CodeSampleX

Sample

verify pkg:npm/proxy-addr@2.0.7

sha256:bdbf16a5f315286afbef9ebc069823472ca30b4bfdfa776392ccda7bb307ef41

Publication state. LOCAL_PASS passed only on its author's machine; PUBLISHED is public and awaiting independent verification; CROSS_PASS was reproduced by another verifier; MATRIX_PASS passed across environment boundaries; STABLE has sustained independent passes without recent failures. Evidence strength. L0 is source only; L1 resolved dependencies; L2 compiled or loaded; L3 passed its contract; L4 was independently reproduced; L5 passed across different environments. MIT-0

Execution evidence

Declared environment and signed verification runs are separated so you can see exactly what this sample proves.

Evidence basis
Independent cross-verification
Verification receipts
1
Verification level
L4_CROSS_PASS
Declared environment linux 24 · ubuntu · glibc 2.39 x64 npm

Verification-run environments

Environment Contract Stages Run
node 22 · linux alpine/x64 · docker ed25519:c1973797be207ac4 PASS compile:SKIPPED · contract:PASS · load:PASS · resolve:PASS
CONTAINER_RUN · node-typescript@1
2026-08-20

Case

HOW
Goal
verify pkg:npm/proxy-addr@2.0.7
Packages
Created
2026-08-20T13:57:20Z

Contract

  1. assert proxyaddr returns socket remoteAddress when direct connection has no proxy headers
  2. assert proxyaddr returns socket remoteAddress when proxy is untrusted
  3. assert proxyaddr returns leftmost client address when trusting all proxies
  4. assert proxyaddr filters local reverse proxy address when using loopback trust range
  5. assert proxyaddr filters private network proxy addresses when using uniquelocal trust range
  6. assert proxyaddr filters multiple trusted hops when configured with array of subnets
  7. assert proxyaddr evaluates addresses with custom predicate trust function
  8. assert proxyaddr supports netmask string notation in subnet trust list
  9. assert proxyaddr.all returns all parsed addresses in chain when trust argument is omitted
  10. assert proxyaddr.all stops at first untrusted address when trust argument is provided
  11. assert proxyaddr.compile creates reusable trust filter function for IP ranges
  12. assert proxyaddr throws TypeError when required request or trust argument is missing

Files

  • PROMPT.md
  • csx.json
  • index.mjs
  • package-lock.json
  • package.json
  • spec.json
  • test/contract.mjs

Download the source artifact (tar.gz)

Origin Seeder

anonymous