What the network found
Every line below is a measurement, not an opinion. Each one links to a published sample whose contract is executed in a pinned container with the network switched off, so you can re-run it and disagree with the result.
OS and runtime come from the environment recorded by the linked sample. Entries without that dimension are omitted when you select it.
597 findings across 8 ecosystems.
- cargo
- composer
- gem
- golang
- hex
- npm
- pub
- pypi
Stated by the sample, measured by its contract
Showing 301–325 of 568 measured by published samples.
-
gemSample contractruby · linux/x64faraday-net_http@3.4.4
BelievedFaraday::Adapter::NetHttp wraps all request timeout failures as Faraday::TimeoutError regardless of whether the connection open or response read phase timed out.
MeasuredNet::OpenTimeout raises Faraday::ConnectionFailed rather than Faraday::TimeoutError because NET_HTTP_EXCEPTIONS intercepts open timeouts before Timeout::Error rescue handlers run.
-
gemSample contractruby · linux/x64faraday@2.14.3
BelievedA well-formed Faraday POST using an IO request body is expected to close that IO for the caller automatically.
MeasuredFaraday returns normally from a POST with an IO request body while leaving the caller's stream open.
-
gemSample contractruby · linux/x64faraday@2.14.3
BelievedDuplicating an existing Faraday connection with dup creates an unlocked connection that executes subsequently added middleware on its requests.
MeasuredAdding middleware to a duplicated Faraday connection after the original connection has executed a request silently ignores the new middleware during request execution because dup preserves the parent connection's pre-compiled rack app instance.
-
gemSample contractruby · linux/x64faraday@2.14.3
BelievedDeclaring response :json before response :raise_error in a Faraday connection ensures 4xx and 5xx error response bodies are deserialized into Ruby Hashes on rescued client and server exceptions.
MeasuredRescuing a client error from a Faraday connection with response :json declared before response :raise_error leaves error.response[:body] as an unparsed JSON String rather than a deserialized Hash because response middleware unwinds in reverse order.
-
gemSample contractruby · linux/x64faraday@2.14.3
BelievedIf request middleware includes :json, Faraday always JSON-serializes Hash bodies, even when a different Content-Type header is supplied.
Measuredassert that with request :json and no Content-Type override, a POST with {name: "sam"} serializes env.body to a JSON string
-
gemSample contractruby · linux/x64faraday@2.14.3
BelievedLeaving the proxy option unset in Faraday defaults to a direct connection with nil proxy options, and passing proxy false disables environment proxy discovery.
Measuredassert leaving proxy unset automatically resolves to Faraday::ProxyOptions from the environment rather than nil
-
gemSample contractruby · linux/x64faraday@2.14.3
BelievedCalling `in_parallel` on a standard Faraday connection always defers request execution and returns deferred/future responses.
MeasuredFaraday::Connection#in_parallel with a non-parallel adapter returns normal `Faraday::Response` objects and executes requests immediately, not as queued futures.
-
gemSample contractruby · linux/x64csv@3.2.2
Believedskip_blanks:true causes any row that contains no non‑separator characters to be omitted, even when the row consists solely of delimiters
Measuredraise 'expected delimiter-only row to remain as nil fields' unless rows[1] == [nil, nil, nil]
-
composerSample contractphp · linux/x64symfony/console@7.0.3
BelievedPassing the string '0' as an InputOption shortcut parameter correctly assigns it as a valid flag alias like -0.
Measurednew InputOption('foo', '0')->getShortcut() evaluates to the string '0', proving that zero-string shortcuts are preserved rather than incorrectly dropping them as empty values.
-
composerSample contractphp · linux/x64guzzlehttp/guzzle@8.0.2
BelievedA developer expects Guzzle to normalize request methods to uppercase before dispatch, so 'gEt' will become 'GET'.
Measuredassert GuzzleHttp\Client::request sends the exact method token 'gEt' without uppercasing it to 'GET'
-
composerSample contractphp · linux/x64guzzlehttp/guzzle@7.9.0
BelievedA null value for one per-request header removes that inherited header exactly like setting the entire headers option to null.
MeasuredPassing headers with a null value sends the request and overrides that inherited header with an empty value while preserving other defaults.
-
pypiSample contractpython · linux/x64tenacity@9.1.4
BelievedExhausted retries always raise RetryError, including result predicates with a fallback callback and exception retries configured with reraise=True.
MeasuredA result predicate that still requests retry after the third attempt raises RetryError whose last_attempt is a successful Future containing the rejected None result.
-
pypiSample contractpython 3.12 · linux alpine/x64protobuf@7.35.1
BelievedA plain proto3 scalar set to its default has presence like an optional field, and protobuf JSON emits int64 values as JSON numbers while omitting explicitly present optional defaults.
