{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D10","name":"Test Quality","shortDescription":{"text":"Test Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D10"},{"id":"D11","name":"Test Reliability","shortDescription":{"text":"Test Reliability"},"helpUri":"https://codehealth.canine.dev/dimensions/D11"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D23","name":"Boundary Type-Coupling","shortDescription":{"text":"Boundary Type-Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D23"},{"id":"D24","name":"Comment Value","shortDescription":{"text":"Comment Value"},"helpUri":"https://codehealth.canine.dev/dimensions/D24"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D39","name":"IL Efficiency","shortDescription":{"text":"IL Efficiency"},"helpUri":"https://codehealth.canine.dev/dimensions/D39"},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AX1","name":"Captive dependencies","shortDescription":{"text":"Captive dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/AX1"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX2","name":"Stateful singletons","shortDescription":{"text":"Stateful singletons"},"helpUri":"https://codehealth.canine.dev/dimensions/AX2"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AX5","name":"Architecture \u0026 structure","shortDescription":{"text":"Architecture \u0026 structure"},"helpUri":"https://codehealth.canine.dev/dimensions/AX5"},{"id":"AX6","name":"Interface segregation","shortDescription":{"text":"Interface segregation"},"helpUri":"https://codehealth.canine.dev/dimensions/AX6"},{"id":"AX8","name":"Test isolation","shortDescription":{"text":"Test isolation"},"helpUri":"https://codehealth.canine.dev/dimensions/AX8"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"C2","name":"Access Controls","shortDescription":{"text":"Access Controls"},"helpUri":"https://codehealth.canine.dev/dimensions/C2"},{"id":"DM1","name":"Aggregate boundaries","shortDescription":{"text":"Aggregate boundaries"},"helpUri":"https://codehealth.canine.dev/dimensions/DM1"},{"id":"DM10","name":"One transaction, one aggregate","shortDescription":{"text":"One transaction, one aggregate"},"helpUri":"https://codehealth.canine.dev/dimensions/DM10"},{"id":"DM11","name":"Constructible invalid state","shortDescription":{"text":"Constructible invalid state"},"helpUri":"https://codehealth.canine.dev/dimensions/DM11"},{"id":"DM12","name":"Ambient inputs in the domain","shortDescription":{"text":"Ambient inputs in the domain"},"helpUri":"https://codehealth.canine.dev/dimensions/DM12"},{"id":"DM5","name":"Encapsulated state","shortDescription":{"text":"Encapsulated state"},"helpUri":"https://codehealth.canine.dev/dimensions/DM5"},{"id":"DM6","name":"Domain \u2194 infrastructure boundary","shortDescription":{"text":"Domain \u2194 infrastructure boundary"},"helpUri":"https://codehealth.canine.dev/dimensions/DM6"},{"id":"DM8","name":"Value-object opportunities","shortDescription":{"text":"Value-object opportunities"},"helpUri":"https://codehealth.canine.dev/dimensions/DM8"},{"id":"DM9","name":"Scattered domain decisions","shortDescription":{"text":"Scattered domain decisions"},"helpUri":"https://codehealth.canine.dev/dimensions/DM9"},{"id":"ED5","name":"Idempotency","shortDescription":{"text":"Idempotency"},"helpUri":"https://codehealth.canine.dev/dimensions/ED5"},{"id":"GD1","name":"Unfinished \u0026 placeholder code","shortDescription":{"text":"Unfinished \u0026 placeholder code"},"helpUri":"https://codehealth.canine.dev/dimensions/GD1"},{"id":"IC1","name":"Incompleteness \u0026 stubs","shortDescription":{"text":"Incompleteness \u0026 stubs"},"helpUri":"https://codehealth.canine.dev/dimensions/IC1"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P2","name":"Observability","shortDescription":{"text":"Observability"},"helpUri":"https://codehealth.canine.dev/dimensions/P2"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P5","name":"DR \u0026 Backup","shortDescription":{"text":"DR \u0026 Backup"},"helpUri":"https://codehealth.canine.dev/dimensions/P5"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"P7","name":"Outbound HTTP resilience","shortDescription":{"text":"Outbound HTTP resilience"},"helpUri":"https://codehealth.canine.dev/dimensions/P7"},{"id":"PF1","name":"Benchmark discipline","shortDescription":{"text":"Benchmark discipline"},"helpUri":"https://codehealth.canine.dev/dimensions/PF1"},{"id":"PF2","name":"Allocation hygiene","shortDescription":{"text":"Allocation hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/PF2"},{"id":"PF3","name":"Async \u0026 latency hygiene","shortDescription":{"text":"Async \u0026 latency hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/PF3"},{"id":"S1","name":"Web-Security Posture","shortDescription":{"text":"Web-Security Posture"},"helpUri":"https://codehealth.canine.dev/dimensions/S1"},{"id":"SC1","name":"Supply-chain hygiene","shortDescription":{"text":"Supply-chain hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/SC1"},{"id":"X1","name":"Async correctness","shortDescription":{"text":"Async correctness"},"helpUri":"https://codehealth.canine.dev/dimensions/X1"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X12","name":"Unreachable branch","shortDescription":{"text":"Unreachable branch"},"helpUri":"https://codehealth.canine.dev/dimensions/X12"},{"id":"X13","name":"Undrained process stream","shortDescription":{"text":"Undrained process stream"},"helpUri":"https://codehealth.canine.dev/dimensions/X13"},{"id":"X16","name":"Unfloored truncation loop","shortDescription":{"text":"Unfloored truncation loop"},"helpUri":"https://codehealth.canine.dev/dimensions/X16"},{"id":"X18","name":"Disposal-pattern correctness","shortDescription":{"text":"Disposal-pattern correctness"},"helpUri":"https://codehealth.canine.dev/dimensions/X18"},{"id":"X19","name":"Unrestored process-global state","shortDescription":{"text":"Unrestored process-global state"},"helpUri":"https://codehealth.canine.dev/dimensions/X19"},{"id":"X2","name":"Cancellation propagation","shortDescription":{"text":"Cancellation propagation"},"helpUri":"https://codehealth.canine.dev/dimensions/X2"},{"id":"X20","name":"Mistyped argument guard","shortDescription":{"text":"Mistyped argument guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X20"},{"id":"X21","name":"Side-effecting pattern guard","shortDescription":{"text":"Side-effecting pattern guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X21"},{"id":"X22","name":"Contradicted release guard","shortDescription":{"text":"Contradicted release guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X22"},{"id":"X23","name":"Unguarded diagnostic materialisation","shortDescription":{"text":"Unguarded diagnostic materialisation"},"helpUri":"https://codehealth.canine.dev/dimensions/X23"},{"id":"X25","name":"Inert configuration knob","shortDescription":{"text":"Inert configuration knob"},"helpUri":"https://codehealth.canine.dev/dimensions/X25"},{"id":"X26","name":"Unsynchronised callback handoff","shortDescription":{"text":"Unsynchronised callback handoff"},"helpUri":"https://codehealth.canine.dev/dimensions/X26"},{"id":"X27","name":"Collection changed while being enumerated","shortDescription":{"text":"Collection changed while being enumerated"},"helpUri":"https://codehealth.canine.dev/dimensions/X27"},{"id":"X28","name":"Index access outside its own emptiness guard","shortDescription":{"text":"Index access outside its own emptiness guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X28"},{"id":"X29","name":"Per-element action decided by a fixed element","shortDescription":{"text":"Per-element action decided by a fixed element"},"helpUri":"https://codehealth.canine.dev/dimensions/X29"},{"id":"X3","name":"Exception handling","shortDescription":{"text":"Exception handling"},"helpUri":"https://codehealth.canine.dev/dimensions/X3"},{"id":"X30","name":"Support guard that admits what it rejects","shortDescription":{"text":"Support guard that admits what it rejects"},"helpUri":"https://codehealth.canine.dev/dimensions/X30"},{"id":"X32","name":"Type resolved by simple name across every loaded assembly","shortDescription":{"text":"Type resolved by simple name across every loaded assembly"},"helpUri":"https://codehealth.canine.dev/dimensions/X32"},{"id":"X4","name":"Structured logging","shortDescription":{"text":"Structured logging"},"helpUri":"https://codehealth.canine.dev/dimensions/X4"},{"id":"X5","name":"Nullable reference types","shortDescription":{"text":"Nullable reference types"},"helpUri":"https://codehealth.canine.dev/dimensions/X5"},{"id":"X6","name":"Hand-rolled structured-format parsing","shortDescription":{"text":"Hand-rolled structured-format parsing"},"helpUri":"https://codehealth.canine.dev/dimensions/X6"},{"id":"X7","name":"Silent fallback defaults","shortDescription":{"text":"Silent fallback defaults"},"helpUri":"https://codehealth.canine.dev/dimensions/X7"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"HttpCommandStateMismatchAnalyzer.AnalyzeInvocation (cyclomatic 41): HttpCommandStateMismatchAnalyzer.AnalyzeInvocation has cyclomatic complexity 41 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Extensions/gen/Eventuous.Extensions.AspNetCore.Generators/HttpCommandStateMismatchAnalyzer.cs"},"region":{"startLine":33}}}],"partialFingerprints":{"codehealthFindingId/v1":"4eb8e10db56b1a84c5294a613f8ae99fd3c0d968f01cdf417edbb5ad133c52f4"}},{"ruleId":"D1","level":"warning","message":{"text":"EventUsageAnalyzer.AnalyzeInvocation (cyclomatic 30): EventUsageAnalyzer.AnalyzeInvocation has cyclomatic complexity 30 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/gen/Eventuous.Shared.Generators/EventUsageAnalyzer.cs"},"region":{"startLine":118}}}],"partialFingerprints":{"codehealthFindingId/v1":"cac9f95d59eaecff379e2ed21431e2629eb790ff97303fcb00670cec4deab3d1"}},{"ruleId":"D1","level":"warning","message":{"text":"ConsumeContextConverterGenerator.TransformWithSymbol (cyclomatic 20): ConsumeContextConverterGenerator.TransformWithSymbol has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/gen/Eventuous.Subscriptions.Generators/ConsumeContextConverterGenerator.cs"},"region":{"startLine":74}}}],"partialFingerprints":{"codehealthFindingId/v1":"ad04913123dfb200672a498ec3e2d6c3ab37dd45fdd9612174c83b0b48040702"}},{"ruleId":"D1","level":"warning","message":{"text":"Handler.Handle (cyclomatic 19): Handler.Handle has cyclomatic complexity 19 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function, or replace a long branch ladder over a single value with a data-driven lookup or dispatch table."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Azure/src/Eventuous.Azure.Storage.Blobs/BlobStorageProjector.cs"},"region":{"startLine":136}}}],"partialFingerprints":{"codehealthFindingId/v1":"2cba9f4f0c3df614a08e209f37c9b7c4506183e9fcc6652770a4e4d8181ab1e2"}},{"ruleId":"D1","level":"warning","message":{"text":"SqlSubscriptionBase.Poll (cyclomatic 17): SqlSubscriptionBase.Poll has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Relational/src/Eventuous.Sql.Base/Subscriptions/SqlSubscriptionBase.cs"},"region":{"startLine":82}}}],"partialFingerprints":{"codehealthFindingId/v1":"76cf161a41898cb59b1e2cc7d0047d412cba65c22a084614e0430d430256b592"}},{"ruleId":"D1","level":"warning","message":{"text":"SetupIndex.AddTier (cyclomatic 16): SetupIndex.AddTier has cyclomatic complexity 16 (threshold 15). Of this number, 8 points are the body\u0027s own statements and 8 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Experimental/src/Eventuous.ElasticSearch/Index/IndexSetup.cs"},"region":{"startLine":91}}}],"partialFingerprints":{"codehealthFindingId/v1":"08653d390e714374cf0e1fc4969616cc673932cf602a5365eea0f3636dda77dc"}},{"ruleId":"D2","level":"warning","message":{"text":"HttpCommandStateMismatchAnalyzer.AnalyzeInvocation (cognitive 81): HttpCommandStateMismatchAnalyzer.AnalyzeInvocation has cognitive complexity 81 (threshold 15). To reduce it, flatten the nesting: invert conditions into early returns or guard clauses so the happy path stays at one level, and lift the deepest nested block into its own named function. This file is where this pass\u0027s cognitive complexity CONCENTRATES: src/Extensions/gen/Eventuous.Extensions.AspNetCore.Generators/HttpCommandStateMismatchAnalyzer.cs holds 2 of the 12 methods over the threshold \u2014 including the worst \u2014 and 67 of the 172 points over it (39%), 2.6\u00D7 the next-largest file (src/Core/gen/Eventuous.Subscriptions.Generators/ConsumeContextConverterGenerator.cs at 26). No single row can show this, because each is measured only against the threshold: reducing this one file moves this dimension further than any other file in the repository."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Extensions/gen/Eventuous.Extensions.AspNetCore.Generators/HttpCommandStateMismatchAnalyzer.cs"},"region":{"startLine":33}}}],"partialFingerprints":{"codehealthFindingId/v1":"95769a1434f3285dc58fc79178ea011fc3ce1bf6e64a1a407368bb628e062e52"}},{"ruleId":"D2","level":"warning","message":{"text":"ConsumeContextConverterGenerator.TransformWithSymbol (cognitive 41): ConsumeContextConverterGenerator.TransformWithSymbol has cognitive complexity 41 (threshold 15). To reduce it, flatten the nesting: invert conditions into early returns or guard clauses so the happy path stays at one level, and lift the deepest nested block into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/gen/Eventuous.Subscriptions.Generators/ConsumeContextConverterGenerator.cs"},"region":{"startLine":74}}}],"partialFingerprints":{"codehealthFindingId/v1":"f2957558ddbd770111b5afa3067093d3a54eb18674f723e7f322fed89e18a5fc"}},{"ruleId":"D2","level":"warning","message":{"text":"KurrentDBEventStore.EnumerateStream (cognitive 30): KurrentDBEventStore.EnumerateStream has cognitive complexity 30 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/KurrentDB/src/Eventuous.KurrentDB/KurrentDBEventStore.cs"},"region":{"startLine":247}}}],"partialFingerprints":{"codehealthFindingId/v1":"066be5733063fa3ab3e30888e3a5fabb94e9f5dec9a754cdcf31feb168c938bf"}},{"ruleId":"D2","level":"warning","message":{"text":"HttpCommandMappingGenerator.Execute (cognitive 28): HttpCommandMappingGenerator.Execute has cognitive complexity 28 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Extensions/gen/Eventuous.Extensions.AspNetCore.Generators/HttpCommandMappingGenerator.cs"},"region":{"startLine":116}}}],"partialFingerprints":{"codehealthFindingId/v1":"be0f90615ba186aad6cfb90165efd77f7d58b93d9a1a51774805a139431f4dcf"}},{"ruleId":"D2","level":"warning","message":{"text":"HttpCommandMappingGenerator.DiscoverStateTypes (cognitive 27): HttpCommandMappingGenerator.DiscoverStateTypes has cognitive complexity 27 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Extensions/gen/Eventuous.Extensions.AspNetCore.Generators/HttpCommandMappingGenerator.cs"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"bda7b134965464eb6af851fff5438c288d84c41a5e81f551d98e1c2f3347ceb9"}},{"ruleId":"D2","level":"warning","message":{"text":"EventUsageAnalyzer.AnalyzeInvocation (cognitive 26): EventUsageAnalyzer.AnalyzeInvocation has cognitive complexity 26 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/gen/Eventuous.Shared.Generators/EventUsageAnalyzer.cs"},"region":{"startLine":118}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c509fa7581ad9dfd33d15a6a7e8f66e0d99b9ecb665655ee12f41172a36ba82"}},{"ruleId":"D2","level":"warning","message":{"text":"SqlSubscriptionBase.Poll (cognitive 25): SqlSubscriptionBase.Poll has cognitive complexity 25 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Relational/src/Eventuous.Sql.Base/Subscriptions/SqlSubscriptionBase.cs"},"region":{"startLine":82}}}],"partialFingerprints":{"codehealthFindingId/v1":"313e9ef40520bbfbebe2ea9874d42a62ed59cbf044a4f19380a0625a1a711464"}},{"ruleId":"D2","level":"warning","message":{"text":"Handler.Handle (cognitive 21): Handler.Handle has cognitive complexity 21 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Azure/src/Eventuous.Azure.Storage.Blobs/BlobStorageProjector.cs"},"region":{"startLine":136}}}],"partialFingerprints":{"codehealthFindingId/v1":"1818b3eb8ecbfb5c3821bedd343ecb1daba3f1cd2037c9a8f5a1682b6235f3fd"}},{"ruleId":"D2","level":"warning","message":{"text":"ChannelExtensions.ReadAllBatches (cognitive 21): ChannelExtensions.ReadAllBatches has cognitive complexity 21 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Subscriptions/Channels/ChannelExtensions.cs"},"region":{"startLine":65}}}],"partialFingerprints":{"codehealthFindingId/v1":"3854a9cb1267a9e1907f18ce494fbbe435acecc8629a13020938c108394474ad"}},{"ruleId":"D2","level":"warning","message":{"text":"EventSubscription.Handler (cognitive 20): EventSubscription.Handler has cognitive complexity 20 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Subscriptions/EventSubscription.cs"},"region":{"startLine":232}}}],"partialFingerprints":{"codehealthFindingId/v1":"e05c5d6bad78e6bca7baa5f8e8ecbc879dbfceaab51aa68dea883203c603d427"}},{"ruleId":"D2","level":"warning","message":{"text":"TypeMappingsGenerator.TryGetEventTypeName (cognitive 16): TypeMappingsGenerator.TryGetEventTypeName has cognitive complexity 16 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/gen/Eventuous.Shared.Generators/TypeMappingsGenerator.cs"},"region":{"startLine":120}}}],"partialFingerprints":{"codehealthFindingId/v1":"b0e539428447cc58b2019b33e620af1a159fd536d0d02d97501b650b89e950ee"}},{"ruleId":"D2","level":"warning","message":{"text":"HttpCommandStateMismatchAnalyzer.GetHttpCommandStateTypeArg (cognitive 16): HttpCommandStateMismatchAnalyzer.GetHttpCommandStateTypeArg has cognitive complexity 16 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body. This file is where this pass\u0027s cognitive complexity CONCENTRATES: src/Extensions/gen/Eventuous.Extensions.AspNetCore.Generators/HttpCommandStateMismatchAnalyzer.cs holds 2 of the 12 methods over the threshold \u2014 including the worst \u2014 and 67 of the 172 points over it (39%), 2.6\u00D7 the next-largest file (src/Core/gen/Eventuous.Subscriptions.Generators/ConsumeContextConverterGenerator.cs at 26). No single row can show this, because each is measured only against the threshold: reducing this one file moves this dimension further than any other file in the repository."