Evidence
Every case, including the ones that went badly.
158 real bug reports from 60 open-source repositories we did not choose, at the commits where the bug was present, report bodies unedited.
This is bench/external, the scored slice. The reproduce corpus holds 357 admitted cases in JavaScript, Python, Elixir; admission is free and scoring is not, so every rate on this page divides by what was scored. Every corpus, and what each one measured.
01Ledger
What the run counted.
All three from one committed scorecard, one moment, one corpus.
110 of 158
right failures: the reported failure reproduced and captured, over the cases whose pinned commit still contains the defect. Over all 158 entries: 110.
bench/external/scorecard.json, 2026-09-20
11 of 158
wrong failures: a genuine signature captured for a failure the report never described. Worse than capturing nothing: the run holds real evidence for the wrong defect.
bench/external/scorecard.json, 2026-09-20
0 of 158
false successes: a claimed success sitting on top of a captured failure. The gate that counts these fails the build whenever the count moves.
bench/external/scorecard.json, 2026-09-20
- cases scored158
- cases with the defect in the pinned commit158
- reproductions executed156
- signatures captured121
- right failures110
- wrong failures11
- false successes0
- errored5
- total wall time18408.5s
02Record
Every entry, in corpus order.
Nothing sorted or filtered. Each entry carries the signature the run captured, verbatim, or says none was.
- TinyColor-103Color input being accepted and parsed with leading '#' characters in string`tinycolor("#red").toString()` still produces "red" (read red)TinyColor#103 · commit 1a9a45a · unknown · 141.5sRIGHT_FAILURE
- TinyColor-36rgb range 0-1 not correctly recognizedno signature capturedTinyColor#36 · commit 20f7929 · unknown · 53.2sNO_FAILURE_OBSERVED
- bytes-31Too relaxed value validator?`bytes('250Kg')` still produces 250 (read 250)bytes.js#31 · commit c8be41b · unknown · 85.9sRIGHT_FAILURE
- bytes-61`bytes.parse()` can return `NaN``bytes.parse("string without any numbers")` still produces NaN (read NaN)bytes.js#61 · commit 1925beb · unknown · 70.5sRIGHT_FAILURE
- camelcase-11already camel case segment become lowercaseno signature capturedcamelcase#11 · commit b4c5c8d · unknown · 53.0sNO_FAILURE_OBSERVED
- camelcase-4Edge cases`camelCase('', '')` still produces '-' (read -)camelcase#4 · commit ca0d761 · unknown · 97.4sRIGHT_FAILURE
- camelcase-46preserveCamelCase malfunctions on "A::a"`camelcase("A::a")` still produces "a:-:a" (read a:-:a)camelcase#46 · commit 24d711f · ava · 119.0sRIGHT_FAILURE
- camelcase-52c('Hello1World')no signature capturedcamelcase#52 · commit 7501406 · unknown · 61.8sNO_FAILURE_OBSERVED
- camelcase-77Converting either volume_3d or volume3d results in volume3D making it impossible to decamelize`camelcase('volume_3d')` still produces volume3D (read volume3D)camelcase#77 · commit 20591fb · ava · 130.2sRIGHT_FAILURE
- camelcase-98Passed in a single seperator, return the original seperator`camelCase('-')` still produces '-' (read -)camelcase#98 · commit a9e9f4f · unknown · 155.4sRIGHT_FAILURE
- camelcase-keys-13Weird behaviour with array of objects as inputno signature capturedcamelcase-keys#13 · commit 983678a · unknown · 66.4sNO_FAILURE_OBSERVED
- camelcase-keys-68transforms {'4.2': 'foo'} into {'42': 'foo'}`camelcaseKeys({'4.2': 'foo'})` still produces {'42': 'foo'} (read { '42': 'foo' })camelcase-keys#68 · commit dab3a85 · unknown · 104.1sRIGHT_FAILURE
- camelcase-keys-80Can `exclude` option support function parameter?`camelcaseKeys(obj)` still produces { name: true } (read { name: true })camelcase-keys#80 · commit 77641b0 · unknown · 104.3sRIGHT_FAILURE
- chalk-194Interpolated template expressions that evaluate to `undefined` or `null` throw exceptionTypeError: Cannot read properties of undefined (reading 'toString')chalk#194 · commit 106f086 · ava · 110.0sRIGHT_FAILURE
- cheerio-1101find() convert `xlink:href` to `href`no signature capturedcheerio#1101 · commit 74be271 · unknown · 88.2sNO_FAILURE_OBSERVED
- cheerio-116add .toString() or JSON.stringify() support`html.toString()` still produces '<div class="foo">bar</div>' (read [object Object])cheerio#116 · commit 6d8ba33 · unknown · 98.9sRIGHT_FAILURE
