@sentry/coreCJS_BINDING_IN_DECLARED_ESMno prior report
Quality assurance for the AI era
Finds it. Fixes it.
Proves it.
It reads the code you have already shipped and finds the bugs and security holes nobody has reported yet. Then it proves the fix with a test that fails before the change and passes after.
- What it does
- Hunts defects nobody reported.
- What comes back
- The fix, and the run that proves it.
- What it touches
- Nothing you did not approve.
- SIGNAL
- INVESTIGATE
- REPRODUCE
- DIAGNOSE
- REPORT
- PATCH
- TEST
- VERIFY
- REVIEW
Credda proposes the diff. A person merges it.
01Find
1229 defects across 751 packages, 1192 with no prior report.
Found by reading 25,177 published packages across 3 sweeps, with no bug report in hand. Each ran at the commit beside it, and again at the maintainer’s fix.
lightningcssENGINES_BELOW_DELIVERED_SYNTAXno prior report
engines.node declares ">= 12.0.0" and the main entry uses logical assignment (??=), which is Node 15.
napi-postinstallENGINES_BELOW_DELIVERED_SYNTAXno prior report
engines.node declares ^12.20.0 || ^14.18.0 || >=16.0.0, and lib/index.js uses optional chaining, which is Node 14.
- @sentry/core
- lightningcss
- napi-postinstall
- tinypool
- prisma
- @vitest/utils
- string.prototype.repeat
- @babel/helper-validator-identifier
- miniflare
- @babel/types
- terser
- import-meta-resolve
- vite-node
- semver
- node-fetch
- js-yaml
- is-my-json-valid
- arraybuffer.prototype.slice
- aria-query
- dunder-proto
- electron-to-chromium
- merge
- fast-xml-parser
- ramda
- dotenv
- traverse
- node-persist
- getopts
- bytes
- diacritics
- figlet
- simple-get
- streamx
- readdir-glob
- typed-array-byte-length
- filename-reserved-regex
- superagent
- make-fetch-happen
- tapable
- logform
- minipass-fetch
- popsicle-redirects
- fast-deep-merge
- gaxios
- isomorphic-fetch
- @remix-run/web-fetch
- electron-fetch
- node-fetch-commonjs
- download
- object-path-immutable
- @standard-schema/spec
- property-expr
- minipass-sized
- signal-exit
- filenamify
- yargs
- mongoose
- cssfilter
- websocket-extensions
- rate-limiter-flexible
- mongodb
- bson
- csv-generate
- mailgun.js
- express-validator
- mysql2
- serialize-javascript
- terser-webpack-plugin
- minimizer-webpack-plugin
- nx
- postcss-normalize-url
- tsx
- @vue/compiler-sfc
- source-map
- get-uri
- probe-image-size
- npm-registry-fetch
- pacote
- @nx/devkit
- @octokit/plugin-paginate-rest
- @babel/plugin-syntax-import-attributes
- reghex
- is-npm
- prettier
- protobufjs
- i18next
- rambda
- suffix-thumb
- libsodium-wrappers
- chrono-node
- compromise
- fuse.js
- @firebase/database
- @azure/msal-browser
- @cypress/request-promise
- popsicle
- request-light
- openid-client
- property-information
- sisteransi
- cli-tableau
- exceljs
- pm2
- xlsx
- postcss-minify-selectors
- react-router
- preact
- @lit/reactive-element
- recoil
- @vue/runtime-core
- @parcel/runtime-rsc
- expect
- @whatwg-node/node-fetch
- apollo-server-env
- eslint-scope
- @apollo/protobufjs
- weak-lru-cache
- @prisma/query-plan-executor
- ethereum-cryptography
- formdata-node
- cbor-x
- @octokit/auth-unauthenticated
- ethers
- @google-cloud/functions-framework
- sharp
- @fastify/swagger
The 169 with a disclosure record, and every sweep behind the rest
02Reproduce
158 bug reports we did not write. 110 reproduced.
Closed issues from 60 repositories, pinned where the bug was present, unedited. That is the scored slice of a reproduce corpus now holding 357 admitted cases in JavaScript, Python and Elixir — every corpus, and what each one measured.
