{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D7","name":"Architectural Integrity","shortDescription":{"text":"Architectural Integrity"},"helpUri":"https://codehealth.canine.dev/dimensions/D7"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D10","name":"Test Quality","shortDescription":{"text":"Test Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D10"},{"id":"D11","name":"Test Reliability","shortDescription":{"text":"Test Reliability"},"helpUri":"https://codehealth.canine.dev/dimensions/D11"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D22","name":"Internal API Consistency","shortDescription":{"text":"Internal API Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D22"},{"id":"D23","name":"Boundary Type-Coupling","shortDescription":{"text":"Boundary Type-Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D23"},{"id":"D24","name":"Comment Value","shortDescription":{"text":"Comment Value"},"helpUri":"https://codehealth.canine.dev/dimensions/D24"},{"id":"D25","name":"ADR Conformance","shortDescription":{"text":"ADR Conformance"},"helpUri":"https://codehealth.canine.dev/dimensions/D25"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D39","name":"IL Efficiency","shortDescription":{"text":"IL Efficiency"},"helpUri":"https://codehealth.canine.dev/dimensions/D39"},{"id":"AC2","name":"Forms \u0026 labels","shortDescription":{"text":"Forms \u0026 labels"},"helpUri":"https://codehealth.canine.dev/dimensions/AC2"},{"id":"AC3","name":"Page structure","shortDescription":{"text":"Page structure"},"helpUri":"https://codehealth.canine.dev/dimensions/AC3"},{"id":"AC5","name":"ARIA correctness","shortDescription":{"text":"ARIA correctness"},"helpUri":"https://codehealth.canine.dev/dimensions/AC5"},{"id":"AC6","name":"Visual \u0026 motion safety","shortDescription":{"text":"Visual \u0026 motion safety"},"helpUri":"https://codehealth.canine.dev/dimensions/AC6"},{"id":"AC7","name":"A11y enforcement","shortDescription":{"text":"A11y enforcement"},"helpUri":"https://codehealth.canine.dev/dimensions/AC7"},{"id":"AX1","name":"Captive dependencies","shortDescription":{"text":"Captive dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/AX1"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX2","name":"Stateful singletons","shortDescription":{"text":"Stateful singletons"},"helpUri":"https://codehealth.canine.dev/dimensions/AX2"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AX5","name":"Architecture \u0026 structure","shortDescription":{"text":"Architecture \u0026 structure"},"helpUri":"https://codehealth.canine.dev/dimensions/AX5"},{"id":"AX6","name":"Interface segregation","shortDescription":{"text":"Interface segregation"},"helpUri":"https://codehealth.canine.dev/dimensions/AX6"},{"id":"AX8","name":"Test isolation","shortDescription":{"text":"Test isolation"},"helpUri":"https://codehealth.canine.dev/dimensions/AX8"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"C2","name":"Access Controls","shortDescription":{"text":"Access Controls"},"helpUri":"https://codehealth.canine.dev/dimensions/C2"},{"id":"ED5","name":"Idempotency","shortDescription":{"text":"Idempotency"},"helpUri":"https://codehealth.canine.dev/dimensions/ED5"},{"id":"GD1","name":"Unfinished \u0026 placeholder code","shortDescription":{"text":"Unfinished \u0026 placeholder code"},"helpUri":"https://codehealth.canine.dev/dimensions/GD1"},{"id":"IC1","name":"Incompleteness \u0026 stubs","shortDescription":{"text":"Incompleteness \u0026 stubs"},"helpUri":"https://codehealth.canine.dev/dimensions/IC1"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P10","name":"Library API \u0026 versioning","shortDescription":{"text":"Library API \u0026 versioning"},"helpUri":"https://codehealth.canine.dev/dimensions/P10"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P2","name":"Observability","shortDescription":{"text":"Observability"},"helpUri":"https://codehealth.canine.dev/dimensions/P2"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"P7","name":"Outbound HTTP resilience","shortDescription":{"text":"Outbound HTTP resilience"},"helpUri":"https://codehealth.canine.dev/dimensions/P7"},{"id":"PF1","name":"Benchmark discipline","shortDescription":{"text":"Benchmark discipline"},"helpUri":"https://codehealth.canine.dev/dimensions/PF1"},{"id":"PF2","name":"Allocation hygiene","shortDescription":{"text":"Allocation hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/PF2"},{"id":"PF3","name":"Async \u0026 latency hygiene","shortDescription":{"text":"Async \u0026 latency hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/PF3"},{"id":"S1","name":"Web-Security Posture","shortDescription":{"text":"Web-Security Posture"},"helpUri":"https://codehealth.canine.dev/dimensions/S1"},{"id":"SC1","name":"Supply-chain hygiene","shortDescription":{"text":"Supply-chain hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/SC1"},{"id":"X1","name":"Async correctness","shortDescription":{"text":"Async correctness"},"helpUri":"https://codehealth.canine.dev/dimensions/X1"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X12","name":"Unreachable branch","shortDescription":{"text":"Unreachable branch"},"helpUri":"https://codehealth.canine.dev/dimensions/X12"},{"id":"X13","name":"Undrained process stream","shortDescription":{"text":"Undrained process stream"},"helpUri":"https://codehealth.canine.dev/dimensions/X13"},{"id":"X16","name":"Unfloored truncation loop","shortDescription":{"text":"Unfloored