Evidenceqs-357
Parsing object with array doesn't split a value
qs#357, at commit 0625c49. A closed issue from a repository Credda did not choose.
LIVE2026-09-20
WRONG_FAILUREexecuted against the upstream checkout.
- Outcome
- INCONCLUSIVE
- Wall time
- 47.5s
- Checks
- 4 passed of 5 applicable
RECORDED
NOT_GRADEDgraded from the transcript committed with this case.
- Outcome
- not recorded
- Checks
- none run
01The signal
The report, exactly as it was filed.
Nothing paraphrased or cleaned up. The mess is the thing under test.
Parsing object with array doesn't split a value
Parsing a query string object with parameter that intended to be an array doesn't split value by comma, while query string in a form of string is parsed correctly.
This is an issue when integrating with frameworks like HAPI that provides query string as a dictionary.
Example
```
const qs = require('qs');
// Works
console.log(qs.parse('color=a,b', { comma: true }));
// Result: { color: [ 'a', 'b' ] }
// Doesn't work
console.log(qs.parse({ color: 'a,b' }, { comma: true }))
// Result: { color: 'a,b' }
// Expected result as above: { color: [ 'a', 'b' ] }
```- Repository
- ljharb/qs
- Issue
- #357
- Commit
- 0625c496f242771b549cd0bc052e5b2716217af1
- Why this commit
- The first parent of the fix commit eecd28d292aa4c89d112ac769f2807c062deebcb, which GitHub binds to this issue via CLOSED_EVENT_COMMIT. Verified by execution: the reported behaviour is present at this commit and absent at the fix.
- How the text was obtained
- Fetched verbatim via the GitHub GraphQL API. Title on the first line, body unmodified below it. Nothing was paraphrased, cleaned up, or supplemented.
- Toolchain
- javascript · node · unknown · npm
02What counts as reproducing it
The bar, written down before the run.
- Symptom
- qs.parse({ color: 'a,b' }, { comma: true }) does not produce { color: [ 'a', 'b' ] }; the fix makes it do so.
- Expression
- qs.parse({ color: 'a,b' }, { comma: true })
- Where that came from
- Proposed by a model reading this report and nothing else -- it never saw the repository or the fix commit -- and read back as a claim by the same parser the harvest uses, SAME_LINE form: `qs.parse({ color: 'a,b' }, { comma: true }) //=> { color: [ 'a', 'b' ] }`. The report sat in the ANNOTATION_IS_PROSE bucket, which no regex reaches. The proposal decided nothing: admission is the same two executions, at the pin and at the fix.
03What happened
A real failure was captured. It was the wrong one.
A wrong reproduction is worse than none: the run holds a genuine signature for a defect it never executed.
`qs.parse('color=a,b', { comma: true })` still produces { color: [ 'a', 'b' ] } (read { color: [ 'a', 'b' ] })The LIVE grading as emitted. A check that did not apply is never shown as a pass.
| Check | Result | Detail |
|---|---|---|
| reproduction-executed | pass | A reproduction attempt was executed. |
| signature-captured | pass | `qs.parse('color=a,b', { comma: true })` still produces { color: [ 'a', 'b' ] } (read { color: [ 'a', 'b' ] }) |
| right-failure | fail | Expected `qs.parse({ color: 'a,b' }, { comma: true })` not producing { color: [ 'a', 'b' ] }. |
| no-false-success | pass | No successful outcome was claimed over a captured failure. |
| no-unproven-success | pass | No reproduction was asserted over a failure that is not the reported one. |
bench/external/scorecard.json, the run of 2026-09-20 against all 158 upstream checkouts.
The same case, graded from the transcript recorded .
The grading the benchmark gate runs on. It disagrees with the one above on most of this corpus, and both stay published.
Check it yourself
Everything here is downstream of a public commit.
Clone it, check out 0625c49, run the report through the CLI the way the study did.
git clone https://github.com/ljharb/qs git checkout 0625c496f242771b549cd0bc052e5b2716217af1 npm install CREDDA_PROVIDER=heuristic \ npx tsx apps/cli/src/main.ts fix <repo-path> @<issue-file> --no-color