Recordsnpm@rollup/plugin-commonjs28.0.9
Change the conditions
Current conditions
@rollup/plugin-commonjs @28.0.9alpine musl · x64 · node 22 · npm · node
package-level total, not an API
1 of 1 passed
Verified — this network ran a contract at this coordinate.
there is a sample here, and our run of it at this coordinate came back clean (5)
- Project observations
- 2 / 2
- Contract verifications
- 1 / 1
- Usage records
- 1
- Independent reporting peers
- 1
- Last recorded
- 2026-08-30
Dependency Health
Observed combinations and failure evidence for this release
First observed break
28.0.9
linux · node@22.23 · moduleSystem=esm · executionContext=node
1 FAIL
· stage: UNKNOWN
· fingerprint: sha256:a064fa24000404436337f1772fbdfdf837f37da95ec8a76bc8e1c53d2d945758
| Library | Version | Health | Measured there | Projects |
|---|---|---|---|---|
| @rollup/pluginutils | 5.4.0 | CANDIDATE Correlated change; unproven combination | contract passed | 7 project-days |
| picomatch | 4.0.7 | CANDIDATE Correlated change; unproven combination | contract passed | 7 project-days |
| commondir | 1.0.1 | PASS All observations passed | contract passed | 7 project-days |
| estree-walker | 2.0.2 | PASS All observations passed | contract passed | 7 project-days |
| fdir | 6.5.0 | PASS All observations passed | contract passed | 7 project-days |
| is-reference | 1.2.1 | PASS All observations passed | contract passed | 7 project-days |
| magic-string | 0.30.21 | PASS All observations passed | contract passed | 7 project-days |
The measured column is about each dependency's own release, not about the pair. A resolver placing two releases side by side is not evidence that they work together.
Dependency versions across releases
What each release of this package resolved its children to. A child whose version moved is listed first: that is where an upgrade changed something underneath you.
| Library | 29.0.3 | 28.0.9 | 28.0.7 | 28.0.2 | 28.0.1 |
|---|---|---|---|---|---|
| @rollup/pluginutils | 5.4.0 | 5.4.0 | 5.4.0 | 5.4.0 | 5.3.0 |
| picomatch | 4.0.7 | 4.0.7 | 4.0.7 | 4.0.7 | 4.0.3 |
| commondir | 1.0.1 | 1.0.1 | 1.0.1 | 1.0.1 | 1.0.1 |
| estree-walker | 2.0.2 | 2.0.2 | 2.0.2 | 2.0.2 | 2.0.2 |
| fdir | 6.5.0 | 6.5.0 | 6.5.0 | 6.5.0 | 6.5.0 |
| is-reference | 1.2.1 | 1.2.1 | 1.2.1 | 1.2.1 | 1.2.1 |
| magic-string | 0.30.21 | 0.30.21 | 0.30.21 | 0.30.21 | 0.30.21 |
| rollup | — | — | 4.34.8 | — | — |
Moved: 2 · unchanged at every release: 6
An edge records that a resolver placed one release beside another on a real machine. It is not a claim that the two work together; that question is answered by samples and contracts, not by presence here.
Recent failure clusters
-
observed UNKNOWN exit 1 ERR_MODULE_NOT_FOUND Evidence gap ×1 28.0.9 executionContext=node · moduleSystem=esm · os=linux · runtime=node@22.23 sha256:a064fa240004…node:internal/modules/esm/resolve:<n> · throw new ERR_MODULE_NOT_FOUND( · ^ · Error [ERR_MODULE_NOT_FOUND]: Cannot find module <str> imported from <path>npm · unclassified-diagnostic · outer npm test · gap stage-unknownEvidence quality: complete · Environment variants: 1 · First recorded: 2026-09-03 · Last seen: 2026-09-03Diagnostic re-verification candidate
-
observed UNKNOWN exit 1 ERR_ASSERTION Evidence gap ×1 28.0.9 executionContext=node · moduleSystem=esm · os=linux · runtime=node@22.23 sha256:df5e9f844963…Contract failed: AssertionError [ERR_ASSERTION]: assert matching target resolves from dynamic module registry · at runContract (<url>) { …node · unclassified-diagnostic · outer node · gap stage-unknownEvidence quality: complete · Environment variants: 1 · First recorded: 2026-09-03 · Last seen: 2026-09-03Diagnostic re-verification candidate