truncation loop"},"helpUri":"https://codehealth.canine.dev/dimensions/X16"},{"id":"X18","name":"Disposal-pattern correctness","shortDescription":{"text":"Disposal-pattern correctness"},"helpUri":"https://codehealth.canine.dev/dimensions/X18"},{"id":"X19","name":"Unrestored process-global state","shortDescription":{"text":"Unrestored process-global state"},"helpUri":"https://codehealth.canine.dev/dimensions/X19"},{"id":"X2","name":"Cancellation propagation","shortDescription":{"text":"Cancellation propagation"},"helpUri":"https://codehealth.canine.dev/dimensions/X2"},{"id":"X20","name":"Mistyped argument guard","shortDescription":{"text":"Mistyped argument guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X20"},{"id":"X21","name":"Side-effecting pattern guard","shortDescription":{"text":"Side-effecting pattern guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X21"},{"id":"X22","name":"Contradicted release guard","shortDescription":{"text":"Contradicted release guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X22"},{"id":"X23","name":"Unguarded diagnostic materialisation","shortDescription":{"text":"Unguarded diagnostic materialisation"},"helpUri":"https://codehealth.canine.dev/dimensions/X23"},{"id":"X25","name":"Inert configuration knob","shortDescription":{"text":"Inert configuration knob"},"helpUri":"https://codehealth.canine.dev/dimensions/X25"},{"id":"X26","name":"Unsynchronised callback handoff","shortDescription":{"text":"Unsynchronised callback handoff"},"helpUri":"https://codehealth.canine.dev/dimensions/X26"},{"id":"X27","name":"Collection changed while being enumerated","shortDescription":{"text":"Collection changed while being enumerated"},"helpUri":"https://codehealth.canine.dev/dimensions/X27"},{"id":"X28","name":"Index access outside its own emptiness guard","shortDescription":{"text":"Index access outside its own emptiness guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X28"},{"id":"X29","name":"Per-element action decided by a fixed element","shortDescription":{"text":"Per-element action decided by a fixed element"},"helpUri":"https://codehealth.canine.dev/dimensions/X29"},{"id":"X3","name":"Exception handling","shortDescription":{"text":"Exception handling"},"helpUri":"https://codehealth.canine.dev/dimensions/X3"},{"id":"X30","name":"Support guard that admits what it rejects","shortDescription":{"text":"Support guard that admits what it rejects"},"helpUri":"https://codehealth.canine.dev/dimensions/X30"},{"id":"X32","name":"Type resolved by simple name across every loaded assembly","shortDescription":{"text":"Type resolved by simple name across every loaded assembly"},"helpUri":"https://codehealth.canine.dev/dimensions/X32"},{"id":"X4","name":"Structured logging","shortDescription":{"text":"Structured logging"},"helpUri":"https://codehealth.canine.dev/dimensions/X4"},{"id":"X5","name":"Nullable reference types","shortDescription":{"text":"Nullable reference types"},"helpUri":"https://codehealth.canine.dev/dimensions/X5"},{"id":"X6","name":"Hand-rolled structured-format parsing","shortDescription":{"text":"Hand-rolled structured-format parsing"},"helpUri":"https://codehealth.canine.dev/dimensions/X6"},{"id":"X7","name":"Silent fallback defaults","shortDescription":{"text":"Silent fallback defaults"},"helpUri":"https://codehealth.canine.dev/dimensions/X7"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"NoiseStandardEndpoints.MapNoiseStandard (cyclomatic 133): NoiseStandardEndpoints.MapNoiseStandard has cyclomatic complexity 133 (threshold 15). Most of this is not in the body itself: 1 of the 133 points is its own statement and the rest belongs to 36 function literals inside it that branch (lines 1780, 860, 1181, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/NoiseStandardEndpoints.cs"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"26c5067202457c4186a6a1c015f4fb0f1c05e653f0fb294e26a58054f9ab347a"}},{"ruleId":"D1","level":"warning","message":{"text":"NoiseSubmissions.Accept (cyclomatic 30): NoiseSubmissions.Accept has cyclomatic complexity 30 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/NoiseSubmissions.cs"},"region":{"startLine":149}}}],"partialFingerprints":{"codehealthFindingId/v1":"4fe101ed9bf120edd8e6e78f43f0a84f2ed2fad6a3ed1578e7000d9b47d879c4"}},{"ruleId":"D1","level":"warning","message":{"text":"PublicationContract.Check (cyclomatic 30): PublicationContract.Check has cyclomatic complexity 30 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/PublicationContract.cs"},"region":{"startLine":97}}}],"partialFingerprints":{"codehealthFindingId/v1":"d8cd0f47fd53a3f0d1057532561f53d32510fe9b2d8eb3db4b9535575b47d29a"}},{"ruleId":"D1","level":"warning","message":{"text":"CaiScorer.ScoreFromEvidence (cyclomatic 17): CaiScorer.ScoreFromEvidence has cyclomatic complexity 17 (threshold 15). Of this number, 16 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Scoring/CaiScorer.cs"},"region":{"startLine":163}}}],"partialFingerprints":{"codehealthFindingId/v1":"46a21a5403102379c1d3b6be988570cd3423ecee2384afe0517fe0873d1acadd"}},{"ruleId":"D2","level":"warning","message":{"text":"NoiseStandardEndpoints.MapNoiseStandard (cognitive 151): NoiseStandardEndpoints.MapNoiseStandard has cognitive complexity 151 (threshold 15). Most of this is not in the body itself: 0 of the 151 points are its own statements and the rest belongs to 36 function literals inside it that branch (lines 1780, 860, 