What the network found
Every line below is a measurement, not an opinion. Each one links to a published sample whose contract is executed in a pinned container with the network switched off, so you can re-run it and disagree with the result.
OS and runtime come from the environment recorded by the linked sample. Entries without that dimension are omitted when you select it.
597 findings across 8 ecosystems.
- cargo
- composer
- gem
- golang
- hex
- npm
- pub
- pypi
Stated by the sample, measured by its contract
Showing 501–525 of 568 measured by published samples.
-
npmSample contractnode · linux/x64@babel/core@8.0.1
BelievedTargeting an environment with known JavaScript engine bugs forces preset-env to downlevel the surrounding modern ES2015+ syntax categories down to ES5 helper functions.
Measuredpreset-env targeting Safari 14 preserves native ES2015 destructuring syntax and parameter defaults while surgically renaming only the colliding parameter identifier to avoid JavaScriptCore scope shadowing bugs
-
npmSample contractnode · linux/x64@babel/preset-env@7.29.7
BelievedLeaving useBuiltIns unset in @babel/preset-env automatically injects polyfills for unsupported ECMAScript standard library methods across configured target environments when corejs is configured or core-js is imported.
MeasuredWhen useBuiltIns is unset, @babel/preset-env defaults to false and leaves standard library methods un-polyfilled without injecting any core-js imports, even when targets lack support or corejs is specified.
-
npmSample contractnode · linux/x64@babel/preset-env@8.0.2
BelievedIn Babel presets, legacy configuration options like loose, spec, bugfixes, and useBuiltIns remain accepted as valid options, and isPluginRequired continues to be exported as a helper function.
MeasuredPassing loose, spec, bugfixes, or useBuiltIns to @babel/preset-env in major version 8 throws descriptive removal errors rather than accepting legacy configuration options or polyfill strategies.
-
composerSample contractphp · linux/x64symfony/console@8.1.4
BelievedSubclassing Command with a static getDefaultName method automatically defines the command name on instantiation, and closures assigned via setCode may omit explicit integer return values.
MeasuredCommand subclasses defining static getDefaultName() have a null name in Symfony Console 8 because getDefaultName() was removed in favor of #[AsCommand], and Application::addCommand() throws LogicException for empty names.
-
npmSample contractnode · linux/x64@rollup/plugin-commonjs@29.0.3
BelievedWhen bundling CommonJS modules that conditionally require Node built-ins into ESM, @rollup/plugin-commonjs preserves lazy evaluation inside functions without hoisting static imports to the module top level.
MeasuredBy default, @rollup/plugin-commonjs hoists conditional require('node:fs') calls to top-level ESM static imports, eagerly loading built-in modules on startup rather than preserving lazy CommonJS evaluation.
-
npmSample contractnode · linux/x64@rollup/plugin-commonjs@28.0.9
BelievedBy default @rollup/plugin-commonjs transforms require expressions into bundled module imports in any file processed by Rollup.
Measuredassert requireReturnsDefault defaults to false, returning an augmented namespace object with __esModule marker rather than unwrapping default export directly when CJS requires ESM
-
gemSample contractruby · linux/x64csv@3.3.2
BelievedA good model expects CSV to inherit its default `row_sep` from `$INPUT_RECORD_SEPARATOR` whenever `row_sep` is not passed.
Measuredassert that setting `$INPUT_RECORD_SEPARATOR` to "|" and calling `CSV.new("a,b")` yields `row_sep == "\n"`
-
gemSample contractruby · linux/x64csv@3.3.2
BelievedThe CSV :numeric and :integer converters parse numeric string values using base-10 decimal representation.
MeasuredCSV.parse_line with converters: :numeric parses leading-zero strings like 012 as octal integer 10, whereas strings with non-octal digits like 008 fall through to float 8.0 rather than parsing as decimal integers or strings
-
gemSample contractruby · linux/x64csv@3.3.2
BelievedCSV.parse treats an input IO stream as caller-managed and leaves it open after parsing, while CSV.open and CSV.foreach automatically release underlying file handles.
MeasuredCSV.parse(io) without a block permanently closes the caller-provided IO or StringIO stream upon completion, whereas CSV.parse(io) with a block leaves the stream open
-
gemSample contractruby · linux/x64csv@3.3.2
BelievedCalling CSV.instance twice with the same source should create independent parser state that starts from the beginning each time.
MeasuredCSV.instance caches one parser per source object and option set, so the second call with the same source reuses the first parser's cursor instead of starting over.
-
gemSample contractruby · linux/x64csv@3.3.2
BelievedPassing converters: :numeric parses numeric strings with leading zeros as decimal numbers or preserves them consistently as strings.
MeasuredCSV.parse_line with converters: :numeric parses leading-zero strings with octal digits 0-7 as octal integers while strings containing 8 or 9 fall back to floats, mutating 0123 into 83 and 0890 into 890.0 across a round trip
-
gemSample contractruby · linux/x64csv@3.3.2
BelievedCSV::InvalidEncodingError inherits from Ruby core's EncodingError, and liberal_parsing: true suppresses unclosed quote errors.
MeasuredCSV::InvalidEncodingError inherits from CSV::MalformedCSVError and RuntimeError rather than EncodingError, so rescue EncodingError fails to catch byte sequence errors during parsing.
-
gemSample contractruby · linux/x64csv@3.3.2
BelievedCSV.parse returns empty strings for unquoted empty fields between delimiters by default.
