Sample
Generate non-cryptographic identifiers with nanoid/non-secure and verify silent empty-string returns on negative size inputs versus cryptographic RangeError
sha256:33fa894d2e8aaa8166a9bf954a74dc0f162cef7ee04cb938033b25c057f076c8
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Execution evidence
Declared environment and signed verification runs are separated so you can see exactly what this sample proves.
Evidence basisSigned contract pass
Verification receipts1
Verification levelL3_CONTRACT_PASS
Declared environment
- Execution context
- node
- Operating system
- linux
- Architecture
- x64
- Runtime
- node
- Language
- node
- Package manager
- npm
Verification-run environments
- Execution context
- node 22
- Operating system
- linux alpine · musl
- Architecture
- x64
- Runtime
- node 22
- Language
- javascript
- Package manager
- npm
- Execution
- container · docker
CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · node-typescript@1 · 2026-08-17
Case
- Goal
- Generate non-cryptographic identifiers with nanoid/non-secure and verify silent empty-string returns on negative size inputs versus cryptographic RangeError HOW
- Packages
-
nanoid 6.0.1
- Environment
- node
- Created
- 2026-08-17T19:54:26Z
Commonly assumed
Negative size arguments passed to nanoid/non-secure functions are expected to throw a RangeError matching cryptographic nanoid behavior.
The sample's author recorded this as what a developer or model would expect here. The contract below is what actually ran.
Contract
- nanoid/non-secure functions return an empty string for negative or non-positive sizes rather than throwing RangeError like root nanoid
- assert nanoid() from nanoid/non-secure generates 21-character URL-safe identifiers by default
- assert nanoid/non-secure customAlphabet produces IDs restricted to the custom alphabet at requested lengths
- assert negative sizes passed to nanoid/non-secure return empty strings while root nanoid throws RangeError
- assert float sizes are truncated to integer via bitwise OR and non-numeric sizes evaluate to empty strings
Files
- NOTES.md
- csx.json
- package-lock.json
- package.json
- src/index.mjs
- test/contract.mjs
Download the source artifact (tar.gz)
Origin Seeder
csx-seed
Verification receipts
- node 22 · linux alpine/x64 · docker · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · node-typescript@1 · 2026-08-17 · ed25519:d91480838ac982c9