Right failure reproduced
110 of 158 · 70%
cases scored, of 158 admitted with the defect present
LIVE, bench/external/scorecard.json, 2026-09-20
False successes
0
claims of no change required, holding the captured failure
LIVE and RECORDED, every graded run
Reproduced, cases we wrote
10 of 10 · 100%
seeded cases with a failure to reproduce
bench/scorecard.json, 2026-08-29
Reproduced, six languages
63 of 63
placed defects across JavaScript, Python, Go, Rust, Ruby and Java, reproduced with no model
bench/language-reproduction/scorecard.json, 2026-09-18
- TinyColor-103right failure
- TinyColor-36no failure present
- bytes-31right failure
- bytes-61right failure
- camelcase-11no failure present
- camelcase-4right failure
- camelcase-46right failure
- camelcase-52no failure present
- camelcase-77right failure
- camelcase-98right failure
- camelcase-keys-13no failure present
- camelcase-keys-68right failure
- camelcase-keys-80right failure
- chalk-194right failure
- cheerio-1101no failure present
- cheerio-116right failure
- cheerio-915right failure
- clsx-17right failure
- color-convert-73right failure
- cookie-21right failure
- cron-parser-239right failure
- cron-parser-424wrong failure
- cron-parser-442right failure
- culori-118no failure present
- dayjs-2230right failure
- dayjs-244right failure
- dayjs-3015right failure
- decamelize-21right failure
- deepmerge-150right failure
- deepmerge-23right failure
- dot-prop-27right failure
- dot-prop-38right failure
- fast-xml-parser-317nothing executed
- filenamify-13right failure
- filesize-77right failure
- filter-obj-20right failure
- immutable-1040right failure
- immutable-1247right failure
- immutable-240right failure
- immutable-406right failure
- immutable-480no failure present
- immutable-703no failure present
- immutable-86right failure
- is-109right failure
- is-number-3right failure
- joi-121right failure
- joi-2176no failure present
- joi-2404wrong failure
- js-yaml-117right failure
- js-yaml-220wrong failure
- js-yaml-303right failure
- js-yaml-321right failure
- js-yaml-784wrong failure
- lodash-1012no failure present
- lodash-1038no failure present
- lodash-1061wrong failure
- lodash-379right failure
- lodash-69right failure
- luxon-1058right failure
- luxon-1068right failure
- luxon-1070right failure
- luxon-709right failure
- luxon-882right failure
- matcher-13right failure
- mathjs-291right failure
- mathjs-2936no failure present
- mathjs-2964no failure present
- mathjs-3100no failure present
- mathjs-680right failure
- micromatch-11right failure
- micromatch-24right failure
- micromatch-45right failure
- micromatch-91wrong failure
- micromatch-96right failure
- minimatch-215right failure
- minimatch-5right failure
- minimist-30right failure
- moment-1075right failure
- moment-1083no failure present
- moment-1290no failure present
- moment-323right failure
- moment-92right failure
- ms-103no failure present
- ms-22right failure
- ms-70no failure present
- mustache-330right failure
- normalize-url-149right failure
- normalize-url-187right failure
- object-inspect-6right failure
- path-to-regexp-148right failure
- pathe-18nothing executed
- picomatch-142right failure
- picomatch-187right failure
- picomatch-2right failure
- picomatch-49right failure
- pluralize-119no failure present
- pluralize-123no failure present
- pluralize-21right failure
- pluralize-22right failure
- pluralize-28no failure present
- pretty-ms-7right failure
- qs-357wrong failure
- qs-37right failure
- qs-390no failure present
- qs-45right failure
- qs-514right failure
- query-string-1right failure
- query-string-296no failure present
- query-string-302right failure
- query-string-346right failure
- query-string-49right failure
- radash-50wrong failure
- ramda-1714no failure present
- ramda-1987right failure
- ramda-2386right failure
- ramda-2391right failure
- remeda-350right failure
- sanitize-html-176right failure
- sanitize-html-249no failure present
- sanitize-html-464right failure
- sanitize-html-593right failure
- semver-201right failure
- semver-333no failure present
- semver-557right failure
- semver-606no failure present
- semver-763right failure
- semver-775no failure present
- semver-801right failure
- showdown-1061right failure
- simple-statistics-813right failure
- slice-ansi-26right failure
- slice-ansi-43right failure
- slice-ansi-6no failure present
- slugify-17right failure
- slugify-9right failure
- spacetime-417right failure
- string-width-55right failure
- ufo-148right failure
- ufo-158right failure
- ufo-282no failure present
- urijs-223right failure
- urijs-224right failure
- urijs-226right failure
- validator-201wrong failure
- validator-272right failure
- validator-309right failure
- validator-343no failure present
- validator-443no failure present
- wrap-ansi-39no failure present
- yaml-366no failure present
- yaml-57no failure present
- yaml-636right failure
- yaml-638right failure
- yaml-653right failure
- yargs-parser-118wrong failure
- yargs-parser-196right failure
- yargs-parser-226right failure
- yargs-parser-261wrong failure
03Record
What one run produced.
