Evidencesemver-557
[BUG] Inconsistent behaviour of caret versions with includePrerelease
node-semver#557, at commit efafcf8. A closed issue from a repository Credda did not choose.
LIVE2026-09-20
RIGHT_FAILUREexecuted against the upstream checkout.
- Outcome
- REPRODUCED_NOT_DIAGNOSED
- Wall time
- 170.3s
- Checks
- 5 passed of 5 applicable
RECORDED
NOT_GRADEDgraded from the transcript committed with this case.
- Outcome
- not recorded
- Checks
- none run
- Repository
- npm/node-semver
- Issue
- #557
- Pinned commit
- efafcf8d029faa3d1ab74b5ec98d620112af859d
01The signal
The report, exactly as it was filed.
Nothing paraphrased or cleaned up. The mess is the thing under test.
[BUG] Inconsistent behaviour of caret versions with includePrerelease
### Is there an existing issue for this?
- [X] I have searched the existing issues
### Current Behavior
The behaviour of `satisfies` when using a caret range with `includePrerease: true` seems to depend on whether a major version number is present:
```
> semver.satisfies('0.0.3-alpha', '^0.0.3', {includePrerelease: true})
true
> semver.satisfies('0.2.3-alpha', '^0.2.3', {includePrerelease: true})
true
> semver.satisfies('1.2.3-alpha', '^1.2.3', {includePrerelease: true})
false
```
### Expected Behavior
I'd expect the above calls to all return false, for consistency with the reasoning in #409
### Steps To Reproduce
_No response_
### Environment
- semver: 7.5.0
- npm: 8.5.1
- Node: 12.22.9
- OS: Ubuntu 22.04.2- Repository
- npm/node-semver
- Issue
- #557
- Commit
- efafcf8d029faa3d1ab74b5ec98d620112af859d
- Why this commit
- The first parent of the fix commit 046da7f527cc72a482b5dea8cb59392be65bf186, which GitHub binds to this issue via CLOSED_EVENT_PR. Verified by execution: the reported behaviour is present at this commit and absent at the fix.
- How the text was obtained
- Fetched verbatim via the GitHub GraphQL API. Title on the first line, body unmodified below it. Nothing was paraphrased, cleaned up, or supplemented.
- Toolchain
- javascript · node · unknown · npm
02What counts as reproducing it
The bar, written down before the run.
- Symptom
- semver.satisfies('0.0.3-alpha', '^0.0.3', {includePrerelease: true}) produces true; the fix makes it produce false.
- Expression
- semver.satisfies('0.0.3-alpha', '^0.0.3', {includePrerelease: true})
- Reported output
- true
- Where that came from
- Read mechanically from the report's fenced code, REPL form: `> semver.satisfies('0.0.3-alpha', '^0.0.3', {includePrerelease: true}) true`.
03What happened
The live run reproduced the reported failure.
The signature below is the defect the reporter described, executed against the pinned commit.
`semver.satisfies('0.0.3-alpha', '^0.0.3', {includePrerelease: true})` still produces true (read true)The LIVE grading as emitted. A check that did not apply is never shown as a pass.
| Check | Result | Detail |
|---|---|---|
| reproduction-executed | pass | A reproduction attempt was executed. |
| signature-captured | pass | `semver.satisfies('0.0.3-alpha', '^0.0.3', {includePrerelease: true})` still produces true (read true) |
| right-failure | pass | Reproduced the reported failure: semver.satisfies('0.0.3-alpha', '^0.0.3', {includePrerelease: true}) produces true; the fix makes it produce false. |
| no-false-success | pass | No successful outcome was claimed over a captured failure. |
| no-unproven-success | pass | No reproduction was asserted over a failure that is not the reported one. |
bench/external/scorecard.json, the run of 2026-09-20 against all 158 upstream checkouts.
The same case, graded from the transcript recorded .
The grading the benchmark gate runs on. It disagrees with the one above on most of this corpus, and both stay published.
Check it yourself
Everything here is downstream of a public commit.
Clone it, check out efafcf8, run the report through the CLI the way the study did.
git clone https://github.com/npm/node-semver git checkout efafcf8d029faa3d1ab74b5ec98d620112af859d npm install CREDDA_PROVIDER=heuristic \ npx tsx apps/cli/src/main.ts fix <repo-path> @<issue-file> --no-color