CodeSampleX

What the network found

Every line below is a measurement, not an opinion. Each one links to a published sample whose contract is executed in a pinned container with the network switched off, so you can re-run it and disagree with the result.

OS and runtime come from the environment recorded by the linked sample. Entries without that dimension are omitted when you select it.

597 findings across 8 ecosystems.

Stated by the sample, measured by its contract

Showing 376–400 of 568 measured by published samples.

  1. npmSample contractnode · linux/x64core-js@3.49.0

    BelievedA naive expectation is that `Iterator.range` coerces `NaN` arguments to usable numbers, so `Iterator.range(NaN, 10)` would still return an iterable.

    MeasuredCalling `Iterator.range` with `NaN` as `start` throws `RangeError` in the patched `core-js` behavior.

  2. npmSample contractnode · linux/x64commander@15.0.0

    BelievedAn option configured with an optional value accepts negative numbers like -1 as its argument regardless of what other short option flags are registered on the command.

    MeasuredPassing -1 after an optional-argument option evaluates that option to boolean true and parses -1 as a distinct flag if any single-digit short option is defined on the command hierarchy, because Commander disables negative number heuristics whenever a digit flag exists.

  3. npmSample contractnode · linux/x64commander@13.1.0

    BelievedParsing multiple command invocations concurrently with parseAsync on a shared Command instance keeps options isolated within each execution promise.

    MeasuredCalling parseAsync on a shared Command instance while an earlier parseAsync execution is suspended at an await overwrites the option store, causing the earlier execution to resume with option values from the later invocation.

  4. npmSample contractnode · linux/x64commander@15.0.0

    BelievedAn option configured with an optional value and a custom argParser coerces a fallback value through argParser when the flag is invoked without an argument on the command line.

    MeasuredOption.preset() supplies a fallback value passed to argParser when an optional-value flag is invoked without arguments, preventing Commander from storing boolean true and bypassing custom parser coercion.

  5. npmSample contractnode · linux/x64bun@1.3.14

    BelievedPinning bun in package.json should let Node import it as a normal dependency module.

    Measuredbun@1.3.14 has no Node import surface in lockfile metadata, because neither `main` nor `exports` is present even though the package is installed as a dependency.

  6. npmSample contractnode · linux/x64bun@1.3.14

    BelievedBun binary APIs receive a typed array's entire backing ArrayBuffer, so passing a subarray with a non-zero offset hashes, compresses, or writes bytes outside the view.

    MeasuredBun.hash produces the same result for a non-zero-offset Uint8Array view and an independent array containing only the view bytes, and a different result for the full backing array

  7. npmSample contractnode · linux/x64@babel/preset-env@7.26.9

    BelievedTargeting modern environments like Node 22 or setting targets.esmodules to true causes @babel/preset-env to preserve ES module import and export syntax by default without transforming them to CommonJS.

    MeasuredEven when targeting modern environments that natively support ES modules such as Node 22 or esmodules: true, @babel/preset-env defaults modules to 'auto' and transforms import and export statements into CommonJS require and exports unless the caller declares supportsStaticESM or modules is explicitly set to false.

  8. npmSample contractnode · linux/x64@babel/preset-env@8.0.2

    BelievedTargeting modern JavaScript runtimes with @babel/preset-env and default modules: 'auto' preserves native export * as ns syntax because the targeted environments natively support ECMAScript namespace re-exports.

    MeasuredWhen modules is unset or 'auto', @babel/preset-env unconditionally injects transform-export-namespace-from and desugars export * as ns statements even when targeting modern runtimes like Chrome 120 or Node 22, unless modules is explicitly false or the caller declares supportsExportNamespaceFrom.

  9. npmSample contractnode · linux/x64@babel/core@8.0.1

    BelievedEquivalent inline plugin option objects are reused across transformSync calls, and createConfigItem remains a synchronous convenience API in Babel 8.

    MeasuredA ConfigItem created once with createConfigItemSync reuses its plugin descriptor so five transformSync calls execute the factory exactly once

  10. npmSample contractnode · linux/x64@babel/core@8.0.1

    BelievedCalling babel.transformAsync allows plugin visitor methods to be async functions whose returned Promises are awaited before AST traversal completes and transformed output code is generated.

    Measuredbabel.transformAsync completes AST traversal synchronously and generates untransformed output code when a plugin visitor returns a Promise, leaving the Promise un-awaited.

  11. npmSample contractnode · linux/x64@babel/core@8.0.1

    BelievedtransformFromAstSync modifies the provided AST object in place during traversal and populates result.ast with the transformed tree.

    MeasuredtransformFromAstSync preserves the input AST node unmodified and sets result.ast to null unless cloneInputAst is set to false and ast is set to true.

  12. npmSample contractnode · linux/x64@babel/core@8.0.1

    Believedbabel.transformSync automatically discovers and loads .babelrc configuration files from the current working directory when transforming code strings.

    Measuredbabel.transformSync and babel.loadPartialConfigSync ignore .babelrc configuration files when filename is omitted, defaulting options.babelrc to false

  13. npmSample contractnode · linux/x64@babel/core@8.0.1

    BelievedSetting configFile: false disables all filesystem configuration loading, while subpackage .babelrc.json configurations are discovered and applied automatically.

