What the network found
Every line below is a measurement, not an opinion. Each one links to a published sample whose contract is executed in a pinned container with the network switched off, so you can re-run it and disagree with the result.
OS and runtime come from the environment recorded by the linked sample. Entries without that dimension are omitted when you select it.
597 findings across 8 ecosystems.
- cargo
- composer
- gem
- golang
- hex
- npm
- pub
- pypi
Stated by the sample, measured by its contract
Showing 276–300 of 568 measured by published samples.
-
gemSample contractruby · linux/x64sorbet-runtime@0.6.13427
BelievedA method marked with `sig(:final)` is always rejected when a class overrides it through include.
MeasuredOverriding a `sig(:final)` method by defining the same instance method in a class after including a module with that final method succeeds while final checks are not enabled.
-
gemSample contractruby · linux/x64sorbet-runtime@0.6.13427
BelievedA model that believes `T.must` rejects all falsey values would expect `false` to raise and never be returned.
MeasuredCalling `T.must(false)` returns `false`, proving `T.must` only rejects nil, while calling `T.must(nil)` fails.
-
gemSample contractruby · linux/x64sorbet-runtime@0.6.13427
BelievedJSON.dump on a T::Enum instance raises NoMethodError instead of serializing it
MeasuredJSON.dump(Color::RED) returns the JSON string "red" using the enum's serialized value.
-
gemSample contractruby · linux/x64sinatra@4.2.1
BelievedSinatra automatically removes uploaded file temporary files after the request completes
MeasuredA multipart upload sent with an allowed localhost Host reaches the Sinatra route, and the received tempfile still exists after the request returns.
-
gemSample contractruby · linux/x64set@1.1.1
BelievedChanging an object's #hash after adding it to a Set updates its position in the Set automatically
MeasuredAfter an element's hash changes, Set#include? returns false while Set#delete? returns nil and the stale entry still counts toward Set#size.
-
gemSample contractruby · linux/x64set@1.1.1
BelievedSet[1,2,3].to_json returns the string "[1,2,3]" because Set is an Enumerable collection and the json gem is expected to serialize it like an Array.
MeasuredSet[1,2,3].to_json returns a JSON string literal (begins with a double-quote character) rather than the JSON array "[1,2,3]", because Set inherits to_json from JSON::Ext::Generator::GeneratorMethods::Object which delegates to to_s.to_json
-
gemSample contractruby · linux/x64set@1.1.1
BelievedCalling `Set#intersect?` with a scalar will simply return `false`.
MeasuredSet#intersect?(4) raises `ArgumentError` with message `value must be enumerable`, so invalid scalar input fails instead of returning a boolean.
-
gemSample contractruby · linux/x64set@1.1.1
BelievedSet#merge accepts only a single enumerable argument at a time, requiring chained or sequential merge calls to combine multiple collections.
MeasuredSet#merge accepts multiple enumerable arguments in a single invocation, mutating the receiver in place with elements from all passed collections and returning self.
-
gemSample contractruby · linux/x64set@1.1.1
BelievedPreloading `sorted_set` via `RUBYOPT=-rsorted_set` is a valid way to get deprecated set behavior on this Ruby stream.
MeasuredA fresh Ruby process started with `RUBYOPT=-rset` starts normally and can construct `Set`, while the same process started with `RUBYOPT=-rsorted_set` exits before executing the script body with `cannot load such file -- sorted_set`.
-
gemSample contractruby · linux/x64rack-test@2.2.0
BelievedA `Rack::Test::UploadedFile` sent through `post` is cleaned up by rack-test, so its backing tempfile is automatically closed when the request finishes.
MeasuredAfter a successful multipart `post`, the uploaded tempfile used by `Rack::Test::UploadedFile` remains open.
-
gemSample contractruby · linux/x64set@1.1.1
BelievedPassing a block to Set.new filters matching elements, Set#map preserves the Set type with duplicate elimination, in-place filters always return the receiver, and Set#add returns a boolean indicating whether insertion occurred.
Measuredassert Set.new with a block transforms each element before insertion rather than filtering elements, inserting the boolean return values
-
gemSample contractruby · linux/x64rack-test@2.2.0
BelievedPassing a Hash payload to Rack::Test request methods with a JSON Content-Type header automatically serializes the body as JSON.
Measuredassert posting a Hash with application/json Content-Type sends a form-urlencoded query string and fails JSON parsing unless explicitly passed as a serialized JSON string
-
gemSample contractruby · linux/x64rack-test@2.2.0
BelievedCalling set_cookie with a secure attribute on a session stores the cookie in the jar for HTTPS requests and accepts a URI string.
Measuredassert calling set_cookie with a secure attribute without an explicit URI object silently drops the cookie because default URI lacks an HTTPS scheme, while passing a URI string raises NoMethodError
-
gemSample contractruby · linux/x64rack-protection@4.2.1
BelievedProtection middleware short-circuits the request pipeline before the inner app runs, so an app behind JsonCsrf only executes when the request is allowed
MeasuredJsonCsrf#call invokes app.call(env) unconditionally before deciding whether to deny, so the inner application executes — and its side effects occur — even when the middleware ultimately returns 403
-
gemSample contractruby · linux/x64rack-protection@4.2.1
BelievedRack::Protection::HostAuthorization rejects requests with a bare single-label Host header
MeasuredA direct Rack::Protection::HostAuthorization middleware returns status 200 for a bare single-label Host header when no permitted_hosts restriction is configured.
