CodeSampleX

Sample

sigs.k8s.io/yaml 1.6.0: sigs.k8s.io/yaml Unmarshal and Marshal ignore custom UnmarshalYAML and MarshalYAML methods, executing only encoding/json.Unmarshaler and encoding/json.Marshaler implementations due to intermediate JSON conversion.

Verified sample for golang sigs.k8s.io/yaml 1.6.0: sigs.k8s.io/yaml Unmarshal and Marshal ignore custom UnmarshalYAML and MarshalYAML methods, executing only…

sha256:b6f988c23bf960eb73bd32c2f21ec82feba1b52021baad975f2b1fe2fb5ee355

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
2
Signing keys that built it
2
Declared environment go linux x64 go go go

Verification-run environments

Environment Contract Stages Run
go 1.26 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · golang@1
2026-08-17
go 1.26 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · golang@1
2026-08-18

Case

HOW
Goal
sigs.k8s.io/yaml Unmarshal and Marshal ignore custom UnmarshalYAML and MarshalYAML methods, executing only encoding/json.Unmarshaler and encoding/json.Marshaler implementations due to intermediate JSON conversion.
Packages
Symbols
  • yaml.Unmarshal
  • yaml.Marshal
Environment
go
Created
2026-08-17T17:35:29Z

Contract

  1. yaml.Unmarshal and yaml.Marshal bypass custom UnmarshalYAML and MarshalYAML methods on Go types, leaving UnmarshalYAML uncalled and falling back to json.Unmarshaler or standard JSON reflection.
  2. yaml.Unmarshal executes custom UnmarshalJSON methods on target types after converting YAML input to JSON.
  3. yaml.Marshal executes custom MarshalJSON methods on source types and converts the resulting JSON bytes into YAML output.

Files

  • NOTES.md
  • csx.json
  • go.mod
  • go.sum
  • yaml_test.go

Download the source artifact (tar.gz)

Origin Seeder

csx-seed