1181, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/NoiseStandardEndpoints.cs"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"155eb1d39c26fb59343679471a0905e51dd5c8d4b7fed633e2b14f58ffee38ac"}},{"ruleId":"D2","level":"warning","message":{"text":"PublicationContract.Check (cognitive 43): PublicationContract.Check has cognitive complexity 43 (threshold 15). To reduce it, flatten the nesting: invert conditions into early returns or guard clauses so the happy path stays at one level, and lift the deepest nested block into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/PublicationContract.cs"},"region":{"startLine":97}}}],"partialFingerprints":{"codehealthFindingId/v1":"38a5a7a43f6166cefe12aca6d02a8b8c9b9cd257ed588d9f9da4c6b868612590"}},{"ruleId":"D2","level":"warning","message":{"text":"NoiseSubmissions.Accept (cognitive 42): NoiseSubmissions.Accept has cognitive complexity 42 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/NoiseSubmissions.cs"},"region":{"startLine":149}}}],"partialFingerprints":{"codehealthFindingId/v1":"4414b720d83e6d109f33a540ae0316d5ba2b4328fc80b8684168f5d35f2935f5"}},{"ruleId":"D2","level":"warning","message":{"text":"CaiScorer.ScoreFromEvidence (cognitive 25): CaiScorer.ScoreFromEvidence has cognitive complexity 25 (threshold 15). Of this number, 24 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Scoring/CaiScorer.cs"},"region":{"startLine":163}}}],"partialFingerprints":{"codehealthFindingId/v1":"483eed6875fd27fb04672c96f1fac40f44efb34d730837c3885cd23d6b298eca"}},{"ruleId":"D2","level":"warning","message":{"text":"Rejudge.Compare (cognitive 16): Rejudge.Compare has cognitive complexity 16 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/Rejudge.cs"},"region":{"startLine":136}}}],"partialFingerprints":{"codehealthFindingId/v1":"fc1d14c408b785c855829364937c25a4a44669d54d6488aeaf0ce826ad85c21b"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: NoiseStandardEndpoints.MapNoiseStandard: MethodTooLong \u2014 MapNoiseStandard runs 1338 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 1238 over it, 13.38\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/NoiseStandardEndpoints.cs"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"cf0d98283475071b8793824bdb05153600c215277e73565d2db7ed6e60882dd6"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: NoiseStandardEndpoints: ClassTooLong \u2014 1551 significant lines (blank, comment-only and punctuation-only lines excluded), 19 methods. The bar is 400 significant lines; this is 1151 over it, 3.88\u00D7 the bar. The type holds no instance state, so there is no shared data to group its members by. To reduce it, split it by area instead: give each cohesive family of members its own smaller type, so no one type has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/NoiseStandardEndpoints.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d615f76d4f982c00725dbfa4b7cef8463fc722c5ef366c937cd3b38c4aaaa7e6"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: Noise/NoiseStandardEndpoints.cs: FileTooLong \u2014 1618 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 1118 over it, 3.24\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/NoiseStandardEndpoints.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"bd5727cf1fc53ed66e3046ee4c459bfbb4dcb2a46f07d530cd7ae435e79a068b"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: PublicationContract.Check: MethodTooLong \u2014 Check runs 138 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 38 over it, 1.38\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/PublicationContract.cs"},"region":{"startLine":97}}}],"partialFingerprints":{"codehealthFindingId/v1":"68b544498a21a8bc932b9e1e72ecf68b29740ae47184af039894d514c6cd2dc6"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: NoiseSubmissions.Accept: MethodTooLong \u2014 Accept runs 127 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 27 over it, 1.27\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/NoiseSubmissions.cs"},"region":{"startLine":149}}}],"partialFingerprints":{"codehealthFindingId/v1":"05d304871fdef28c74d39a9b8fc116328888a3e289519c0bfdd1b2d778d72a4e"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: SqliteNoiseStore: TooManyMethods \u2014 498 significant lines (blank, comment-only and punctuation-only lines excluded), 34 methods. The bar is 30 methods; this is 4 over it, 1.13\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/NoiseStore.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"93a659569c5b769c6c125cdbb0a06d5e62f36c8f89bc2e6cb6ffaf14d80ba66a"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: Noise/NoiseStore.cs: FileTooLong \u2014 557 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 57 over it, 1.11\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/NoiseStore.