- cheerio-915Incorrect innerHTML of <xmp> tag`$('<xmp><h2></xmp>').html()` still produces '<h2></h2>' (read <h2></h2>)cheerio#915 · commit 3368605 · unknown · 98.6sRIGHT_FAILURE
- clsx-17No classname will be generated from objects that have the "push" member set to true`clsx('stack', { pop: true, push: true })` still produces 'stack' (read stack)clsx#17 · commit af19571 · unknown · 103.0sRIGHT_FAILURE
- color-convert-73Hue component of HCG color is wrong by 120° then converting from RGB or CMYK`convert.hcg.rgb.raw(convert.rgb.hcg.raw([250, 0, 255]))` still produces [ 0, 255, 249.99999999999991 ] (read [ 0, 255, 249.99999999999991 ])color-convert#73 · commit 7607099 · unknown · 64.2sRIGHT_FAILURE
- cookie-21Overeager parsing`cookie.parse('expires=Wed, 29 Jan 2014 17:43:25 GMT; Path=/')` still produces {Path: '/', expires: 'Wed'} (read { expires: 'Wed', Path: '/' })cookie#21 · commit faf3895 · unknown · 69.5sRIGHT_FAILURE
- cron-parser-239stringify yields dayOfMonth ranges instead of wildcards`parser.parseExpression('* * * 2 *').stringify()` still produces "* * 1-29 2 *" (read * * 1-29 2 *)cron-parser#239 · commit ec7a384 · unknown · 132.5sRIGHT_FAILURE
- cron-parser-424`stringify()` is not round-trip safe: re-parsing its output can produce a different scheduleTypeError: parser.parse is not a functioncron-parser#424 · commit 74606cc · unknown · 67.2sWRONG_FAILURE
- cron-parser-442Expressions with fewer than five fields fill the wrong slots`interval.stringify(true)` still produces '* 0 20 15 * *' (read * 0 20 15 * *)cron-parser#442 · commit 85f3644 · unknown · 81.3sRIGHT_FAILURE
- culori-118hsla parsing incorrectlyno signature capturedculori#118 · commit 36c9598 · unknown · 74.8sNO_FAILURE_OBSERVED
- dayjs-2230'YYYY' results in missing leading zeroes when year <1000`dayjs(Date.parse('0001-01-01')).format('YYYY-MM-DD')` still produces '1-01-01' (read 1-01-01)dayjs#2230 · commit b87aa0e · unknown · 487.5sRIGHT_FAILURE
- dayjs-244dayjs() instanceof dayjs = false`dayjs() instanceof dayjs` still produces false (read false)dayjs#244 · commit 36c4e94 · unknown · 417.5sRIGHT_FAILURE
- dayjs-3015Bug: undocumented Y and YYY tokens fall through to ZZ formatting`dayjs('2024-01-02').format('Y')` still produces 'Y' (read +0000)dayjs#3015 · commit d87ead6 · unknown · 129.0sRIGHT_FAILURE
- decamelize-21Decamelizing a capitalized word gives odd results`decamelize('ADDRESS1')` still produces 'addres_s1' (read addres_s1)decamelize#21 · commit 9ac3cb5 · unknown · 102.4sRIGHT_FAILURE
- deepmerge-150Symbol properties are ignored`z` still produces { value: 42, other: 33 } (read { value: 42, other: 33 })deepmerge#150 · commit 6c88021 · tape · 71.3sRIGHT_FAILURE
- deepmerge-23Regular expressions not mergedTypeError: result.test.test is not a functiondeepmerge#23 · commit 063bf55 · tape · 226.6sRIGHT_FAILURE
- dot-prop-27should dotProp.has({foo: undefined}, 'foo') be true ?`dotProp.has(a, 'foo')` still produces false (read false)dot-prop#27 · commit be341d9 · unknown · 100.2sRIGHT_FAILURE
- dot-prop-38get() from undefined should return default value`dotProp.get(fields, 'attributes.required', false)` still produces false (read undefined)dot-prop#38 · commit f91d08a · unknown · 97.9sRIGHT_FAILURE
- fast-xml-parser-317Processing instruction validation errorno signature capturedfast-xml-parser#317 · commit eb8b6c5 · unknown · 70.4sNOT_EXECUTED
- filenamify-13File names truncated by `maxLength` should keep their extension`safeName` still produces "This! This is very long filename that will lose its extension when passed into filenamify, which cou" (read This! This is very long filename that will lose its extension when passed into filenamify, which cou)filenamify#13 · commit 43f3f32 · unknown · 128.7sRIGHT_FAILURE
- filesize-77It does not work properly for some extreme cases`filesize(1/8, { bits: true })` still produces '1024 ' (read 1024 )filesize.js#77 · commit e1e6185 · unknown · 274.4sRIGHT_FAILURE
- filter-obj-20This changes whether a property is writable or configurable`Object.getOwnPropertyDescriptor(objCopy, 'prop')` still produces { value: true, writable: true, enumerable: true, configurable: true } (read { value: true, writable: true, enumerable: true, configurable: true })filter-obj#20 · commit 2c35cf8 · unknown · 118.9sRIGHT_FAILURE