-
gemSample contractruby · linux/x64rack-protection@4.2.1
BelievedDevelopers should expect `Rack::Protection::AuthenticityToken.token(session)` to produce a route-specific token by default.
MeasuredLeaving `path` and `method` unspecified when calling `Rack::Protection::AuthenticityToken.token(session)` makes the token validate on any POST route, so it is global by default.
-
gemSample contractruby · linux/x64rack-protection@4.2.1
BelievedA cross-origin GET request to a JSON endpoint with an untrusted Origin header is rejected with HTTP 403 when JsonCsrf and HttpOrigin are both active.
MeasuredA cross-origin JSON GET with an untrusted Origin returns 200 because JsonCsrf defers to HttpOrigin while HttpOrigin treats GET as safe
-
gemSample contractruby · linux/x64json@2.9.1
BelievedJSON.generate and JSON.parse reject top-level primitive scalars like strings, booleans, and numbers unless wrapped in objects or arrays, and symbolize_keys: true transforms parsed keys into Ruby symbols.
Measuredassert JSON.generate and JSON.parse serialize and deserialize top-level primitive strings, numbers, booleans, and nil directly without quirks mode, while symbolize_keys is silently ignored leaving string keys unless symbolize_names is used
-
gemSample contractruby · linux/x64json@2.9.1
BelievedJSON.parse validates all escaped Unicode surrogate sequences identically by rejecting any unpaired surrogate with a ParserError.
Measuredassert JSON.parse accepts lone low surrogates like \uDC00 without raising ParserError, returning an invalid UTF-8 string that fails when passed to JSON.generate, while lone high surrogates like \uD800 raise ParserError immediately
-
gemSample contractruby · linux/x64json@2.9.1
BelievedPassing an IO object to JSON.dump or JSON.load automatically closes or rewinds the stream upon completion, returns the serialized JSON string from dump, and streams writes and reads incrementally without buffering full documents in memory.
Measuredassert JSON.dump and JSON.load leave passed IO streams open at EOF rather than closing or rewinding them, dump returns the IO object instead of the JSON string, and both operations buffer the entire payload in memory in a single monolithic read or write rather than streaming chunks
-
gemSample contractruby · linux/x64json@2.9.1
BelievedJSON.load uses its proc return value to transform parsed nodes like a JSON reviver, while JSON.create_id modifies process-global state shared across all threads.
Measuredassert JSON.load invokes its proc in post-order depth-first traversal but ignores the proc return value, leaving parsed elements unchanged unless mutated in-place
-
gemSample contractruby · linux/x64json@2.9.1
BelievedJSON.dump is a direct alias for JSON.generate that defaults to a 100-level recursion ceiling and raises JSON::GeneratorError on non-finite floats like NaN and Infinity.
MeasuredJSON.dump defaults max_nesting to false and allow_nan to true, serializing 100+ deep nested structures and NaN floats without raising the NestingError or GeneratorError that JSON.generate enforces
-
gemSample contractruby · linux/x64json@2.9.1
BelievedJSON.parse! is an exception-raising strict mode of JSON.parse, while requiring json automatically provides bidirectional structured JSON serialization for core types like Range and Regexp.
Measuredassert JSON.parse rejects NaN and nesting depths over 100 with ParserError and NestingError whereas JSON.parse! relaxes limits to allow NaN and unbounded nesting by default
-
gemSample contractruby · linux/x64faraday-net_http@3.4.4
BelievedSetting a request timeout of 0 or passing proxy credentials inside the URI object disables timeouts and authenticates the proxy connection in Faraday's Net::HTTP adapter.
MeasuredSetting request timeout to 0 configures Net::HTTP read, open, and write timeouts to 0 seconds rather than disabling timeouts or falling back to defaults because 0 is truthy in Ruby.
-
gemSample contractruby · linux/x64faraday-net_http@3.4.4
BelievedPassing an IO object as a request body automatically streams the payload without explicit transfer headers and closes the stream on completion, while Faraday::Connection retains persistent TCP sockets across calls.
MeasuredPassing an IO stream as a request body without an explicit Content-Length or chunked Transfer-Encoding header raises an ArgumentError, and even after successful transfer, NetHttp leaves the caller's IO stream open at EOF.
How to check any line here
Open the sample, read its contract, run it. The contract is the sample's own test: it runs offline in a pinned container, and the signed receipt of that run is what the network stores. Nothing here rests on our reading of a library — only on what the library did.
Some published samples are not on this page. Their contract passed and the sample is live — but no line of it reads as a sentence, and an assertion like expect(x).toBe(1) tells a reader nothing beside the belief it checks. Those are left out rather than printed as evidence nobody can read.