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"20e76e49a5f81031ba19670619df2e89e87976ff8ecdc6b187ac4bb659bd0fcb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (18 lines \u00D7 2): src/Cai.Web/Noise/NoiseStore.cs:474-491 | src/Cai.Web/Registry/RegistryStore.cs:211-228 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/NoiseStore.cs"},"region":{"startLine":474}}}],"partialFingerprints":{"codehealthFindingId/v1":"c0a2e71cbd084d358021d2466c3304ae076f82d39692feeeb32a1e714fe1f276"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): src/Cai.Delivery/Keys.cs:13-24 | src/Cai.Delivery/Keys.cs:62-73 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Cai.Delivery/Keys.cs:13\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Delivery/Keys.cs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"c0bf5beb25cd11439b8884fc7cc9e0a575e9591ef6e065c30b463fbccb86ddd0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): src/Cai.Web/Noise/NoiseStore.cs:282-287 | src/Cai.Web/Registry/RegistryStore.cs:131-136 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Note first that the copies are not typed on the same thing: the declarations holding them bind \u0060logger\u0060 to \u0060ILogger\u003CSqliteNoiseStore\u003E\u0060 in one and \u0060ILogger\u003CSqliteRegistryStore\u003E\u0060 in another, and the duplicated lines use it. The extracted unit therefore needs a parameter type that fits BOTH \u2014 their common supertype where they have one, or a new abstraction over them where they do not \u2014 and settling that is the step that comes BEFORE the extraction above. Where the two types are deliberately unrelated, the duplication is the price of that separation and the honest resolution is to record the decision rather than to extract."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/NoiseStore.cs"},"region":{"startLine":282}}}],"partialFingerprints":{"codehealthFindingId/v1":"16f5860746d464069449ab7374253eb942a4ba856f17aeb237cfd793b3408476"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: Cai.Scoring: Cai.Scoring: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and depended on by 3 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e3a5e347eb37dae389a3faad229f0601ec498c50dab3bf63ad005c492c2c7a7f"}},{"ruleId":"D8","level":"warning","message":{"text":"Coverage not measured \u2014 no coverage collector is wired up: Coverage NOT MEASURED: \u0060--collect:\u0022XPlat Code Coverage\u0022\u0060 names a data collector that ships in the \u0060coverlet.collector\u0060 package, and this repository wires up none \u2014 no test project references it and no runsettings declares one. The absence of coverage here is therefore not evidence about the suite or about our analyzer environment: without a collector, \u0060--collect\u0060 produces nothing even from a suite that builds and passes. Add a \u0060coverlet.collector\u0060 PackageReference to the test project(s) (or commit the Cobertura/OpenCover/lcov report your CI produces) and real coverage will be measured. It is excluded from the score rather than counted as a near-zero defect."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"62e63e619c28f057e129f2997c965d32a457366a9ce18ca019ffb6bdfba85c99"}},{"ruleId":"D10","level":"warning","message":{"text":"Depends on a live external host: A_marketing_origin_may_call_the_api_from_a_browser: This test fetches \u0060https://codeassuranceindex.info\u0060 while it runs, so it passes only while codeassuranceindex.info is up, reachable from the build machine, and still serving what this test expects \u2014 none of which this repository controls. It goes red on an aeroplane, behind a corporate proxy, in a sealed CI network, and on the day the third party edits that document. Serve the payload from the repository instead (a checked-in fixture file), or stub the transport; if the point really is to check the remote contract, move it out of the unit suite into a separately-scheduled integration job that is allowed to fail for someone else\u0027s reasons."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/Cai.Tests/PublicCorsTests.cs"},"region":{"startLine":28}}}],"partialFingerprints":{"codehealthFindingId/v1":"b6319da314042f6bd6a12158351bb8ff2f153f43b98902d6355af877b1b9f937"}},{"ruleId":"D10","level":"warning","message":{"text":"Depends on a live external host: Credentials_are_never_allowed: This test fetches \u0060https://codeassuranceindex.info\u0060 while it runs, so it passes only while codeassuranceindex.info is up, reachable from the build machine, and still serving what this test expects \u2014 none of which this repository controls. It goes red on an aeroplane, behind a corporate proxy, in a sealed CI network, and on the day the third party edits that document. Serve the payload from the repository instead (a checked-in fixture file), or stub the transport; if the point really is to check the remote contract, move it out of the unit suite into a separately-scheduled integration job that is allowed to fail for someone else\u0027s reasons."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/Cai.Tests/PublicCorsTests.cs"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"525909a9096933d9155948fe6e65e45ea6ea421ac834641ebc7c97e391d17aa0"}},{"ruleId":"D13","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bba3f54e3b05eca8e08a2a61bcc056d5f70590a4ec69632eb284b0518e295f4d"},"taxa":[{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/Cai.Web/Noise/NoiseStandardEndpoints.cs: src/Cai.Web/Noise/NoiseStandardEndpoints.cs changed 38 times in last 90 days, max cyclomatic complexity 133 in NoiseStandardEndpoints.MapNoiseStandard at line 50. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-15..2026-09-13, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-15 15:21:50 \u002B02:00\u0027 --until=\u00272026-09-13 15:21:50 \u002B02:00\u0027 --full-history --no-merges -- src/Cai.Web/Noise/NoiseStandardEndpoints.cs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/NoiseStandardEndpoints.cs"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"214db7cb6edbe013218b7c15f025e6fd26b01d0839eb8701d7bc7a3a051979b6"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/Cai.Web/Noise/NoiseSubmissions.cs: src/Cai.Web/Noise/NoiseSubmissions.cs changed 8 times in last 90 days, max cyclomatic complexity 30 in NoiseSubmissions.Accept at line 149. 