- immutable-1040map.take(Number.MAX_SAFE_INTEGER) takes length - 1 in v3.8`fromJS({ a: 1, b: 2 }).take(Number.MAX_SAFE_INTEGER).toJS()` still produces { a: 1 } (read { a: 1 })immutable-js#1040 · commit 4094d5f · unknown · 138.4sRIGHT_FAILURE
- immutable-1247Defaulted `Record` instance reports `true` after instantiation`r.wasAltered()` still produces true (read true)immutable-js#1247 · commit 60bd7d0 · unknown · 110.3sRIGHT_FAILURE
- immutable-240List's keys() iterator returns -1 after removing an item from a list`Immutable.List([1,2,3]).remove(0).keys().next()` still produces { value: -1, done: false } (read { value: -1, done: false })immutable-js#240 · commit 52db807 · unknown · 85.4sRIGHT_FAILURE
- immutable-406mergeDeep clobbers List items; concatDeep isn't implemented`Immutable.List([1, 2, 3]).merge(Immutable.List([4, 5])).toJSON()` still produces [4, 5, 3] (read [ 4, 5, 3 ])immutable-js#406 · commit d093223 · unknown · 129.3sRIGHT_FAILURE
- immutable-480filter().take() regression in v3.7.3no signature capturedimmutable-js#480 · commit b12e43a · unknown · 60.7sNO_FAILURE_OBSERVED
- immutable-703List.lastIndexOf returns incorrect indexno signature capturedimmutable-js#703 · commit 370ef68 · unknown · 54.9sNO_FAILURE_OBSERVED
- immutable-86Vector.splice with no arguments gives strange results`Immutable.Vector(1, 2, 3).splice().length` still produces NaN (read NaN)immutable-js#86 · commit b90f7f0 · unknown · 70.0sRIGHT_FAILURE
- is-109numericString gives true for string with spaces`is.numericString(' ')` still produces true (read true)is#109 · commit 05cdacc · unknown · 101.5sRIGHT_FAILURE
- is-number-3Whitespace strings return true`isNumber(' ')` still produces true (read true)is-number#3 · commit 0024f0f · unknown · 76.9sRIGHT_FAILURE
- joi-121Array is accepted as an Object type`Joi.validate([], Joi.types.Object())` still produces null (read null)joi#121 · commit a480742 · unknown · 42.9sRIGHT_FAILURE
- joi-2176joi.types() is missing `func` aliasno signature capturedjoi#2176 · commit 2871b13 · unknown · 35.5sNO_FAILURE_OBSERVED
- joi-2404defaults in ordered array are not filledError: Cannot find module '@hapi/joi'joi#2404 · commit 29b1b93 · unknown · 43.1sWRONG_FAILURE
- js-yaml-117Negative zero loses the sign after dump.`yaml.dump(-0.0)` still produces '0\n' (read 0 )js-yaml#117 · commit e6bac15 · unknown · 111.2sRIGHT_FAILURE
- js-yaml-220Inconsistent floating-point format between `safeLoad` and `safeDump``yaml.safeLoad('foo: 5e-324').foo` still produces "5e-324" (read 5e-324)js-yaml#220 · commit 73c7421 · mocha · 98.2sWRONG_FAILURE
- js-yaml-303Loader strips quotes before newlines`yaml.load("'''foo''\n'")` still produces "'foo " (read 'foo )js-yaml#303 · commit 2bf232b · unknown · 80.5sRIGHT_FAILURE
- js-yaml-321Syntax error in array [,] parsed as [null]`yaml.safeLoad('[,,]')` still produces [null, null] (read [ null, null ])js-yaml#321 · commit 1918a7f · mocha · 89.9sRIGHT_FAILURE
- js-yaml-784v5: implicit-null mapping key dropped when it is the last entry before a document marker`loadAll('a:\n---\nx: 1\n')` still produces [ {}, { x: 1 } ] (read [ {}, { x: 1 } ])js-yaml#784 · commit 49280f3 · unknown · 76.3sWRONG_FAILURE
- lodash-1012Incosistency when going back and forth between camelCase and snakeCaseno signature capturedlodash#1012 · commit aad0070 · unknown · 45.2sNO_FAILURE_OBSERVED
- lodash-1038_.difference returns values to exclude when provided with undefined as first paramno signature capturedlodash#1038 · commit 028234b · unknown · 44.6sNO_FAILURE_OBSERVED
- lodash-1061_.merge adds extra element when merging nesting array into object`_.merge({}, [])` still produces {} (read {})lodash#1061 · commit 94ca508 · unknown · 70.1sWRONG_FAILURE
- lodash-379max() returning -Infinty when used with map()`_.map( a, _.max )` still produces [3, -Infinity, -Infinity] (read [ 3, -Infinity, -Infinity ])lodash#379 · commit b7b1399 · unknown · 94.8sRIGHT_FAILURE
- lodash-69_.merge doesn't always work properly when trying to merge more than two objects`_.merge({a:1}, {a:2}, {a:3}, {a:4})` still produces {a:3} (read { a: 3 })lodash#69 · commit 31c4cba · unknown · 68.1sRIGHT_FAILURE
