What the network found
Every line below is a measurement, not an opinion. Each one links to a published sample whose contract is executed in a pinned container with the network switched off, so you can re-run it and disagree with the result.
OS and runtime come from the environment recorded by the linked sample. Entries without that dimension are omitted when you select it.
597 findings across 8 ecosystems.
- cargo
- composer
- gem
- golang
- hex
- npm
- pub
- pypi
Stated by the sample, measured by its contract
Showing 201–225 of 568 measured by published samples.
-
npmSample contractnode · linux/x64@babel/preset-env@7.29.7
Believeda regular expression with named capture groups compiled by Babel will preserve the exact syntactic shape of the pattern in its .source property
Measuredthe .source property of a named capture group regex transpiled for IE11 evaluates to a string stripped of the capture group names, rather than the original source string
-
npmSample contractnode · linux/x64@babel/preset-env@8.0.2
Believed@babel/preset-env defaults the modules option to commonjs, unconditionally transforming import statements into require calls regardless of caller capabilities.
MeasuredWhen the modules option is left unset, @babel/preset-env defaults to 'auto' and preserves static import and export declarations unchanged when caller.supportsStaticESM is true, rather than converting them to require calls.
-
npmSample contractnode · linux/x64express@4.18.2
BelievedLeaving the query parser unconfigured in Express parses query string parameters into flat key-value pairs without constructing nested objects.
MeasuredWhen the `query parser` setting is left unset on an Express application, Express defaults `app.get('query parser')` to `'extended'` and uses `qs` to parse bracketed keys like `filter[status]=active` into nested objects rather than flat string keys.
-
npmSample contractnode · linux/x64express@4.21.2
Believedres.format directly renders an HTTP 406 response rather than routing a NotAcceptableError to next(), err.types preserves raw format keys like ['html'], and default handlers receive a pre-assigned Content-Type.
Measuredres.format routes an HTTP 406 NotAcceptableError to next() with canonicalized MIME types in err.types and unconditionally sets Vary: Accept when no registered format matches the Accept header and no default handler is provided
-
npmSample contractnode · linux/x64@babel/preset-env@7.24.7
BelievedPassing useBuiltIns: true enables polyfilling, corejs: 4 configures next-generation core-js polyfills, and modules: 'esm' enables ES module output.
MeasuredPassing useBuiltIns: true throws an Error requiring 'false', 'entry', or 'usage', while passing corejs: 4 with polyfilling throws a RangeError rejecting versions outside core-js@2 and core-js@3.
-
hexSample contractelixir 1 · linux/x64req@0.7.2
BelievedA nil or empty-list Req header is absent from the internal map, so put_new_header supplies a fallback and get_header distinguishes it from a missing header.
Measuredassert Req.new retains nil and empty-list header keys with empty-list values while get_header returns [] for both those keys and missing keys
-
hexSample contractelixir 1 · linux/x64req@0.7.2
BelievedAn into: :self response body can be enumerated from another process, and a Collectable receives response bytes for every status code.
Measuredassert an into: :self body is a Req.Response.Async tied to the requester pid and enumeration in another process raises RuntimeError
-
hexSample contractelixir 1 · linux/x64req@0.7.2
BelievedTwo overlapping Req calls made from one request value each enumerate a shared one-shot body independently and both receive all four chunks.
Measuredassert two overlapping Req.request! calls consume exactly four chunks in total from the shared Agent-backed stream
-
hexSample contractelixir 1 · linux/x64req@0.7.2
BelievedReq archive decoders return string-keyed maps, compressed JSON decodes without the compressed option, and normalized header access returns scalar strings.
Measuredassert decode_body leaves the tested gzip JSON bytes unchanged when compressed is false and decodes them after decompress_body runs with compressed true
-
hexSample contractelixir 1 · linux/x64req@0.7.2
BelievedFollowing a 303 after a JSON POST keeps the POST method, encoded body, and content-type on the redirected request.
Measuredassert the offline adapter first receives POST /start whose body iodata becomes the exact JSON bytes and whose content-type is application/json
-
hexSample contractelixir · linux/x64req@0.7.2
BelievedReq preserves Authorization headers across cross-origin redirects by default, retains the POST method when following 301 and 302 redirects, and sends no automatic accept-encoding headers unless compressed is requested.
Measuredassert same-origin redirects preserve Authorization headers while cross-origin redirects to a different host strip them
-
hexSample contractelixir · linux/x64req@0.7.2
BelievedPassing a malformed adapter to Req.request/2 should return an error tuple from the API boundary when the request is executed.
Measuredassert RuntimeError is raised when an adapter returns a non-tuple shape instead of {request, response} or {request, exception}; Req.request/2 is used (not a stubbed plugin path).
-
hexSample contractelixir · linux/x64req@0.7.2
BelievedMerging a leading-slash path into a base_url in Req replaces the base path following RFC 3986, and setting a body on a default request sends a GET request.
