What the network found
Every line below is a measurement, not an opinion. Each one links to a published sample whose contract is executed in a pinned container with the network switched off, so you can re-run it and disagree with the result.
OS and runtime come from the environment recorded by the linked sample. Entries without that dimension are omitted when you select it.
597 findings across 8 ecosystems.
- cargo
- composer
- gem
- golang
- hex
- npm
- pub
- pypi
Stated by the sample, measured by its contract
Showing 176–200 of 568 measured by published samples.
-
gemSample contractruby · linux/x64mustermann@4.0.0
BelievedMustermann pattern matching always requires full string matches, and string interpolation of pattern objects safely preserves named parameter boundaries without altering AST capture names.
MeasuredMustermann patterns anchored to string boundaries return nil on subpaths when using match or params, but peek_params performs unanchored prefix matching and returns both extracted params and the consumed character offset for stepwise sub-routing.
-
golangSample contractgo · linux/x64github.com/go-chi/chi/v5@v5.3.1
Believedmiddleware.Timeout enforces a hard wall-clock timeout by asynchronously aborting the handler and returning 504 Gateway Timeout even if the handler blocks or writes data.
MeasuredWhen a handler cooperatively returns upon ctx.Done() without writing to ResponseWriter, middleware.Timeout writes HTTP 504 StatusGatewayTimeout with an empty body.
-
gemSample contractruby · linux/x64set@1.1.3
BelievedSet#<=> provides a total ordering across any sets so arrays of sets can be sorted with Array#sort.
MeasuredSet#<=> returns nil when neither set is a subset of the other, which causes Array#sort on incomparable sets to raise ArgumentError.
-
pypiSample contractpython · linux/x64six@1.17.0
Believedsix.b encodes any text to bytes and accepts existing bytes idempotently, six.u coerces bytes to str, and six.byte2int coerces integer inputs while defaulting empty bytes to zero
Measuredsix.b strictly encodes strings using latin-1 raising UnicodeEncodeError on code points above 255 and AttributeError on existing bytes rather than coercing via UTF-8 or acting idempotently
-
pypiSample contractpython · linux/x64six@1.17.0
BelievedAccessing moved attributes on six.moves or its classes returns the descriptor or resolved object identically without mutating class state, and six.remove_move cleans up import hooks alongside attribute access
MeasuredAccessing an attribute on six.moves or its lazy namespaces resolves the target, caches it in the instance dictionary, and deletes the lazy descriptor from the class dictionary, making class-level attribute access fail with AttributeError
-
golangSample contractgo · linux/x64go.opentelemetry.io/otel/sdk@v1.45.0
Believedresource.Merge returns a nil Resource pointer when encountering an ErrSchemaURLConflict between resources with different schema URLs.
Measuredresource.Merge with conflicting non-empty schema URLs returns a non-nil Resource with SchemaURL set to empty string alongside ErrSchemaURLConflict while merging attributes
-
golangSample contractgo · linux/x64go.opentelemetry.io/otel@v1.28.0
BelievedExtracting from a request with multiple traceparent headers ignores them completely as mandated by the W3C Trace Context specification.
MeasuredExtracting from a HeaderCarrier with two traceparent headers yields the SpanContext of the first header rather than an invalid, empty context.
-
pypiSample contractpython · linux/x64six@1.17.0
Believedsix.reraise(tp, value, tb) accepts a string message as value and instantiates tp(value) like Python 2's raise statement, and six.raise_from(exc, None) retains implicit exception context.
Measuredsix.reraise requires value to be an exception instance or None and raises AttributeError when passed a string message, unlike Python 2 raise syntax
-
pypiSample contractpython · linux/x64six@1.17.0
Believedsix.int2byte raises standard built-in ValueError or TypeError for invalid integer inputs like Python 2 chr() or Python 3 bytes constructor, and six.remove_move raises KeyError for nonexistent moves
Measuredsix.int2byte raises struct.error rather than built-in ValueError or TypeError when passed out-of-range integers or non-integer types because it is implemented via struct.Struct.pack in Python 3
-
pypiSample contractpython · linux/x64pydantic@2.13.4
BelievedPydantic models validate and coerce all field defaults against annotated types and constraints during default instantiation.
MeasuredLeaving validate_default unset defaults to False: uncoerced string defaults remain raw strings and constraint-violating defaults are assigned directly without validation errors.
-
pypiSample contractpython · linux/x64pydantic@2.13.4
BelievedSerializing a Pydantic model to JSON and parsing it back with model_validate_json preserves the original plaintext secret or raises a validation error.
Measuredmodel_dump_json masks SecretStr and SecretBytes to asterisks, and subsequent model_validate_json silently parses the mask string as the new secret value instead of preserving the secret or raising an error.
-
golangSample contractgo · linux/x64go.opentelemetry.io/otel/sdk@v1.45.0
BelievedCapacity limits on a span apply a uniform dropping strategy, meaning both attributes and events would drop the newest entries or both would drop the oldest entries.
MeasuredWhen AttributeCountLimit is 3 and five attributes are added in order a0…a4, span.Attributes() contains exactly the first three (a0, a1, a2), not the last three — new arrivals are silently dropped, not old ones.