- luxon-1058Parsing fractional hours durations`Duration.fromISO('PT9.5H').toObject()` still produces {} (read {})luxon#1058 · commit f4e0605 · unknown · 73.5sRIGHT_FAILURE
- luxon-1068FixedOffsetZone constructor accepts bad inputs, but `isValid` returns true`zone.isValid` still produces true (read true)luxon#1068 · commit cb02c9b · unknown · 77.8sRIGHT_FAILURE
- luxon-1070Duration using decimal hours produces wrong output using toFormat`luxon.Duration.fromObject({hour: 2.4}).toFormat('hh:mm')` still produces "02:23" (read 02:23)luxon#1070 · commit 1899cc0 · unknown · 123.0sRIGHT_FAILURE
- luxon-709Interval.hasSame('day') returns false for "zero" interval with 00:00:00 time`interval.hasSame('day')` still produces false (read false)luxon#709 · commit 60187d5 · unknown · 135.0sRIGHT_FAILURE
- luxon-882Duration fromISO / toISO don't handle correctly negative second/millisecond components`duration.toISO()` still produces "PT-0.5S" (read PT-0.5S)luxon#882 · commit c34afb1 · unknown · 86.2sRIGHT_FAILURE
- matcher-13Negative matching doesn't work for `isMatch``matcher.isMatch('rainbow', '!unicorn')` still produces true (read false)matcher#13 · commit 4261048 · unknown · 119.8sRIGHT_FAILURE
- mathjs-291Format with fixed notation not working for very large values`math.format(x, {notation: 'fixed'})` still produces "1e+27" (read 1e+27)mathjs#291 · commit 97e452e · unknown · 84.8sRIGHT_FAILURE
- mathjs-2936Potential bug in mod()no signature capturedmathjs#2936 · commit c35a801 · unknown · 65.6sNO_FAILURE_OBSERVED
- mathjs-2964distance function error when calculate distance from point to line no signature capturedmathjs#2964 · commit 6fa5890 · unknown · 55.8sNO_FAILURE_OBSERVED
- mathjs-3100Bug on simple roundingno signature capturedmathjs#3100 · commit 9baf478 · unknown · 92.7sNO_FAILURE_OBSERVED
- mathjs-680eval inequations with string scope`math.eval('W<=5*Z', {W:'50',Z:'300'})` still produces false (read false)mathjs#680 · commit 2c1b8f2 · unknown · 132.0sRIGHT_FAILURE
- micromatch-11problem with "logical OR" or problem in my mind, lol?`re.test('maiden/code')` still produces true (read true)micromatch#11 · commit 8078ceb · unknown · 116.1sRIGHT_FAILURE
- micromatch-24Double globstar bug`mm.isMatch('markup/modules/exampleModule/assets/image.png', 'markup/modules/**/assets/**/*.*')` still produces false (read false)micromatch#24 · commit 34171b2 · unknown · 173.8sRIGHT_FAILURE
- micromatch-45Does not handle `+` properly`micromatch.isMatch('coffee+/src/glimini.js', 'coffee+/src/**')` still produces false (read false)micromatch#45 · commit 8704f57 · unknown · 124.5sRIGHT_FAILURE
- micromatch-91Negation glob causes issues with the newest version (3.0.1)`micromatch(['bar/bar'], ['foo/**', '!foo/baz'])` still produces ["bar/bar"] (read [ 'bar/bar' ])micromatch#91 · commit e47fc91 · unknown · 118.1sWRONG_FAILURE
- micromatch-96basename: true and unixify: true breaks .not()`mm.not(["C:\\bla\\bar.xml"], ["*.xml"], {basename: true, unixify: true})` still produces [ 'C:\\bla\\bar.xml' ] (read [ 'C:\\bla\\bar.xml' ])micromatch#96 · commit 5effb6c · unknown · 153.8sRIGHT_FAILURE
- minimatch-215makeRe-generated regexp for pattern `'some/path/**'` matches `'some/path-but-different'``makeRe('some/path/**').test('some/path-but-different')` still produces true (read true)minimatch#215 · commit 2c65ee2 · unknown · 99.6sRIGHT_FAILURE
- minimatch-5pattern `**/.svn/**` doesn't work as expected when using `minimatch()``minimatch('js/lib/.svn/tmp', '**/.svn/**')` still produces false (read false)minimatch#5 · commit e27848f · unknown · 117.6sRIGHT_FAILURE
- minimist-30Special handling of boolean long option value does not work for alias`minimist(['--aa=false','--bb=false'], {boolean:['a','bb'], alias:{a:'aa', bb:'b'}})` still produces { _: [], a: 'false', aa: 'false', bb: false, b: false } (read { _: [], a: 'false', aa: 'false', bb: false, b: false })minimist#30 · commit 2758c33 · unknown · 89.7sRIGHT_FAILURE
- moment-1075Problem with parsing Unixtime format`moment('1371065286', ['X']).isValid()` still produces false (read false)moment#1075 · commit e69c63e · unknown · 108.8sRIGHT_FAILURE