    MeasuredSetting configFile: false disables only project-wide babel.config.json while leaving file-relative .babelrc.json active, and subpackage .babelrc.json files are ignored under default babelrcRoots: true

  14. hexSample contractelixir · linux/x64nimble_pool@1.1.0

    BelievedNimblePool.handle_info/2 follows the same return convention as GenServer.handle_info/2, accepting (message, state) and returning {:noreply, state}, because NimblePool is built on GenServer.

    MeasuredReturning {:noreply, worker_state} from handle_info/2 crashes the pool process with CaseClauseError, because NimblePool routes stray messages to each idle worker's handle_info/2, then pattern-matches the result against {:ok, _}, killing the pool and making all subsequent checkouts exit with :noproc.

  15. golangSample contractgo · linux/x64net/http@go1.26.5

    BelievedHeaders set on http.ResponseWriter after calling WriteHeader are included in the HTTP response.

    MeasuredHeaders set on http.ResponseWriter after calling WriteHeader are omitted from the client response.

  16. golangSample contractgo · linux/x64net/http@v1.26.5

    BelievedSetting the Host header via http.Request.Header.Set("Host", ...) overrides the Host header sent on the wire by http.Client.

    Measuredreq.Header.Set("Host", ...) does not override the wire Host header sent by http.Client

  17. golangSample contractgo 1.26 · linux/x64gorm.io/gorm@v1.31.2

    BelievedCalling Scopes(Tenant(id)) before Where(...).Or(...) keeps the tenant predicate in force for both OR branches because the scope appears first in the chain.

    Measuredassert Scopes(Tenant(7)).Where("active = ?", true).Or("role = ?", "admin") generates WHERE active = ? OR role = ? AND tenant_id = ?, so SQL precedence allows active rows from other tenants

  18. golangSample contractgo 1.26 · linux/x64google.golang.org/grpc@v1.83.0

    BelievedA unary client interceptor can call metadata.NewOutgoingContext to add its own field without affecting outgoing metadata the caller already attached.

    MeasuredA grpc.NewClient call reaches a manually registered unary service through bufconn, a context dialer, and insecure transport credentials without opening a TCP listener.

  19. golangSample contractgo 1.26 · linux/x64github.com/spf13/viper@v1.21.0

    BelievedMergeConfigMap treats its argument as immutable input and copies it, so changing or reusing the caller's map after the call cannot alter Viper's configuration.

    Measuredassert MergeConfigMap lowercases both top-level and nested keys in the caller-supplied maps themselves

  20. golangSample contractgo · linux/x64github.com/golang-jwt/jwt/v5@v5.3.1

    Believedproviding an invalid key type (such as a byte slice instead of an RSA public key) to jwt.Parse during RSA verification returns jwt.ErrTokenUnverifiable or jwt.ErrInvalidKeyType rather than jwt.ErrTokenSignatureInvalid

    Measuredassert jwt.Parse returns jwt.ErrTokenSignatureInvalid when a key of invalid type is provided for RSA verification, rather than ErrTokenUnverifiable or ErrInvalidKeyType directly

  21. golangSample contractgo · linux/x64github.com/golang-jwt/jwt/v5@v5.3.1

    BelievedDefining a Valid() error method on a custom claims struct in github.com/golang-jwt/jwt/v5 triggers custom validation during parsing, and missing expiration claims cause parsing to fail by default.

    MeasuredDefining a Valid() error method on a custom claims struct has no effect in v5 because custom validation requires implementing the jwt.ClaimsValidator interface via a Validate() error method.

  22. golangSample contractgo · linux/x64github.com/golang-jwt/jwt/v5@v5.3.1

    BelievedA single-element jwt.ClaimStrings slice serializes to a JSON string value by default.

    MeasuredSerializing a single-element jwt.ClaimStrings audience produces a JSON array by default because jwt.MarshalSingleStringAsArray is true.

  23. golangSample contractgo · linux/x64github.com/golang-jwt/jwt/v5@v5.2.2

    BelievedParseUnverified returns a slice containing all split string segments when parsing a malformed token string with extra dot delimiters.

    MeasuredParseUnverified returns a nil parts slice rather than a populated slice of all split segments when given a token with extra dot delimiters.

  24. golangSample contractgo · linux/x64github.com/golang-jwt/jwt/v5@v5.3.1

    BelievedDefining a Valid() error method on a custom claims struct validates claims during jwt.ParseWithClaims.

    Measuredjwt.ParseWithClaims silently ignores a custom claims Valid() error method, passing validation unless the struct implements ClaimsValidator with Validate() error.

  25. golangSample contractgo · linux/x64github.com/go-chi/chi/v5@v5.2.1

    Believedmiddleware.AllowContentType rejects POST requests lacking a Content-Type header and ignores Content-Type headers on GET requests.

    Measuredmiddleware.AllowContentType allows a body-less POST request with an empty Content-Type header through to the handler with HTTP 200 rather than rejecting it based on the HTTP method

How to check any line here

Open the sample, read its contract, run it. The contract is the sample's own test: it runs offline in a pinned container, and the signed receipt of that run is what the network stores. Nothing here rests on our reading of a library — only on what the library did.

Some published samples are not on this page. Their contract passed and the sample is live — but no line of it reads as a sentence, and an assertion like expect(x).toBe(1) tells a reader nothing beside the belief it checks. Those are left out rather than printed as evidence nobody can read.