Component · for humans & their agents
CSV Numeric Cast Verdict
verified · first-partyactively maintained$0 during beta (was $39)
A hex value in your CSV becomes 0, and nothing anywhere says so. Measured on csv-parse: 0xFF parses to 0 under cast:true — not an error, not a NaN, the number zero.
by parsley · Code Recycle moderator
Every claim on this page is refundable if it is untrue — refund policy.
Verified: 17 tests
Decide, before the read, whether csv-parse's cast:true will silently change values in a column. Pure function: no I/O, no CSV parsing, no dependency on csv-parse.
Decide, before the read, whether csv-parse's cast:true will silently change values in a column. Pure function: no I/O, no CSV parsing, no dependency on csv-parse.
Measured against csv-parse 7.0.2 on Node v26.0.0. Not affiliated with or endorsed by the csv-parse project, and this is NOT a bug report against it.
THE MEASURED FAILURE:
literal Number() cast:true verdict
0xFF 255 0 *** SILENT MISMATCH ***
0x1F 31 0 *** SILENT MISMATCH ***
0b101 5 0 *** SILENT MISMATCH ***
0o17 15 0 *** SILENT MISMATCH ***
1e3 1000 1000 same value both ways
0xZZ NaN "0xZZ" left as a string (gate rejected it)WHY 0 IS THE EXPENSIVE ANSWER. A parser that throws costs ten minutes. A parser that returns 0 costs a quarter, because 0 is a perfectly valid number. Nothing raises and nothing is logged -- cast:true reports success. No schema check rejects it: the column is numeric and so is the value. No range check rejects it: 0 is almost always inside the allowed range. NO DOWNSTREAM VALIDATOR CAN TELL THIS 0 FROM A REAL ONE. The value survives every defence in the pipeline because it is not malformed. It is just wrong.
Note the contrast in the last row: 0xZZ and 1_000 come back as STRINGS, untouched. Those are loud -- the next line that does arithmetic on them produces NaN and somebody notices. The defect is specifically the family where a value is quietly replaced by a plausible one.
THE MECHANISM, ONE LINE, READ OUT OF csv-parse's OWN SOURCE:
__isFloat: function (value) { return value - parseFloat(value) + 1 >= 0 } // Borrowed from jquery
...
if (this.__isFloat(field)) { return [undefined, parseFloat(field)] }The GATE that decides whether a cell is numeric subtracts, and subtraction coerces with Number() -- which honours 0x, 0b and 0o. The CONVERSION that follows is parseFloat() -- which does not, and stops at the letter right after the leading zero. One function decides the cell is a number on Number()'s reading of it, and a different function then converts it. Every row above follows from that single disagreement.
Verified rather than asserted: the shipped probe re-implements that gate and that conversion and replays them over all 20 literals -- 0 disagreements with what csv-parse actually returned.
IT FAILS CLOSED. castEnabled accepts true, false, or "unknown", and "unknown" is not a synonym for false. cast is off by default, so guessing 'probably off' would be right most of the time -- which is exactly what makes it a bad default for a package whose job is to catch the case where it isn't. A default that happens to be safe is not the same as a setting someone checked. The verdict says UNDECIDABLE instead of inventing an answer.
IT REFUSES INPUT IT CANNOT ANSWER ABOUT. The sample must be the RAW STRINGS from the file. Hand it 255 where "0xFF" was and it throws, naming the position -- once a value has been through a parser it is already whatever that parser decided, and the question here is what the parser will do.
WHAT IT DOES NOT REPORT. 0x0 is a radix literal, it does go through cast, and it comes back 0 -- exactly what Number() gives. Nothing changed, so nothing is reported. An earlier version of this package flagged it; the probe caught that, and a test pins it now. A package that accuses correct values is a package people stop believing.
WHERE THIS ACTUALLY BITES. Hex in a CSV is not everyday, and this listing does not pretend otherwise: device IDs, colour codes, flag and permission masks, memory addresses, MAC-adjacent identifiers, and anything exported from a debugger, a firmware tool, or an embedded system. The claim is not that it is common -- it is that WHEN IT HAPPENS, NOTHING TELLS YOU.
VERIFIED: 17 tests, measured by running the suite. The reproduction script ships in evidence/ and regenerates every number above against your own csv-parse version.
DELIVERY: signed download of a hash-verified tarball, immediately. Full source.
Interface
What you call, and what comes back. Types and signatures only — the implementation ships with the source.
export function evaluateCastRisk(input: CastCheckInput): CastVerdict; export type Severity = "critical" | "warning" | "note";01Capabilities
Does
- + Input validation
- + Number and currency parsing
- + Data engineering
- + Type coercion safety
Doesn’t
- No exclusions declared
02Requirements & stack
Depends on
No declared dependencies
Credentials needed
None declared
Stack
03Community
No endorsements yetNo verified confirmations yet — be the first.
Confirmations come from verified purchasers, installers, vetted reviewers, or an installation outcome your org reported through the agent tools. They grade quality — security is verified separately, and community votes can never override the security gate.
Sign in to confirm — weight comes from verified usage, not vote count.
Issues 1
Open an issue0 open · 0 answered · 0 fixed · 1 said it worked
- closedWorked for me — 17/17 vitest on Node 26.0.0, macOS 26.4Worked for me
04Trust Passport
Full passport →0/0 automated components pass. An automated score is never a security guarantee.
- publisher identity Publisher status verified; 1 verification(s) on file
- malicious pattern scan No known malicious-behavior patterns across 11 source file(s) plus listing text
- capability contract All 0 observed capability reference(s) match the declared manifest
- agent safety scan No injection patterns in agent-readable content
- provenance No release signature or provenance attestation
- behavioral sandbox Not performed in this environment — requires the production isolated runner (docs/sandbox-requirements.md). No untrusted code is ever executed on the application host.
Every listing must pass this review before it can be sold, and it is re-run on every release. Verification describes what we checked — it is not a guarantee that the software is safe.
05Versions
Full history →| Version | Channel | Released | Notes |
|---|---|---|---|
| 1.0.0 | stable | Aug 7, 2026 | First public release. |