Sample
sigs.k8s.io/yaml Unmarshal and Marshal ignore custom UnmarshalYAML and MarshalYAML methods, executing only encoding/json.Unmarshaler and encoding/json.Marshaler implementations due to intermediate JSON conversion.
sha256:b6f988c23bf960eb73bd32c2f21ec82feba1b52021baad975f2b1fe2fb5ee355
PUBLISHED
L3_CONTRACT_PASS
MIT-0
Execution evidence
Declared environment and signed verification runs are separated so you can see exactly what this sample proves.
Evidence basisSigned contract pass
Verification receipts1
Verification levelL3_CONTRACT_PASS
Declared environment
- Execution context
- go
- Operating system
- linux
- Architecture
- x64
- Runtime
- go
- Language
- go
- Package manager
- go
Verification-run environments
- Execution context
- go 1.26
- Operating system
- linux alpine · musl
- Architecture
- x64
- Runtime
- go 1.26
- Language
- go
- Package manager
- go
- Execution
- container · docker
CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · golang@1 · 2026-08-17
Case
- Goal
- sigs.k8s.io/yaml Unmarshal and Marshal ignore custom UnmarshalYAML and MarshalYAML methods, executing only encoding/json.Unmarshaler and encoding/json.Marshaler implementations due to intermediate JSON conversion. HOW
- Packages
-
sigs.k8s.io/yaml 1.6.0
- Environment
- go
- Created
- 2026-08-17T17:35:29Z
Commonly assumed
A YAML parsing and serialization library invokes custom UnmarshalYAML and MarshalYAML hook methods implemented on Go types when decoding and encoding YAML documents.
The sample's author recorded this as what a developer or model would expect here. The contract below is what actually ran.
Contract
- yaml.Unmarshal and yaml.Marshal bypass custom UnmarshalYAML and MarshalYAML methods on Go types, leaving UnmarshalYAML uncalled and falling back to json.Unmarshaler or standard JSON reflection.
- yaml.Unmarshal executes custom UnmarshalJSON methods on target types after converting YAML input to JSON.
- yaml.Marshal executes custom MarshalJSON methods on source types and converts the resulting JSON bytes into YAML output.
Files
- NOTES.md
- csx.json
- go.mod
- go.sum
- yaml_test.go
Download the source artifact (tar.gz)
Origin Seeder
csx-seed
Verification receipts
- go 1.26 · linux alpine/x64 · docker · CONTAINER_RUN · compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS · golang@1 · 2026-08-17 · ed25519:d91480838ac982c9