Evidencelodash-69
_.merge doesn't always work properly when trying to merge more than two objects
lodash#69, at commit 31c4cba. A closed issue from a repository Credda did not choose.
LIVE2026-09-20
RIGHT_FAILUREexecuted against the upstream checkout.
- Outcome
- PATCH_REJECTED
- Wall time
- 68.1s
- Checks
- 5 passed of 5 applicable
RECORDED
NOT_GRADEDgraded from the transcript committed with this case.
- Outcome
- not recorded
- Checks
- none run
- Repository
- lodash/lodash
- Issue
- #69
- Pinned commit
- 31c4cbab701642a75d287d837cda79645fa0a099
01The signal
The report, exactly as it was filed.
Nothing paraphrased or cleaned up. The mess is the thing under test.
_.merge doesn't always work properly when trying to merge more than two objects
```
_.merge({a:1}, {a:2}, {a:3}, {a:4}); // -> {a:3}
```
The ellipses in the documentation for merge shows that this should be possible:
> _.merge(object [, source1, source2, …, indicator, stack=[]])
_Edit_: To get an even better idea of the problem, check out the referenced commit.- Repository
- lodash/lodash
- Issue
- #69
- Commit
- 31c4cbab701642a75d287d837cda79645fa0a099
- Why this commit
- The first parent of the fix commit 0f5228410c14f1606a1f941fe827a0c86a27c93a, which GitHub binds to this issue via CLOSED_EVENT_COMMIT. Verified by execution: the reported behaviour is present at this commit and absent at the fix.
- How the text was obtained
- Fetched verbatim via the GitHub GraphQL API. Title on the first line, body unmodified below it. Nothing was paraphrased, cleaned up, or supplemented.
- Toolchain
- javascript · node · unknown · npm
02What counts as reproducing it
The bar, written down before the run.
- Symptom
- _.merge({a:1}, {a:2}, {a:3}, {a:4}) produces { a: 3 }; the fix makes it produce { a: 4 }.
- Expression
- _.merge({a:1}, {a:2}, {a:3}, {a:4})
- Reported output
- {a:3}
- Where that came from
- Read mechanically from the report's fenced code, SAME_LINE form: `_.merge({a:1}, {a:2}, {a:3}, {a:4}); // -> {a:3}`.
03What happened
The live run reproduced the reported failure.
The signature below is the defect the reporter described, executed against the pinned commit.
`_.merge({a:1}, {a:2}, {a:3}, {a:4})` still produces {a:3} (read { a: 3 })The LIVE grading as emitted. A check that did not apply is never shown as a pass.
| Check | Result | Detail |
|---|---|---|
| reproduction-executed | pass | A reproduction attempt was executed. |
| signature-captured | pass | `_.merge({a:1}, {a:2}, {a:3}, {a:4})` still produces {a:3} (read { a: 3 }) |
| right-failure | pass | Reproduced the reported failure: _.merge({a:1}, {a:2}, {a:3}, {a:4}) produces { a: 3 }; the fix makes it produce { a: 4 }. |
| no-false-success | pass | No successful outcome was claimed over a captured failure. |
| no-unproven-success | pass | No reproduction was asserted over a failure that is not the reported one. |
bench/external/scorecard.json, the run of 2026-09-20 against all 158 upstream checkouts.
The same case, graded from the transcript recorded .
The grading the benchmark gate runs on. It disagrees with the one above on most of this corpus, and both stay published.
Check it yourself
Everything here is downstream of a public commit.
Clone it, check out 31c4cba, run the report through the CLI the way the study did.
git clone https://github.com/lodash/lodash git checkout 31c4cbab701642a75d287d837cda79645fa0a099 npm install CREDDA_PROVIDER=heuristic \ npx tsx apps/cli/src/main.ts fix <repo-path> @<issue-file> --no-color