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Extensions/gen/Eventuous.Extensions.AspNetCore.Generators/HttpCommandStateMismatchAnalyzer.cs"},"region":{"startLine":149}}}],"partialFingerprints":{"codehealthFindingId/v1":"db601c65b39095f04ac09abeeff1b52218e986001edcf93ecb488f5345cb93da"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (25 lines \u00D7 2): src/Core/src/Eventuous.Application/Persistence/WriterExtensions.cs:42-66 | src/Core/src/Eventuous.Persistence/EventStore/StoreFunctions.cs:64-88 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Core/src/Eventuous.Application/Persistence/WriterExtensions.cs:42\u0060 it runs out through the closing brace of the declaration holding it \u2014 the window is that declaration\u0027s tail, not a fragment that begins part-way through something, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Application/Persistence/WriterExtensions.cs"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"1a1e80402ecf965f11ee3d7b93ed540d21628e24c0e456c9cd5c2e583769ea2a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (20 lines \u00D7 2): src/Redis/src/Eventuous.Redis/Subscriptions/RedisSubscriptionBase.cs:51-70 | src/Relational/src/Eventuous.Sql.Base/Subscriptions/SqlSubscriptionBase.cs:229-248 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Redis/src/Eventuous.Redis/Subscriptions/RedisSubscriptionBase.cs:51\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Redis/src/Eventuous.Redis/Subscriptions/RedisSubscriptionBase.cs"},"region":{"startLine":51}}}],"partialFingerprints":{"codehealthFindingId/v1":"6592273db6ab8ed3605f6577d2ddf5f6564af7c51193d90660de69094dc297be"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16\u201319 lines \u00D7 3): src/Extensions/gen/Eventuous.Extensions.AspNetCore.Generators/HttpCommandStateMismatchAnalyzer.cs:54-72 | src/Extensions/gen/Eventuous.Extensions.AspNetCore.Generators/HttpCommandStateMismatchAnalyzer.cs:84-99 | src/Extensions/gen/Eventuous.Extensions.AspNetCore.Generators/HttpCommandStateMismatchAnalyzer.cs:129-146 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Extensions/gen/Eventuous.Extensions.AspNetCore.Generators/HttpCommandStateMismatchAnalyzer.cs:54\u0060 it runs out through the closing brace of the declaration holding it \u2014 the window is that declaration\u0027s tail, not a fragment that begins part-way through something, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Extensions/gen/Eventuous.Extensions.AspNetCore.Generators/HttpCommandStateMismatchAnalyzer.cs"},"region":{"startLine":54}}}],"partialFingerprints":{"codehealthFindingId/v1":"a397cb9c3c3a17ee8b7837e15b89f8fe7c98d962ae615f34fa3a54f93ca78195"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9\u201319 lines \u00D7 2): src/Relational/src/Eventuous.Sql.Base/SqlEventStoreBase.cs:230-248 | src/Sqlite/src/Eventuous.Sqlite/SqliteStore.cs:132-140 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Relational/src/Eventuous.Sql.Base/SqlEventStoreBase.cs:230\u0060 it runs out through the closing brace of the declaration holding it \u2014 the window is that declaration\u0027s tail, not a fragment that begins part-way through something, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. \u2605 These copies have DRIFTED, and that is worth reading before extracting anything: just before the matched lines, \u0060src/Sqlite/src/Eventuous.Sqlite/SqliteStore.cs:130\u0060 calls \u0060RollbackAsync\u0060, \u0060NoContext\u0060 and \u0060src/Relational/src/Eventuous.Sql.Base/SqlEventStoreBase.cs:230\u0060 does not \u2014 after which the two agree again for 3 more lines. One of those two behaviours is the intended one and the other is what a copy-paste left behind, so decide which BEFORE unifying them: extracting the shared part will silently settle it, and if the copy that skips the call is the wrong one, that bug is already live."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Relational/src/Eventuous.Sql.Base/SqlEventStoreBase.cs"},"region":{"startLine":230}}}],"partialFingerprints":{"codehealthFindingId/v1":"dc6d4be65642ce6e910e273349aeecaa18f472ab76b9836657e7984166919af3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11\u201316 lines \u00D7 3): src/Postgres/src/Eventuous.Postgresql/Schema.cs:42-57 | src/SqlServer/src/Eventuous.SqlServer/Schema.cs:37-51 | src/Sqlite/src/Eventuous.Sqlite/Schema.cs:34-44 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 3 call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made 3 times. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Postgres/src/Eventuous.Postgresql/Schema.cs:42\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Postgres/src/Eventuous.Postgresql/Schema.cs"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"0eded95c565ba1fc39f61724f2c1642bd47d90843536863515d66d2010f41969"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13\u201315 lines \u00D7 2): src/Core/gen/Eventuous.Shared.Generators/TypeMappingsGenerator.cs:240-254 | src/Experimental/gen/Eventuous.Spyglass.Generators/SpyglassGenerator.cs:231-243 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/gen/Eventuous.Shared.Generators/TypeMappingsGenerator.cs"},"region":{"startLine":240}}}],"partialFingerprints":{"codehealthFindingId/v1":"575e653a050849bf9a4f55b82ab3727d068d6d86016978a16407978b4807edd0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): src/SqlServer/src/Eventuous.SqlServer/SchemaInitializer.cs:12-25 | src/Sqlite/src/Eventuous.Sqlite/SchemaInitializer.cs:12-25 \u2014 before extracting anything, compare \u0060src/SqlServer/src/Eventuous.SqlServer/SchemaInitializer.cs\u0060 and \u0060src/Sqlite/src/Eventuous.Sqlite/SchemaInitializer.cs\u0060 as WHOLE FILES: 86% of the shorter file\u0027s lines also appear in the other, so this reads as one file having been copied from the other rather than as a helper waiting to be extracted. The 1 duplicated block(s) this scan matched between them are fragments of that copy, not the extent of it \u2014 treat the file pair as the unit. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/SqlServer/src/Eventuous.SqlServer/SchemaInitializer.cs:12\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/SqlServer/src/Eventuous.SqlServer/SchemaInitializer.cs"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"af5b860e1f2c754db427a86e4ed95bac75474f3bc1769d1404d3f062e07bc30e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11\u201312 lines \u00D7 2): src/Core/gen/Eventuous.Subscriptions.Generators/ConsumeContextConverterGenerator.cs:78-89 | src/Core/gen/Eventuous.Subscriptions.Generators/ConsumeContextConverterGenerator.cs:108-118 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Core/gen/Eventuous.Subscriptions.Generators/ConsumeContextConverterGenerator.cs:78\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/gen/Eventuous.Subscriptions.Generators/ConsumeContextConverterGenerator.cs"},"region":{"startLine":78}}}],"partialFingerprints":{"codehealthFindingId/v1":"f4bd2f814c298c8626fc391c02fb3b0f0f72f303a47a9058994401892157ac68"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): src/SqlServer/src/Eventuous.SqlServer/Subscriptions/SqlServerCheckpointStore.cs:43-54 | src/Sqlite/src/Eventuous.Sqlite/Subscriptions/SqliteCheckpointStore.cs:43-54 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/SqlServer/src/Eventuous.SqlServer/Subscriptions/SqlServerCheckpointStore.cs:43\u0060 it runs out through the closing brace of the declaration holding it and carries on into the declaration that follows \u2014 the window is the tail of one member plus the head of the next, so no call can be substituted for those exact lines, and the smallest declaration that contains all of them is the type they sit in. The repeated unit is the member each site sits in: where those members\u0027 bodies are the same, move one whole member to the shared location and have the others delegate to it; where the copies are a run of near-identical overloads or wrappers that differ only in their signatures, the repetition IS the run \u2014 a one-line delegation has no helper inside it to lift \u2014 so generate the run from the set it enumerates, or accept it and keep each member\u0027s own documentation with it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/SqlServer/src/Eventuous.SqlServer/Subscriptions/SqlServerCheckpointStore.cs"},"region":{"startLine":43}}}],"partialFingerprints":{"codehealthFindingId/v1":"3f08aa31c6c8d4a7291164ae70ba1f1c0b131a3ce95dc3ae1403b0edbe5edefb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): src/Extensions/src/Eventuous.Extensions.DependencyInjection/Registrations/Services.cs:22-32 | src/Extensions/src/Eventuous.Extensions.DependencyInjection/Registrations/Services.cs:43-53 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Each matched range is the entire body of the declaration above it, so the region is already a complete unit: move that whole declaration to the shared location and have each site call it, rather than lifting the lines out of their bodies. Any \u0060return\u0060 inside it is the body\u0027s own exit and keeps its meaning in the moved unit."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Extensions/src/Eventuous.Extensions.DependencyInjection/Registrations/Services.cs"},"region":{"startLine":22}}}],"partialFingerprints":{"codehealthFindingId/v1":"7b8c92405cecf3d722e5055baceb85f218806ba28f3e4867f41cdc59bffa411d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): src/SqlServer/src/Eventuous.SqlServer/Extensions/RegistrationExtensions.cs:76-86 | src/Sqlite/src/Eventuous.Sqlite/Extensions/RegistrationExtensions.cs:76-86 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/SqlServer/src/Eventuous.SqlServer/Extensions/RegistrationExtensions.cs:76\u0060 it runs out through the closing brace of the declaration holding it \u2014 the window is that declaration\u0027s tail, not a fragment that begins part-way through something, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/SqlServer/src/Eventuous.SqlServer/Extensions/RegistrationExtensions.cs"},"region":{"startLine":76}}}],"partialFingerprints":{"codehealthFindingId/v1":"3b6bf153ea9658d08df848b8efd072edbdea05aa23d4dea526572ed14c71bc35"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): src/Azure/src/Eventuous.Azure.ServiceBus/Subscriptions/ServiceBusSubscription.cs:182-189 | src/Azure/src/Eventuous.Azure.ServiceBus/Subscriptions/ServiceBusSubscription.cs:209-216 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Each matched range is the entire body of the declaration above it, so the region is already a complete unit: move that whole declaration to the shared location and have each site call it, rather than lifting the lines out of their bodies. Any \u0060return\u0060 inside it is the body\u0027s own exit and keeps its meaning in the moved unit."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Azure/src/Eventuous.Azure.ServiceBus/Subscriptions/ServiceBusSubscription.cs"},"region":{"startLine":182}}}],"partialFingerprints":{"codehealthFindingId/v1":"128333677a7de9a9f446a17aea9b1c635fdca961b5bef4f9d6fc4c5b820524fe"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): src/Relational/src/Eventuous.Sql.Base/SqlEventStoreBase.cs:212-219 | src/Sqlite/src/Eventuous.Sqlite/SqliteStore.cs:112-119 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Relational/src/Eventuous.Sql.Base/SqlEventStoreBase.cs:212\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Relational/src/Eventuous.Sql.Base/SqlEventStoreBase.cs"},"region":{"startLine":212}}}],"partialFingerprints":{"codehealthFindingId/v1":"8f1e8a2f4f4bdacd899a9dd4c9888d610cf79dc6b20057e2199fa4e0c59aa124"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): src/Core/gen/Eventuous.Shared.Generators/EventUsageAnalyzer.cs:128-133 | src/Core/gen/Eventuous.Shared.Generators/EventUsageAnalyzer.cs:163-168 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Core/gen/Eventuous.Shared.Generators/EventUsageAnalyzer.cs:128\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/gen/Eventuous.Shared.Generators/EventUsageAnalyzer.cs"},"region":{"startLine":128}}}],"partialFingerprints":{"codehealthFindingId/v1":"afdb563eeaaac32ed62cdbaa55d831210a66396ab94dc92d064bde48a574ba11"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): src/Extensions/src/Eventuous.Extensions.DependencyInjection/Registrations/Stores.cs:127-132 | src/Extensions/src/Eventuous.Extensions.DependencyInjection/Registrations/Stores.cs:150-155 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Extensions/src/Eventuous.Extensions.DependencyInjection/Registrations/Stores.cs:127\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Extensions/src/Eventuous.Extensions.DependencyInjection/Registrations/Stores.cs"},"region":{"startLine":127}}}],"partialFingerprints":{"codehealthFindingId/v1":"463f7d5a1749ccb52b73a60ac3b8882504c2d46bf14bdc97f8004a2636f341e9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): src/Core/src/Eventuous.Application/AggregateService/CommandService.cs:108-112 | src/Core/src/Eventuous.Application/FunctionalService/CommandService.cs:110-114 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it. \u2605 These copies have DRIFTED, and that is worth reading before extracting anything: just before the matched lines, \u0060src/Core/src/Eventuous.Application/AggregateService/CommandService.cs:106\u0060 calls \u0060Create\u0060 and \u0060src/Core/src/Eventuous.Application/FunctionalService/CommandService.cs:108\u0060 does not \u2014 after which the two agree again for 4 more lines. One of those two behaviours is the intended one and the other is what a copy-paste left behind, so decide which BEFORE unifying them: extracting the shared part will silently settle it, and if the copy that skips the call is the wrong one, that bug is already live."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Application/AggregateService/CommandService.cs"},"region":{"startLine":108}}}],"partialFingerprints":{"codehealthFindingId/v1":"d2121c0c1dd2e58359b1380d9d7d289f9a28d62861e0d93c2959934691ecf2f1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): src/Experimental/src/ElasticPlayground/CombinedStore.cs:39-47 | src/Experimental/src/ElasticPlayground/ConnectorAndArchive.cs:43-51 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Experimental/src/ElasticPlayground/CombinedStore.cs"},"region":{"startLine":39}}}],"partialFingerprints":{"codehealthFindingId/v1":"48b251603d58cb7a934235af7ff7d421e6d83541cc816b04648231e1fc279444"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): src/SqlServer/src/Eventuous.SqlServer/Subscriptions/SqlServerCheckpointStore.cs:23-30 | src/Sqlite/src/Eventuous.Sqlite/Subscriptions/SqliteCheckpointStore.cs:23-30 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/SqlServer/src/Eventuous.SqlServer/Subscriptions/SqlServerCheckpointStore.cs"},"region":{"startLine":23}}}],"partialFingerprints":{"codehealthFindingId/v1":"580b2058a848dfab44835610cf5319b734df1e3fd5b279d089b41ebd059620fb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (29 lines \u00D7 2): samples/kurrentdb/Bookings/Application/Queries/MyBookingsProjection.cs:8-36 | samples/postgres/Bookings/Application/Queries/MyBookingsProjection.cs:8-36 \u2014 before extracting anything, compare \u0060samples/kurrentdb/Bookings/Application/Queries/MyBookingsProjection.cs\u0060 and \u0060samples/postgres/Bookings/Application/Queries/MyBookingsProjection.cs\u0060 as WHOLE FILES: 100% of the shorter file\u0027s lines also appear in the other, so this reads as one file having been copied from the other rather than as a helper waiting to be extracted. The 1 duplicated block(s) this scan matched between them are fragments of that copy, not the extent of it \u2014 treat the file pair as the unit. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"samples/kurrentdb/Bookings/Application/Queries/MyBookingsProjection.cs"},"region":{"startLine":8}}}],"partialFingerprints":{"codehealthFindingId/v1":"89f6d91ae767d34f9fda65993fc968795f6b12b3b72c949b6c51d769e1c4cba5"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17\u201318 lines \u00D7 2): samples/kurrentdb/Bookings/Application/Queries/BookingStateProjection.cs:11-27 | samples/postgres/Bookings/Application/Queries/BookingStateProjection.cs:11-28 \u2014 before extracting anything, compare \u0060samples/kurrentdb/Bookings/Application/Queries/BookingStateProjection.cs\u0060 and \u0060samples/postgres/Bookings/Application/Queries/BookingStateProjection.cs\u0060 as WHOLE FILES: 89% of the shorter file\u0027s lines also appear in the other, so this reads as one file having been copied from the other rather than as a helper waiting to be extracted. The 1 duplicated block(s) this scan matched between them are fragments of that copy, not the extent of it \u2014 treat the file pair as the unit. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"samples/kurrentdb/Bookings/Application/Queries/BookingStateProjection.cs"},"region":{"startLine":11}}}],"partialFingerprints":{"codehealthFindingId/v1":"e1163a4744033bbd694b6ce23a7008577fdbc12c29eb3e02a8760a6dfd66fe96"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10\u201314 lines \u00D7 2): samples/kurrentdb/Bookings/Infrastructure/Mongo.cs:11-24 | samples/postgres/Bookings/Infrastructure/Mongo.cs:12-21 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060samples/kurrentdb/Bookings/Infrastructure/Mongo.cs:11\u0060 it runs out through the closing brace of the declaration holding it \u2014 the window is that declaration\u0027s tail, not a fragment that begins part-way through something, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"samples/kurrentdb/Bookings/Infrastructure/Mongo.cs"},"region":{"startLine":11}}}],"partialFingerprints":{"codehealthFindingId/v1":"4fbe5d673a1dd4ca3bc8398d1e31f10f1e12ed07279ea0b10eda52afeecc8140"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): samples/kurrentdb/Bookings/Application/BookingsCommandService.cs:18-30 | samples/postgres/Bookings/Application/BookingsCommandService.cs:18-30 \u2014 before extracting anything, compare \u0060samples/kurrentdb/Bookings/Application/BookingsCommandService.cs\u0060 and \u0060samples/postgres/Bookings/Application/BookingsCommandService.cs\u0060 as WHOLE FILES: 96% of the shorter file\u0027s lines also appear in the other, so this reads as one file having been copied from the other rather than as a helper waiting to be extracted. The 1 duplicated block(s) this scan matched between them are fragments of that copy, not the extent of it \u2014 treat the file pair as the unit. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place. Read the line range as the matched WINDOW rather than a finished unit: at \u0060samples/kurrentdb/Bookings/Application/BookingsCommandService.cs:18\u0060 it runs out through the closing brace of the declaration holding it and carries on into the declaration that follows \u2014 the window is the tail of one member plus the head of the next, so no call can be substituted for those exact lines, and the smallest declaration that contains all of them is the type they sit in. The repeated unit is the member each site sits in: where those members\u0027 bodies are the same, move one whole member to the shared location and have the others delegate to it; where the copies are a run of near-identical overloads or wrappers that differ only in their signatures, the repetition IS the run \u2014 a one-line delegation has no helper inside it to lift \u2014 so generate the run from the set it enumerates, or accept it and keep each member\u0027s own documentation with it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"samples/kurrentdb/Bookings/Application/BookingsCommandService.cs"},"region":{"startLine":18}}}],"partialFingerprints":{"codehealthFindingId/v1":"aaf792e513c0edda8b79ddb1448b5ff1c701583dd8d0839d900b5e47cb9bcedd"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9\u201311 lines \u00D7 2): samples/kurrentdb/Bookings/Registrations.cs:32-40 | samples/postgres/Bookings/Registrations.cs:31-41 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"samples/kurrentdb/Bookings/Registrations.cs"},"region":{"startLine":32}}}],"partialFingerprints":{"codehealthFindingId/v1":"458585d4a9e283dcdc23cb42e877fd5d09d31658836f2d92a268204b81732dd4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): samples/kurrentdb/Bookings/Integration/Payments.cs:14-20 | samples/postgres/Bookings/Integration/Payments.cs:14-29 \u2014 before extracting anything, compare \u0060samples/kurrentdb/Bookings/Integration/Payments.cs\u0060 and \u0060samples/postgres/Bookings/Integration/Payments.cs\u0060 as WHOLE FILES: 88% of the shorter file\u0027s lines also appear in the other, so this reads as one file having been copied from the other rather than as a helper waiting to be extracted. The 1 duplicated block(s) this scan matched between them are fragments of that copy, not the extent of it \u2014 treat the file pair as the unit. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"samples/kurrentdb/Bookings/Integration/Payments.cs"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"a35d581bbf53e8d69a9a16c5664ab445bad6b3f176a7a3c29e93faff59c23c28"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): samples/kurrentdb/Bookings/HttpApi/Bookings/QueryApi.cs:13-17 | samples/postgres/Bookings/HttpApi/Bookings/QueryApi.cs:13-17 \u2014 before extracting anything, compare \u0060samples/kurrentdb/Bookings/HttpApi/Bookings/QueryApi.cs\u0060 and \u0060samples/postgres/Bookings/HttpApi/Bookings/QueryApi.cs\u0060 as WHOLE FILES: 91% of the shorter file\u0027s lines also appear in the other, so this reads as one file having been copied from the other rather than as a helper waiting to be extracted. The 1 duplicated block(s) this scan matched between them are fragments of that copy, not the extent of it \u2014 treat the file pair as the unit. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"samples/kurrentdb/Bookings/HttpApi/Bookings/QueryApi.cs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"f5e90912f327a6c66c6213ee1d780df895b9535c9c19d25ad8546ab0f46262f1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): samples/postgres/Bookings.Payments/Program.cs:46-51 | samples/postgres/Bookings/Program.cs:50-55 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"samples/postgres/Bookings.Payments/Program.cs"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"44a16500a0955bdfb9f8efe9941a9e01af225f9597598deb242bf8f8bdb6bad1"}},{"ruleId":"D5","level":"error","message":{"text":"Layer violation: Application \u2192 Infrastructure: Eventuous.Application (Application) references Eventuous.Persistence (Infrastructure) \u2014 dependencies must point inward (Web \u2192 Application \u2192 Domain; Infrastructure implements inner interfaces, nothing depends outward on it)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e27aca6f791fcbe2465e67f515025cce032234649858060654062cf706cdb54c"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: Eventuous.Diagnostics.Logging(net10.0): Eventuous.Diagnostics.Logging(net10.0): abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and depended on by 5 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"68523abaa9d7ead695773e5281fb2c3dadfd0d7d38cbf85bf5ded66d35449d49"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: Eventuous.TestHelpers.TUnit(net9.0): Eventuous.TestHelpers.TUnit(net9.0): abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and depended on by 3 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"42ba318dc4c26557345d431b5044e2ef89b1a94e0725acc582d9a6ff8f5f7646"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: Eventuous.TestHelpers(net9.0): Eventuous.TestHelpers(net9.0): abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and depended on by 3 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6dce76931e55c6d48ce64cff352739e0ab506df82e47f7f680d41cf043f8e6cb"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: Eventuous.Shared(net10.0): Eventuous.Shared(net10.0): abstractness 0.10, instability 0.03, distance 0.88 \u2014 the shape a shared-kernel / building-block library has BY DESIGN \u2014 concrete and widely depended-on is what makes it useful, and this dimension does not penalise it (the distance is reported for completeness, not as a defect). Worth a look only if it has grown past one coherent kernel into an everything-bucket."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d9fcce9d679e8a877a2c6da8ae05b9dda9597ee389690e724bec48468adf41d1"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: Eventuous.Diagnostics(net10.0): Eventuous.Diagnostics(net10.0): abstractness 0.07, instability 0.06, distance 0.87 \u2014 zone of pain \u2014 concrete and depended on by 32 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"8eb3f9aa210d931d75e703c71ec9c02a1dc652be5d5fe2a504566fda811e3970"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: Eventuous.Extensions.Logging(net10.0): Eventuous.Extensions.Logging(net10.0): abstractness 0.00, instability 0.20, distance 0.80 \u2014 zone of pain \u2014 concrete and depended on by 4 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"2bd3978f8515b6721398a509a90c3a536ae94e0ecba3e5ecd134789354ffbb94"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: AllocationHotspotsBenchmarks (LCOM4 8): AllocationHotspotsBenchmarks\u0027s methods fall into 8 groups that share no field and call none of each other, against a bar of more than 3 for this run (LCOM4, configurable \u2014 your repository\u0027s bar is the one quoted here). Each group is a set of methods reachable from one another through shared fields or direct calls, so 8 groups means the type has that many internally-connected clusters with nothing tying them together. Types whose shape makes a high count expected \u2014 and which would otherwise dominate this list \u2014 are excluded before this row is raised, so this is a genuine split candidate rather than a metric reading. It is still a shape, not a defect: confirm the groups match responsibilities you can name before splitting."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Benchmarks/Benchmarks/AllocationHotspotsBenchmarks.cs"},"region":{"startLine":11}}}],"partialFingerprints":{"codehealthFindingId/v1":"952f83a248a92d91b107ec28978e9a3da1ead4bcfb9bc6aec9a7c9cf8bdbd109"}},{"ruleId":"D10","level":"warning","message":{"text":"No assertions: should_produce_payment_registered: This method\u0027s body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* \u2014 so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as \u0027no assertion this check knows how to see\u0027, and if that is right, add one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/test/Eventuous.Tests/Aggregates/OperateOnExistingSpec.cs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"3f2f8995400e8771673cab67d36c56220d6c68c5063f5845b72316eb4ff7c52b"}},{"ruleId":"D10","level":"warning","message":{"text":"No assertions: should_produce_outstanding_changed: This method\u0027s body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* \u2014 so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as \u0027no assertion this check knows how to see\u0027, and if that is right, add one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/test/Eventuous.Tests/Aggregates/OperateOnExistingSpec.cs"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee5afeb7010f6fce921a4f0fc39bd209902e01ad301a9a94bc5917a7a16b7552"}},{"ruleId":"D10","level":"warning","message":{"text":"No assertions: should_produce_fully_paid_event: This method\u0027s body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* \u2014 so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as \u0027no assertion this check knows how to see\u0027, and if that is right, add one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/test/Eventuous.Tests/Aggregates/TwoAggregateOpsSpec.cs"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"58d4fa20a11c72ea6f8d954d0da836ce592f236780469e43a7dd1cc965b6acbf"}},{"ruleId":"D10","level":"warning","message":{"text":"No assertions: should_produce_payment_registered: This method\u0027s body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* \u2014 so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as \u0027no assertion this check knows how to see\u0027, and if that is right, add one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/test/Eventuous.Tests/Aggregates/TwoAggregateOpsSpec.cs"},"region":{"startLine":23}}}],"partialFingerprints":{"codehealthFindingId/v1":"57da227bf76c967d6c70fda6fd9fd905d3b10ea4a47d85d727f3df2a82145a97"}},{"ruleId":"D10","level":"warning","message":{"text":"No assertions: should_produce_outstanding_changed: This method\u0027s body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* \u2014 so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as \u0027no assertion this check knows how to see\u0027, and if that is right, add one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/test/Eventuous.Tests/Aggregates/TwoAggregateOpsSpec.cs"},"region":{"startLine":26}}}],"partialFingerprints":{"codehealthFindingId/v1":"9560e7c15328622086e5a99108ac2711ddf8e094344961591508209a119a51be"}},{"ruleId":"D10","level":"warning","message":{"text":"No assertions: should_emit_event: This method\u0027s body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* \u2014 so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as \u0027no assertion this check knows how to see\u0027, and if that is right, add one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/test/Eventuous.Tests/AggregateWithId/OperateOnAggregateWithId.cs"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"d68f0539fffd5f1f80b1f66ddb3a3dc0c2b193095f6b9f5f5b40c5240e3b777f"}},{"ruleId":"D10","level":"warning","message":{"text":"No assertions: Test: This method\u0027s body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* \u2014 so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as \u0027no assertion this check knows how to see\u0027, and if that is right, add one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Gateway/test/Eventuous.Tests.Gateway/RegistrationTests.cs"},"region":{"startLine":18}}}],"partialFingerprints":{"codehealthFindingId/v1":"d2ebc4df767f3a50b99634331a4674485444ab05028a13a0c671ccbfaff2e47a"}},{"ruleId":"D10","level":"warning","message":{"text":"No assertions: AppendedEventShouldBeTraced: This method\u0027s body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* \u2014 so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as \u0027no assertion this check knows how to see\u0027, and if that is right, add one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/KurrentDB/test/Eventuous.Tests.KurrentDB/Store/AggregateStoreTests.cs"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"0337f85fd1d9756a0146b0c93eee2e64e9ea59b817343d76602d56fc535e2e94"}},{"ruleId":"D10","level":"warning","message":{"text":"No assertions: Sqlite_ShouldTolerateRepeatedUnsubscribe: This method\u0027s body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* \u2014 so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as \u0027no assertion this check knows how to see\u0027, and if that is right, add one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Sqlite/test/Eventuous.Tests.Sqlite/Subscriptions/SubscriptionRestartTests.cs"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"0f967441454092db1ee7fb8755f788b6386ddfbdd76fd3113426bc66bbb3e124"}},{"ruleId":"D10","level":"warning","message":{"text":"Fixed-sleep synchronisation: Concurrent_commits_all_land: This test starts a background task and then orders itself against it with \u0060Task.Delay(20)\u0060 \u2014 a fixed wait, not a signal that the work is done. Whether it passes depends on how loaded the machine is, which is why a test written this way is green on a developer\u0027s box and random in CI. Wait for the event itself instead: the process\u0027s own exit or output, a completion handle, or a condition polled to a timeout."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/test/Eventuous.Tests.Subscriptions/CheckpointCommitHandlerLifecycleTests.cs"},"region":{"startLine":104}}}],"partialFingerprints":{"codehealthFindingId/v1":"8ebf26667b9435f394fce41755b776060dc3eb9b71a7cae8c248991e3679835e"}},{"ruleId":"D10","level":"warning","message":{"text":"Fixed-sleep synchronisation: LiveEvents_DeliveredAfterSubscribe: This test starts a background task and then orders itself against it with \u0060Task.Delay(1000)\u0060 \u2014 a fixed wait, not a signal that the work is done. Whether it passes depends on how loaded the machine is, which is why a test written this way is green on a developer\u0027s box and random in CI. Wait for the event itself instead: the process\u0027s own exit or output, a completion handle, or a condition polled to a timeout."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/SignalR/test/Eventuous.Tests.SignalR.Integration/SignalREndToEndTests.cs"},"region":{"startLine":169}}}],"partialFingerprints":{"codehealthFindingId/v1":"289276eb535697ca0565fed1b3d4ca2215a1ed3d099594d6dbd6c1bcd5debaf3"}},{"ruleId":"D10","level":"warning","message":{"text":"Fixed-sleep synchronisation: SubscribeAsync_CreatesSubscriptionViaFactory: This test starts a background task and then orders itself against it with \u0060Task.Delay(50)\u0060 \u2014 a fixed wait, not a signal that the work is done. Whether it passes depends on how loaded the machine is, which is why a test written this way is green on a developer\u0027s box and random in CI. Wait for the event itself instead: the process\u0027s own exit or output, a completion handle, or a condition polled to a timeout."