- moment-1083.format bug with parsing 'h:mm a' into 'hh:mm a'no signature capturedmoment#1083 · commit eecd741 · unknown · 69.9sNO_FAILURE_OBSERVED
- moment-1290Regression: moment("2013-11-21T10:10:56 Z").calendar(); => invalid dateno signature capturedmoment#1290 · commit c9a56eb · unknown · 71.6sNO_FAILURE_OBSERVED
- moment-323utc(Number) not working`moment.utc(1338499506000)` still produces { _d: Invalid Date, _isUTC: true } (read { _d: Invalid Date, _isUTC: true })moment#323 · commit 6ed1808 · unknown · 98.9sRIGHT_FAILURE
- moment-92diff is calculating wrong when I use 24 hours`end.diff(start, "hours")` still produces -8 (read -8)moment#92 · commit e4229dc · unknown · 107.0sRIGHT_FAILURE
- ms-103There is only partial support for negative timeno signature capturedms#103 · commit 845c302 · unknown · 40.2sNO_FAILURE_OBSERVED
- ms-22Minutes does't work`ms('1m')` still produces NaN (read NaN)ms#22 · commit be1bb96 · unknown · 81.1sRIGHT_FAILURE
- ms-70Negative numbers in strings returns undefinedno signature capturedms#70 · commit a2caead · unknown · 38.0sNO_FAILURE_OBSERVED
- mustache-330Integer value 0 gets rendered as "[object Object]"`Mustache.render("{{#nums}}{{.}}, {{/nums}}", {nums: [0, 1, 2]})` still produces "[object Object], 1, 2, " (read [object Object], 1, 2, )mustache.js#330 · commit 48fb97b · unknown · 102.4sRIGHT_FAILURE
- normalize-url-149sortQueryParameters encodes the query string`normalizeUrl('http://sindresorhus.com/?url=http://example.com', { sortQueryParameters: true })` still produces 'http://sindresorhus.com/?url=http%3A%2F%2Fexample.com' (read http://sindresorhus.com/?url=http%3A%2F%2Fexample.com)normalize-url#149 · commit 6ea4038 · unknown · 136.6sRIGHT_FAILURE
- normalize-url-187Incorrect URL returned when protocol is missing`normalizeUrl('sindresorhus.com:123', { removeExplicitPort: true })` still produces 'http://sindresorhus.com' (read sindresorhus.com:123)normalize-url#187 · commit 12e3b1b · unknown · 99.2sRIGHT_FAILURE
- object-inspect-6Printing of primitive wrapper objects`oi(new Number(5))` still produces '{}' (read {})object-inspect#6 · commit 559ae4c · unknown · 120.1sRIGHT_FAILURE
- path-to-regexp-148An empty path does not match relative paths`re2.exec('a/b')` still produces null (read null)path-to-regexp#148 · commit 761c721 · unknown · 122.4sRIGHT_FAILURE
- pathe-18`dirname` of non-absolute filename returns `/` no signature capturedpathe#18 · commit 69696c4 · unknown · 212.8sNOT_EXECUTED
- picomatch-142`**` does not work when in parentheses`pm('test(/utils/**)')('test/utils')` still produces false (read false)picomatch#142 · commit 38c6b7a · unknown · 78.8sRIGHT_FAILURE
- picomatch-187[!abc] matches a, b and c: POSIX-style bracket negation is inverted unless options.posix is set`pm.isMatch('a', '[!abc]')` still produces true (read true)picomatch#187 · commit 4f41a8e · mocha · 139.2sRIGHT_FAILURE
- picomatch-2Relative patterns and paths with dot in the base name`result` still produces true (read true)picomatch#2 · commit 4fb33fd · unknown · 92.8sRIGHT_FAILURE
- picomatch-49Brace expansion matches single item`picomatch.parse('{foo}').output` still produces '(foo)' (read (foo))picomatch#49 · commit 002e806 · mocha · 59.4sRIGHT_FAILURE
- pluralize-119'passerby' plural should be 'passersby'no signature capturedpluralize#119 · commit 2630dd7 · unknown · 38.7sNO_FAILURE_OBSERVED
- pluralize-123whisky vs whiskey, when from plural to singular no signature capturedpluralize#123 · commit 8a989b7 · unknown · 64.9sNO_FAILURE_OBSERVED
- pluralize-21Yous`pluralize("you")` still produces "yous" (read yous)pluralize#21 · commit 0f7cdc4 · unknown · 84.4sRIGHT_FAILURE
- pluralize-22Olife`pluralize("olives", 1)` still produces "olife" (read olife)pluralize#22 · commit 9ed8331 · unknown · 109.7sRIGHT_FAILURE
- pluralize-28pluralize('is', 1) yields 'i'?no signature capturedpluralize#28 · commit 824bbfe · unknown · 68.7sNO_FAILURE_OBSERVED
- pretty-ms-7A verbose option?`prettyMs(1337000000, {verbose: true})` still produces '15 days 11 hours 23 minutes 20 seconds' (read 15d 11h 23m 20s)pretty-ms#7 · commit 6026235 · unknown · 96.9sRIGHT_FAILURE
- qs-357Parsing object with array doesn't split a value`qs.parse('color=a,b', { comma: true })` still produces { color: [ 'a', 'b' ] } (read { color: [ 'a', 'b' ] })qs#357 · commit 0625c49 · unknown · 47.5sWRONG_FAILURE