Measuredassert parsing unquoted empty fields returns nil rather than empty string when nil_value is left unset
-
gemSample contractruby · linux/x64csv@3.3.2
BelievedA developer expects duplicated header values to follow normal Ruby Hash last-wins semantics when using CSV row conversion.
MeasuredCSV.parse("id,id,name\n1,2,alice\n", headers: true).first.to_h["id"] evaluates to "1", not "2", because CSV::Row#to_h preserves the first duplicate header.
-
cargoSample contractrust · linux/x64winnow@1.0.4
BelievedCalling `Parser::default_value()` makes a parser yield the default value whenever the wrapped parser fails.
Measuredassert `alpha1.default_value()` on '123' returns `Err(ErrMode::Backtrack(_))` instead of falling back to `0`
-
npmSample contractnode · linux/x64@babel/core@8.0.1
BelievedloadPartialConfig({...}) returns a PartialConfig object synchronously, because that is how every Babel 7 example, README snippet, and tool integration calls it; the callback form was always optional.
MeasuredCalling loadPartialConfig() without a callback in Babel 8 throws an Error whose message names loadPartialConfigSync as the required synchronous replacement — in Babel 7 the identical call returned a PartialConfig object without throwing.
-
hexSample contractelixir · linux/x64nimble_csv@1.3.0
BelievedWhen a parser is defined with separator: ["|", ";"], dumping rows that were parsed from semicolon-delimited input will preserve the semicolon separator, because the parser accepted that format.
MeasuredParsing semicolon-separated CSV with a multi-separator parser succeeds, but dump_to_iodata emits pipe-separated output — the first separator in the list — not the semicolon the input used, because the dump separator is fixed at compile time by the first list entry.
-
hexSample contractelixir · linux/x64nimble_pool@1.1.0
BelievedA model expects that starting a lazy pool with lazy: true defers worker module validation until checkout, allowing start_link to return {:ok, pid} even when given an unresolvable worker module or an atom :infinity for pool_size.
MeasuredNimblePool.start_link/1 with lazy: true eagerly ensures the worker module is loaded in init/1 and fails pool startup with an ArgumentError when the module is not found.
-
hexSample contractelixir · linux/x64ecto@3.12.5
BelievedEcto.Multi.run/3 accepts a single-argument callback receiving the accumulated changes map, matching other Multi dynamic callbacks and Ecto 2 conventions.
Measuredassert Ecto.Multi.run/3 requires a 2-arity function taking repo and changes and raises FunctionClauseError on a 1-arity function, whereas Multi.insert/3 and Multi.merge/2 accept 1-arity functions receiving only changes
-
golangSample contractgo · linux/x64net/http@go1.26.5
BelievedOnce net/http drops Authorization for a cross-domain redirect, the header stays absent for the rest of the chain — but before go1.23.7 / go1.24.1, a same-domain hop immediately following a cross-domain hop silently restores Authorization to the request, leaking the credential to the second domain while the HTTP response stays 200.
MeasuredAfter a three-hop redirect chain where the first cross-domain hop strips Authorization, the Authorization header must be absent at the same-domain second hop on serverB — before go1.23.7 / go1.24.1 this assertion fails silently with a 200 response.
-
golangSample contractgo · linux/x64net/http@v1.26.5
BelievedSetting http.Transport.MaxIdleConns to a high value allows all idle connections to a single target host to be pooled when MaxIdleConnsPerHost is left unset.
MeasuredLeaving http.Transport.MaxIdleConnsPerHost unset (0) with MaxIdleConns set to 100 retains only 2 idle connections for a host, rejecting the 3rd connection with 'too many idle connections for host'.
-
golangSample contractgo · linux/x64net/http@go1.22.0
BelievedReadHeaderTimeout enforces a deadline on reading the request body
Measuredthe server handler takes >2s to read the request body despite ReadHeaderTimeout=1s
-
golangSample contractgo · linux/x64net/http@v1.26.5
BelievedCalling resp.Body.Close() — the pattern shown in every tutorial — is sufficient for http.Transport to reclaim and reuse the underlying TCP connection for the next request.
MeasuredWhen resp.Body.Close() is called without draining the body first, http.Transport opens a brand-new TCP connection for the very next request to the same host, measured via httptrace.GotConnInfo.Reused being false.
-
golangSample contractgo · linux/x64net/http@v1.26.5
BelievedA second request on the same `http.Client` should proceed after the first `Do` call returns, even if that first response body is never read or closed.
MeasuredA second request using the same `http.Client` and `http.Transport{MaxConnsPerHost: 1}` does not complete while the first response body remains open, returning a context timeout instead.
-
golangSample contractgo · linux/x64net/http@go1.26.5
BelievedA setting named `GODEBUG=http2server=0` only affects debug output, so an explicit HTTP/2-only setup should still work.
MeasuredAn HTTP/2-only client-server pair should negotiate and return `HTTP/2.0` by default, while the same code with `GODEBUG=http2server=0` must fail because no shared protocol is available.
How to check any line here
Open the sample, read its contract, run it. The contract is the sample's own test: it runs offline in a pinned container, and the signed receipt of that run is what the network stores. Nothing here rests on our reading of a library — only on what the library did.
Some published samples are not on this page. Their contract passed and the sample is live — but no line of it reads as a sentence, and an assertion like expect(x).toBe(1) tells a reader nothing beside the belief it checks. Those are left out rather than printed as evidence nobody can read.