1 of those changes was a fix/bug commit, and the other 7 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-15..2026-09-13, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-15 15:21:50 \u002B02:00\u0027 --until=\u00272026-09-13 15:21:50 \u002B02:00\u0027 --full-history --no-merges -- src/Cai.Web/Noise/NoiseSubmissions.cs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/NoiseSubmissions.cs"},"region":{"startLine":149}}}],"partialFingerprints":{"codehealthFindingId/v1":"1f31dc24d5500ca60f9247596f01fc4e0c1a1a6af0d1a29df8b1c4641945c92c"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/Cai.Scoring/CaiScorer.cs: src/Cai.Scoring/CaiScorer.cs changed 9 times in last 90 days, max cyclomatic complexity 17 in CaiScorer.ScoreFromEvidence at line 163. 1 of those changes was a fix/bug commit, and the other 8 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-15..2026-09-13, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-15 15:21:50 \u002B02:00\u0027 --until=\u00272026-09-13 15:21:50 \u002B02:00\u0027 --full-history --no-merges -- src/Cai.Scoring/CaiScorer.cs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Scoring/CaiScorer.cs"},"region":{"startLine":163}}}],"partialFingerprints":{"codehealthFindingId/v1":"4337ed18b897feda66831d89d0e6670db1ed5310cc2cfd071fcf996637616d74"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/Cai.Web/Noise/PublicationContract.cs: src/Cai.Web/Noise/PublicationContract.cs changed 5 times in last 90 days, max cyclomatic complexity 30 in PublicationContract.Check at line 97. 1 of those changes was a fix/bug commit, and the other 4 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-15..2026-09-13, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-15 15:21:50 \u002B02:00\u0027 --until=\u00272026-09-13 15:21:50 \u002B02:00\u0027 --full-history --no-merges -- src/Cai.Web/Noise/PublicationContract.cs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/PublicationContract.cs"},"region":{"startLine":97}}}],"partialFingerprints":{"codehealthFindingId/v1":"272ea5b63cb12259789419105540b6bf34fd39188c488f436799c7316161ee4e"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/Cai.Web/Registry/RegistryEndpoints.cs: src/Cai.Web/Registry/RegistryEndpoints.cs changed 3 times in last 90 days, max cyclomatic complexity 15 in RegistryEndpoints.PublishAsync at line 68. 1 of those changes was a fix/bug commit, and the other 2 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-15..2026-09-13, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-15 15:21:50 \u002B02:00\u0027 --until=\u00272026-09-13 15:21:50 \u002B02:00\u0027 --full-history --no-merges -- src/Cai.Web/Registry/RegistryEndpoints.cs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Registry/RegistryEndpoints.cs"},"region":{"startLine":68}}}],"partialFingerprints":{"codehealthFindingId/v1":"d4b15101822a7cc5f15ed3c14efe69ab10510e58f54854154b63d2dac9fa9b9a"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: src/Cai.Web/ApiRateLimiting.cs: src/Cai.Web/ApiRateLimiting.cs changed 5 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 13 (its worst body is ApiRateLimiting.Compute at line 188), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix(web): the app host\u0027s own redirect table still pointed home\u201D; \u201Cfix(web): the standard had two websites, and the one with the working tools was unreachable\u201D; \u201Cfix(web): traffic-class rate limiter \u2014 registry principals and public probes off the anonymous budget\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-06-15..2026-09-13, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-15 15:21:50 \u002B02:00\u0027 --until=\u00272026-09-13 15:21:50 \u002B02:00\u0027 --full-history --no-merges -- src/Cai.Web/ApiRateLimiting.cs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/ApiRateLimiting.cs"},"region":{"startLine":188}}}],"partialFingerprints":{"codehealthFindingId/v1":"d8486613f5cc96e55e0bf0d899deea62ebc5e3f641409ad4df1cf0e0b01537a7"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: contradicts the code: The document describes the v1 registry API, but the companion cai-delivery package format (v1 addendum) is now out-of-date and no longer referenced in the text. Update to reflect that the v2 delivery package format is implemented and its companion endpoints are live."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/CHALLENGE.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"2f1df7a3bca21a3d79c02bf45a7af800549b964b2da0d1a938fc8b560f515246"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: written for insiders: The brand section references \u0060cai-mark.svg\u0060, \u0060cai-favicon-64.png\u0060, and \u0060cai-og.png\u0060 as inline assets but does not explain the mark\u0027s purpose or how it relates to the CAI standard. Add a sentence stating what the band/glass callout signifies (the reading magnified) so readers understand its role in conveying the standard without brand colour."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/brand/README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"282e130e5427d886edfcf891c4c309faa448edc03e4d842e332fcbad92df44fd"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no project overview: The repository\u0027s README files do not describe what CAI is, its purpose, or its main value proposition. Add a one-line summary stating that CAI is an open reproducible scoring standard for codebase assurance."