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/SignalR/test/Eventuous.Tests.SignalR/SubscriptionGatewayTests.cs"},"region":{"startLine":56}}}],"partialFingerprints":{"codehealthFindingId/v1":"43288c36d02b785b416b9e0e91f14ba5381c41474b9b9eea7d10ef3a6b9a1496"}},{"ruleId":"D10","level":"warning","message":{"text":"Fixed-sleep synchronisation: UnsubscribeAsync_RemovesSubscription: This test starts a background task and then orders itself against it with \u0060Task.Delay(50)\u0060 \u2014 a fixed wait, not a signal that the work is done. Whether it passes depends on how loaded the machine is, which is why a test written this way is green on a developer\u0027s box and random in CI. Wait for the event itself instead: the process\u0027s own exit or output, a completion handle, or a condition polled to a timeout."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/SignalR/test/Eventuous.Tests.SignalR/SubscriptionGatewayTests.cs"},"region":{"startLine":66}}}],"partialFingerprints":{"codehealthFindingId/v1":"736f986c97fbf4d9dff0c9c2332eb71ae5b30ad71de48a659120d8cf935830f4"}},{"ruleId":"D10","level":"warning","message":{"text":"Fixed-sleep synchronisation: RemoveConnectionAsync_CleansUpAllSubscriptions: This test starts a background task and then orders itself against it with \u0060Task.Delay(50)\u0060 \u2014 a fixed wait, not a signal that the work is done. Whether it passes depends on how loaded the machine is, which is why a test written this way is green on a developer\u0027s box and random in CI. Wait for the event itself instead: the process\u0027s own exit or output, a completion handle, or a condition polled to a timeout."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/SignalR/test/Eventuous.Tests.SignalR/SubscriptionGatewayTests.cs"},"region":{"startLine":80}}}],"partialFingerprints":{"codehealthFindingId/v1":"63192e86f6098b0d5838b86dc59f295ae86c18ca17fd853c8c75384350acc5f9"}},{"ruleId":"D10","level":"warning","message":{"text":"Fixed-sleep synchronisation: DuplicateSubscribe_ReplacesPrevious: This test starts a background task and then orders itself against it with \u0060Task.Delay(50)\u0060 \u2014 a fixed wait, not a signal that the work is done. Whether it passes depends on how loaded the machine is, which is why a test written this way is green on a developer\u0027s box and random in CI. Wait for the event itself instead: the process\u0027s own exit or output, a completion handle, or a condition polled to a timeout."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/SignalR/test/Eventuous.Tests.SignalR/SubscriptionGatewayTests.cs"},"region":{"startLine":102}}}],"partialFingerprints":{"codehealthFindingId/v1":"c20026b8c4a81a8b738a7babfcc50170d97272ffcbcbd0da9ba6e30e3470490e"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: NEST: NEST 7.17.5 \u2014 Legacy \u2014 the publisher\u0027s replacement is \u0060Elastic.Clients.Elasticsearch\u0060; migrate the reference to it."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c16244640cacd2907e225a4f5357c75a96c1d619e959af529e5aa5db74147e5f"}},{"ruleId":"D12","level":"warning","message":{"text":"Prerelease dependency: OpenTelemetry.Exporter.Prometheus.AspNetCore: OpenTelemetry.Exporter.Prometheus.AspNetCore resolves to 1.15.3-beta.1, a prerelease build. Prerelease packages carry no support policy, may change breaking between previews and can be unlisted \u2014 pin a stable release before shipping, or record the reason this preview is required."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"374a942dab3621b8f5d661aa15ff3ab19650b896e978375b911ad7a29c15a9ba"}},{"ruleId":"D12","level":"warning","message":{"text":"Prerelease dependency: OpenTelemetry.Instrumentation.GrpcNetClient: OpenTelemetry.Instrumentation.GrpcNetClient resolves to 1.15.1-beta.1, a prerelease build. Prerelease packages carry no support policy, may change breaking between previews and can be unlisted \u2014 pin a stable release before shipping, or record the reason this preview is required."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a7ba92ae84f0c8618628bb29e6420de71d2b94485fdd4f537f5333848a1fb7f1"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/Relational/src/Eventuous.Sql.Base/Subscriptions/SqlSubscriptionBase.cs: src/Relational/src/Eventuous.Sql.Base/Subscriptions/SqlSubscriptionBase.cs changed 5 times in last 90 days, max cyclomatic complexity 17 in SqlSubscriptionBase.Poll at line 82. 4 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-22..2026-09-20, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-22 15:50:06 \u002B02:00\u0027 --until=\u00272026-09-20 15:50:06 \u002B02:00\u0027 --full-history --no-merges -- src/Relational/src/Eventuous.Sql.Base/Subscriptions/SqlSubscriptionBase.cs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Relational/src/Eventuous.Sql.Base/Subscriptions/SqlSubscriptionBase.cs"},"region":{"startLine":82}}}],"partialFingerprints":{"codehealthFindingId/v1":"807fd06ea7a075906f886c597a8d341f3271fe9013e08b5549aac69bc90555ed"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/Core/src/Eventuous.Subscriptions/EventSubscription.cs: src/Core/src/Eventuous.Subscriptions/EventSubscription.cs changed 5 times in last 90 days, max cyclomatic complexity 15 in EventSubscription.Handler at line 232. 3 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-22..2026-09-20, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-22 15:50:06 \u002B02:00\u0027 --until=\u00272026-09-20 15:50:06 \u002B02:00\u0027 --full-history --no-merges -- src/Core/src/Eventuous.Subscriptions/EventSubscription.cs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Subscriptions/EventSubscription.cs"},"region":{"startLine":232}}}],"partialFingerprints":{"codehealthFindingId/v1":"089287d12678901006d89e3a467917d9b353d0bbdecaa4ce4c975daf444f1f92"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/Core/gen/Eventuous.Shared.Generators/EventUsageAnalyzer.cs: src/Core/gen/Eventuous.Shared.Generators/EventUsageAnalyzer.cs changed 2 times in last 90 days, max cyclomatic complexity 30 in EventUsageAnalyzer.AnalyzeInvocation at line 118. 1 of those changes was a fix/bug commit, and the other 1 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-22..2026-09-20, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-22 15:50:06 \u002B02:00\u0027 --until=\u00272026-09-20 15:50:06 \u002B02:00\u0027 --full-history --no-merges -- src/Core/gen/Eventuous.Shared.Generators/EventUsageAnalyzer.cs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/gen/Eventuous.Shared.Generators/EventUsageAnalyzer.cs"},"region":{"startLine":118}}}],"partialFingerprints":{"codehealthFindingId/v1":"1bb2e03dcb446e9b224bd6ceffb13f4a02f3ca1066458cadfb7dc04cd829dbaf"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/Core/gen/Eventuous.Subscriptions.Generators/ConsumeContextConverterGenerator.cs: src/Core/gen/Eventuous.Subscriptions.Generators/ConsumeContextConverterGenerator.cs changed 2 times in last 90 days, max cyclomatic complexity 20 in ConsumeContextConverterGenerator.TransformWithSymbol at line 74. 1 of those changes was a fix/bug commit, and the other 1 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-22..2026-09-20, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-22 15:50:06 \u002B02:00\u0027 --until=\u00272026-09-20 15:50:06 \u002B02:00\u0027 --full-history --no-merges -- src/Core/gen/Eventuous.Subscriptions.Generators/ConsumeContextConverterGenerator.cs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/gen/Eventuous.Subscriptions.Generators/ConsumeContextConverterGenerator.cs"},"region":{"startLine":74}}}],"partialFingerprints":{"codehealthFindingId/v1":"98c01920dd1d1a38a3735bd18130724d39836a95a7fde3d6aa71818e504ad77c"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: src/Core/src/Eventuous.Subscriptions/Channels/ChannelWorkerBase.cs: src/Core/src/Eventuous.Subscriptions/Channels/ChannelWorkerBase.cs changed 4 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 3 (its worst body is ChannelWorkerBase.Write at line 29), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201CFix resubscribe race (#571)\u201D; \u201Cfix(subscriptions): harden the worker dispose failure path (#563)\u201D; \u201Cfix(subscriptions): stop double-dispose crashing host shutdown (#562)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-06-22..2026-09-20, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-22 15:50:06 \u002B02:00\u0027 --until=\u00272026-09-20 15:50:06 \u002B02:00\u0027 --full-history --no-merges -- src/Core/src/Eventuous.Subscriptions/Channels/ChannelWorkerBase.cs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Subscriptions/Channels/ChannelWorkerBase.cs"},"region":{"startLine":29}}}],"partialFingerprints":{"codehealthFindingId/v1":"2bf987d51c298a0aa2e12837d4185c08430f7d35707d80b7b97acd5701acd1a8"}},{"ruleId":"D17","level":"warning","message":{"text":"BareSuppressMessage: SuppressMessage \u2014 the suppression records no reason: either it carries no justification argument at all, or one that states nothing a reader can weigh (\u0022OK\u0022, \u0022By design\u0022). A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited. Write what makes this site legitimately different \u2014 the invariant that holds, the framework contract that forces the shape \u2014 or remove the suppression and fix what it hides."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Azure/test/Eventuous.Tests.Azure.ServiceBus/TestSetup.cs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"7f48da5d30fb13be7e2fc5f8674629a6cdf74d7239774d317ea548e331209930"}},{"ruleId":"D17","level":"warning","message":{"text":"BareSuppressMessage: SuppressMessage \u2014 the suppression records no reason: either it carries no justification argument at all, or one that states nothing a reader can weigh (\u0022OK\u0022, \u0022By design\u0022). A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited. Write what makes this site legitimately different \u2014 the invariant that holds, the framework contract that forces the shape \u2014 or remove the suppression and fix what it hides."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Subscriptions/Logging/Logger.cs"},"region":{"startLine":34}}}],"partialFingerprints":{"codehealthFindingId/v1":"5b18eb13c2701a15e29e7dce7b8d4e23959d4d96304afdc0e21d0a1a8546ce12"}},{"ruleId":"D17","level":"warning","message":{"text":"BareSuppressMessage: SuppressMessage \u2014 the suppression records no reason: either it carries no justification argument at all, or one that states nothing a reader can weigh (\u0022OK\u0022, \u0022By design\u0022). A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited. Write what makes this site legitimately different \u2014 the invariant that holds, the framework contract that forces the shape \u2014 or remove the suppression and fix what it hides."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/test/Eventuous.Tests.Subscriptions.Base/TestSetup.cs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"481ebde708beb03ccf44422bda050a0c1972dc2ec33455a253831872771c0a8a"}},{"ruleId":"D17","level":"warning","message":{"text":"BareSuppressMessage: SuppressMessage \u2014 the suppression records no reason: either it carries no justification argument at all, or one that states nothing a reader can weigh (\u0022OK\u0022, \u0022By design\u0022). A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited. Write what makes this site legitimately different \u2014 the invariant that holds, the framework contract that forces the shape \u2014 or remove the suppression and fix what it hides."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/test/Eventuous.Tests.Subscriptions/DefaultConsumerTests.cs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"c2f34d05c2d37c60f17d2063582bc24a783586b2b826e251b5f58a894a903716"}},{"ruleId":"D17","level":"warning","message":{"text":"BareSuppressMessage: SuppressMessage \u2014 the suppression records no reason: either it carries no justification argument at all, or one that states nothing a reader can weigh (\u0022OK\u0022, \u0022By design\u0022). A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited. Write what makes this site legitimately different \u2014 the invariant that holds, the framework contract that forces the shape \u2014 or remove the suppression and fix what it hides."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/test/Eventuous.Tests.Subscriptions/TestSetup.cs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"01aeb3b406a7c77aa4bdeec5af07061e55f89dca7c88acf7139bca0f948ef39c"}},{"ruleId":"D17","level":"warning","message":{"text":"BareSuppressMessage: SuppressMessage \u2014 the suppression records no reason: either it carries no justification argument at all, or one that states nothing a reader can weigh (\u0022OK\u0022, \u0022By design\u0022). A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited. Write what makes this site legitimately different \u2014 the invariant that holds, the framework contract that forces the shape \u2014 or remove the suppression and fix what it hides."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Gateway/test/Eventuous.Tests.Gateway/TestSetup.cs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"2eb58ed2fbfff8b9fc31dc90c61b1f46421815c1019129a283dd1975a7a5a7a4"}},{"ruleId":"D17","level":"warning","message":{"text":"BareSuppressMessage: SuppressMessage \u2014 the suppression records no reason: either it carries no justification argument at all, or one that states nothing a reader can weigh (\u0022OK\u0022, \u0022By design\u0022). A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited. Write what makes this site legitimately different \u2014 the invariant that holds, the framework contract that forces the shape \u2014 or remove the suppression and fix what it hides."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/SignalR/test/Eventuous.Tests.SignalR.Integration/TestSetup.cs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"44177e961780f9cd3a627ca98659bd1442e1b4c464188f0226ad458d7cde6273"}},{"ruleId":"D17","level":"warning","message":{"text":"BareSuppressMessage: SuppressMessage \u2014 the suppression records no reason: either it carries no justification argument at all, or one that states nothing a reader can weigh (\u0022OK\u0022, \u0022By design\u0022). A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited. Write what makes this site legitimately different \u2014 the invariant that holds, the framework contract that forces the shape \u2014 or remove the suppression and fix what it hides."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/SignalR/test/Eventuous.Tests.SignalR/TestSetup.cs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"84c6cdc58ecc84d434b0d587be9d673d0b4fb617f9ba627be457ca26f8f219be"}},{"ruleId":"D17","level":"error","message":{"text":"FileScopedPragmaDisable: #pragma warning disable CS3019 \u2014 the disable has no matching restore anywhere in this file, so it does not end with the construct that needed it: it runs to the end of the file and silences the rule for everything written below, including code added years later that nobody weighed against it. Close it with the matching restore directive immediately after the construct it covers \u2014 that alone turns a standing exemption into a scoped one \u2014 or fix the cause and drop the directive entirely."