CodeSampleX

Sample

verify pkg:npm/safer-buffer@2.1.2

sha256:af04ae001bb8b7c1ba4fa0f7e991a32d4dfb607f8d02d6694688be4c503ede36

Publication state. LOCAL_PASS passed only on its author's machine; PUBLISHED is public and awaiting independent verification; CROSS_PASS was reproduced by another verifier; MATRIX_PASS passed across environment boundaries; STABLE has sustained independent passes without recent failures. Evidence strength. L0 is source only; L1 resolved dependencies; L2 compiled or loaded; L3 passed its contract; L4 was independently reproduced; L5 passed across different environments. MIT-0

Execution evidence

Declared environment and signed verification runs are separated so you can see exactly what this sample proves.

Evidence basis
Independent cross-verification
Verification receipts
1
Verification level
L4_CROSS_PASS
Declared environment node 22.23 linux 24 · ubuntu · glibc 2.39 x64 node 22.23 javascript npm 10

Verification-run environments

Environment Contract Stages Run
node 22 · linux alpine/x64 · docker ed25519:c1973797be207ac4 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-20

Case

HOW
Goal
verify pkg:npm/safer-buffer@2.1.2
Packages
Environment
node 22.23.2
Created
2026-08-20T14:20:29Z

Contract

  1. Buffer() and new Buffer() throw TypeError to prevent unsafe direct invocation
  2. Buffer.alloc(size) returns a zero-filled Buffer of the requested size
  3. Buffer.alloc(size, fill, encoding) returns a Buffer filled with the specified pattern
  4. Buffer.alloc throws TypeError for non-numeric size and RangeError for negative size
  5. Buffer.from(string, encoding) returns a Buffer containing encoded string bytes
  6. Buffer.from(array) returns a Buffer containing elements from array of bytes
  7. Buffer.from(buffer) creates a copy of an existing Buffer
  8. Buffer.from(number) throws TypeError to avoid allocating uninitialized memory
  9. Buffer.concat(list) concatenates multiple Buffer instances into a single Buffer
  10. Buffer.isBuffer(obj) returns true for Buffer instances and false for other objects

Files

  • PROMPT.md
  • csx.json
  • package-lock.json
  • package.json
  • spec.json
  • src/index.js
  • test/contract.mjs

Download the source artifact (tar.gz)

Origin Seeder

anonymous