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a9d216b750a64033eec23b43e4ae3f6218f655fc8291ccd2f6c5eac103c488cc"}},{"ruleId":"D21","level":"note","message":{"text":"The property \u0060Ct\u0060 is used in two different test classes. While \u0060Ct\u0060 is a common abbreviation for \u0027Context\u0027 or \u0027Count\u0027 in testing frameworks, using the same short, ambiguous abbreviation for potentially different concepts (e.g., a test context object vs. a count of items) reduces readability. It is preferable to use descriptive names like \u0060TestContext\u0060 or \u0060ItemCount\u0060.: Rename to descriptive names such as \u0060TestContext\u0060 or \u0060Count\u0060 depending on the actual type and usage. (symbols: Cai.Tests.VocabularyDriftTests.Ct, Cai.Tests.JudgePanelShapeTests.Ct)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b202f048ddc805b182eb494d6e9bcb14313fd56d9f419a838611a204ab6ae183"}},{"ruleId":"D22","level":"warning","message":{"text":"Duplicate intent: Both \u0060Bands\u0060 and \u0060BandCutlines\u0060 provide a \u0060For\u0060 method that maps a score to a \u0060Band\u0060. \u0060BandCutlines\u0060 is a property of \u0060ScoringParameters\u0060 and likely contains the specific cutlines used for a version, while \u0060Bands\u0060 appears to be a static utility. This creates ambiguity on which class to use for score-to-band conversion.: Remove \u0060Bands.For\u0060 and rely exclusively on \u0060BandCutlines.For\u0060 (or \u0060ScoringParameters.Bands.For\u0060) to ensure the banding logic is tied to the specific rubric version\u0027s parameters. (signatures: Cai.Scoring.Bands.For(double scoreZeroToOneHundred) | Cai.Scoring.BandCutlines.For(double scoreZeroToOneHundred))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a5fd7b760115663f55e6c32ad338f9b4ee44ccdb91f31fd3cafb17b4d5d33cc3"}},{"ruleId":"D22","level":"warning","message":{"text":"Confusingly similar names: \u0060Sign\u0060 and \u0060SignPackage\u0060 are distinct operations (one returns \u0060DeliverySignature\u0060, the other \u0060DeliveryPackage\u0060), but the naming convention suggests \u0060SignPackage\u0060 might be a variant of \u0060Sign\u0060 rather than a distinct higher-level operation. It is unclear if \u0060Sign\u0060 is a low-level primitive or if \u0060SignPackage\u0060 is the primary entry point.: Rename \u0060Sign\u0060 to \u0060CreateSignature\u0060 or \u0060SignPayload\u0060 to clearly distinguish it from \u0060SignPackage\u0060, which implies the creation of the final signed artifact. (signatures: Cai.Delivery.DeliverySigner.Sign(DeliveryPayload payload) | Cai.Delivery.DeliverySigner.SignPackage(DeliveryPayload payload))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1a1afce877cdb507a6d3dabe3f6035d65b448975e2e0b3e69375d2e24e09a361"}},{"ruleId":"D22","level":"warning","message":{"text":"Ambiguous boolean semantics: \u0060SignatureValid\u0060 checks cryptographic integrity, while \u0060AuthenticAndReproducing\u0060 likely checks semantic correctness (score reproduction). However, \u0060Reproduced\u0060 is also a property. The naming \u0060AuthenticAndReproducing\u0060 is a compound boolean that obscures whether it is a logical AND of \u0060SignatureValid\u0060 and \u0060Reproduced\u0060 or a separate check. If it is derived, it should be a method or clearly documented as a composite property.: If \u0060AuthenticAndReproducing\u0060 is simply \u0060SignatureValid \u0026\u0026 Reproduced\u0060, expose it as a computed property with a clear name like \u0060IsVerified\u0060 or remove it in favor of checking the two constituent properties explicitly. (signatures: Cai.Delivery.DeliveryVerification.AuthenticAndReproducing | Cai.Delivery.DeliveryVerification.SignatureValid)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"59f205b97627db27bedb870da0cbb3cfb541f255b023c449987387b695c66049"}},{"ruleId":"D26","level":"note","message":{"text":"Projects may be oversized for their cohesion: 1 of 6 project(s) overshoot their size bounds, lowering Project Cohesion to 7.1/10. The most over is \u0060Cai.Web\u0060 (10165 LoC, 139 public types across 4 namespaces). Review these for cohesion \u2014 split a project that spans unrelated responsibilities."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d5a94650dc74886a0f1f08eb9fb6775f1fc395279ef7e901c970c9d26f767a72"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"207acf8aa6371c28cee6cf2b7c99cd7ae2beeeca9951d86021c77b58d434ad29"},"properties":{"commitSha":"098ef54ade12d0757c0d7650434d35dd345fbccf"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7ece479db26211712cfef17e9be4ba0e0f8fb6f957de020bff772a8e8fc728a3"},"properties":{"commitSha":"bc4880c853a42f28e7491e55b5cfc404b15461da"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3551a176446398301d7483f4e83f65c9f23be38a929e4bbd89e1ef364647c84b"},"properties":{"commitSha":"2b10b9104d14b2b87b1e85946419029ada510a2a"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6d8fac46c3079aa5b4f24dcea84f30e44994bd75fc44d7d0b6d440d1d4c24544"},"properties":{"commitSha":"098ef54ade12d0757c0d7650434d35dd345fbccf"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"df11b4282c91e955e6c8499dffde563d7edc454a56c413225081ddf2b5228614"},"properties":{"commitSha":"098ef54ade12d