallSendMsgSize on the client.
MeasuredWhen a gRPC server returns a 5MB payload to a client with default options, the server transmits it without error but the client fails to decode the response with status code ResourceExhausted because the default client-side receive limit is 4MB.
-
pubSample contractdart · linux/x64shelf@1.4.2
BelievedA shelf Cascade cascades to subsequent handlers on any 4xx or 5xx client or server error response by default.
MeasuredCascade defaults to cascading only on 404 and 405 status codes, requiring explicit statusCodes or shouldCascade configuration to cascade past 400 Bad Request, 401 Unauthorized, or 500 Internal Server Error responses.
-
golangSample contractgo · linux/x64go.uber.org/zap@v1.27.0
Believedzap.Config.Build automatically resolves unregistered URI schemes to file paths or creates default sink wrappers for custom protocol schemes
Measuredzap.Config.Build fails with a 'no sink found for scheme' error when OutputPaths contains a URI scheme that has not been registered via zap.RegisterSink.
-
golangSample contractgo 1.26 · linux/x64github.com/gin-gonic/gin@v1.12.0
Believedgin.Context implements context.Context so it automatically delegates Value, Deadline, and Done to the underlying http.Request context without extra configuration.
MeasuredBy default gin.Engine has ContextWithFallback disabled, causing gin.Context to return nil for all http.Request context values and ignore request deadlines and cancellation.
-
pypiSample contractpython · linux/x64pillow@10.4.0
BelievedImage.open checks image size limits only during pixel rasterization and raises a generic MemoryError rather than DecompressionBombError when pixels exceed Image.MAX_IMAGE_PIXELS.
MeasuredImage.open eagerly raises PIL.Image.DecompressionBombError during header parsing when total pixels exceed twice Image.MAX_IMAGE_PIXELS without allocating pixel memory.
-
pypiSample contractpython · linux/x64anyio@4.13.0
BelievedCancelling a task waiting on anyio.to_thread.run_sync cancels immediately without waiting for the synchronous thread, and setting abandon_on_cancel=True keeps worker thread concurrency strictly bounded by the CapacityLimiter.
MeasuredWith abandon_on_cancel=False, cancelling the calling scope blocks until the worker thread finishes running, whereas abandon_on_cancel=True exits the scope immediately while releasing the CapacityLimiter before the synchronous thread finishes.
-
hexSample contractelixir · linux/x64decimal@3.1.1
BelievedSetting a Decimal context configuration applies across the application or automatically propagates to spawned child processes and tasks.
MeasuredDecimal context is scoped to the calling process dictionary and is not inherited by spawned child tasks
-
npmSample contractnode · linux/x64vue@3.5.41
BelievedIn production mode (NODE_ENV=production), an unhandled error thrown during Vue SSR component setup or rendering causes renderToString() to reject with the error.
MeasuredIn production mode, unhandled errors in component setup or rendering are suppressed and logged to console by default, causing renderToString to resolve with partial markup unless app.config.throwUnhandledErrorInProduction is set to true.
-
pypiSample contractpython · linux/x64tenacity@9.1.4
Believedretry_unless_exception_type retries functions that raise unexpected exceptions while allowing successful returns to exit immediately without retrying.
Measuredretry_unless_exception_type treats successful return values as retryable states, retrying until stop exhaustion and raising RetryError with a successful last_attempt Future.
-
gemSample contractruby · linux/x64minitest@6.0.6
BelievedCalling parallelize_me! inside a test class always enables parallel test execution across worker threads or raises an error if threads cannot be allocated
MeasuredWhen MT_CPU is 1 or less at load time, Minitest.parallel_executor is nil, causing parallelize_me! to leave test class run_order as :random without including Minitest::Parallel::Test, running tests synchronously on the main thread
-
npmSample contractnode · linux/x64jose@6.2.9
BelievedSetting maxTokenAge only limits allowable token age when an iat claim is present, falling back to exp expiration checking when iat is omitted.
MeasuredjwtVerify with maxTokenAge configured rejects tokens lacking an iat claim with JWTClaimValidationFailed and reason 'missing' rather than falling back to exp validation.
-
npmSample contractnode · linux/x64rollup@4.34.8
BelievedA bare import with no specifiers, such as import './polyfill.js', is always retained during tree-shaking because it declares an intentional side effect with no unused bindings to eliminate.
MeasuredSetting treeshake: { moduleSideEffects: false } causes Rollup to strip bare side-effect imports that have no consumed exports, whereas treeshake: { moduleSideEffects: 'no-external' } retains internal side-effect imports and strips unused external ones.
-
golangSample contractgo · linux/x64github.com/google/go-cmp@v0.7.0
BelievedPassing multiple cmp.Transformer or cmp.Comparer options for the same underlying type automatically evaluates them in order or restricts them to their intended struct context.
Measuredassert cmp.Diff panics with ambiguous set of applicable options when multiple transformers or comparers target the same type without path filters
-
pypiSample contractpython · linux/x64pyarrow@25.0.1
Believedpyarrow.csv.read_csv parses tokens defined in null_values as null values across all columns regardless of inferred column data type.
MeasuredCSV columns inferred as strings preserve tokens matching null_values as literal strings unless strings_can_be_null is explicitly set to True, whereas numeric columns convert them to nulls by default.
How to check any line here
Open the sample, read its contract, run it. The contract is the sample's own test: it runs offline in a pinned container, and the signed receipt of that run is what the network stores. Nothing here rests on our reading of a library — only on what the library did.
Some published samples are not on this page. Their contract passed and the sample is live — but no line of it reads as a sentence, and an assertion like expect(x).toBe(1) tells a reader nothing beside the belief it checks. Those are left out rather than printed as evidence nobody can read.