Evidencejs-yaml-784
v5: implicit-null mapping key dropped when it is the last entry before a document marker
js-yaml#784, at commit 49280f3. A closed issue from a repository Credda did not choose.
LIVE2026-09-20
WRONG_FAILUREexecuted against the upstream checkout.
- Outcome
- REPRODUCED_NOT_DIAGNOSED
- Wall time
- 76.3s
- Checks
- 3 passed of 5 applicable
RECORDED
NOT_GRADEDgraded from the transcript committed with this case.
- Outcome
- not recorded
- Checks
- none run
- Repository
- nodeca/js-yaml
- Issue
- #784
- Pinned commit
- 49280f3e799b6deb596ba9a041b0ebe2bba83c77
01The signal
The report, exactly as it was filed.
Nothing paraphrased or cleaned up. The mess is the thing under test.
v5: implicit-null mapping key dropped when it is the last entry before a document marker
### What happens
In v5, a mapping key whose value is an implicit null is dropped if it is the last entry of a document that ends with an explicit document marker (`---` or `...`). No error is raised, the key is just missing.
```js
import { loadAll } from 'js-yaml'
loadAll('a:\n---\nx: 1\n')
// v4.3.0 => [ { a: null }, { x: 1 } ]
// v5.2.2 => [ {}, { x: 1 } ]
```
### Expected
`[ { a: null }, { x: 1 } ]`, as in v4. `yaml` (eemeli) also returns `{ a: null }` for this input.
### Scope
Only the combination of implicit null value, last entry in the document, and an explicit terminator triggers it. Everything adjacent is correct, which makes it easy to miss:
| input | v5 result | note |
| --- | --- | --- |
| `m:\n a:\n b:\n---\nx: 1\n` | `{m: {a: null}}` | `b` dropped |
| `a:\nb:\n---\nx: 1\n` | `{a: null}` | `b` dropped, nesting irrelevant |
| `m:\n a:\n b: 2\n---\nx: 1\n` | correct | last value is not null |
| `m:\n a:\n b: null\n---\nx: 1\n` | correct | explicit null is fine |
| `m:\n - a\n -\n---\nx: 1\n` | correct | sequences unaffected |
| `m:\n a:\n b:\n` | correct | no terminator |
| `m:\n a:\n b:\n...\n` | `{m: {a: null}}` | `...` also triggers it |
Not schema dependent: the same result occurs with default options, an explicit `CORE_SCHEMA`, `YAML11_SCHEMA`, and `FAILSAFE_SCHEMA`-derived schemas.
### Versions
Reproduces on 5.0.0, 5.1.0, 5.2.0, 5.2.1 and 5.2.2. Correct on 4.1.1 and 4.3.0. Verified on Node v24.18.0 and Bun 1.3.10.- Repository
- nodeca/js-yaml
- Issue
- #784
- Commit
- 49280f3e799b6deb596ba9a041b0ebe2bba83c77
- Why this commit
- The first parent of the fix commit 40fcb4f45c1f25e4e9495cf27094405d1d740881, which GitHub binds to this issue via REFERENCED_COMMIT. Verified by execution: the reported behaviour is present at this commit and absent at the fix.
- How the text was obtained
- Fetched verbatim via the GitHub GraphQL API. Title on the first line, body unmodified below it. Nothing was paraphrased, cleaned up, or supplemented.
- Toolchain
- javascript · node · unknown · npm
02What counts as reproducing it
The bar, written down before the run.
- Symptom
- loadAll('a:\n---\nx: 1\n') produces [ {}, { x: 1 } ]; the fix makes it produce [ { a: null }, { x: 1 } ].
- Expression
- loadAll('a:\n---\nx: 1\n')
- Reported output
- [{}, {x: 1}]
- Where that came from
- Proposed by a model reading this report and nothing else -- it never saw the repository or the fix commit -- and read back as a claim by the same parser the harvest uses, SAME_LINE form: `loadAll('a:\n---\nx: 1\n') //=> [{}, {x: 1}]`. The report sat in the ANNOTATION_IS_PROSE bucket, which no regex reaches. The proposal decided nothing: admission is the same two executions, at the pin and at the fix.
03What happened
A real failure was captured. It was the wrong one.
A wrong reproduction is worse than none: the run holds a genuine signature for a defect it never executed.
`loadAll('a:\n---\nx: 1\n')` still produces [ {}, { x: 1 } ] (read [ {}, { x: 1 } ])The LIVE grading as emitted. A check that did not apply is never shown as a pass.
| Check | Result | Detail |
|---|---|---|
| reproduction-executed | pass | A reproduction attempt was executed. |
| signature-captured | pass | `loadAll('a:\n---\nx: 1\n')` still produces [ {}, { x: 1 } ] (read [ {}, { x: 1 } ]) |
| right-failure | fail | Expected `loadAll('a:\n---\nx: 1\n')` still producing [{}, {x: 1}]. |
| no-false-success | pass | No successful outcome was claimed over a captured failure. |
| no-unproven-success | fail | Concluded REPRODUCED_NOT_DIAGNOSED, which asserts the reported failure was reproduced, while the captured failure graded WRONG_FAILURE. |
bench/external/scorecard.json, the run of 2026-09-20 against all 158 upstream checkouts.
The same case, graded from the transcript recorded .
The grading the benchmark gate runs on. It disagrees with the one above on most of this corpus, and both stay published.
Check it yourself
Everything here is downstream of a public commit.
Clone it, check out 49280f3, run the report through the CLI the way the study did.
git clone https://github.com/nodeca/js-yaml git checkout 49280f3e799b6deb596ba9a041b0ebe2bba83c77 npm install CREDDA_PROVIDER=heuristic \ npx tsx apps/cli/src/main.ts fix <repo-path> @<issue-file> --no-color