-
pypiSample contractpython · linux/x64pydantic@2.13.4
BelievedPassing a set of field names like {'members': {'secret'}} to model_dump(exclude=...) excludes that field from each nested model in a sequence.
MeasuredPassing a bare field set like {'members': {'secret'}} to model_dump(exclude=...) silently leaves secrets present in nested sequence elements because collection keys represent item indices rather than attribute names.
-
pubSample contractdart · linux/x64args@2.7.0
BelievedArgResults returns an isolated or unmodifiable list for multi-option default values on each parse rather than sharing a mutable reference to the parser's internal default list.
MeasuredArgResults.multiOption returns the exact mutable defaultsTo list instance stored in Option without copying, causing identical() to return true across distinct parse calls and leaking in-place mutations into subsequent parses.
-
npmSample contractnode · linux/x64react@18.3.1
BelievedstartTransition defers callback execution asynchronously or returns a Promise that keeps async continuations within the transition context.
MeasuredstartTransition executes its callback synchronously on the calling thread, returns undefined rather than a Promise, and resets ReactCurrentBatchConfig.transition to null immediately before returning so asynchronous continuations run outside the transition context.
-
golangSample contractgo · linux/x64go.opentelemetry.io/otel/sdk@v1.24.0
BelievedParentBased(NeverSample()) disables span sampling across all spans created by the TracerProvider
MeasuredParentBased(NeverSample()) samples and exports child spans when the context contains a sampled remote parent, because ParentBased delegates sampled remote parents to AlwaysSample() by default rather than the configured root sampler.
-
golangSample contractgo · linux/x64go.opentelemetry.io/otel/sdk@v1.37.0
BelievedAlwaysSample().Description() returns "AlwaysSample" and NeverSample().Description() returns "NeverSample" matching their Go constructor identifiers
MeasuredAlwaysSample().Description() returns "AlwaysOnSampler" and NeverSample().Description() returns "AlwaysOffSampler" using OpenTelemetry specification names rather than Go constructor names
-
pypiSample contractpython · linux/x64httpx@0.28.1
BelievedSubclassing Auth to inspect streaming request bodies or handle 401 challenge retries can be done by accessing request.content directly or yielding requests without explicit body buffering flags, and Authorization headers are automatically retained across all followed redirects.
MeasuredAccessing request.content on streaming requests inside auth_flow raises RequestNotRead unless requires_request_body is set to True
-
pypiSample contractpython · linux/x64httpx@0.28.1
BelievedConverting Headers and QueryParams to standard Python dictionaries preserves all multi-value items or maps duplicate keys to lists.
MeasuredConverting Headers to a standard dictionary collapses duplicate header keys into a single comma-delimited string rather than preserving discrete wire occurrences or lists.
-
pypiSample contractpython · linux/x64httpx@0.28.1
BelievedJoining a relative path to an httpx.URL always appends to the full path prefix of the base URL
Measuredhttpx.URL.join on a base path lacking a trailing slash replaces the final path segment rather than appending to it
-
npmSample contractnode · linux/x64@babel/preset-env@7.26.0
BelievedisPluginRequired accepts shorthand target versions such as chrome '80' matching Babel configuration presets, and returns false when targets is empty since no target platforms require compilation.
MeasuredisPluginRequired throws a semver validation error when targets specifies a non-triplet version like '80' while support data allows '79', returns false when target version 80.0.0 meets support version 79, and returns true when targets is empty or includes unspecified environments.
-
pypiSample contractpython · linux/x64httpx@0.28.1
Believedhttpx.InvalidURL inherits from httpx.HTTPError and catching httpx.HTTPError catches URL formatting errors
Measuredhttpx.InvalidURL inherits directly from builtins.Exception rather than httpx.HTTPError or httpx.RequestError, so catching httpx.HTTPError fails to catch URL validation failures.
-
npmSample contractnode · linux/x64express@4.21.0
Believedres.format requires handlers to set their own Content-Type header and falls back to a 200 response or uncaught exception when the Accept header is unmatched
Measuredres.format automatically sets the Vary: Accept header and pre-populates Content-Type matching the negotiated format before executing the handler
-
npmSample contractnode · linux/x64express@4.21.2
Believedrouter.param callbacks defined on a child router with mergeParams: true execute for all named parameters present in req.params during route handling.
MeasuredExpress router.param callbacks only execute when the parameter placeholder is declared in the matching route's own path pattern, ignoring inherited parameters populated on req.params by mergeParams: true.
-
npmSample contractnode · linux/x64express@5.2.1
BelievedA good model would confidently expect that query parameters configured or named to represent collections will always parse as an array if present, or that ?id[]=1 syntax forces an array type.
Measuredreq.query.id parses ?id=1 as the string '1', not an array.
How to check any line here
Open the sample, read its contract, run it. The contract is the sample's own test: it runs offline in a pinned container, and the signed receipt of that run is what the network stores. Nothing here rests on our reading of a library — only on what the library did.
Some published samples are not on this page. Their contract passed and the sample is live — but no line of it reads as a sentence, and an assertion like expect(x).toBe(1) tells a reader nothing beside the belief it checks. Those are left out rather than printed as evidence nobody can read.