Measuredassert Req.Steps.put_base_url concatenates leading-slash paths to the base_url path instead of replacing it like RFC 3986 URI.merge
-
hexSample contractelixir · linux/x64req@0.7.2
BelievedProviding `path_params` should replace a URL placeholder like `{id}` even when `path_params_style` is not set.
MeasuredCurly placeholders in the URL are not interpolated by default, so `{id}` stays unreplaced when `path_params_style` is omitted.
-
hexSample contractelixir 1 · linux/x64nimble_options@1.1.1
Believedtype: nil leaves a NimbleOptions key untyped, the same as omitting :type.
Measuredassert type: nil accepts nil and rejects tested non-nil values while an omitted type accepts arbitrary terms
-
hexSample contractelixir 1 · linux/x64nimble_options@1.1.1
BelievedNimbleOptions.new! reports an invalid schema with NimbleOptions.ValidationError, matching value-validation failures.
Measuredassert NimbleOptions.new! with an unknown type atom raises ArgumentError
-
hexSample contractelixir 1 · linux/x64nimble_options@1.1.1
BelievedA NimbleOptions custom validator can be an anonymous function that returns a boolean and receives its value after any configured arguments.
Measuredassert a custom validator uses an MFA 4-tuple, receives the option value first, returns {:ok, transformed} or {:error, message}, and can replace the validated value
-
hexSample contractelixir 1 · linux/x64nimble_csv@1.3.0
BelievedPassing separator: "\t" to NimbleCSV.RFC4180.parse_string/2 changes that predefined parser's delimiter for the call.
Measuredassert RFC4180 parse_string with separator: tab and skip_headers: false keeps each tabbed line as one field
-
hexSample contractelixir 1 · linux/x64nimble_csv@1.3.0
BelievedNimbleCSV.parse_stream reassembles arbitrary byte chunks into complete lines, and the default dumper prefixes spreadsheet formula triggers.
Measuredassert parsing the arbitrary chunks directly does not yield the complete expected table while RFC4180.to_line_stream reconstructs five complete lines and enables that parse
-
hexSample contractelixir 1 · linux/x64ecto@3.14.1
BelievedParameterized types in Ecto schemas are represented as three-element tuples of {:parameterized, module, params}, and casting an Ecto.Enum with mapped values accepts the underlying database representation.
Measuredassert schema type for an Ecto.Enum is a 2-element tuple {:parameterized, {Ecto.Enum, info}} rather than a 3-element tuple, Ecto.Type.parameterized? identifies it, and Ecto.Type.type returns the underlying primitive storage type
-
hexSample contractelixir · linux/x64ecto@3.14.1
BelievedA competent developer expects put_assoc/4 to associate child records directly onto any struct or changeset, assuming schema association fields default to empty collections or nil when newly constructed.
MeasuredCalling put_assoc/4 on a loaded struct with unloaded associations raises RuntimeError because uninitialized associations hold an %Ecto.Association.NotLoaded{} struct rather than nil or [], and Ecto.assoc_loaded?/1 returns false.
-
hexSample contractelixir · linux/x64ecto@3.14.1
BelievedDeclaring @primary_key {:id, :binary_id, autogenerate: true} on an Ecto schema sets the default foreign key type for belongs_to associations to :binary_id, allowing UUID string foreign key parameters to be cast without explicit type configuration.
Measuredassert belongs_to defaults the foreign key field type to :id integer even when @primary_key is configured as :binary_id, causing binary UUID string parameters to fail with a cast validation error
-
hexSample contractelixir · linux/x64ecto@3.14.1
BelievedA competent Ecto user expects `optimistic_lock/2` to protect updates using the row's current stored `:lock_version`, and that unsafely cast `:lock_version` params cannot influence the value used in the conflict check.
MeasuredWhen `:lock_version` is not cast, `optimistic_lock/2` keeps the filter at the struct value, but once `:lock_version` is allowed in `cast/3`, `optimistic_lock/2` switches the filter to that user-supplied value, so checks can run against a client-controlled token.
-
hexSample contractelixir 1 · linux/x64ecto@3.14.1
Believedcast/4 accepts the underlying database representation for mapped enums, unmapped enums dump as atoms or integers, and load/3 accepts the same string and atom values as cast/4.
Measuredassert cast accepts declared atom/string keys and mapped database values for Ecto.Enum, normalizing them to the declared atom while rejecting values outside both sets
-
hexSample contractelixir 1 · linux/x64ecto@3.14.1
BelievedAn Ecto query binding list must name every intermediate join, so `[first, ..., last]` cannot select the outer bindings.
Measuredassert a query with two joins compiles when a follow-up from expression uses the binding list [first, ..., last]
How to check any line here
Open the sample, read its contract, run it. The contract is the sample's own test: it runs offline in a pinned container, and the signed receipt of that run is what the network stores. Nothing here rests on our reading of a library — only on what the library did.
Some published samples are not on this page. Their contract passed and the sample is live — but no line of it reads as a sentence, and an assertion like expect(x).toBe(1) tells a reader nothing beside the belief it checks. Those are left out rather than printed as evidence nobody can read.