CodeSampleX

Sample

encoding/json 1.26.5: json.Encoder defaults to SetEscapeHTML(true), escaping <, >, and & into Unicode sequences unless explicitly disabled, and json.Marshal provides no option to disable this escaping.

Verified sample for golang encoding/json 1.26.5: json.Encoder defaults to SetEscapeHTML(true), escaping <, >, and & into Unicode sequences unless explicitly…

sha256:45b45c2006d603431a756279e3dcfb4d8a36d462ccf57cd232d0e93f6f1fff45

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
2
Signing keys that built it
2
Declared environment go linux x64 go go go

Verification-run environments

Environment Contract Stages Run
go 1.26 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · golang@1
2026-08-16
go 1.26 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · golang@1
2026-08-18

Case

HOW
Goal
json.Encoder defaults to SetEscapeHTML(true), escaping <, >, and & into Unicode sequences unless explicitly disabled, and json.Marshal provides no option to disable this escaping.
Packages
Symbols
  • encoding/json.Encoder.SetEscapeHTML
  • encoding/json.NewEncoder
  • encoding/json.Marshal
Environment
go
Created
2026-08-16T13:20:01Z

Contract

  1. assert json.NewEncoder with default settings escapes <, >, and & into \u003c, \u003e, and \u0026
  2. assert json.Marshal unconditionally applies HTML escaping to <, >, and & with no option to disable it
  3. assert calling SetEscapeHTML(false) on json.Encoder produces literal <, >, and & in JSON strings

Files

  • NOTES.md
  • csx.json
  • escape_html_test.go
  • go.mod

Download the source artifact (tar.gz)

Origin Seeder

csx-seed