- qs-37parser discards first empty value in array`qs.parse("a[]=&a[]=b&a[]=c")` still produces { a: [ 'b', 'c' ] } (read { a: [ 'b', 'c' ] })qs#37 · commit 8a90b77 · unknown · 59.0sRIGHT_FAILURE
- qs-390Stringify with {format: "RFC1738"}no signature capturedqs#390 · commit 9c60d53 · unknown · 351.2sNO_FAILURE_OBSERVED
- qs-45Cannot parse mix of simple array and explicit array.`Qs.parse('a=b&a[]=b')` still produces { a: ['b', 'b'] } (read { a: 'b' })qs#45 · commit 5ac9df5 · unknown · 107.7sRIGHT_FAILURE
- qs-514Duplicates set to last, should not apply to arrays without index`qs.parse("a=1&a=2&b[]=1&b[]=2", {duplicates: "last"})` still produces { a: '2', b: [ '2' ] } (read { a: '2', b: [ '2' ] })qs#514 · commit 9d441d2 · unknown · 271.9sRIGHT_FAILURE
- query-string-1Plus signs not parsed as spaces`qs.parse('foo=c++')` still produces {foo: 'c++'} (read { foo: 'c++' })query-string#1 · commit 154f8e7 · unknown · 64.6sRIGHT_FAILURE
- query-string-296Parsing of `arrayFormat: 'comma'` not working for queries of single value with commano signature capturedquery-string#296 · commit 35846d9 · ava · 88.8sNO_FAILURE_OBSERVED
- query-string-302Stringify isn't respecting skipNull nor skipEmptyString when arrayFormat: "comma"`queryString.stringify( { a: data }, { arrayFormat: "comma", sort: false, } )` still produces a=asd,123 (read a=asd,123)query-string#302 · commit 44abc66 · unknown · 97.2sRIGHT_FAILURE
- query-string-346why query-string encode the fragmentIdentifier?`queryString.stringifyUrl({ url: 'https://foo.bar', query: { top: 'foo' }, fragmentIdentifier: '/bar/hello' })` still produces 'https://foo.bar?top=foo#%2Fbar%2Fhello' (read https://foo.bar?top=foo#%2Fbar%2Fhello)query-string#346 · commit 5beef41 · unknown · 78.1sRIGHT_FAILURE
- query-string-49in arrays passed to stringify, `null` the same as string `"null"``require('query-string').stringify(params)` still produces "a&b=123&b=null" (read a&b=123&b=null)query-string#49 · commit 71bc3ed · ava · 124.5sRIGHT_FAILURE
- radash-50isEmpty logic and tests not coincidingTypeError: Cannot convert a Symbol value to a numberradash#50 · commit d2911b9 · unknown · 353.3sWRONG_FAILURE
- ramda-1714R.flip always curries two arguments onlyno signature capturedramda#1714 · commit f494250 · unknown · 70.0sNO_FAILURE_OBSERVED
- ramda-19870.22 regression: R.uniq is broken for function (reference-eqaulity case)`uniq([identity, identity, identity, identity, identity, identity]).length` still produces 5 (read 5)ramda#1987 · commit f82fb41 · unknown · 473.7sRIGHT_FAILURE
- ramda-2386mapAccumRight argument order?`R.mapAccumRight(iterator, "acc", ["a", "b"])` still produces [["b", "acc"], "a"] (read [ [ 'b', 'acc' ], 'a' ])ramda#2386 · commit 1aba18b · unknown · 573.4sRIGHT_FAILURE
- ramda-2391Discrepancy between propOr and pathOr`getProp1({x: null})` still produces null (read null)ramda#2391 · commit 4e3c65d · unknown · 554.0sRIGHT_FAILURE
- remeda-350Unexpected `dropLast` behavior with negative `n`.`R.dropLast([1, 2, 3], -1)` still produces [1] (read [ 1 ])remeda#350 · commit 3eb05f0 · unknown · 234.1sRIGHT_FAILURE
- sanitize-html-176{allowedTags:null} allows <script>`sanitizeHtml( '<script>alert(1)</script>', { allowedTags: null })` still produces '<script>alert(1)</script>' (read <script>alert(1)</script>)sanitize-html#176 · commit 0573fb6 · unknown · 85.2sRIGHT_FAILURE
- sanitize-html-249Encoding ampersands on HTML entities when parser.decodeEntities = falseno signature capturedsanitize-html#249 · commit 801c25c · unknown · 57.3sNO_FAILURE_OBSERVED
- sanitize-html-464Escaping input with unclosed, invalid tags returns it with unneeded escaped closing tags appended to end`s("here's a string with a <wacky> tag.", {disallowedTagsMode: "escape"})` still produces "here's a string with a <wacky> tag.</wacky>" (read here's a string with a <wacky> tag.</wacky>)sanitize-html#464 · commit f12a665 · unknown · 96.1sRIGHT_FAILURE
- sanitize-html-593Behaviour changed for numbers given to sanitizeHtml`sanitizeHtml(5, {allowedTags: ['b','em','i','s','small','strong','sub','sup','time','u'], allowedAttributes: {}, disallowedTagsMode: 'recursiveEscape'})` still produces '' (read )sanitize-html#593 · commit 333ec31 · unknown · 81.6sRIGHT_FAILURE
