Sample
Pin Viper 1.21.0 string-slice parsing differences across environment values, pflag StringSlice values, and in-memory YAML
sha256:a8a9630ca346da32b160e5e78bdd2de5b40347a27f3c473d7655f5610be6f6e7
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Execution evidence
Declared environment and signed verification runs are separated so you can see exactly what this sample proves.
Evidence basisSigned contract pass
Verification receipts1
Verification levelL3_CONTRACT_PASS
Declared environment
- Execution context
- go
- Operating system
- linux
- Architecture
- x64
- Runtime
- go
- Language
- go
- Package manager
- go
Verification-run environments
- Execution context
- go 1.26
- Operating system
- linux alpine · musl
- Architecture
- x64
- Runtime
- go 1.26
- Language
- go
- Package manager
- go
- Execution
- container · docker
CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · golang@1 · 2026-08-17
Case
- Goal
- Pin Viper 1.21.0 string-slice parsing differences across environment values, pflag StringSlice values, and in-memory YAML HOW
- Packages
-
github.com/spf13/viper v1.21.0
github.com/spf13/pflag v1.0.10
- Environment
- go
- Created
- 2026-08-17T03:51:40Z
Commonly assumed
viper.GetStringSlice parses a comma-separated environment value into the same multi-element slice as viper.Unmarshal.
The sample's author recorded this as what a developer or model would expect here. The contract below is what actually ran.
Contract
- assert GetStringSlice returns one comma-containing element for a comma-separated environment value
- assert Unmarshal returns two elements for that same comma-separated environment value
- assert GetStringSlice splits a whitespace-separated environment value while Unmarshal retains it as one element
- assert GetStringSlice and Unmarshal both return two elements when a bound pflag.StringSlice has already parsed the comma
- assert a YAML sequence returns two elements for both APIs while a YAML comma-separated scalar remains one element in GetStringSlice and becomes two through Unmarshal
Files
- NOTES.md
- csx.json
- go.mod
- go.sum
- slice_test.go
Download the source artifact (tar.gz)
Origin Seeder
csx-seed
Verification receipts
- go 1.26 · linux alpine/x64 · docker · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · golang@1 · 2026-08-17 · ed25519:d91480838ac982c9