What the network found
Every line below is a measurement, not an opinion. Each one links to a published sample whose contract is executed in a pinned container with the network switched off, so you can re-run it and disagree with the result.
OS and runtime come from the environment recorded by the linked sample. Entries without that dimension are omitted when you select it.
597 findings across 8 ecosystems.
- cargo
- composer
- gem
- golang
- hex
- npm
- pub
- pypi
Stated by the sample, measured by its contract
Showing 426–450 of 568 measured by published samples.
-
npmSample contractnode · linux/x64commander@15.0.0
BelievedSpawning git-style executable subcommands with Commander cleans up all process-level event listeners once the subcommand process exits.
MeasuredSpawning executable subcommands in commander registers signal event listeners on the global process object that are never unregistered upon process termination, accumulating memory leaks on subsequent command invocations.
-
npmSample contractnode · linux/x64commander@10.0.1
BelievedPassing a string option name to Option.implies() sets that option to true when the triggering option is parsed.
MeasuredOption.implies('quiet') on an option implicitly sets the boolean quiet option to true when the parent flag is present in Commander 10.0.1 instead of decomposing the string into numeric character properties as in 10.0.0
-
npmSample contractnode · linux/x64bun@1.2.17
BelievedThe bun npm package package.json maps the bunx binary entry to bin/bun.exe rather than a dedicated bin/bunx.exe target.
Measuredassert bun package.json bin field maps bunx to bin/bunx.exe rather than bin/bun.exe in version 1.2.17
-
gemSample contractruby · linux/x64rack-test@2.2.0
BelievedPassing an HTTP header dictionary as the third argument to Rack::Test request methods translates header names into Rack environment keys for that single request.
Measuredassert passing raw HTTP header names in the third argument leaves them un-prefixed in env rather than transforming to HTTP_ CGI keys
-
gemSample contractruby · linux/x64rack-protection@4.2.1
BelievedRack::Protection::CookieTossing evaluates each request independently so that a subsequent valid request with no duplicate cookies succeeds after an earlier attack request was rejected.
MeasuredCalling Rack::Protection::CookieTossing with a subsequent valid request returns HTTP status 403 Forbidden rather than 200 OK because detected malicious cookie names are retained on the middleware instance in @bad_cookies across requests.
-
gemSample contractruby · linux/x64rack-protection@4.2.1
BelievedParameter values with non-string leaf types should survive a round trip through `EscapedParams` unchanged.
MeasuredWhen a pre-seeded `rack.request.query_hash` with mixed values passes through `Rack::Protection::EscapedParams`, integer and symbol leaves become `nil` before the request body reaches the app, while string leaves are HTML-escaped.
-
composerSample contractphp · linux/x64symfony/console@8.1.1
BelievedA developer expects the default ChoiceQuestion label to be escaped, so `<comment>...` appears in the prompt brackets.
MeasuredIn 8.1.1, running a ChoiceQuestion with default `<comment>Add new tag</comment>` must print the prompt with `Select a tag [Add new tag]:` and must not print `[<comment>Add new tag</comment>]`.
-
gemSample contractruby · linux/x64json@2.9.1
BelievedJSON.parse with symbolize_names: true and create_additions: true deserializes custom domain objects while symbolizing remaining hash keys, and JSON.generate serializes objects that implement as_json.
Measuredassert JSON.parse raises ArgumentError when :symbolize_names and :create_additions are combined, making addition deserialization mutually exclusive with key symbolization
-
gemSample contractruby · linux/x64json@2.9.1
BelievedPassing nil to JSON.parse should raise JSON::ParserError because it is invalid JSON text.
MeasuredJSON.load(nil) returns nil, so the two APIs are not behaviorally equivalent on nil input.
-
gemSample contractruby · linux/x64faraday-net_http@3.4.4
BelievedAll Ruby Net::HTTP timeout exceptions inherit from Timeout::Error and are expected to be caught under Faraday::TimeoutError.
MeasuredNet::OpenTimeout is mapped to Faraday::ConnectionFailed rather than Faraday::TimeoutError because faraday-net_http routes socket open failures through its connection failure handler.
-
npmSample contractnode · linux/x64@babel/preset-env@7.29.7
BelievedModifying .browserslistrc on disk causes @babel/preset-env to automatically pick up the updated target environment on subsequent transformSync calls in a long-running process.
MeasuredWhen .browserslistrc is modified on disk during a process lifetime, @babel/preset-env continues to emit transpiled code matching the stale cached targets until browserslist.clearCaches() is explicitly invoked.
-
npmSample contractnode · linux/x64@babel/preset-env@8.0.2
BelievedSetting targets to an empty array [] behaves identically to an empty object {} by defaulting to the standard baseline and leaving modern syntax untranspiled.
MeasuredPassing targets: [] resolves to an empty environment matching zero engines and forces full ES5 transpilation of modern arrow functions and const declarations, whereas targets: {} defaults to the modern baseline.
-
gemSample contractruby · linux/x64faraday-net_http@3.4.4
Believedall Net::HTTP timeout conditions including connection open timeouts raise Faraday::TimeoutError
Measuredassert Net::OpenTimeout raises Faraday::ConnectionFailed rather than Faraday::TimeoutError
-
gemSample contractruby · linux/x64faraday@2.14.3
BelievedPassing a nil parameter value in a Faraday query hash omits the key from the serialized URL or encodes it with an empty string equals sign, while parsing a valueless query flag always returns nil across all encoders.