The queue, the run against the unfixed tree, and throw separated from fault.
Triage what arrived
13 seeded runs, ordered by what finishes first.
Membership and order come from attentionReason() and attentionRank(), the two functions the console files its own queue with, rather than a second copy of them written for this page. 1 of 13 runs leave something for a person. Nothing here is live, and this instance has no customers and no runs of its own.
| Case | Outcome recorded | Waiting on a person |
|---|---|---|
| vague-performance-report | No runnable check | Sharpen the report. Nothing ran: no runnable check could be derived from the report. Nothing was established about this repository in either direction. |
| async-unhandled-rejection | Verified | Nothing waiting |
| auth-idor-order-lookup | Verified | Nothing waiting |
| checkout-tax-missing-country | Verified | Nothing waiting |
| command-injection-log-search | Verified | Nothing waiting |
| config-not-code | No change required | Nothing waiting |
| issue-already-resolved | No change required | Nothing waiting |
| pagination-off-by-one | Verified | Nothing waiting |
| path-traversal-attachment-download | Verified | Nothing waiting |
| regression-from-recent-change | Verified | Nothing waiting |
| symptom-vs-cause-trap | Verified | Nothing waiting |
| vulnerability-not-exploitable | No change required | Nothing waiting |
| working-as-intended | Reproduced; the tests assert it | Nothing waiting |
Reproduce before explaining
Against the tree with the defect still in it.
$ node repro-268.js
src/stock-api.js:28
const available = record.onHand - record.reserved;
^
TypeError: Cannot read properties of undefined (reading 'onHand')
at availabilityFor (src/stock-api.js:28:28)
at Object.<anonymous> (repro-268.js:9:13)
exit code 1Separate throw from fault
Where it threw, and where it went wrong.
src/stock-api.js:27
function availabilityFor(store, sku) {
const record = store.lookup(sku);
const available = record.onHand - record.reserved;src/stock-store.js:20 (createStockStore)
const key = normalizeSku(row.sku); // every key is normalised
index.set(key, { sku: key, onHand: ... });
src/stock-store.js:41 (lookup)
return index.get(sku); // this one is notbench/scorecard.json 2026-08-29 · case symptom-vs-cause-trap 2026-08-22, node v24.18.0 · vitest 2.1.9. Our own work.
04Report
What a report contains.
Each stage, with the record it produced. When the fix is proven, the last one is a pull request you review and merge.
SIGNAL
preserveCamelCase malfunctions on "A::a"
> const camelcase = require("camelcase");
undefined
> camelcase("A::a");
"a:-:a"
> camelcase("A::a",{pascalCase:true});
"A:-:a"
I'm not saying this would be common in the wild, but this is nonetheless a surprising behavior.
Note that `c.toLowerCase() === c` and `c.toUpperCase() === c` both evaluates to true when c does not contain any alphabets.- Repository
- sindresorhus/camelcase
- Issue
- #46
- Commit
- 24d711f77ca11fda56aec7ef899ea16c73246f6e
- Why this commit
- The fix commit's parent where the closing commit was identifiable in the repository, otherwise the commit that was HEAD of the default branch at the moment the issue was filed. fixCommit bound 2026-08-26: issue #46 was closed by its own reporter as a duplicate of #42 ('Duplicate of #42', the only comment on the thread), and #42 was fixed by PR #49, squash-merged as bba938e. That commit changes exactly the two lines the reporter diagnosed -- isLastCharLower/isLastCharUpper in preserveCamelCase now also require the character to HAVE an opposite-case variant -- and its test.js hunk adds `camelCase('A::a') === 'a::a'` and `camelCase('A::a', {pascalCase: true}) === 'A::a'`, the reporter's own two expressions. It is not this case's pinned parent (the pin is HEAD-at-filing), so the two are not two ends of one edge here.
- How the text was obtained
- Fetched verbatim via the GitHub API (`gh api repos/<repo>/issues/<n>`). Title on the first line, body unmodified below it. Nothing was paraphrased, cleaned up, or supplemented.
