EvidenceTinyColor-103
Color input being accepted and parsed with leading '#' characters in string
TinyColor#103, at commit 1a9a45a. A closed issue from a repository Credda did not choose.
LIVE2026-09-20
RIGHT_FAILUREexecuted against the upstream checkout.
- Outcome
- PATCH_REJECTED
- Wall time
- 141.5s
- Checks
- 5 passed of 5 applicable
RECORDED
NOT_GRADEDgraded from the transcript committed with this case.
- Outcome
- not recorded
- Checks
- none run
- Repository
- bgrins/TinyColor
- Issue
- #103
- Pinned commit
- 1a9a45a27d7b2253d96cbbedec380abae508beb0
01The signal
The report, exactly as it was filed.
Nothing paraphrased or cleaned up. The mess is the thing under test.
Color input being accepted and parsed with leading '#' characters in string
`.isValid()` returns true for these cases
```
var color1 = tinycolor("#red").isValid();
var color2 = tinycolor("#############123456").isValid();
```
However If I add `.toString()` to those, colors I get the correct values:
```
var color1 = tinycolor("#red").toString(); // returns "red"
var color2 = tinycolor("#############123456").toString(); // returns "#123456"
```- Repository
- bgrins/TinyColor
- Issue
- #103
- Commit
- 1a9a45a27d7b2253d96cbbedec380abae508beb0
- Why this commit
- The first parent of the fix commit b86cca765cb78936839db8a60f4641d8b5bf404e, which GitHub binds to this issue via REFERENCED_COMMIT. Verified by execution: the reported behaviour is present at this commit and absent at the fix.
- How the text was obtained
- Fetched verbatim via the GitHub GraphQL API. Title on the first line, body unmodified below it. Nothing was paraphrased, cleaned up, or supplemented.
- Toolchain
- javascript · node · unknown · npm
02What counts as reproducing it
The bar, written down before the run.
- Symptom
- tinycolor("#red").toString() produces 'red'; the fix makes it produce '#000000'.
- Expression
- tinycolor("#red").toString()
- Reported output
- "red"
- Where that came from
- Read mechanically from the report's fenced code, SAME_LINE form: `var color1 = tinycolor("#red").toString(); // returns "red"`.
03What happened
The live run reproduced the reported failure.
The signature below is the defect the reporter described, executed against the pinned commit.
`tinycolor("#red").toString()` still produces "red" (read red)The LIVE grading as emitted. A check that did not apply is never shown as a pass.
| Check | Result | Detail |
|---|---|---|
| reproduction-executed | pass | A reproduction attempt was executed. |
| signature-captured | pass | `tinycolor("#red").toString()` still produces "red" (read red) |
| right-failure | pass | Reproduced the reported failure: tinycolor("#red").toString() produces 'red'; the fix makes it produce '#000000'. |
| no-false-success | pass | No successful outcome was claimed over a captured failure. |
| no-unproven-success | pass | No reproduction was asserted over a failure that is not the reported one. |
bench/external/scorecard.json, the run of 2026-09-20 against all 158 upstream checkouts.
The same case, graded from the transcript recorded .
The grading the benchmark gate runs on. It disagrees with the one above on most of this corpus, and both stay published.
Check it yourself
Everything here is downstream of a public commit.
Clone it, check out 1a9a45a, run the report through the CLI the way the study did.
git clone https://github.com/bgrins/TinyColor git checkout 1a9a45a27d7b2253d96cbbedec380abae508beb0 npm install CREDDA_PROVIDER=heuristic \ npx tsx apps/cli/src/main.ts fix <repo-path> @<issue-file> --no-color