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/gen/Eventuous.Shared.Generators/Polyfills/Range.cs"},"region":{"startLine":7}}}],"partialFingerprints":{"codehealthFindingId/v1":"b8402c7ceeea28996f50573df2c0704c8a31c17cc06986d7a0023da976bf5d34"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] OnNewAsync"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Application/AggregateService/CommandService.Async.cs"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"0b9f0486f2c01f0b31fda978d6c02e8a804f658b7448ee766c23860f901021b2"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] OnExistingAsync"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Application/AggregateService/CommandService.Async.cs"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"75720422453dcccfe4f3bc37e7426718c906df89528b4f65c0d4a9e059109c1c"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] OnExistingAsync"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Application/AggregateService/CommandService.Async.cs"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"516372bc3af10ce6658443099b501968c4468d8e0ec6d841bdf8a5fe2785e85f"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] OnAnyAsync"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Application/AggregateService/CommandService.Async.cs"},"region":{"startLine":79}}}],"partialFingerprints":{"codehealthFindingId/v1":"4d101c58f13ca9f8c9bf10afad36c779b234c5f1b7f09a069ba3e807a5566dd7"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] OnAnyAsync"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Application/AggregateService/CommandService.Async.cs"},"region":{"startLine":101}}}],"partialFingerprints":{"codehealthFindingId/v1":"faafb6a4b4a6e80cfe97c0918dc0d738b5d5e217c61ecfd104c4fa3011e0ee23"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] OnNew"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Application/AggregateService/CommandService.Sync.cs"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"144a51af530544c7a893d45b6d2ae97c68cebfc8fbf7217c089f4cdce2df195e"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] OnNew"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Application/FunctionalService/CommandService.cs"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"bd3d6d035568b164212e28f90dd74bbbb2e4ab38e99db8f47f3951adf70cf9a7"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] OnExisting"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Application/AggregateService/CommandService.Sync.cs"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"a6a0e1e079c264505a3a53df09ed3e497dfbafddd11eb57ff268d542f8c6f2bc"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] OnExisting"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Application/FunctionalService/CommandService.cs"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"255697f5c4738824680c9a195e875d61eaeed70dd3a15c0c0afb9547f697f935"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] OnAny"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Application/AggregateService/CommandService.Sync.cs"},"region":{"startLine":56}}}],"partialFingerprints":{"codehealthFindingId/v1":"99aee6b29860ead664061e4b2ef237c93202a695f96e0d9df36264b5859c570e"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] OnAny"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Application/FunctionalService/CommandService.cs"},"region":{"startLine":25}}}],"partialFingerprints":{"codehealthFindingId/v1":"7711dcf0b21ea3ad5c3152aea6fbbf6de7565539cbda7a4120cb30bd5bef8537"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] Load"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Persistence/AggregateStore/AggregateStoreExtensions.cs"},"region":{"startLine":19}}}],"partialFingerprints":{"codehealthFindingId/v1":"f96980bdcadf3d7a61d98d6bacc2feacea441477068a73c05be52717e5ce360d"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] LoadOrNew"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Persistence/AggregateStore/AggregateStoreExtensions.cs"},"region":{"startLine":39}}}],"partialFingerprints":{"codehealthFindingId/v1":"fc7851ee2f2d30cb30fa53911fbb1092617c572bfd15387e0e19ed3713d8cf21"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] LoadOrNew"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Persistence/AggregateStore/IAggregateStore.cs"},"region":{"startLine":76}}}],"partialFingerprints":{"codehealthFindingId/v1":"b47e2f3e987a34a38fbacfd72d0d338947483de0967693cd1c4da620aa116206"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] LoadState"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Persistence/StateStore/IStateStore.cs"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"71b4399e177bfd7dfc41775ad3485de5fc3824872db873b49e8ad8bb15ba26c0"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] LoadState"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Persistence/StateStore/StateStore.cs"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"f701faf9bd2daf55b0fb9372f2e639e6a5688d12283e66be85d122c3d22c4833"}},{"ruleId":"D17","level":"error","message":{"text":"WriteOnlyPrivateField: private IEventSerializer _serializer \u2014 assigned 1 time(s), read never \u2014 this field is written and never read anywhere its type can be reached from, so the state it keeps answers no question: every assignment to it computes a value that nothing observes, on every instance, for the lifetime of each one. It reads as a flag the code branches on, and nothing branches on it. Delete the field and its assignments \u2014 or, if the value was MEANT to be consulted, the missing read is the defect this row is pointing at, and the branch that should have depended on it is not there."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Persistence/StateStore/StateStore.cs"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"ea0b6e0895ef32453d5267a2805ac67be3d9dc3ab0b2292ac95a8552efe12415"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] StateStore"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Persistence/StateStore/StateStore.cs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"f8c646eaea2e2de50e758782f4957f9edcbf5f84d4efb360f7061c1617cd97cc"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] AddEventProducer"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Producers/RegistrationExtensions.cs"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"36484170df457b646448a05c85016bc9a761bbecc2ef6843e3fe4855f5ff21f6"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] AddEventProducer"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Producers/RegistrationExtensions.cs"},"region":{"startLine":36}}}],"partialFingerprints":{"codehealthFindingId/v1":"7e6ba40ad1960d7de0abcebbca7d721e067d1ec54dda11e339ac628a589884d0"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] AddEventProducer"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Producers/RegistrationExtensions.cs"},"region":{"startLine":53}}}],"partialFingerprints":{"codehealthFindingId/v1":"b5493b7360ea2b3849cc50669213ce2d31b60fdbbecdec46f23517b0f3caaf21"}},{"ruleId":"D17","level":"warning","message":{"text":"BarePragmaDisable: #pragma warning disable CS8524 \u2014 the disable is closed again below, so its scope is not the problem; what it records is no reason: there is nothing on the directive line, and no ordinary comment attached to it either side. A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited and it outlives the code it was written for. Put the reason on the directive line \u2014 what makes this site legitimately different \u2014 or fix what the rule is pointing at and delete the pair. A rationale in the member\u0027s documentation comment does not clear this row and is not meant to: it explains the member to its callers, and the next person to touch the suppression is not reading it for that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Subscriptions/EventSubscriptionWithCheckpoint.cs"},"region":{"startLine":44}}}],"partialFingerprints":{"codehealthFindingId/v1":"1ab2dbb818e332087ee34e05646335c40ecf33fad2c60e5ca77149d22038cb6d"}},{"ruleId":"D17","level":"warning","message":{"text":"BarePragmaDisable: #pragma warning disable CA2254 \u2014 the disable is closed again below, so its scope is not the problem; what it records is no reason: there is nothing on the directive line, and no ordinary comment attached to it either side. A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited and it outlives the code it was written for. Put the reason on the directive line \u2014 what makes this site legitimately different \u2014 or fix what the rule is pointing at and delete the pair. A rationale in the member\u0027s documentation comment does not clear this row and is not meant to: it explains the member to its callers, and the next person to touch the suppression is not reading it for that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Subscriptions/Logging/InternalLogger.cs"},"region":{"startLine":11}}}],"partialFingerprints":{"codehealthFindingId/v1":"deddb5dc7fb04f3289fe911e1351594a968b5570d709ed08f0ba6e1c00c385c8"}},{"ruleId":"D17","level":"warning","message":{"text":"BarePragmaDisable: #pragma warning disable CA2254 \u2014 the disable is closed again below, so its scope is not the problem; what it records is no reason: there is nothing on the directive line, and no ordinary comment attached to it either side. A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited and it outlives the code it was written for. Put the reason on the directive line \u2014 what makes this site legitimately different \u2014 or fix what the rule is pointing at and delete the pair. A rationale in the member\u0027s documentation comment does not clear this row and is not meant to: it explains the member to its callers, and the next person to touch the suppression is not reading it for that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Diagnostics/src/Eventuous.Diagnostics.Logging/LoggingEventListener.cs"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"00337b13de0b8becf64a5312d09ee86587ae43694979f955bc5a9f95c88c4950"}},{"ruleId":"D17","level":"warning","message":{"text":"BarePragmaDisable: #pragma warning disable CA2254 \u2014 the disable is closed again below, so its scope is not the problem; what it records is no reason: there is nothing on the directive line, and no ordinary comment attached to it either side. A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited and it outlives the code it was written for. Put the reason on the directive line \u2014 what makes this site legitimately different \u2014 or fix what the rule is pointing at and delete the pair. A rationale in the member\u0027s documentation comment does not clear this row and is not meant to: it explains the member to its callers, and the next person to touch the suppression is not reading it for that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/KurrentDB/src/Eventuous.KurrentDB/KurrentDBEventStore.cs"},"region":{"startLine":286}}}],"partialFingerprints":{"codehealthFindingId/v1":"64eadff54a2dc080e56c4453b47ce7ab3a06ea233d720927f5865ab3ce0ef6b8"}},{"ruleId":"D17","level":"warning","message":{"text":"BarePragmaDisable: #pragma warning disable CA2254 \u2014 the disable is closed again below, so its scope is not the problem; what it records is no reason: there is nothing on the directive line, and no ordinary comment attached to it either side. A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited and it outlives the code it was written for. Put the reason on the directive line \u2014 what makes this site legitimately different \u2014 or fix what the rule is pointing at and delete the pair. A rationale in the member\u0027s documentation comment does not clear this row and is not meant to: it explains the member to its callers, and the next person to touch the suppression is not reading it for that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/KurrentDB/src/Eventuous.KurrentDB/KurrentDBEventStore.cs"},"region":{"startLine":361}}}],"partialFingerprints":{"codehealthFindingId/v1":"6ff3f91310d118d78db2ea484a8576787b80375473d7000de96a091a542208ab"}},{"ruleId":"D17","level":"warning","message":{"text":"BarePragmaDisable: #pragma warning disable CA1822 \u2014 the disable is closed again below, so its scope is not the problem; what it records is no reason: there is nothing on the directive line, and no ordinary comment attached to it either side. A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited and it outlives the code it was written for. Put the reason on the directive line \u2014 what makes this site legitimately different \u2014 or fix what the rule is pointing at and delete the pair. A rationale in the member\u0027s documentation comment does not clear this row and is not meant to: it explains the member to its callers, and the next person to touch the suppression is not reading it for that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/test/Eventuous.Tests.Subscriptions/CompositionHandlerTests.cs"},"region":{"startLine":117}}}],"partialFingerprints":{"codehealthFindingId/v1":"ad58f0d9ccbd560f91a32e3b499f46e7da78c651a2e35c54e2931540a08227b5"}},{"ruleId":"D17","level":"warning","message":{"text":"BarePragmaDisable: #pragma warning disable CA1822 \u2014 the disable is closed again below, so its scope is not the problem; what it records is no reason: there is nothing on the directive line, and no ordinary comment attached to it either side. A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited and it outlives the code it was written for. Put the reason on the directive line \u2014 what makes this site legitimately different \u2014 or fix what the rule is pointing at and delete the pair. A rationale in the member\u0027s documentation comment does not clear this row and is not meant to: it explains the member to its callers, and the next person to touch the suppression is not reading it for that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/KurrentDB/src/Eventuous.KurrentDB/Subscriptions/PersistentSubscriptionBase.cs"},"region":{"startLine":175}}}],"partialFingerprints":{"codehealthFindingId/v1":"4fc30111f0792c2768b5429e7affb2f0dd677e523b6b8b8a50d6c01692530d1c"}},{"ruleId":"D17","level":"warning","message":{"text":"BarePragmaDisable: #pragma warning disable EVTC001 \u2014 the disable is closed again below, so its scope is not the problem; what it records is no reason: there is nothing on the directive line, and no ordinary comment attached to it either side. A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited and it outlives the code it was written for. Put the reason on the directive line \u2014 what makes this site legitimately different \u2014 or fix what the rule is pointing at and delete the pair. A rationale in the member\u0027s documentation comment does not clear this row and is not meant to: it explains the member to its callers, and the next person to touch the suppression is not reading it for that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/test/Eventuous.Tests/ForgotToSetId.cs"},"region":{"startLine":25}}}],"partialFingerprints":{"codehealthFindingId/v1":"6e8195e307ca7a6450e630d0631a6aa34cec63084260c9ee1946d5d6929fcfe7"}},{"ruleId":"D17","level":"warning","message":{"text":"BarePragmaDisable: #pragma warning disable CS8767 \u2014 the disable is closed again below, so its scope is not the problem; what it records is no reason: there is nothing on the directive line, and no ordinary comment attached to it either side. A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited and it outlives the code it was written for. Put the reason on the directive line \u2014 what makes this site legitimately different \u2014 or fix what the rule is pointing at and delete the pair. A rationale in the member\u0027s documentation comment does not clear this row and is not meant to: it explains the member to its callers, and the next person to touch the suppression is not reading it for that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Diagnostics/test/Eventuous.Tests.OpenTelemetry/Fakes/TestExporter.cs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"6904ba810320e11947df2ea5216a661dcc5280f00da13d5995b2aecec22b5bfd"}},{"ruleId":"D17","level":"warning","message":{"text":"CommentedOutCode: 10 consecutive commented-code lines"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Diagnostics/test/Eventuous.Tests.OpenTelemetry/MetricsTests.cs"},"region":{"startLine":25}}}],"partialFingerprints":{"codehealthFindingId/v1":"271db633939593924b449be8d1bdde57dd0bb3d411ebbed9141b1aecbbc6a52f"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] AddEventuousSpyglass"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Experimental/src/Eventuous.Spyglass/RegistrationExtensions.cs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"fbab9dcf096732eb2915d58631f68fd770a6f24464e5f053a5aa9c23cf1a5a0a"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Figure out what to do with it \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Extensions/src/Eventuous.Extensions.AspNetCore/Http/CommandMappingRegistry.cs"},"region":{"startLine":22}}}],"partialFingerprints":{"codehealthFindingId/v1":"0993d9fed7747922271b587fa09a836622da125ac7a2a9b45d674d59c3f82065"}},{"ruleId":"D17","level":"warning","message":{"text":"BarePragmaDisable: #pragma warning disable ASP0027 \u2014 the disable is closed again below, so its scope is not the problem; what it records is no reason: there is nothing on the directive line, and no ordinary comment attached to it either side. A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited and it outlives the code it was written for. Put the reason on the directive line \u2014 what makes this site legitimately different \u2014 or fix what the rule is pointing at and delete the pair. A rationale in the member\u0027s documentation comment does not clear this row and is not meant to: it explains the member to its callers, and the next person to touch the suppression is not reading it for that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Extensions/test/Eventuous.Sut.AspNetCore/Program.cs"},"region":{"startLine":22}}}],"partialFingerprints":{"codehealthFindingId/v1":"064735cdb7a0c356ebafab0f0c02f0f86e163e2c52285a29bb4e9a540706aa18"}},{"ruleId":"D17","level":"warning","message":{"text":"BarePragmaDisable: #pragma warning disable EVTA001 \u2014 the disable is closed again below, so its scope is not the problem; what it records is no reason: there is nothing on the directive line, and no ordinary comment attached to it either side. A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited and it outlives the code it was written for. Put the reason on the directive line \u2014 what makes this site legitimately different \u2014 or fix what the rule is pointing at and delete the pair. A rationale in the member\u0027s documentation comment does not clear this row and is not meant to: it explains the member to its