0757c0d7650434d35dd345fbccf"}},{"ruleId":"D28","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3cdfd7beb31b791ae18dcb425e21eb157c842e7bbcd522cc330573c1a6538db1"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d5b8f11381d61a58459ffc7c595fd52d09c03c711894a63a9578043d2338412b"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ba055b046a93209fc775a0153703f25c2250765b0b767d6e9c1129469a2566db"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ab54e6003c6ffa042a1155bc0945c20696a4e49e119dbb3ca9d29ec0cb1c6b43"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"283311b10597af6acd38907c1f0efc582310639bf329ffdbc71148f8b075185c"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b27347034fcc21f49d0f72a6b69b651f735e020a43de9ca06f450d2e96a65b3b"},"taxa":[{"id":"CWE-214","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-532","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c31bbd23dad36a314258479a9363d6d4229976a469cad7159e1c717578f81289"},"taxa":[{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ef8e795bd703fa2b737fc70b9220fddda417964e4520656acfd017a65cc636bf"},"taxa":[{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0f4021ff4cdee4fb9514798299ac25a6416795651b3edb6947b4e4f8c9f69502"},"taxa":[{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"76d92d7f06536ed17ba40ab902ddb601d96a46d94696dbbe40ab567a0b7cb10d"},"taxa":[{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cd938d1525ebe4e982af4faf2e2287e2c60531fbdd76be376f04ba2703c0911a"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1352","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"06e6e7c7d4c152bda5109bbad4ba391564907c5447f1e45b8bacf79561630391"},"taxa":[{"id":"CWE-22","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"221179058c584989cf84a8f7b1ff75bbb1068e274dd2e26b89eca3ab7ebf17f0"},"taxa":[{"id":"CWE-22","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"53cab37baac85e896457b5abb9dde7e709aab338711b4d8a0c459bec64975a80"},"taxa":[{"id":"CWE-290","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a89b898a3941fc7e8c45a8640a34629b0004f16c48340482bc642e4dfb739f95"},"taxa":[{"id":"CWE-290","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eaa16f313d2d2751ca189c32a8603107c2e17cd1f471e7ff222fda127a6ecec5"},"taxa":[{"id":"CWE-290","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ac85f7290ca4510ee492c0cc70bd21366b4dff5cbf6996599a3c00ec908ec6d4"},"taxa":[{"id":"CWE-290","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7a77ac681acfa274736fde3c0e23d0549f3fb01e85083c9fb6c50602f22c5687"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c5928b81075799790cb18fed2980a6b6e8aa5072772041c9951633efe8eb3542"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d657599f6f99da1927d3377533dfc0888b34c4d84aa7d5579841fd72d0e39bce"}},{"ruleId":"D39","level":"note","message":{"text":"IL efficiency: 8 authored method(s) exceed the IL budget: 8 of 443 first-party methods compile to oversized IL bodies (\u003E 250 instructions); worst: Cai.Web.Noise.NoiseSubmissions.Accept @ src/Cai.Web/Noise/NoiseSubmissions.cs:153, 685 IL instructions; that pulled this dimension to 9.6/10. These bodies are far past the JIT\u0027s inline budget, so splitting them does not make them inlinable \u2014 what moves the number is emitting less: collapsing LINQ chains and closures on hot paths, and interpolation built eagerly where it is only sometimes used."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/NoiseSubmissions.cs"},"region":{"startLine":153}}}],"partialFingerprints":{"codehealthFindingId/v1":"31877a3bcaee25c89e488c521b270661278c64289720ad3da383e1dae8497842"}},{"ruleId":"AC2","level":"warning","message":{"text":"\u003Cfieldset\u003E without a \u003Clegend\u003E: A fieldset groups related controls but has no \u003Clegend\u003E to name the group. Add a \u003Clegend\u003E as its first child \u2014 or, if the group already has a visible caption beside it (or the fieldset is there only to disable its subtree and carries no group box), point aria-labelledby at that caption\u0027s id instead, which names the group without rendering a second one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Components/Pages/NoiseRate.razor"},"region":{"startLine":183}}}],"partialFingerprints":{"codehealthFindingId/v1":"99ee94970c5279c13380091e4c5c84ad8781185e22297f2acb7210a0f1ac13b4"}},{"ruleId":"AX6","level":"note","message":{"text":"Fat interface: INoiseStore (28 members): \u0060INoiseStore\u0060 declares 28 members: \u0060TryRecordSubmission\u0060, \u0060FindSubmission\u0060, \u0060AlreadySubmitted\u0060, \u0060ListSubmissions\u0060, \u0060ConfigurationJson\u0060, \u0060RecordVerdict\u0060, \u0060RecordResolution\u0060, \u0060RegisterPrompt\u0060, \u0060ListVerdicts\u0060, \u0060ListResolutions\u0060, \u0060ListPrompts\u0060, \u0060RecordPublication\u0060, \u0060LatestPublication\u0060, \u0060PublishedPeriods\u0060, \u0060PublishedTallies\u0060, \u0060RecordRejudge\u0060, \u0060ListRejudge\u0060, \u0060RaiseDispute\u0060, \u0060FindDispute\u0060, \u0060ResolveDispute\u0060, \u0060ListDisputes\u0060, \u0060RegisterIntent\u0060, \u0060ListIntent\u0060, \u0060RecordFindings\u0060, \u0060FindFinding\u0060, \u0060RecordCost\u0060, \u0060CostFor\u0060, \u0060JudgedPeriods\u0060. Counted as the author wrote them \u2014 a property is ONE member and its get/set accessors are not counted separately, and an event counts once. A wide interface forces every implementer and caller to depend on methods they don\u0027t use (the Interface-Segregation \u0027I\u0027 in SOLID). Split it into focused role-interfaces."