← Package details

Runtime evidence / smoke tested

lodash4.18.1

Observed 2026-10-05 06:03 UTC · Linux amd64 / glibc

Download JSON
Immutable loading evidence badge for lodash
Passed

All applicable planned loading observations completed.

This is loading evidence. It does not establish functional correctness or package safety.

Runtime matrix

4 pinned runtimes · production_f10071512e0e7e24c6867f11e90a7da0

Import uses ESM; require uses CommonJS. Root modes use fresh sandboxes. Subpath batches share module caches and globals. Select a result to inspect its evidence.

Does lodash work in Node.js, Bun and Deno?

All applicable planned loading checks completed. The runtimes used the same installed dependency snapshot. Test environment: Linux amd64 / glibc, with install scripts and execution networking disabled. Successful import or require does not prove that package functions, native features or your application work.

Does lodash work with Node.js?

lodash@4.18.1 passed the applicable loading checks in Node.js 24.21.0. 2 passed · 0 failed.

lodash@4.18.1 passed the applicable loading checks in Node.js 26.10.0. 2 passed · 0 failed.

Does lodash work with Bun?

lodash@4.18.1 passed the applicable loading checks in Bun 1.4.2. 2 passed · 0 failed.

Does lodash work with Deno?

lodash@4.18.1 passed the applicable loading checks in Deno 2.9.7. 2 passed · 0 failed.

Compare npm package compatibility across Node.js, Bun and Deno · Browse observed runtime loading failures

Shared preparation

Passed

1 installed packages · 0 optional dependencies omitted · lifecycle scripts disabled

The omitted count covers locked optional dependencies. Optional peers are separate and are not automatically installed.

Static manifest, native and script observations

Static indicators are context; their presence alone does not establish a prerequisite or failure.

Coverage and evidence

Node.js 24.21.0 · Root · ESM importPassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Node.js 24.21.0 · Root · CommonJS requirePassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Node.js 24.21.0 · Subpaths · ESM importNot applicable

0 passed · 0 failed · 0 observed of 0 planned

Evidence JSON
Node.js 24.21.0 · Subpaths · CommonJS requireNot applicable

0 passed · 0 failed · 0 observed of 0 planned

Evidence JSON
Node.js 26.10.0 · Root · ESM importPassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Node.js 26.10.0 · Root · CommonJS requirePassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Node.js 26.10.0 · Subpaths · ESM importNot applicable

0 passed · 0 failed · 0 observed of 0 planned

Evidence JSON
Node.js 26.10.0 · Subpaths · CommonJS requireNot applicable

0 passed · 0 failed · 0 observed of 0 planned

Evidence JSON
Bun 1.4.2 · Root · ESM importPassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Bun 1.4.2 · Root · CommonJS requirePassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Bun 1.4.2 · Subpaths · ESM importNot applicable

0 passed · 0 failed · 0 observed of 0 planned

Evidence JSON
Bun 1.4.2 · Subpaths · CommonJS requireNot applicable

0 passed · 0 failed · 0 observed of 0 planned

Evidence JSON
Deno 2.9.7 · Root · ESM importPassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Deno 2.9.7 · Root · CommonJS requirePassed

1 passed · 0 failed · 1 observed of 1 planned

Evidence JSON
Deno 2.9.7 · Subpaths · ESM importNot applicable

0 passed · 0 failed · 0 observed of 0 planned

Evidence JSON
Deno 2.9.7 · Subpaths · CommonJS requireNot applicable

0 passed · 0 failed · 0 observed of 0 planned

Evidence JSON
Planner omissions
pattern
0
non executable
0
not exported
0
invalid subpath
0
coverage limit
0

    Reproduce these inputs

    Download the recorded inputs and exact dependency lock. These files do not include the CLI, runtime images or installed packages.

    Local replay requires setup. The CLI currently runs from the CompatLab source repository on a qualified Linux amd64/runsc host. Hosted runtime images are not yet distributed for public download; an operator must supply the exact images named in this report. A fresh image build does not substitute for them. CLI setup and replay requirements

    Command for a configured host

    Run from the built CompatLab repository with both downloads in that directory and the exact runtime images loaded. Rebuilding creates a new snapshot generation.

    sudo "$(command -v node)" apps/cli/dist/bin.js reproduce ./70e276ef-4b62-4381-9a18-522752d8940d-reproduction.json --rebuild --lockfile ./package-lock.json --json

    The original worker last reported its sealed snapshot as available. Verified reuse requires those actual bytes in your local state directory.

    Exact provenance
    artifact
    lodash@4.18.1
    integrity
    sha512-dMInicTPVE8d1e5otfwmmjlxkZoUpiVLwyeTdUsi/Caj/gfzzblBcCE5sRHV/AsjuCmxWrte2TNGSYuCeCq+0Q==
    tarball
    https://registry.npmjs.org/lodash/-/lodash-4.18.1.tgz
    snapshot
    7daca743-57e2-4da0-90d1-d2253d10025c
    generation
    c54c4ab9-f794-4bf5-8e71-d059cc6ceaab
    lockDigest
    83fef5fcee40d4d3cf5f87faf3e6186bd458a3426e13daf128676747b5fcb198
    treeDigest
    29b6528827272276b455e671eae28ffc20c8a19344cade66f09d678344a70b57
    installerImage
    node:24.21.0-bookworm-slim@sha256:5cbc7caba8c2c0f0bca675d1b61b9f2857e1cf1853c6164ee9dd409501a936e7
    preparationProfile
    npm_11_19_0_linux_amd64_v2
    harness
    load_v2
    planner
    explicit_exports_v1
    policy
    runtime_limits_v2
    classifier
    classifier_v2
    classifiedAt
    2026-10-09T05:14:33.920Z

    node_24_21_0

    sha256:cb6150e21f96e0cced8169843922f9f0363d32d3be86393172958aeb9d653aac

    Built 2026-10-04 15:20 UTC · runtime_image_v1

    node_26_10_0

    sha256:348bbebdc16cde773af001ccf9734936485091fadf0b6162224c796fbf343a81

    Built 2026-10-04 15:20 UTC · runtime_image_v1

    bun_1_4_2

    sha256:58846b11e3e63c83dd1bbfa12097e641025bd57febe737c2bfaf2962a63fbacb

    Built 2026-10-04 15:21 UTC · runtime_image_v1

    deno_2_9_7

    sha256:d2ee9affe35ff6eb8d788fcdc202e2e74802a2936e9acdfc63cd6b7d2aea0777

    Built 2026-10-04 15:21 UTC · runtime_image_v1

    Evidence limitations

    • Only installation and loading were observed; functional correctness and package safety are not established.
    • Subpath batches share module caches and globals; root modes use separate fresh sandboxes.
    • Package-visible harness observations can be tampered with. They are not adversarial attestation.
    • Evidence applies to these exact artifacts, dependency snapshot, runtime images and Linux amd64/glibc policy.
    • Runtime error codes are captured observations and can also be thrown by package code.
    lodash@4.18.1: Node.js, Bun & Deno test report | CompatLab