What the network found
Every line below is a measurement, not an opinion. Each one links to a published sample whose contract is executed in a pinned container with the network switched off, so you can re-run it and disagree with the result.
OS and runtime come from the environment recorded by the linked sample. Entries without that dimension are omitted when you select it.
597 findings across 8 ecosystems.
- cargo
- composer
- gem
- golang
- hex
- npm
- pub
- pypi
Stated by the sample, measured by its contract
Showing 451–475 of 568 measured by published samples.
-
gemSample contractruby · linux/x64sorbet-runtime@0.6.13427
BelievedT::Enum instances compare equal to their serialized string or symbol values, and from_serialized returns nil for unmatched strings instead of raising KeyError.
Measuredassert T::Enum instances are not equal to strings or symbols, and that passing a raw string to a T::Enum parameter raises TypeError
-
gemSample contractruby · linux/x64sinatra@4.2.1
BelievedAn empty PATH_INFO is treated as a normal non-match and should fail with a 404 instead of entering `get('/')`.
Measuredassert a request with PATH_INFO '' receives status 200 from GET / and returns the same body as PATH_INFO '/'
-
gemSample contractruby · linux/x64sinatra@4.2.1
BelievedSinatra::IndifferentHash.new({"role" => "admin"}) produces a populated hash where the string and symbol keys both resolve to "admin", matching the same pattern that worked in Sinatra 3
MeasuredSinatra::IndifferentHash.new({"role" => "admin", "id" => 7}) returns an empty hash of size 0 whose default value is the argument object, so ih["role"] returns the original seed hash rather than "admin" — the constructor no longer merges its argument in Sinatra 4
-
gemSample contractruby · linux/x64sinatra@4.2.1
BelievedA competent developer expects bare query flags `?flag` to parse as empty strings or booleans, optional route parameters like `(/:id)?` to omit the key from `params` when absent and accept trailing slashes, named parameters `:id` to stop at dots before extensions, `redirect back` to raise or fail when no `Referer` header is present, and wildcard `splat` arrays to be overwritten by query parameters named `splat`.
Measuredassert an omitted optional route parameter in (/:id)? populates params[:id] as nil with params.key?('id') true while trailing slash /users/ returns 404, bare query flags parse as nil rather than empty strings, and named route params capture across dots
-
gemSample contractruby · linux/x64sinatra@4.2.1
BelievedEach overlapping request to the same Sinatra app instance is isolated from in-flight request mutations.
MeasuredTwo in-flight calls to the same Sinatra app can share one class-level state slot, so the first call can observe the second call’s write before it returns.
-
gemSample contractruby · linux/x64sinatra@4.2.1
BelievedCalling pass inside a matched route handler discards intermediate modifications to the HTTP status code, response headers, cookies, and request params before dispatching to subsequent matching routes.
MeasuredCalling pass retains any HTTP status code, response headers, cookies, and params mutations made by the passed route rather than resetting the response state for the fallback handler.
-
gemSample contractruby · linux/x64sinatra@4.2.1
BelievedCalling halt with a status integer and headers hash sets the HTTP response status code and headers with an empty body.
Measuredassert halt with status code and hash assigns the hash to the response body and leaves headers unset
-
gemSample contractruby · linux/x64sinatra@4.2.1
BelievedConfiguring settings with Sinatra's set method replaces existing Hash configurations, stores Proc and lambda values as callable objects on the settings object, and passes form HTTP verb overrides through to DELETE and PUT route handlers by default.
MeasuredSinatra::Base.set merges new Hash options into previous Hash settings rather than overwriting them, and evaluates Proc or lambda settings on every property access rather than returning the callable object.
-
gemSample contractruby · linux/x64set@1.1.1
BelievedA Ruby developer would expect `Set#^` to return a plain `Set` regardless of subclass, so subclass-only behavior hooks are irrelevant.
Measuredassert Set#^ returns an object of the left operand's subclass when both operands are `Set` subclasses
-
gemSample contractruby · linux/x64set@1.1.1
BelievedSet#divide with a 2-arity predicate block partitions elements by directly evaluating the block on every pair and grouping each matching pair together, so Set[1,2,3,4].divide { |a,b| (a-b).abs == 1 } produces multiple partitions matching the adjacent pairs rather than collapsing all transitively-connected elements into one.
MeasuredSet[1,2,3,4].divide { |a,b| (a-b).abs == 1 } returns a single partition containing all four elements rather than multiple pairwise groups, because the 2-arity form performs a transitive-closure (union-find) over all pairs, merging 1-2, 2-3, and 3-4 into one equivalence class
-
gemSample contractruby · linux/x64set@1.1.1
BelievedA developer can mutate a `Set` from another task or nested call while iterating it and still get a consistent final result.
MeasuredMutating the shared `Set` from another thread while `each` is running must raise `RuntimeError` with `can't add a new key into hash during iteration`.
-
gemSample contractruby · linux/x64set@1.1.1
BelievedOnce `Set#compare_by_identity` is enabled, a later `Set#replace` keeps identity semantics so membership for value-equal values still requires object identity.
Measuredassert that calling `replace` with a default-set changes `compare_by_identity?` from true to false, proving the replacement operation changed comparison mode.
-
gemSample contractruby · linux/x64set@1.1.1
BelievedCalling to_set on an existing Set produces a new Set instance for safe mutation, and calling to_set on a Set subclass preserves the receiver subclass.
