Evidencelodash-1061
_.merge adds extra element when merging nesting array into object
lodash#1061, at commit 94ca508. A closed issue from a repository Credda did not choose.
LIVE2026-09-20
WRONG_FAILUREexecuted against the upstream checkout.
- Outcome
- REPRODUCED_NOT_DIAGNOSED
- Wall time
- 70.1s
- Checks
- 3 passed of 5 applicable
RECORDED
NOT_GRADEDgraded from the transcript committed with this case.
- Outcome
- not recorded
- Checks
- none run
- Repository
- lodash/lodash
- Issue
- #1061
- Pinned commit
- 94ca50883f7d94d61e037587a3547869d785c76c
01The signal
The report, exactly as it was filed.
Nothing paraphrased or cleaned up. The mess is the thing under test.
_.merge adds extra element when merging nesting array into object
`_.merge({set:{}}, {set:[]})` creates a set array with length of 1, `{set:[0:undefined]}`. I'm assuming it should return `{set:{}}` similar to how `_.merge({}, [])` just returns `{}`.- Repository
- lodash/lodash
- Issue
- #1061
- Commit
- 94ca50883f7d94d61e037587a3547869d785c76c
- Why this commit
- The first parent of the fix commit c250aa804a759d5e446aeb71d3de048d49d826e1, which GitHub binds to this issue via CLOSED_EVENT_COMMIT. Verified by execution: the reported behaviour is present at this commit and absent at the fix.
- How the text was obtained
- Fetched verbatim via the GitHub GraphQL API. Title on the first line, body unmodified below it. Nothing was paraphrased, cleaned up, or supplemented.
- Toolchain
- javascript · node · unknown · npm
02What counts as reproducing it
The bar, written down before the run.
- Symptom
- _.merge({set:{}}, {set:[]}) produces { set: [ undefined ] }; the fix makes it produce { set: [] }.
- Expression
- _.merge({set:{}}, {set:[]})
- Reported output
- {"set":[undefined]}
- Where that came from
- Proposed by a model reading this report and nothing else -- it never saw the repository or the fix commit -- and read back as a claim by the same parser the harvest uses, SAME_LINE form: `_.merge({set:{}}, {set:[]}) //=> {"set":[undefined]}`. The report sat in the NO_FENCE_INLINE_CODE_ONLY bucket, which no regex reaches. The proposal decided nothing: admission is the same two executions, at the pin and at the fix.
03What happened
A real failure was captured. It was the wrong one.
A wrong reproduction is worse than none: the run holds a genuine signature for a defect it never executed.
`_.merge({}, [])` still produces {} (read {})The LIVE grading as emitted. A check that did not apply is never shown as a pass.
| Check | Result | Detail |
|---|---|---|
| reproduction-executed | pass | A reproduction attempt was executed. |
| signature-captured | pass | `_.merge({}, [])` still produces {} (read {}) |
| right-failure | fail | Expected `_.merge({set:{}}, {set:[]})` still producing {"set":[undefined]}. |
| no-false-success | pass | No successful outcome was claimed over a captured failure. |
| no-unproven-success | fail | Concluded REPRODUCED_NOT_DIAGNOSED, which asserts the reported failure was reproduced, while the captured failure graded WRONG_FAILURE. |
bench/external/scorecard.json, the run of 2026-09-20 against all 158 upstream checkouts.
The same case, graded from the transcript recorded .
The grading the benchmark gate runs on. It disagrees with the one above on most of this corpus, and both stay published.
Check it yourself
Everything here is downstream of a public commit.
Clone it, check out 94ca508, run the report through the CLI the way the study did.
git clone https://github.com/lodash/lodash git checkout 94ca50883f7d94d61e037587a3547869d785c76c npm install CREDDA_PROVIDER=heuristic \ npx tsx apps/cli/src/main.ts fix <repo-path> @<issue-file> --no-color