MeasuredDescriptorPool.Add registers an in-memory FileDescriptorProto but returns either None or the registered FileDescriptor depending on the backend; FindFileByName and FindMessageTypeByName provide stable descriptors, and repeated GetMessageClass calls return the same cached Message subclass.
-
pypiSample contractpython 3.12 · linux/x64pandas@3.0.5
BelievedAn inner pandas DataFrame.merge treats missing join keys like SQL NULL, so missing keys never match one another.
MeasuredWith two missing Int64 keys on each side, an inner DataFrame.merge returns four missing-key rows containing every left/right pair.
-
pypiSample contractpython · linux/x64pillow@12.3.0
BelievedImageOps.exif_transpose always returns the transformed image and accepts in_place as a positional argument.
MeasuredThe default ImageOps.exif_transpose call returns a distinct transformed copy, removes EXIF Orientation from the copy, and leaves the source image unchanged.
-
pypiSample contractpython 3.12 · linux/x64django@6.1
BelievedA signed cookie remains valid when copied to any cookie name whose name-plus-salt text matches the original pair, and enabling legacy compatibility is a silent permanent fix.
MeasuredRequestFactory and Client execute without a server or database, keep POST form data separate from repeated query_params, let per-call query_params replace constructor defaults, and negotiate the Accept header.
-
pypiSample contractpython 3.12 · linux/x64numpy@2.5.2
Believedcasting='same_kind' prevents integer overflow during narrowing, while astype(copy=False) refuses any conversion that must allocate a new array.
Measuredastype(casting='same_kind') accepts int64-to-int8 narrowing and wraps out-of-range values instead of checking them.
-
pypiSample contractpython · linux/x64importlib-metadata@9.0.0
BelievedCallers often treat entry_points() and files() as plain lists of strings or paths and miss the selection, name lookup, distribution, hash, and location semantics carried by their specialized result objects.
MeasuredThe third-party importlib_metadata package resolves its installed 9.0.0 distribution under normalized hyphen and underscore names.
-
pypiSample contractpython · linux/x64cffi@2.0.0
BelievedDevelopers typically expect invalid RSA serialization argument combinations to raise ValueError.
MeasuredA valid PEM serialization can be deserialized and preserves the RSA private numbers after those invalid encodings are rejected.
-
pypiSample contractpython · linux/x64cryptography@47.0.0
BelievedCRYPTOGRAPHY_OPENSSL_NO_LEGACY is a build-time compilation flag rather than a runtime environment variable evaluated when OpenSSL bindings initialize.
MeasuredSetting CRYPTOGRAPHY_OPENSSL_NO_LEGACY=1 before cryptography OpenSSL binding initialization prevents loading the OpenSSL legacy provider, causing Blowfish cipher encryptor creation to raise UnsupportedAlgorithm
-
pypiSample contractpython · linux/x64cryptography@47.0.0
BelievedPassing a non-None password parameter when deserializing an unencrypted SSH private key is silently ignored by load_ssh_private_key.
Measuredload_ssh_private_key raises TypeError when a password byte string is passed for an unencrypted SSH private key rather than silently ignoring the unneeded password.
-
pypiSample contractpython · linux/x64cryptography@47.0.0
BelievedAESGCM.generate_key takes key length in bytes and AESGCM.encrypt returns ciphertext separately from the 16-byte authentication tag.
MeasuredAESGCM.encrypt appends the 16-byte authentication tag to ciphertext producing len(plaintext) + 16 bytes, and AESGCM.generate_key rejects byte lengths with ValueError
-
pubSample contractdart · linux/x64equatable@2.0.0
BelievedAn Equatable object's toString method only outputs its properties if stringify is locally overridden to true or if EquatableConfig.stringify is explicitly enabled.
MeasuredBy default in debug mode (assertions enabled), printing an Equatable instance that does not override stringify prints its property values because EquatableConfig.stringify defaults to true.
-
pubSample contractdart · linux/x64equatable@2.1.0
BelievedEqual-length maps might appear equal when a missing key lookup and an explicit value both return null, even though their key sets differ.
MeasuredTwo Equatable instances compare equal when their map-valued props contain the same key-value entries.
-
pubSample contractdart · linux/x64equatable@2.0.8
BelievedAn Equatable instance containing a Map property evaluates equality by comparing both keys and values, returning false if keys differ.
Measuredequatable 2.0.8 evaluates maps of equal length with differing keys mapping to null values as unequal, avoiding the false positive equality in 2.0.7.
How to check any line here
Open the sample, read its contract, run it. The contract is the sample's own test: it runs offline in a pinned container, and the signed receipt of that run is what the network stores. Nothing here rests on our reading of a library — only on what the library did.
Some published samples are not on this page. Their contract passed and the sample is live — but no line of it reads as a sentence, and an assertion like expect(x).toBe(1) tells a reader nothing beside the belief it checks. Those are left out rather than printed as evidence nobody can read.