MeasuredFaraday::NestedParamsEncoder and Faraday::FlatParamsEncoder serialize a nil value as a valueless query key without an equals sign rather than omitting it or appending an equals sign, while FlatParamsEncoder decodes valueless query keys as the boolean true rather than nil.
-
npmSample contractnode · linux/x64@babel/preset-env@8.0.2
BelievedTranspiling object rest destructuring and object spread with @babel/preset-env preserves accessor descriptors like getters and copies inherited prototype properties onto the resulting object.
MeasuredTranspiling object rest destructuring and object spread with @babel/preset-env evaluates getters into plain data properties, drops inherited prototype properties and non-enumerable properties, but preserves own enumerable Symbol keys.
-
gemSample contractruby · linux/x64zeitwerk@2.8.3
BelievedZeitwerk autovivifies a namespace module for every subdirectory in a managed root directory, treating empty folders and non-Ruby asset directories as constant namespaces.
Measuredassert empty directories and directories containing only non-Ruby assets or hidden dotfiles do not autovivify namespace modules and raise NameError on constant access rather than resolving to Module instances
-
gemSample contractruby · linux/x64faraday@2.14.3
BelievedFaraday::NestedParamsEncoder.decode raises Faraday::ParsingError when query parameters conflict, and client timeouts inherit from Faraday::ClientError rather than Faraday::ServerError.
MeasuredFaraday::NestedParamsEncoder.decode raises Ruby core TypeError instead of Faraday::ParsingError when a scalar parameter precedes a nested key, but silently overwrites and returns the scalar when the nested key comes first.
-
gemSample contractruby · linux/x64zeitwerk@2.8.3
BelievedDefining a non-module object in an explicit namespace file raises Ruby's standard TypeError on nested constant access or Zeitwerk::NameError during autoloading.
Measuredassert assigning a non-module object in an explicit namespace file immediately raises Zeitwerk::Error from const_added during autoload, escaping rescue NameError and rescue TypeError
-
npmSample contractnode · linux/x64@babel/core@8.0.1
BelievedDynamic import expressions are parsed as CallExpression AST nodes with an Import callee property.
MeasuredparseSync parses dynamic import('./mod') as an ImportExpression node with a source property rather than a CallExpression with callee Import
-
gemSample contractruby · linux/x64sorbet-runtime@0.6.13426
BelievedA `checked(:never)` method in a class with duplicate `method_added` hooks still incurs wrapper allocations on every call.
MeasuredA method annotated with `sig { returns(Integer).checked(:never) }` after a duplicated `method_added` chain runs with 1 allocation on first call and 0 on second call.
-
gemSample contractruby · linux/x64sorbet-runtime@0.6.13427
BelievedA sig block failing on first invocation can be retried once its dependencies resolve, sig binds to the next lexically defined method across threads, and re-entering a method during sig evaluation executes the underlying method body.
MeasuredRetrying a method whose lazy sig block previously raised an exception fails with RuntimeError: 'A previous invocation... raised, and the current one succeeded' rather than recovering when the sig block now succeeds.
-
gemSample contractruby · linux/x64sorbet-runtime@0.6.13427
BelievedInitializing a T::Struct with an undeclared attribute is silently ignored at runtime
MeasuredInitializing a T::Struct with an unknown attribute raises ArgumentError
-
gemSample contractruby · linux/x64sorbet-runtime@0.6.13427
BelievedT::Struct.from_hash rejects unknown payload keys by default with an error, matching T::Struct.new constructor validation.
Measuredassert from_hash! and from_hash with strict: true raise RuntimeError when unknown keys are provided
-
gemSample contractruby · linux/x64sorbet-runtime@0.6.13427
BelievedA method signed with T::Array[Integer] raises TypeError at the call site when the caller passes an array whose elements are not Integers, because the annotation explicitly names the element type.
MeasuredCalling a sig-annotated method with T::Array[Integer] and an array of strings does not raise TypeError; the runtime erases the Integer type parameter and accepts any Array without inspecting its elements.
-
gemSample contractruby · linux/x64sorbet-runtime@0.6.13427
BelievedSetting T::Configuration.default_checked_level = :never anywhere before application code runs disables runtime type checking globally, even if class definitions have already been loaded.
MeasuredCalling T::Configuration.default_checked_level= after any sig-annotated method has been invoked raises RuntimeError with 'Set the default checked level earlier', because sorbet-runtime evaluates sig blocks lazily on first call — meaning class loading alone does not trigger evaluation, but one call does.
How to check any line here
Open the sample, read its contract, run it. The contract is the sample's own test: it runs offline in a pinned container, and the signed receipt of that run is what the network stores. Nothing here rests on our reading of a library — only on what the library did.
Some published samples are not on this page. Their contract passed and the sample is live — but no line of it reads as a sentence, and an assertion like expect(x).toBe(1) tells a reader nothing beside the belief it checks. Those are left out rather than printed as evidence nobody can read.