CodeSampleX

Sample

superjson 2.2.6: Observe how superjson's metadata format versioning (meta.v), deduplication mode, in-place deserialization, and registry keying alter serialization behavior silently across boundaries

Verified sample for npm superjson 2.2.6: Observe how superjson's metadata format versioning (meta.v), deduplication mode, in-place deserialization, and…

sha256:e6cb64b107388f3fa051f1da09fd44d009cf211ada6b133e516d380c798ce68a

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
2
Signing keys that built it
2
Declared environment node linux x64 node node npm

Verification-run environments

Environment Contract Stages Run
node 22 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-16
node 22 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-18

Case

HOW
Goal
Observe how superjson's metadata format versioning (meta.v), deduplication mode, in-place deserialization, and registry keying alter serialization behavior silently across boundaries
Packages
Symbols
  • superjson.serialize
  • superjson.deserialize
  • superjson.stringify
  • superjson.parse
  • superjson.registerSymbol
  • superjson.registerClass
  • superjson.registerCustom
  • SuperJSON
  • SuperJSONResult.meta
Environment
node
Created
2026-08-16T06:23:09Z

Contract

  1. assert meta.v is 1 in modern superjson and escapes dots with backslashes so dotted keys round-trip intact
  2. assert unversioned or legacy meta.v < 1 payloads silently misroute dotted paths to nested sibling properties, leaving the top-level key as a string and creating an Invalid Date without throwing
  3. assert deserialize defaults to inPlace: false via a deep clone leaving the input payload untouched, whereas inPlace: true directly mutates payload.json into live runtime objects
  4. assert parse uses inPlace: true internally on the parsed JSON tree rather than cloning
  5. assert dedupe: false preserves full duplicate structures in json while annotating referential equalities, allowing non-superjson consumers to read the payload
  6. assert dedupe: true replaces duplicate object instances with null in json, causing silent data loss for plain JSON consumers while superjson restores referential equality
  7. assert circular references write null at the cycle point and restore referential equality on deserialization in both modes
  8. assert registerSymbol without an explicit identifier keys by description, so registering two distinct symbols with identical descriptions silently causes the second to overwrite the first upon deserialization
  9. assert registerClass with allowProps silently strips any unlisted properties from the serialized JSON payload
  10. assert registerCustom does not recursively walk the returned structure, treating its output as a terminal leaf and leaving inner types unannotated
  11. assert superjson strictly forbids prototype pollution keys (__proto__, constructor, prototype) by throwing during serialization, unlike standard JSON.stringify

Files

  • NOTES.md
  • csx.json
  • package-lock.json
  • package.json
  • src/boundaries.mjs
  • test/contract.mjs

Download the source artifact (tar.gz)

Origin Seeder

csx-seed