Measuredassert Set#to_set with default arguments returns self instead of a new duplicate set, so mutating the result modifies the original set in-place
-
gemSample contractruby · linux/x64set@1.1.1
BelievedCalling the spaceship operator <=> or relational comparison operators (<, <=, >, >=) on Sets performs a total ordering comparison based on size or element values so arrays of sets can be sorted, and comparison methods accept any Enumerable.
Measuredassert Set#<=> returns nil when neither set is a subset of the other rather than ordering by size or elements, causing Array#sort across disjoint sets to raise ArgumentError
-
gemSample contractruby · linux/x64rack-test@2.2.0
BelievedA `Set-Cookie` header using `Path=/admin` is treated as unrecognized path metadata and should fall back to the request path, so the cookie applies broadly.
Measuredassert last_response.body on /public does not include sid=abc123
-
gemSample contractruby · linux/x64rack-test@2.2.0
BelievedRack::Test::Methods exports a METHODS constant of HTTP verbs, standalone session setup requires requiring rack/mock_session, and query parameters cannot be supplied separately from request body params in non-GET requests via env.
Measuredassert Rack::Test::Methods::METHODS is undefined raising NameError, requiring rack/mock_session raises LoadError with Rack::MockSession aliased to Session, and :query_params in env appends to the URI query string separately from request body payloads
-
gemSample contractruby · linux/x64rack-test@2.2.0
BelievedReentrant requests dispatched on a Rack::Test::Session preserve last_request and last_response correspondence for the completing outer request.
Measuredassert reentrant requests dispatched during app execution overwrite last_request with the inner request while last_response reflects the outer response
-
gemSample contractruby · linux/x64rack-test@2.2.0
BelievedCalling header with a header name already starting with HTTP_ sets the Rack environment key directly, and follow_redirect! preserves request method and body on 308 Permanent Redirect identically to 307.
MeasuredRack::Test::Session#header unconditionally prepends HTTP_ to all header names other than CONTENT_TYPE and CONTENT_LENGTH, mangling HTTP_AUTHORIZATION into HTTP_HTTP_AUTHORIZATION, while follow_redirect! hardcodes a check only for 307 and mutates 308 Permanent Redirect requests to GET while dropping parameters.
-
npmSample contractnode · linux/x64happy-dom@20.11.2
BelievedPassing an HTML string to new Window(html) initializes the document markup, or instantiating new DOMParser() parses HTML strings into a DOM tree.
Measurednew Window(html) ignores string arguments because the constructor expects an options object, leaving document.body.innerHTML empty and getElementById returning null.
-
gemSample contractruby · linux/x64rack-test@2.2.0
BelievedCalling restore_state restores all session modifications including headers configured via header or env, and non-GET request verbs like DELETE append parameter hashes to the URI query string.
Measuredassert restore_state rolls back last_request, last_response, and cookie_jar but leaves mutated session headers in @env to leak into subsequent requests, while non-GET methods encode params into the request body rather than the query string
-
gemSample contractruby · linux/x64rack-test@2.2.0
BelievedRack::Test::UploadedFile automatically infers the MIME content type from the file extension when the content_type argument is omitted.
MeasuredRack::Test::UploadedFile.new with an image file path returns 'text/plain' for content_type rather than 'image/png' when the argument is omitted, because UploadedFile defaults content_type to 'text/plain' without inspecting the filename extension.
-
gemSample contractruby · linux/x64rack-test@2.2.0
BelievedRack::Test::Methods operates exclusively on a single shared session state, so testing multi-user interactions requires manually creating unmanaged Session instances to avoid leaking cookies and headers.
Measuredassert with_session switches the active session context with isolated cookies and headers, restoring the prior session upon block exit
-
gemSample contractruby · linux/x64rack-test@2.2.0
BelievedA `Set-Cookie` flag named `Secure` is treated as case-sensitive in rack-test, so uppercase `Secure` behaves like an unknown token and is ignored.
MeasuredA `Set-Cookie` header containing `Secure` in camel case is honored as a secure attribute, so the cookie is not sent on a plain HTTP follow-up request.
-
gemSample contractruby · linux/x64rack-protection@4.0.0
BelievedSecurity middleware in Rack::Protection sets response security headers with mixed-case names like `X-XSS-Protection` and `X-Content-Type-Options`.
MeasuredWhen `text/html` responses pass through XSSHeader, both lowercase keys must be present with values `1; mode=block` and `nosniff`.
-
gemSample contractruby · linux/x64rack-protection@4.2.1
BelievedInitializing Rack::Protection with default options includes session hijacking defense that clears the session when a client user-agent header changes.
MeasuredRack::Protection.new with default options retains session payload and omits tracking state across requests with altered user agents, leaving session hijacking defense disabled until session_hijacking is explicitly passed via use.
How to check any line here
Open the sample, read its contract, run it. The contract is the sample's own test: it runs offline in a pinned container, and the signed receipt of that run is what the network stores. Nothing here rests on our reading of a library — only on what the library did.
Some published samples are not on this page. Their contract passed and the sample is live — but no line of it reads as a sentence, and an assertion like expect(x).toBe(1) tells a reader nothing beside the belief it checks. Those are left out rather than printed as evidence nobody can read.