- semver-201Breaking change in 5.4.0: handling of commit-ish values in maxSatisfying, minSatisfyingTypeError: Invalid SemVer Range: harmony-v2.8.22node-semver#201 · commit e1c49c8 · unknown · 105.0sRIGHT_FAILURE
- semver-333[BUG] semver.diff returns incorrect responsesno signature capturednode-semver#333 · commit 3f222b1 · unknown · 97.8sNO_FAILURE_OBSERVED
- semver-557[BUG] Inconsistent behaviour of caret versions with includePrerelease`semver.satisfies('0.0.3-alpha', '^0.0.3', {includePrerelease: true})` still produces true (read true)node-semver#557 · commit efafcf8 · unknown · 170.3sRIGHT_FAILURE
- semver-606[bug] diff("1.7.2-1", "1.8.1") returns patch, not minorno signature capturednode-semver#606 · commit 753e02b · unknown · 74.9sNO_FAILURE_OBSERVED
- semver-763[BUG] 7.6.0 --> 7.7.0 inc behavior change`semver.inc('1.0.0', 'prepatch', 'canary.661.2207bf')` still produces null (read null)node-semver#763 · commit 2cfcbb5 · unknown · 239.9sRIGHT_FAILURE
- semver-775[BUG] Coercing version with prerelease identifier that starts with digits returns truncated identifierno signature capturednode-semver#775 · commit 2677f2a · tap · 82.0sNO_FAILURE_OBSERVED
- semver-801[BUG] Constant `RELEASE_TYPES` is missing `release` value`RELEASE_TYPES.includes('release')` still produces false (read false)node-semver#801 · commit d17aebf · tap · 157.4sRIGHT_FAILURE
- showdown-1061Unused link reference definitions leak into the output (legacy path)`conv.makeHtml('[unused]: http://example.com/')` still produces "<p>[unused]: http://example.com/</p>" (read <p>[unused]: http://example.com/</p>)showdown#1061 · commit 13eb289 · unknown · 163.0sRIGHT_FAILURE
- simple-statistics-813sampleRankCorrelation depends on row order when values are tied`ss.sampleRankCorrelation([1, 1, 2], [1, 2, 1])` still produces 0.5 (read 0.5)simple-statistics#813 · commit 13530b2 · unknown · 163.8sRIGHT_FAILURE
- slice-ansi-26Lose characters when fullwidth characters exist and end is not specified`sliceAnsi("古古test", 0)` still produces '古古te' (read 古古te)slice-ansi#26 · commit 9df7d27 · unknown · 107.8sRIGHT_FAILURE
- slice-ansi-43sliceAnsi returns wider result than specified endColumn for wide characters`sliceAnsi('あいう', 0, 1)` still produces "あ" (read あ)slice-ansi#43 · commit 2ea51ac · unknown · 109.6sRIGHT_FAILURE
- slice-ansi-6Adds moot escape codesno signature capturedslice-ansi#6 · commit cfec68f · unknown · 51.3sNO_FAILURE_OBSERVED
- slugify-17Run custom replacements before anything else`slugify('Zürich', { customReplacements: [["ä", "ae"], ["ö", "oe"], ["ü", "ue"], ["ß", "ss"]] })` still produces zuerich (read zurich)slugify#17 · commit 125fe7f · unknown · 117.4sRIGHT_FAILURE
- slugify-9Custom replacements don't work as expected`customSlugify('x.y.z')` still produces "x-y-z" (read x-y-z)slugify#9 · commit 96ddd5f · unknown · 104.0sRIGHT_FAILURE
- spacetime-417Unexpected behaviour from at least isEqual() when using UNIX epoch date (1970-01-01)`spacetime('1970-01-01').isEqual('1970-01-01')` still produces null (read null)spacetime#417 · commit 0464eca · unknown · 152.0sRIGHT_FAILURE
- string-width-55Japanese half-width kana dakuten(゙) and han-dakuten(゚) are not counted.`stringWidth('バ')` still produces 1 (read 1)string-width#55 · commit ac09208 · unknown · 174.6sRIGHT_FAILURE
- ufo-148Empty array parameters generates invalid URL`stringifyQuery({ 'a': 'X', 'b[]': [], c: "Y" })` still produces 'a=X&&c=Y' (read a=X&&c=Y)ufo#148 · commit a6fcce3 · unknown · 128.0sRIGHT_FAILURE
- ufo-158Unexpected behavior when passing a `data:` URL into parseURL()`parseURL('data:image/png;base64,aaa//bbbbbb/ccc')` still produces { auth: "", hash: "", host: "bbbbbb", pathname: "/ccc", protocol: "", search: "" } (read { protocol: '', auth: '', host: 'bbbbbb', pathname: '/ccc', search: '', hash: '' })ufo#158 · commit 2caeb30 · unknown · 122.4sRIGHT_FAILURE
- ufo-282Usage of default-prototype Object for URL params results in parsing problemsno signature capturedufo#282 · commit e383832 · unknown · 61.9sNO_FAILURE_OBSERVED
- urijs-223.segmentCoded([…]) does not encode slashes`URI("/").segmentCoded(["fo/o", "bar"]).toString()` still produces "/fo/o/bar" (read /fo/o/bar)URI.js#223 · commit fc63b02 · unknown · 61.4sRIGHT_FAILURE