- Toolchain
- javascript · node · ava · npm
REPRODUCE
| Check | Result | Detail |
|---|---|---|
| reproduction-executed | pass | A reproduction attempt was executed. |
| signature-captured | pass | `camelcase("A::a")` still produces "a:-:a" (read a:-:a) |
| right-failure | pass | Reproduced the reported failure: camelcase('A::a') returns 'a:-:a' instead of leaving the non-alphabetic separator alone. |
| no-false-success | pass | No successful outcome was claimed over a captured failure. |
| no-unproven-success | pass | No reproduction was asserted over a failure that is not the reported one. |
provenance changes here seeded case symptom-vs-cause-trap, 2026-08-22. No external run reached diagnosis.
REPORT
The trail for issue 268, executed 2026-08-22.
| ID | Type | Phase | Strength | Summary |
|---|---|---|---|---|
| ev-01 | Reproduction | before | Strong | TypeError: Cannot read properties of undefined (reading 'onHand'), exit 1 |
| ev-02 | Stack Trace | before | Strong | Origin frame inside the repository: src/stock-api.js:28 in availabilityFor |
| ev-03 | Code Reference | independent | Moderate | Index keys are written through normalizeSku(); lookup() reads index.get(sku) raw |
| ev-04 | Test Result | before | Strong | Regression test for issue 268: 2 failed against the unpatched tree |
| ev-05 | Test Result | after | Strong | Patched tree: regression 2 / 2 and the existing suite 12 / 12 |
REVIEW
3 scopes, one repository write. contents: write is not among them, and a committed test fails if a merge call appears in any connection-layer package, last captured 2026-08-22. The whole grant.
8 of 8 cases expecting a change produced one. 0 of 13 changed what nothing asked for. packages/shared/src/states.ts · ADR 0018, ADR 0019
05Ledger
A rate means nothing if the misses are hidden.
What the reporter described, beside what Credda captured.
> const camelcase = require("camelcase");
undefined
> camelcase("A::a");
"a:-:a"The report, unedited. Issue 46.camelcase("A::a") → "a:-:a"What the reporter said should be reproduced.SyntaxError: Unexpected token '>'WRONG_FAILUREA real failure, and the wrong one: the run executed the REPL transcript as a script and tripped over its own prompt characters.
`camelcase("A::a")` still produces "a:-:a" (read a:-:a)RIGHT_FAILUREThe same case, executed against the upstream checkout today. This is the reported defect, not a failure that resembles it.NO_CHANGE_REQUIRED ran and found nothing; NO_RUNNABLE_CHECK ran nothing. Separate metrics.
bench/scorecard.json 2026-08-29 5 of 5 abstention cases reached the expected outcome. Every miss, separately.
06Next
The next environment is a machine, and it is simulated.
An autonomous system states what its action is expected to cause before it acts, and evidence settles the claim afterwards. One loop either way: observe, understand, plan, act, verify, learn.
in developmentA domain-neutral platform and a deterministic manufacturing cell. Versioned contracts, a hash-chained event log, six autonomy levels with a human approval step, and verification that judges the expectations stated before an action from sealed events. In one recorded run, reducing the load on the failing machine was forecast to produce 44 good units against 50 for doing nothing, and the run reports that rather than hiding it behind a ranking.
simulatedNo robot, PLC, MES, sensor, camera or plant is connected. No model has been trained, there is no pilot and no customer, and none of it is for sale. Every figure from that run carries the word SIMULATED.
Install
Two things you paste.
A GitHub Action, in your own runner, on your own token. Or the app, on ours.
# .github/workflows/credda.yml
name: Credda on labeled issues
on:
issues:
types: [labeled]
permissions:
contents: read # checkout of the repository under test
issues: write # the one report comment
id-token: write # mint the OIDC token that fetches the engine
jobs:
investigate:
if: github.event.label.name == 'credda'
runs-on: ubuntu-latest
timeout-minutes: 30
steps:
- uses: actions/checkout@v4
- uses: Credda-io/action@v1
with:
label: credda
# license: ${{ secrets.CREDDA_LICENSE }}
# with:
# anthropic-api-key: ${{ secrets.ANTHROPIC_API_KEY }}
gh label create credda --description 'Credda reproduces this bug in a sandbox and comments what it established.'
permissions: is the whole grant. Pin the tag. The commentary, and the triage job.
the other way inThe app is one click and runs on every push, but clones onto Credda’s infrastructure rather than into your runner. Both paths, side by side.
Point it at a repository you already trust.
It comes back with the failure, or with nothing.