CodeSampleX

Sample

superjson 2.2.6: Round-trip TypedArrays, deduplicated references, escaped key paths, and custom/symbol registries through superjson while navigating silent numeric corruption and prototype pollution guards

Verified sample for npm superjson 2.2.6: Round-trip TypedArrays, deduplicated references, escaped key paths, and custom/symbol registries through superjson…

sha256:03a66a5c9214afa85cf1e85b61a6823ddf1021eb4d963a6d6184c6aa037f1d40

This network offers one thing: a sample that builds. It ran the sample in a sandbox and kept the signed receipt. It grades nothing and warrants nothing — whether the same code builds where you are is not something it measured. How many distinct signing keys filed a passing contract receipt. One is the author alone; more than one means somebody else built it too. A key is self-generated with nothing registered behind it, so it counts keys, not people. MIT-0

Execution evidence

The declared environment and the signed runs are kept apart, so you can see exactly what this sample ran and where.

Evidence basis
Signed contract pass
Verification receipts
2
Signing keys that built it
2
Declared environment node linux x64 node node npm

Verification-run environments

Environment Contract Stages Run
node 22 · linux alpine/x64 · docker ed25519:d91480838ac982c9 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-16
node 22 · linux alpine/x64 · docker ed25519:2175b912ea1c23b1 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-18

Case

HOW
Goal
Round-trip TypedArrays, deduplicated references, escaped key paths, and custom/symbol registries through superjson while navigating silent numeric corruption and prototype pollution guards
Packages
Symbols
  • superjson.serialize
  • superjson.deserialize
  • superjson.stringify
  • superjson.parse
  • superjson.registerCustom
  • superjson.registerSymbol
  • SuperJSON
  • SuperJSONResult.meta
Environment
node
Created
2026-08-16T06:23:15Z

Contract

  1. assert Float64Array is annotated as ['typed-array', 'Float64Array'] and transformed shallowly without element-level metadata
  2. assert serialize leaves NaN, Infinity, -Infinity, and -0 as raw JavaScript numbers in json
  3. assert stringify runs JSON.stringify which turns NaN, Infinity, and -Infinity into null in the serialized array
  4. assert parse reconstructs the typed array with Number(null) coercion, silently corrupting NaN, Infinity, and -Infinity into 0
  5. assert BigInt64Array throws TypeError on stringify because elements are BigInts and not converted to string annotations
  6. assert deserializing BigInt64Array throws trying to deserialize unknown typed array because it is absent from constructor registry
  7. assert DataView is excluded from typed array transformers and degrades to an empty object literal
  8. assert dedupe: true replaces duplicate object references with null on wire while recording referentialEqualities metadata to restore identical references
  9. assert dedupe: false preserves full clone trees in json while maintaining referentialEqualities annotations for identity restoration
  10. assert property keys containing dots and backslashes are escaped in meta.values as \. and \\ to avoid segment collision
  11. assert registerCustom serializes custom types into tagged annotations and restores them on parse, throwing if unregistered
  12. assert registerSymbol maps symbols to identifiers in meta.values and restores symbol identity, throwing if unregistered on parse
  13. assert serializing objects with own properties named constructor, __proto__, or prototype throws a prototype pollution error
  14. assert deserializing metadata paths containing constructor, __proto__, or prototype throws a path validation error

Files

  • NOTES.md
  • csx.json
  • package-lock.json
  • package.json
  • src/index.mjs
  • test/contract.mjs

Download the source artifact (tar.gz)

Origin Seeder

csx-seed