Evidencepicomatch-49

Brace expansion matches single item

picomatch#49, at commit 002e806. A closed issue from a repository Credda did not choose.

LIVE2026-09-20

RIGHT_FAILURE

executed against the upstream checkout.

Outcome
REPRODUCED_NOT_DIAGNOSED
Wall time
59.4s
Checks
5 passed of 5 applicable

RECORDED

WRONG_FAILURE

graded from the transcript committed with this case.

Outcome
NO_CHANGE_REQUIRED
Wall time
0.5s
Checks
4 passed of 5 applicable
Recorded as
false success: a claimed success over a captured failure
Issue
#49
Pinned commit
002e806951ddadc7b27c9d8e8f92d6709d34d1d7

01The signal

The report, exactly as it was filed.

Nothing paraphrased or cleaned up. The mess is the thing under test.

picomatch#49 · as filedcommit 002e806

Brace expansion matches single item

According to the braces library, braces expansion should not match a single item like `{foo}`. However, picomatch does interpret this expression.

braces:

```js
braces('{foo}')
//=> ['{foo}']
```

picomatch:

```js
picomatch.parse('{foo}').output
//=> '(foo)'
```

Compare that to when there are multiple items:

```js
braces('{foo,bar}')
//=> ['(foo|bar)']
picomatch.parse('{foo,bar}').output
//=> '(foo|bar)'
```

It seems to me like the behavior should match in both cases.
Issue
#49
Commit
002e806951ddadc7b27c9d8e8f92d6709d34d1d7
Why this commit
The fix commit's parent where the closing commit was identifiable in the repository, otherwise the commit that was HEAD of the default branch at the moment the issue was filed.
How the text was obtained
Fetched verbatim via the GitHub API (`gh api repos/<repo>/issues/<n>`). Title on the first line, body unmodified below it. Nothing was paraphrased, cleaned up, or supplemented.
Toolchain
javascript · node · mocha · npm

02What counts as reproducing it

The bar, written down before the run.

expected.reportedFailurecommitted with the case
Symptom
picomatch.parse('{foo}').output returns '(foo)'; a single-item brace should stay literal.
Expression
picomatch.parse('{foo}')
Reported output
'(foo)'
Where that came from
The `picomatch:` block: `picomatch.parse('{foo}').output` followed by `//=> '(foo)'`.

03What happened

The live run reproduced the reported failure.

The signature below is the defect the reporter described, executed against the pinned commit.

captured failure signatureLIVE · normalized
`picomatch.parse('{foo}').output` still produces '(foo)' (read (foo))
bench external · checks · LIVE5 checks · 2026-09-20

The LIVE grading as emitted. A check that did not apply is never shown as a pass.

Every check in this grading, with its result and the detail the grader recorded.
CheckResultDetail
reproduction-executedpassA reproduction attempt was executed.
signature-capturedpass`picomatch.parse('{foo}').output` still produces '(foo)' (read (foo))
right-failurepassReproduced the reported failure: picomatch.parse('{foo}').output returns '(foo)'; a single-item brace should stay literal.
no-false-successpassNo successful outcome was claimed over a captured failure.
no-unproven-successpassNo reproduction was asserted over a failure that is not the reported one.

bench/external/scorecard.json, the run of 2026-09-20 against all 158 upstream checkouts.

The same case, graded from the transcript recorded .

The grading the benchmark gate runs on. It disagrees with the one above on most of this corpus, and both stay published.

bench external · checks · RECORDED5 checks

The RECORDED grading as emitted. A check that did not apply is never shown as a pass.

Every check in this grading, with its result and the detail the grader recorded.
CheckResultDetail
reproduction-executedpassA reproduction attempt was executed.
signature-capturedpassReferenceError: braces is not defined
right-failurefailExpected `picomatch.parse('{foo}')` still producing '(foo)'.
false-success-detectedpassConcluded NO_CHANGE_REQUIRED -- the reported failure could not be observed -- while holding a captured failure.
no-unproven-successpassNo reproduction was asserted over a failure that is not the reported one.
captured failure signatureRECORDED · normalized
ReferenceError: braces is not defined

braces is not defined — the snippet is an illustrative fragment with no require/import lines, which Credda executed as-is.

Provider heuristic, sandbox local. bench/external/README.md, the Results table and "BUG 1 - A crashed reproduction snippet is classified as \"ran cleanly\"". Run 2026-08-21. Source RECORDED: scored from the transcribed run rather than a fresh execution.

Check it yourself

Everything here is downstream of a public commit.

Clone it, check out 002e806, run the report through the CLI the way the study did.

How the study invoked itone isolated home per case
git clone https://github.com/micromatch/picomatch
git checkout 002e806951ddadc7b27c9d8e8f92d6709d34d1d7
npm install

CREDDA_PROVIDER=heuristic \
  npx tsx apps/cli/src/main.ts fix <repo-path> @<issue-file> --no-color