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Cai.Web/Noise/NoiseStore.cs"},"region":{"startLine":79}}}],"partialFingerprints":{"codehealthFindingId/v1":"d2f8b56e386ca1364e56fa36059ece3cd8d7900422068cd0d1270161cde23245"}},{"ruleId":"C2","level":"note","message":{"text":"Anonymous-heavy surface: [AllowAnonymous] (15) outweighs [Authorize] (1) \u2014 review whether the open surface is intended."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"fe36ed341d024b5c2f9815c8c57995cf558c1d2de2ca9e7139e1c48695961190"}},{"ruleId":"P10","level":"note","message":{"text":"Large public API surface: 187/207 types (90%) are public. For a library, every public type is a stability contract \u2014 make internal-by-default and expose only the intended API."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ed2ba843444ae377c17142f58f714e281e4bd3f183ab100ee1fbef389875d3e6"}},{"ruleId":"P12","level":"warning","message":{"text":"Test suite runs only after the merge: \u0060deploy.yml\u0060, \u0060publish-packages.yml\u0060 run(s) the test suite, but no workflow that runs tests is triggered by a pull request (or a merge queue) \u2014 so the suite reports on code that is already on the default branch. A red build there blocks nothing and the only remedy is a revert. Add the pull-request trigger to the workflow that runs your suite so the gate applies before the merge, not after it."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"731ad560de6aa35d3e92103d5ad0fbec4c54f771b709281e852941847e03ef03"}},{"ruleId":"P2","level":"note","message":{"text":"Logging is not universal: Only 2/3 service-like projects use logging (pure contract/DTO projects are excluded \u2014 they have nothing to log). Of those 3, 2 ship a process this repository operates; the rest are libraries their consumer hosts, where the logging decision belongs to the host."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"91a94e21d6d4d0e6a2003f94505b0b02b157176f0b24c4820f3f82b4447a97fe"}},{"ruleId":"SC1","level":"warning","message":{"text":"NuGet dependencies are not locked: No packages.lock.json and no central package management \u2014 restores aren\u0027t reproducible or pinned (SSDF PW.4.4). Enable \u003CRestorePackagesWithLockFile\u003Etrue\u003C/RestorePackagesWithLockFile\u003E (commit the lockfile) or adopt Directory.Packages.props. Advisory \u2014 never scored."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0a97b4f69ccac509400ece7eedefb06d3ede0522cd4d8bcb5c068bea719545a6"}},{"ruleId":"X2","level":"note","message":{"text":"Not all async methods take a CancellationToken: Only 0/2 async methods accept a CancellationToken, so in-flight work can\u0027t be stopped early when the caller gives up \u2014 whatever ends it in your host (shutdown signal, timeout, abandoned request, user cancel). Thread a token through the call chain and honour it at each await and loop; where a method genuinely cannot be interrupted, omitting it is a deliberate choice \u2014 judge against your hosting model."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"bf623a92fb752b336427856888a9b386c434e686662a2cdc1bba21832c0a048c"}},{"ruleId":"X5","level":"note","message":{"text":"Null-forgiving operator (\u0060!\u0060) suppressions reduce the NRT score: ~1.1 \u0060!\u0060 suppressions per 1k syntax nodes \u2014 61 suppression(s) across the 53929 syntax node(s) in code where nullable warnings are ENABLED, which is the only code a \u0060!\u0060 can suppress anything in (a \u0060!\u0060 under \u0060#nullable disable\u0060 is inert and is not counted, and its file\u0027s nodes are not in the denominator). Each one tells the compiler to trust you about null, suppressing the very safety NRTs provide."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"93cfe05d4ad8c8c171267603b23dfe289b74842e38edd1b7bfed59cc32bda337"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1104","guid":"4c918cb5-b2a6-6c55-9963-a44ee464305e","name":"CWE-1104","shortDescription":{"text":"CWE-1104"},"helpUri":"https://cwe.mitre.org/data/definitions/1104.html"},{"id":"CWE-1352","guid":"5257f322-5cfc-6b52-bedd-0b9a526b4c7d","name":"CWE-1352","shortDescription":{"text":"CWE-1352"},"helpUri":"https://cwe.mitre.org/data/definitions/1352.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-214","guid":"b10ad120-fb22-1351-9348-aa23b453e815","name":"CWE-214","shortDescription":{"text":"CWE-214"},"helpUri":"https://cwe.mitre.org/data/definitions/214.html"},{"id":"CWE-22","guid":"b68d9ca7-bdde-d057-a6cc-9f8b1e739552","name":"CWE-22","shortDescription":{"text":"CWE-22"},"helpUri":"https://cwe.mitre.org/data/definitions/22.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-290","guid":"379b1e66-a292-7b59-aa1e-a5bb4a6a99e9","name":"CWE-290","shortDescription":{"text":"CWE-290"},"helpUri":"https://cwe.mitre.org/data/definitions/290.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-532","guid":"1cd8877a-76e8-ce54-b40b-779af23364a0","name":"CWE-532","shortDescription":{"text":"CWE-532"},"helpUri":"https://cwe.mitre.org/data/definitions/532.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-829","guid":"13c33925-97fb-5a5e-b40c-56d328b8a4d7","name":"CWE-829","shortDescription":{"text":"CWE-829"},"helpUri":"https://cwe.mitre.org/data/definitions/829.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":26,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}