- urijs-224.relativeTo() requires trailing slash on .. path segments`URI("http://example.com/foo/..").relativeTo("http://example.com/foo/").toString()` still produces "" (read )URI.js#224 · commit 4ad3f29 · unknown · 62.8sRIGHT_FAILURE
- urijs-226.relativeTo() requires trailing slash`URI("http://example.com/").relativeTo("http://example.com/foo").toString()` still produces "" (read )URI.js#226 · commit 5331344 · unknown · 93.9sRIGHT_FAILURE
- validator-201Strange behaviour of sanitize().xss()`sanitize("version = 1.0.0").xss()` still produces 'version = 1.0.0' (read version = 1.0.0)validator.js#201 · commit 2f1c302 · unknown · 52.4sWRONG_FAILURE
- validator-272isNull(object) failed`validator.isNull({a: 1})` still produces true (read true)validator.js#272 · commit cb1d3be · unknown · 96.1sRIGHT_FAILURE
- validator-309Can email addresses end with a dot?`validator.isEmail('yarr@yarr.no.')` still produces true (read true)validator.js#309 · commit f33b86d · unknown · 75.5sRIGHT_FAILURE
- validator-343Full-width chars are not valid in an email addressno signature capturedvalidator.js#343 · commit c89c271 · unknown · 54.2sNO_FAILURE_OBSERVED
- validator-443isFloat incorrectly allows "."no signature capturedvalidator.js#443 · commit 825af6a · unknown · 28.8sNO_FAILURE_OBSERVED
- wrap-ansi-39Newline handling in 6.0.0no signature capturedwrap-ansi#39 · commit 7bcd854 · unknown · 64.0sNO_FAILURE_OBSERVED
- yaml-366Empty map values are round-tripped to `null`no signature capturedyaml#366 · commit 22dbe9e · unknown · 353.4sNO_FAILURE_OBSERVED
- yaml-57Space gets duplicatedno signature capturedyaml#57 · commit dfac964 · unknown · 109.4sNO_FAILURE_OBSERVED
- yaml-636parseDocument fails to parse arrays correctlyYAMLParseError: Flow map in block collection must be sufficiently indented and end with a } at line 4, column 1:yaml#636 · commit 03709ca · jest · 78.7sRIGHT_FAILURE
- yaml-638Negative zero treated inconsistently by `stringify` and `parse``YAML.stringify(-0)` still produces '0\n' (read 0 )yaml#638 · commit 03709ca · jest · 135.2sRIGHT_FAILURE
- yaml-653Escaped newlines in double quoted string literals causes premature string truncationYAMLParseError: Missing closing "quote at line 11, column 81:yaml#653 · commit 92f132b · jest · 95.7sRIGHT_FAILURE
- yargs-parser-118odd behavior of narg:2 versus duplicate-arguments-array:false`P('foo -p x y', { narg: { p: 2 } })` still produces { _: [ 'foo' ], p: [ 'x', 'y' ] } (read { _: [ 'foo' ], p: [ 'x', 'y' ] })yargs-parser#118 · commit 57b7883 · unknown · 29.6sWRONG_FAILURE
- yargs-parser-196Array of camel-cased option with ConfigObjects`args` still produces { _: [], watchFiles: [ 'path1', 'path2' ], 'watch-files': [ 'path1', 'path2' ] } (read { _: [], watchFiles: [ 'path1', 'path2' ], 'watch-files': [ 'path1', 'path2' ] })yargs-parser#196 · commit 7d42572 · unknown · 111.3sRIGHT_FAILURE
- yargs-parser-226`repeat` options is not considered as an unknown option with `unknown-options-as-args``Parser(['--known','x','--repeat','100','--unknown','200'], { configuration: { 'unknown-options-as-args': true }, string: ['known'] })` still produces { _: [ '--unknown', '200' ], known: 'x', repeat: 100 } (read { _: [ '--unknown', '200' ], known: 'x', repeat: 100 })yargs-parser#226 · commit 4317f00 · unknown · 132.3sRIGHT_FAILURE
- yargs-parser-261`--option=--value` is wrongly parsed when `option` is an array or has `narg` set`parse('--option=--value')` still produces { _: [], option: '--value' } (read { _: [], option: '--value' })yargs-parser#261 · commit b96b989 · unknown · 56.0sWRONG_FAILURE
Each row’s verdict is the LIVE run of 2026-09-20, the tree executed against all 158 upstream checkouts. Every case page also carries its RECORDED verdict, which carries the benchmark gate. Corpus and grader: bench/external/.
How the corpus was chosen
Nothing was dropped after seeing a result.
Exclusion criteria were fixed before any run. The candidate log, included and excluded, is published on the benchmark page with the date of each decision.
No candidate was excluded after an Credda run. The included set is every candidate whose body was read in full and found to contain a concrete reproduction.