callers, and the next person to touch the suppression is not reading it for that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Extensions/test/Eventuous.Tests.Extensions.AspNetCore/AggregateCommandsTests.cs"},"region":{"startLine":60}}}],"partialFingerprints":{"codehealthFindingId/v1":"63b96fde9d547a34d0dd1dec666f457d4177a37edc8e4f0b716a293f52310150"}},{"ruleId":"D17","level":"warning","message":{"text":"BarePragmaDisable: #pragma warning disable CA2208 \u2014 the disable is closed again below, so its scope is not the problem; what it records is no reason: there is nothing on the directive line, and no ordinary comment attached to it either side. A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited and it outlives the code it was written for. Put the reason on the directive line \u2014 what makes this site legitimately different \u2014 or fix what the rule is pointing at and delete the pair. A rationale in the member\u0027s documentation comment does not clear this row and is not meant to: it explains the member to its callers, and the next person to touch the suppression is not reading it for that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/KurrentDB/src/Eventuous.KurrentDB/Subscriptions/StreamSubscription.cs"},"region":{"startLine":79}}}],"partialFingerprints":{"codehealthFindingId/v1":"6c238013f3d14f466878e5c134f3757f02522cd2c461589fc815a879239243f5"}},{"ruleId":"D17","level":"warning","message":{"text":"CommentedOutCode: 3 consecutive commented-code lines"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/KurrentDB/test/Eventuous.Tests.KurrentDB/Subscriptions/StreamSubscriptionWithLinksTests.cs"},"region":{"startLine":85}}}],"partialFingerprints":{"codehealthFindingId/v1":"d5d70371fade9d63316521e81de1e25e3fd7fcc60fd9fc3a9809320e5089f594"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Make this an option (idempotence based on commit position) \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Mongo/src/Eventuous.Projections.MongoDB/Operations/UpdateBuilder.cs"},"region":{"startLine":28}}}],"partialFingerprints":{"codehealthFindingId/v1":"db6856d5cfe5a0562b789dbe17cdd9c4211f8ecd8a0919ed2d998852daacc23b"}},{"ruleId":"D17","level":"warning","message":{"text":"CommentedOutCode: 4 consecutive commented-code lines"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Mongo/src/Eventuous.Projections.MongoDB/Operations/UpdateBuilder.cs"},"region":{"startLine":29}}}],"partialFingerprints":{"codehealthFindingId/v1":"878995502bc1934a9f61bbb7139acdfbf092946eed056646dd4bd6af02341950"}},{"ruleId":"D17","level":"warning","message":{"text":"BarePragmaDisable: #pragma warning disable TUnit0023 \u2014 the disable is closed again below, so its scope is not the problem; what it records is no reason: there is nothing on the directive line, and no ordinary comment attached to it either side. A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited and it outlives the code it was written for. Put the reason on the directive line \u2014 what makes this site legitimately different \u2014 or fix what the rule is pointing at and delete the pair. A rationale in the member\u0027s documentation comment does not clear this row and is not meant to: it explains the member to its callers, and the next person to touch the suppression is not reading it for that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/RabbitMq/test/Eventuous.Tests.RabbitMq/CustomQueueSubscriptionSpec.cs"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"e5dbd8ad3a83641769700ac35df7956e015c07ecdbfb658b4d31ea20893667a7"}},{"ruleId":"D17","level":"warning","message":{"text":"BarePragmaDisable: #pragma warning disable TUnit0023 \u2014 the disable is closed again below, so its scope is not the problem; what it records is no reason: there is nothing on the directive line, and no ordinary comment attached to it either side. A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited and it outlives the code it was written for. Put the reason on the directive line \u2014 what makes this site legitimately different \u2014 or fix what the rule is pointing at and delete the pair. A rationale in the member\u0027s documentation comment does not clear this row and is not meant to: it explains the member to its callers, and the next person to touch the suppression is not reading it for that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/RabbitMq/test/Eventuous.Tests.RabbitMq/HandlerFailureSpec.cs"},"region":{"startLine":28}}}],"partialFingerprints":{"codehealthFindingId/v1":"c8fc222eeb1ac39081c8f47fe9c6cfc3d3789f702d5298e7dacefc3ffb2314fd"}},{"ruleId":"D17","level":"warning","message":{"text":"BarePragmaDisable: #pragma warning disable TUnit0023 \u2014 the disable is closed again below, so its scope is not the problem; what it records is no reason: there is nothing on the directive line, and no ordinary comment attached to it either side. A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited and it outlives the code it was written for. Put the reason on the directive line \u2014 what makes this site legitimately different \u2014 or fix what the rule is pointing at and delete the pair. A rationale in the member\u0027s documentation comment does not clear this row and is not meant to: it explains the member to its callers, and the next person to touch the suppression is not reading it for that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/RabbitMq/test/Eventuous.Tests.RabbitMq/SubscriptionSpec.cs"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c0f74371092be17d7e3621a375f01b16172e2ac4b2a9523fa3d2872b6607875"}},{"ruleId":"D17","level":"note","message":{"text":"ObsoleteWithoutCallers: [Obsolete] CreateTestAggregateInstanceForAggregateId"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Testing/src/Eventuous.Testing/AggregateFactoryExtensions.cs"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"a420a08cff2435149bcbaad81be5354027728ca9b03b54909484907e0aa940db"}},{"ruleId":"D17","level":"error","message":{"text":"NoWarnInCsproj: CA1822 \u2014 this warning is switched off for the WHOLE project, in every file it builds, including code written years from now: nothing at the call site records that the rule was ever silenced, so the next reader has no reason to look here. Fix what the rule is reporting and drop the code from the list, or \u2014 if some occurrences really are legitimate \u2014 narrow the suppression to those sites and give each one its reason, so the rule keeps protecting the rest of the project."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Sqlite/test/Eventuous.Tests.Sqlite/Eventuous.Tests.Sqlite.csproj"},"region":{"startLine":6}}}],"partialFingerprints":{"codehealthFindingId/v1":"8ea4adfa80e63d5703a15e4720ef83bc212554c31563c8dffce015a975619d14"}},{"ruleId":"D17","level":"error","message":{"text":"NoWarnInCsproj: CA1822 \u2014 this warning is switched off for the WHOLE project, in every file it builds, including code written years from now: nothing at the call site records that the rule was ever silenced, so the next reader has no reason to look here. Fix what the rule is reporting and drop the code from the list, or \u2014 if some occurrences really are legitimate \u2014 narrow the suppression to those sites and give each one its reason, so the rule keeps protecting the rest of the project."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Postgres/test/Eventuous.Tests.Postgres/Eventuous.Tests.Postgres.csproj"},"region":{"startLine":7}}}],"partialFingerprints":{"codehealthFindingId/v1":"2ca62fbc47eaad156f7527fa62f0eb78966af0b7e81ba74e142e83b44c147519"}},{"ruleId":"D17","level":"error","message":{"text":"NoWarnInCsproj: CS8524 \u2014 this warning is switched off for the WHOLE project, in every file it builds, including code written years from now: nothing at the call site records that the rule was ever silenced, so the next reader has no reason to look here. Fix what the rule is reporting and drop the code from the list, or \u2014 if some occurrences really are legitimate \u2014 narrow the suppression to those sites and give each one its reason, so the rule keeps protecting the rest of the project."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Relational/src/Eventuous.Sql.Base/Eventuous.Sql.Base.csproj"},"region":{"startLine":3}}}],"partialFingerprints":{"codehealthFindingId/v1":"48c02b6c088d98e648f13da264d3a3a48969a77f324f3330c91af595b55f887c"}},{"ruleId":"D17","level":"error","message":{"text":"NoWarnInCsproj: CA2254 \u2014 this warning is switched off for the WHOLE project, in every file it builds, including code written years from now: nothing at the call site records that the rule was ever silenced, so the next reader has no reason to look here. Fix what the rule is reporting and drop the code from the list, or \u2014 if some occurrences really are legitimate \u2014 narrow the suppression to those sites and give each one its reason, so the rule keeps protecting the rest of the project."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/KurrentDB/src/Eventuous.KurrentDB/Eventuous.KurrentDB.csproj"},"region":{"startLine":3}}}],"partialFingerprints":{"codehealthFindingId/v1":"5689bef4618c4d0f56ef82c4e0ee55a6cbf277bcdbc0babbbe231dbda31ff74c"}},{"ruleId":"D17","level":"error","message":{"text":"NoWarnInCsproj: CS1591 \u2014 this project generates an XML documentation file as a build output, so its documentation is something it PUBLISHES to whoever consumes the assembly, and this entry switches off a rule whose only job is to report that documentation missing or malformed. The two decisions sit in the same file and the quiet one wins: the documentation this project ships has holes exactly where the rule would have pointed, no build says so, and the people who meet the gap are downstream \u2014 in their editor, at the moment they are trying to use the member. Write the documentation the rule is asking for and drop the code from the list; where only some elements genuinely cannot carry it, narrow the suppression to those sites and give each one its reason, so the rest of the API stays covered. If the documentation was never meant to be consumed, the honest fix is the other line \u2014 stop generating the file, so the project no longer publishes something it is choosing not to check."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Directory.Build.props"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"9bfaeed98051325855d924ee10f99437c9643d2b5db4e11e939ef9af9aff9628"}},{"ruleId":"D17","level":"error","message":{"text":"NoWarnInCsproj: CS0618 \u2014 this warning is switched off for the WHOLE project, in every file it builds, including code written years from now: nothing at the call site records that the rule was ever silenced, so the next reader has no reason to look here. Fix what the rule is reporting and drop the code from the list, or \u2014 if some occurrences really are legitimate \u2014 narrow the suppression to those sites and give each one its reason, so the rule keeps protecting the rest of the project."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Directory.Build.props"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"4492afff11f56b453dc6ae8c42236152bc9d31bce28c497b802417051e39ce2d"}},{"ruleId":"D18","level":"note","message":{"text":"Shell project: Eventuous(net10.0): \u0060Eventuous(net10.0)\u0060 contributes only 0 significant line(s) \u2014 an empty/placeholder project is structural noise. Remove it or fold its contents into a real project."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous/Eventuous.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"804a793d3eab584092e27c9606b686a2b838cbaa6fde9a17fd6b8a2614a7f622"}},{"ruleId":"D18","level":"note","message":{"text":"Thin analysable surface across projects: 1 project(s) carry only a thin slice of real code (e.g. \u0060Eventuous.TestHelpers(net9.0)\u0060 with 39 significant line(s)). The mean analysable-surface weight is 97 %, lowering Solution Shape by about 0.28 point(s). Consolidate thin projects or grow them into substantial, well-scoped assemblies."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"dd0b92fd965c2065080f16843920964ee00f7696ea03d87cdf61aed4cd2c746a"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no installation or build instructions: No build or setup instructions for installing Eventuous from source. Add a short install guide covering how to get the source, restore packages, and any prerequisites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1fa6bfcd5c6ae231d1b8ee99bced50b832d1f61cde9da6cbb533467b879a57db"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no usage examples: Usage is mostly conceptual with no real examples (e.g. how to run the Bookings.Postgres sample). Add a Usage section or inline runnable code for the Bookings.Postgres example, showing how to start Docker Compose and access Swagger."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1355eb4e127a4bc9236772ce1c46f09510aa9286e7a06d1e47f308229df19049"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no contributor guidance: No guidance on contributing (how to run benchmarks, submit PRs). Add a Contributing section covering benchmarking/run/PR process for the Eventuous.Subscriptions benchmarks directory."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"620f29787918fa3406ae55cb63eefa1b50410845435c4e47bda852816aaea084"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found. No recognised ADR directory (\u0060docs/adr/\u0060, \u0060docs/decisions/\u0060, \u0060adr/\u0060, \u0060docs/rfcs/\u0060, an \u0060ADR0001/\u0060 folder, or their siblings) exists anywhere in this tree. What was searched, so you can tell an empty log from a search that missed one: every directory under the tree (build output, dependencies and VCS metadata excepted), for a document that is either any non-index page inside a recognised ADR directory, whatever its name and however deeply nested (\u0060docs/adr/use-postgres.md\u0060, \u0060docs/adr/2024/0001-x.md\u0060); or a file anywhere whose name is ADR-shaped (\u00600001-use-postgres.md\u0060, \u0060adr-012-caching.md\u0060); or, when neither turned anything up, a document carrying the decision-record signature (an \u0022Architecture Decision Record\u0022 heading, or Status / Context / Decision / Consequences as section headings). A decision log that clears none of these \u2014 unnumbered files outside any recognised directory, without those headings \u2014 is not seen by this check and this row is then wrong. If that is your case, say so rather than renaming anything; otherwise, consider recording architectural decisions in \u0060docs/adr/\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D24","level":"note","message":{"text":"redundant comment: \u0022Start Azurite container for blob storage\u0022 \u2014 "},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Azure/test/Eventuous.Tests.Azure.Storage.Blobs/Fixtures/IntegrationFixture.cs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"9df0bfdf15daeb282e3f95b0450ea935bcc6017afa4baf0c00e3fbfeea63f5b8"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d5b8f11381d61a58459ffc7c595fd52d09c03c711894a63a9578043d2338412b"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7c94a78138b4868771f99828efd441bd4974bbae3a5d6df40f62c57ad7e8106c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b17a20ebb7325ba8bf637799f4b60c29a6401eb0de3db5aee678b380140cd3bc"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9123867085669ccd778dab964074ff45f9afffa30cf9088de856c601d1e43327"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6edd4dcd74152cffa7946b4863d331435a6e5ac9fff1d0010c69daa98ab7f25e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1f20ea00b87e6844cb8b55e821928f04169e74cc9cab538318e3a0f73d3b2aae"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"da437c77adf6e6da18ed294f45b71c3b1e1a4a214c7171345bf37016c0b450cd"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4605d90208aa912f686365b6f14debdbcc499c88d697f0cbfb5b0cc49f87e4d2"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4fbc6df3d72864219648f8a5e2a3fe4857d204776cc76785ab693bf45ade35c2"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"abaca134b0077464533bcf611411185fc7fee957917d13ad6a7e0bfe6879ab95"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9c4050c906e8fc4430668aba5fbb8d255570d7cce60b885515d24f0031e79b29"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1cff35a7d8384cc25e4e51005d012e9a4ff4a4e291bb48f02e7fb12b7351ea64"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a8d137fd1dfd90d511e43fe3ac9989d1247f8c8527fe7a0adc8b16c07adb1f66"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fcc53031fa987d6bc5a5b08489e3381c86035392521a66ecd56088c20fcbe155"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c5d4833cee469a8d77934f50c183f4376d648904ecd405f90509411d1d945e4e"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"910d42167a582e34510a5931aec6499e6392e6edce044d10128ca85bc22b127e"},"taxa":[{"id":"CWE-284","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d0f129c38b16a4cdec76248b6fd004c7da567013c35da5be38660cb4bed16e36"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2d442bfc4fb88596509b7eac4378b200dc48c79ea1c3b5caa214cf94aa1dd922"},"taxa":[{"id":"CWE-269","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d96f5937b7b18795d4c969da22b5a29e6b745865e6b88227364404df159d3915"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0c9b7062ff2570529693c7a6c6b3652920b327bf1ddb4553a1781d2ac0dedca7"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0932404e06d3a26ed56f3606257e6fe5a2e6f3d986501ac15d952851a1ed551c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ae7546c31a94d25a8c30a0a9c2734ee86a029884fd5255f2ce212df3a124d6c0"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c98b9b97919003d5f61034eb9b717e6ea89253211b430c2cfcf2ec6aef2c8ab9"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ddffb023fea1d761c248046cbe3f0a45096fa06ede1c0d06b498275bf275d5b2"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bb1b9214288e49708d4fcecf1bc47f713cdc19f70c7fcb29e92bdfcf384aabb3"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9ee3a59773d571d57cd8b85dd66805c1a1f1724525e2cf1476806f4c4261d766"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1352","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5d538696be9048e4d6f4b41d2ced6c6eb7f4ac17852a3da0ba5c92af99918841"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"40d09895564d2bbd2d1bfacc7e86c14815d72bab0cc5ddc6557330f7c35b7adb"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"915e3081575bb24f85dc0757be5b60d736a433d6066c1b77d3169d4b924d89df"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"647b8ae7ffa36d8f3efef0af4010adcc7b84a53b2d799c728cba2e2e42d169bf"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4a72ad95dfebaa32378c4cc080a5e0d2265aef84fe79855814fc63eeac58992d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"62023d2a2d8e9cc9a7153d30904cd98d1a667f053897ea6631b202ae7d358620"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7287ea50ac47cf8786f4bac23ae97a6d0e6b088ea5292096223abee5598f2c0f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"19f9753b1275ccb620c9acc5eead7d36a8c1df84bb60118b2b624e4b7d91251b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d08243e69a8e9c88b4388218a046892fe525ac33f37fc9725a22fea21a429187"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d603a9831ed9acbcea416a521423409d3c3c53544fb6f6d187b6da08a7940e26"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fd66039e6eb0c0c116a9b3c3bc8a316be420228f164daf3076631f811542bd1f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ef686dc5bf9c934096e4c41b8e85fcc1f6f6482eb75431496359c2673f91da22"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2e0666b501e6583a123ee85715159f94e5856347b717272ec2d2028a0b076f7d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"78d27fba2c1d86d261b7fa876dcd231b5daa55655233d73aff68e3520d042419"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e5c00865c6c4f9ab1d5c7b3635363ff83f033c3ef904e7933ee0cf4b5a46a886"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dc0e85c748f117078761ac1fb75a499fefaaecc0be9e906e25035f2f5a46f451"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"095489d4408045682bd533f615820a9f2e421e156ce24fbacaab1d6747e0b543"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4443ed91389f4df1499664cf8174bad373955ef72c9e28a26eb1a44959fe3067"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bcdebdbdf0d262128092837b58d14d6ef2bb6c15dca7a43e1a9505b53f11a9f5"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ef87cc0c8685f1b9b39173f5ae601f7561d8390741702b3136fe209abfd52c35"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"da12d535654bfb0a76c713802ca30e89943b90eb8a3b49ec172ec2e576b1c0b4"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d1fefb771a2ae72ca10fe461e963b230ee6b3d09ac464c6eeb6d16e3118036fb"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"222a85e789c1760c359d1f082f05fa35d4949e33cc5b88792388a610e5dff3ba"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"14bdc37f3c6d6eeaec62d2f88bc44bfb9c7c95d7a5f3ebedf07791b5e01cc4b4"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6ca3ecc77ad6c7e6c314a10362016924c22969164ab0bcdbb7eb4dae163e6ecf"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: EventuousDiagnostics.cs \u2194 MeterProviderBuilderExtensions.cs: \u0060src/Core/src/Eventuous.Diagnostics/EventuousDiagnostics.cs\u0060 and \u0060src/Diagnostics/src/Eventuous.Diagnostics.OpenTelemetry/MeterProviderBuilderExtensions.cs\u0060 change together 55% of the time (6 of the 11 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets). They sit in different directories, but in this ecosystem the namespace is declared in the FILE, not by the folder \u2014 so the two may well share one namespace and reference each other with no import for this pass to see. Read the pair before acting: if one derives from or overrides the other, the dependency is explicit in the type declaration and the co-change is definitional; if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE and the thing to add is a comment saying so; if they simply belong together, co-locate them; if none of these holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 6 shared commits counted here, the most recent 3 are \u0060efb66b3c\u0060 fix(diagnostics): respect sampling regardless of initialization order\u2026; \u00604fc36479\u0060 Fixing metrics (#175); \u0060b6dafe68\u0060 Pre release cleanup (#68) (at that commit the file was still \u0060src/Diagnostics/src/Eventuous.Diagnostics/EventuousDiagnostics.cs\u0060) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Diagnostics/EventuousDiagnostics.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"4e33fa00649134f967a8486ba2306f24d225fbe07c22f62c082f5126512d67bb"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: EventSubscription.cs \u2194 AsyncHandlingFilter.cs: \u0060src/Core/src/Eventuous.Subscriptions/EventSubscription.cs\u0060 and \u0060src/Core/src/Eventuous.Subscriptions/Filters/AsyncHandlingFilter.cs\u0060 change together 54% of the time (7 of the 13 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets). They sit in different directories, but in this ecosystem the namespace is declared in the FILE, not by the folder \u2014 so the two may well share one namespace and reference each other with no import for this pass to see. Read the pair before acting: if one derives from or overrides the other, the dependency is explicit in the type declaration and the co-change is definitional; if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE and the thing to add is a comment saying so; if they simply belong together, co-locate them; if none of these holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 7 shared commits counted here, the most recent 3 are \u006065e358c5\u0060 Optimise structs; \u0060608feda3\u0060 - Fixes remaining logging issues (#143); \u006035cf1f64\u0060 Further trace issue investigation (at that commit the file was still \u0060src/Core/src/Eventuous.Subscriptions/Filters/ConcurrentFilter.cs\u0060) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Subscriptions/EventSubscription.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"65a9a02788e6cb17caa1791f38c3b204e13f038573acecbd7573ba0c94e9f777"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1b213f6eedd4b140d0bc37bdf1496f72811a643f34064f12518b32e9e83bcfc7"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e17f71490e4d120a48b2b2881ab866c93b272bef2febb673a3e8e42b2c288ab"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eb00976a698a5d68999b7ee6d27206fd374e916853e7ff1ead5eed42386f043f"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"90f83b4fa27db32740afe9540c905f3c0499caed87f61049a8a903ecc95b41c3"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0752d0df7434000fcabf1048e2de30a7a1a8b982b3db9a19898c4dec199856b4"}},{"ruleId":"D39","level":"note","message":{"text":"IL efficiency: 5 authored method(s) exceed the IL budget: 5 of 2233 first-party methods compile to oversized IL bodies (\u003E 250 instructions); worst: Eventuous.Extensions.AspNetCore.Generators.HttpCommandMappingGenerator.Execute @ src/Extensions/gen/Eventuous.Extensions.AspNetCore.Generators/HttpCommandMappingGenerator.cs:117, 507 IL instructions; that pulled this dimension to 10.0/10. These bodies are far past the JIT\u0027s inline budget, so splitting them does not make them inlinable \u2014 what moves the number is emitting less: collapsing LINQ chains and closures on hot paths, and interpolation built eagerly where it is only sometimes used."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Extensions/gen/Eventuous.Extensions.AspNetCore.Generators/HttpCommandMappingGenerator.cs"},"region":{"startLine":117}}}],"partialFingerprints":{"codehealthFindingId/v1":"51ec0309790dc34c47cbd205c321d51a2df4052581ffaca01f4afc9928b4dd5f"}},{"ruleId":"AX2","level":"warning","message":{"text":"Stateful singleton: TypeMapper: \u0060TypeMapper\u0060 is a singleton (one shared instance) but mutates instance state outside any lock (_reverseMap, _map; e.g. \u0060_reverseMap\u0060 at line 85)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Shared/TypeMap/TypeMapper.cs"},"region":{"startLine":37}}}],"partialFingerprints":{"codehealthFindingId/v1":"2dac2f0a6b37e1cb35fca0a2324da5f2e90dd945915d23b229463fbf1918abfa"}},{"ruleId":"AX4","level":"error","message":{"text":"Dependency-rule violation: Eventuous.Application (Application) \u2192 Eventuous.Persistence (Infrastructure): \u0060Eventuous.Application\u0060 is a Application project but references \u0060Eventuous.Persistence\u0060, a Infrastructure project. The clean-architecture rule is that dependencies point INWARD \u2014 the domain/application core must not depend on outer layers (infrastructure/web). Invert it: define the abstraction in the inner layer and implement it in the outer one."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f2722fb545794de812cde18311d1c8631726e9fd276bbebe62561063b362091b"}},{"ruleId":"AX6","level":"note","message":{"text":"Fat interface: IBaseConsumeContext (16 members): \u0060IBaseConsumeContext\u0060 declares 16 members: \u0060MessageId\u0060, \u0060MessageType\u0060, \u0060ContentType\u0060, \u0060Stream\u0060, \u0060EventNumber\u0060, \u0060StreamPosition\u0060, \u0060GlobalPosition\u0060, \u0060Created\u0060, \u0060Metadata\u0060, \u0060Items\u0060, \u0060ParentContext\u0060, \u0060HandlingResults\u0060, \u0060CancellationToken\u0060, \u0060Sequence\u0060, \u0060SubscriptionId\u0060, \u0060LogContext\u0060. Counted as the author wrote them \u2014 a property is ONE member and its get/set accessors are not counted separately, and an event counts once. A wide interface forces every implementer and caller to depend on methods they don\u0027t use (the Interface-Segregation \u0027I\u0027 in SOLID). Split it into focused role-interfaces."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Subscriptions/Context/IMessageConsumeContext.cs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"a01ca1b3d000c6dcd31859a26a6e383815ad07eafd0b0f9974b0a843709d6bb6"}},{"ruleId":"DM8","level":"note","message":{"text":"Primitive data clump: [bookingprice, currency, guestid, outstandingamount, prepaidamount, roomid]: The parameters [bookingprice, currency, guestid, outstandingamount, prepaidamount, roomid] travel together across 8 signatures and were confirmed as a coherent concept by the model \u2014 that\u0027s a missing value object. Extracting them into one type (e.g. \u0060Address\u0060, \u0060Money\u0060, \u0060Coordinate\u0060) removes repetition, prevents argument-order mistakes, and gives the concept a home for its rules."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"samples/kurrentdb/Bookings.Domain/Bookings/BookingEvents.cs"},"region":{"startLine":10}}}],"partialFingerprints":{"codehealthFindingId/v1":"bbf0c8b626baaeb0e53c14bda7c1581bcfb493af958b50a58497686507acec63"}},{"ruleId":"DM8","level":"note","message":{"text":"Primitive data clump: [currency, outstanding, paidamount, paidby, paymentid]: The parameters [currency, outstanding, paidamount, paidby, paymentid] travel together across 8 signatures and were confirmed as a coherent concept by the model \u2014 that\u0027s a missing value object. Extracting them into one type (e.g. \u0060Address\u0060, \u0060Money\u0060, \u0060Coordinate\u0060) removes repetition, prevents argument-order mistakes, and gives the concept a home for its rules."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"samples/kurrentdb/Bookings.Domain/Bookings/BookingEvents.cs"},"region":{"startLine":23}}}],"partialFingerprints":{"codehealthFindingId/v1":"acef1e2a61347c74d69afd6a391c6e05222c161005e3ebaba3c884e83a7e51b3"}},{"ruleId":"DM9","level":"note","message":{"text":"Rule about [ErrorCode, Status] decided in 2 places: Azure.RequestFailedException\u0027s [ErrorCode, Status] are judged in Eventuous.Azure.Storage.Blobs.BlobStorageProjector\u003CT\u003E, Eventuous.Azure.Storage.Blobs.BlobStorageProjector\u003CT\u003E.Handler\u003CTEvent\u003E \u2014 the same decision, restated. Every copy is a chance to drift, and copies drift silently because each one looks correct on its own. Move the judgement onto the type that owns the members and let the call sites ask it."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f6d03321190abd45683ac713b1135a7118444d04ccc1e388436676de94e53be1"}},{"ruleId":"DM9","level":"note","message":{"text":"Rule about [Current, Status] decided in 2 places: System.Diagnostics.Activity\u0027s [Current, Status] are judged in Eventuous.Subscriptions.Context.ContextResultExtensions, Eventuous.Subscriptions.Context.ContextResultExtensions.extension(Eventuous.Subscriptions.Context.IBaseConsumeContext) \u2014 the same decision, restated. Every copy is a chance to drift, and copies drift silently because each one looks correct on its own. Move the judgement onto the type that owns the members and let the call sites ask it."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f20c7edaae4a91110ddd92c5823f75014a80001fa157b5a031f230ed91df7e2d"}},{"ruleId":"ED5","level":"warning","message":{"text":"Non-idempotent mutation: Base.TestEventHandler.HandleEvent: \u0060Base.TestEventHandler.HandleEvent\u0060 mutates persistent state (a repository write) with no idempotency guard, and the model confirms a re-run would double-apply it. A retry or at-least-once redelivery means it can run twice \u2014 add an exists/dedup check, an upsert, an idempotency-key/inbox, or a versioned write."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/test/Eventuous.Tests.Subscriptions.Base/Fixtures/TestEventHandler.cs"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"c2aa0d12555996e6050fd5c7fad63d0cc49e13c46b269feef1b666cc429760c9"}},{"ruleId":"GD1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: A shipped member still throws NotImplementedException \u2014 generated scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Kafka/src/Eventuous.Kafka/Subscriptions/KafkaBasicSubscription.cs"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"8fea28d3fa38320fadb1f9f05668c3e588d08c8cfcdb85dd56cb5dd213cdf950"}},{"ruleId":"GD1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: A shipped member still throws NotImplementedException \u2014 generated scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Experimental/src/Eventuous.ElasticSearch/Store/ElasticEventStore.cs"},"region":{"startLine":107}}}],"partialFingerprints":{"codehealthFindingId/v1":"c1c68255a037a88d12507adeb3ae4caba6e65369e69fdc588c7c063868079d4c"}},{"ruleId":"GD1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: A shipped member still throws NotImplementedException \u2014 generated scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Experimental/src/Eventuous.ElasticSearch/Store/ElasticEventStore.cs"},"region":{"startLine":114}}}],"partialFingerprints":{"codehealthFindingId/v1":"122ff5131d9fef994eaaa92635d7bc7e89a6f16378c19cce71bcf172b1df416c"}},{"ruleId":"GD1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: A shipped member still throws NotImplementedException \u2014 generated scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Redis/src/Eventuous.Redis/RedisStore.cs"},"region":{"startLine":93}}}],"partialFingerprints":{"codehealthFindingId/v1":"150ee4a74bab5d395522be4cbbfafc1e56204b8d88ad968b2442c1bd49b1494e"}},{"ruleId":"GD1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: A shipped member still throws NotImplementedException \u2014 generated scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Relational/src/Eventuous.Sql.Base/SqlEventStoreBase.cs"},"region":{"startLine":261}}}],"partialFingerprints":{"codehealthFindingId/v1":"82a958f145480dffbd1e013e1a1472a58fc5b0dab6ad028177e12ae082031ac0"}},{"ruleId":"IC1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: \u0060TruncateStream\u0060 is a shipped member whose whole body throws NotImplementedException \u2014 scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Experimental/src/Eventuous.ElasticSearch/Store/ElasticEventStore.cs"},"region":{"startLine":107}}}],"partialFingerprints":{"codehealthFindingId/v1":"13229d294248d5be51f06aa78b8e6c76f37e5877533dd215bf5543fd8522175f"}},{"ruleId":"IC1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: \u0060DeleteStream\u0060 is a shipped member whose whole body throws NotImplementedException \u2014 scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Experimental/src/Eventuous.ElasticSearch/Store/ElasticEventStore.cs"},"region":{"startLine":114}}}],"partialFingerprints":{"codehealthFindingId/v1":"89c621f764e7f678cd0f60ae3e19cc126847fbedc4c876a6498d0592df4cb6f8"}},{"ruleId":"IC1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: \u0060Connect\u0060 is a shipped member whose whole body throws NotImplementedException \u2014 scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Kafka/src/Eventuous.Kafka/Subscriptions/KafkaBasicSubscription.cs"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"f24f7bcbdefaa888c932e34d15aa5e5b6b24453fdbeb57e0d3ae0d6b47fdadff"}},{"ruleId":"IC1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: \u0060ReadEventsBackwards\u0060 is a shipped member whose whole body throws NotImplementedException \u2014 scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Redis/src/Eventuous.Redis/RedisStore.cs"},"region":{"startLine":93}}}],"partialFingerprints":{"codehealthFindingId/v1":"065add866176c131c4cfe58f0857b6419fdfe590ac46a5370262895304058350"}},{"ruleId":"IC1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: \u0060DeleteStream\u0060 is a shipped member whose whole body throws NotImplementedException \u2014 scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Relational/src/Eventuous.Sql.Base/SqlEventStoreBase.cs"},"region":{"startLine":261}}}],"partialFingerprints":{"codehealthFindingId/v1":"f2ab0f09ef98e61bb1a6cae02fde179afc931df941f37dca2ecea024d186b670"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Subscriptions/Filters/AsyncHandlingFilter.cs"},"region":{"startLine":114}}}],"partialFingerprints":{"codehealthFindingId/v1":"1607948be8b420396b588adc27cd5d96eb0ae3c61bb825279e3295d9c8ae1765"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Subscriptions/Filters/AsyncHandlingFilter.cs"},"region":{"startLine":115}}}],"partialFingerprints":{"codehealthFindingId/v1":"3b4e2433b1c25d82e859fb40e169586d787ee433be22efcf63ff8901fff674de"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Subscriptions/Filters/PartitioningFilter.cs"},"region":{"startLine":37}}}],"partialFingerprints":{"codehealthFindingId/v1":"bdf3771e615636155cfa17214682d79ebbd4a21282cdd24daa81dd8f8f09af1d"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Subscriptions/Registrations/NamedRegistrations.cs"},"region":{"startLine":18}}}],"partialFingerprints":{"codehealthFindingId/v1":"69dff3bc0deee30bcb4ba14343e2b87f03c7cffeaef54ab4354db31b7aa131b8"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Experimental/src/ElasticPlayground/Program.cs"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"9a0b0fc05da4711dae8c00821363899b601c16a44134629f69c150a9df515b8b"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Experimental/src/ElasticPlayground/Program.cs"},"region":{"startLine":32}}}],"partialFingerprints":{"codehealthFindingId/v1":"373be564021ae5e3183ed7b3de22ed38296f9cb170b06b49c7aa39c0452cb49f"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Experimental/src/ElasticPlayground/Program.cs"},"region":{"startLine":34}}}],"partialFingerprints":{"codehealthFindingId/v1":"fce365ccf6a85ad9964652521598828a4b8fe0ef1a513a0074ddbedd4f90a658"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Experimental/src/ElasticPlayground/Program.cs"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"fda5e5c639bba30d3154a5c31c4422d7826a60e56760ed3bd0ae86fc5cbea0ee"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Experimental/src/ElasticPlayground/Program.cs"},"region":{"startLine":37}}}],"partialFingerprints":{"codehealthFindingId/v1":"3da99faa057cfb8006c6c42f90b1b2bff724aa628ec5c6b5c8bfd659f9b9dac9"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Experimental/src/ElasticPlayground/Program.cs"},"region":{"startLine":38}}}],"partialFingerprints":{"codehealthFindingId/v1":"2af96751cb83a41988229195fa92c4f260e1340c9a6a077dc5d0be24795ebacc"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Experimental/src/Eventuous.ElasticSearch/Index/IndexSetup.cs"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"40eee8637af486115af6403aafbbed02b267f50f22fdc61f6058fd2fd74a5dea"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Extensions/src/Eventuous.Extensions.AspNetCore/Http/HttpCommandMapping.cs"},"region":{"startLine":92}}}],"partialFingerprints":{"codehealthFindingId/v1":"5dd5d8c0e199bd4c7cfe04bb17070e908ffe8bfc334800cd5c4b6954ce254b0c"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Gateway/src/Eventuous.Gateway/GatewayProducer.cs"},"region":{"startLine":33}}}],"partialFingerprints":{"codehealthFindingId/v1":"4d0de7320e25f1dd88f63fa3e7dd009efd46036872370eb1c75df576459977d7"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"P12","level":"note","message":{"text":"Sleep-based test synchronization: 75 Task.Delay/Thread.Sleep call(s) in test code synchronize with background work by sleeping \u2014 a known flakiness precursor on slow runners. Prefer polling with a deadline or completion signals."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6a03a2c4f0cdb020131eedb5050e85716d2d15c3e6c049458617ddd83166de9e"}},{"ruleId":"P2","level":"note","message":{"text":"Logging is not universal: Only 29/48 service-like projects use logging (pure contract/DTO projects are excluded \u2014 they have nothing to log). Of those 48, 7 ship a process this repository operates; the rest are libraries their consumer hosts, where the logging decision belongs to the host."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"91a94e21d6d4d0e6a2003f94505b0b02b157176f0b24c4820f3f82b4447a97fe"}},{"ruleId":"P3","level":"note","message":{"text":"No SAST: No static application security testing detected. For this repository\u0027s stack, add CodeQL\u0027s csharp pack, or a .NET security analyzer package (or \u0060semgrep --config=auto\u0060, which runs on any language) as a CI step. What was searched, so you can tell an absence from a miss: the 11095 CI workflow file(s) in this repository, and the scanner and linter configuration checked in beside them. A scan that runs outside CI, one configured in your forge\u0027s web UI rather than in a committed file, or a tool whose name is none of those this check carries, is not seen \u2014 if that is your case the row is wrong, and saying so is more useful than adding a second scanner."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6e54424179c892f03ef2fd003130ac4bd43f39bbf3b1ca0a0143e25acb80ec87"}},{"ruleId":"P4","level":"note","message":{"text":"No rollback/health safety: Deployment is orchestrated by compose, but no service declares a \u0060healthcheck:\u0060 and nothing pins a previous image to fall back to \u2014 the runtime can tell that the container is up, not that it is serving, so a bad release is harder to detect and reverse."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"db6bab8a28a2145f47e5a4e6683cda39d2ba0296c723238e8057da979ae1c706"}},{"ruleId":"P4","level":"note","message":{"text":"No release approval gate: Deployment is automated and no gate that pauses it for a human is DECLARED IN THIS REPOSITORY\u0027S PIPELINE FILES. What was read: every file under \u0060.github/workflows/\u0060, \u0060.forgejo/workflows/\u0060, \u0060.gitea/workflows/\u0060, \u0060.azuredevops/\u0060 and \u0060.azure-pipelines/\u0060, plus \u0060.gitlab-ci*\u0060 and \u0060azure-pipelines*\u0060 \u2014 with comment text stripped, so documenting a gate is not declaring one. What would have counted: GitLab\u0027s \u0060when: manual\u0060, CircleCI\u0027s \u0060type: approval\u0060, an Azure \u0060ManualValidation@\u0060 task or an \u0060approvals:\u0060 block, a Jenkins \u0060input\u0060 step, a \u0060uses:\u0060 step naming an approval action, an \u0060environment:\u0060 paired with \u0060reviewers\u0060 / \u0060required_reviewers\u0060 / \u0060protection\u0060 / \u0060wait-timer\u0060 / \u0060deployment_branch_policy\u0060, a draft-release step, a \u0060workflow_dispatch\u0060 promotion, or a release-event gate. \u2605 What this cannot see, because none of it is a file: a GitHub environment whose required reviewers are configured in repo SETTINGS, a branch protection rule, or an organisation deployment policy \u2014 all of them real, enforced gates that live outside the repository. If yours is one of those, this row is wrong and nothing in the tree could have told us. Otherwise: whatever reaches the release trigger goes to production unreviewed, so a mistaken merge or tag is live before anyone can stop it."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6c11e2dbd483b4b423b95ac61bfcc7af1d55351b28a20d2b1105b31cfe38cc60"}},{"ruleId":"P6","level":"note","message":{"text":"No changelog: No CHANGELOG/HISTORY/RELEASES file \u2014 what shipped when isn\u0027t easy to reconstruct for support or audit. (Versioning/tagging makes releases traceable, but a changelog records the what.)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"dda5aa5aed8cbb292c3ef2b733bc138f614293ae6426c85e98bf31ef330d9415"}},{"ruleId":"PF3","level":"warning","message":{"text":"Sync-over-async blocking: 2 blocking call(s) on async work (.Wait()/.GetAwaiter().GetResult()) \u2014 these waste a thread and can deadlock wherever a synchronization context is in play (a UI thread, or a caller that has one)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"2dedb76432d7d4f359386b5c37564c0f3de368182a77e31aa8af9ba73f9a4def"}},{"ruleId":"S1","level":"note","message":{"text":"No security response headers detected: No Content-Security-Policy / X-Frame-Options / X-Content-Type-Options configuration found \u2014 defense in depth, even when a reverse proxy could set them. (\u22122.0 on this card.)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"bd19c680309417e132c0be93c2002123f0664b42afe6172b1319da65a6a57ba7"}},{"ruleId":"S1","level":"note","message":{"text":"No app-layer HTTPS enforcement detected: No UseHttpsRedirection/UseHsts and no reverse-proxy signal \u2014 transport security is unverified at the app layer. (\u22122.0 on this card.)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"8697c7a8b4c37084f15e81b8ec84d4cf62954730be74a0816d39b2127a21fd9b"}},{"ruleId":"X1","level":"warning","message":{"text":"Sync-over-async (deadlock risk): Blocking on a Task with \u0060.Wait()\u0060/\u0060.GetAwaiter().GetResult()\u0060 can deadlock (and wastes a thread). Prefer awaiting it: make the caller \u0060async\u0060 and \u0060await\u0060 instead. Where a synchronous entry point must stay \u2014 a public sync API you cannot break, or a process entry point that must not return until the work finishes \u2014 the block belongs in ONE documented bridge and never inside code that is already async; and where it already is that bridge, give the wait a TIMEOUT so a hung task fails the call instead of hanging the process."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Kafka/src/Eventuous.Kafka/Producers/KafkaBasicProducer.cs"},"region":{"startLine":75}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7e053b32020b5ada74842067c6bf94bf4e731f034f0392673efc090133c96d7"}},{"ruleId":"X1","level":"warning","message":{"text":"Sync-over-async (deadlock risk): Blocking on a Task with \u0060.Wait()\u0060/\u0060.GetAwaiter().GetResult()\u0060 can deadlock (and wastes a thread). Prefer awaiting it: make the caller \u0060async\u0060 and \u0060await\u0060 instead. Where a synchronous entry point must stay \u2014 a public sync API you cannot break, or a process entry point that must not return until the work finishes \u2014 the block belongs in ONE documented bridge and never inside code that is already async; and where it already is that bridge, give the wait a TIMEOUT so a hung task fails the call instead of hanging the process."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Subscriptions/Diagnostics/SubscriptionMetrics.cs"},"region":{"startLine":115}}}],"partialFingerprints":{"codehealthFindingId/v1":"b473ab91af2c35f1346ed38a02ad087e67bb5676f12321c9785d729394eeb133"}},{"ruleId":"X10","level":"note","message":{"text":"Duplicated predicate: \u0060e.Message.Contains(\u0022Reading is not allowed after reader was completed\u0022) || cancellationToken.IsCancellationRequested\u0060 appears character-identically in 2 files \u2014 src/Redis/src/Eventuous.Redis/RedisStore.cs, src/Redis/src/Eventuous.Redis/Subscriptions/RedisSubscriptionBase.cs. It is one line, so the duplication detector\u0027s token window never sees it; the copies drift when only one is corrected. Give the condition a name and one home."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Redis/src/Eventuous.Redis/RedisStore.cs"},"region":{"startLine":85}}}],"partialFingerprints":{"codehealthFindingId/v1":"750d8b6af57b116d3ad2e822ce04467d4206500c2d6ed470e6c96d2f144c4cfc"}},{"ruleId":"X2","level":"note","message":{"text":"Not all async methods take a CancellationToken: Only 151/194 async methods accept a CancellationToken, so in-flight work can\u0027t be stopped early when the caller gives up \u2014 whatever ends it in your host (shutdown signal, timeout, abandoned request, user cancel). Thread a token through the call chain and honour it at each await and loop; where a method genuinely cannot be interrupted, omitting it is a deliberate choice \u2014 judge against your hosting model."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"bf623a92fb752b336427856888a9b386c434e686662a2cdc1bba21832c0a048c"}},{"ruleId":"X3","level":"warning","message":{"text":"Swallowed exception (caught, then discarded): \u0060catch (Exception)\u0060 takes every exception and records none of it \u2014 the body neither logs it, rethrows it, nor even names it, so the failure is discarded as completely as by an empty catch and only the substituted value survives. Log it through whatever this codebase already uses to report problems, narrow the catch to the exception this call can actually raise, or say in a comment on the catch why the failure genuinely cannot matter."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Diagnostics/Tags/TracingMeta.cs"},"region":{"startLine":30}}}],"partialFingerprints":{"codehealthFindingId/v1":"042c608f2c9672d04a12fa820283dfcb0ea3ba765c1cc2514d7f0a06060c565d"}},{"ruleId":"X5","level":"note","message":{"text":"Null-forgiving operator (\u0060!\u0060) suppressions reduce the NRT score: ~1.2 \u0060!\u0060 suppressions per 1k syntax nodes \u2014 146 suppression(s) across the 117389 syntax node(s) in code where nullable warnings are ENABLED, which is the only code a \u0060!\u0060 can suppress anything in (a \u0060!\u0060 under \u0060#nullable disable\u0060 is inert and is not counted, and its file\u0027s nodes are not in the denominator). Each one tells the compiler to trust you about null, suppressing the very safety NRTs provide."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"93cfe05d4ad8c8c171267603b23dfe289b74842e38edd1b7bfed59cc32bda337"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on parse failure: \u0060GetItem\u0060 falls back to \u0060default\u0060 when \u0060_items.TryGetValue(key, out var value) \u0026\u0026 value is T val\u0060 is false, with no log or throw \u2014 a malformed value silently becomes that default. Log the input or fail validation. If that constant is the correct answer to the test rather than a stand-in for a value that could not be read, this is not a silent default: say so in a comment on the member and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Benchmarks/Benchmarks/ImplementedOptimizationsValidationBenchmarks.cs"},"region":{"startLine":201}}}],"partialFingerprints":{"codehealthFindingId/v1":"f3d547eac89b0512a64e405e55945dec95c954ea02df6573a816bff33e52d2e2"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on parse failure: \u0060GetItem\u0060 falls back to \u0060default\u0060 when \u0060_items.TryGetValue(key, out var value) \u0026\u0026 value is T val\u0060 is false, with no log or throw \u2014 a malformed value silently becomes that default. Log the input or fail validation. If that constant is the correct answer to the test rather than a stand-in for a value that could not be read, this is not a silent default: say so in a comment on the member and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Benchmarks/Benchmarks/OptimizationComparisonBenchmarks.cs"},"region":{"startLine":83}}}],"partialFingerprints":{"codehealthFindingId/v1":"2c823a8daeaac971527dc9f242fc8377c08ae93276375ecf23ac7da6d9f85a47"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on parse failure: \u0060GetString\u0060 falls back to \u0060default\u0060 when \u0060TryGetValue(key, out var value)\u0060 is false, with no log or throw \u2014 a malformed value silently becomes that default. Log the input or fail validation. If that constant is the correct answer to the test rather than a stand-in for a value that could not be read, this is not a silent default: say so in a comment on the member and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Shared/Meta/Metadata.cs"},"region":{"startLine":24}}}],"partialFingerprints":{"codehealthFindingId/v1":"39216d5e08d1db6f7c16d0d3d48805aa644a38cd2f51d7772453b318773483cb"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on parse failure: \u0060Get\u0060 falls back to \u0060default\u0060 when \u0060TryGetValue(key, out var value) \u0026\u0026 value is T v\u0060 is false, with no log or throw \u2014 a malformed value silently becomes that default. Log the input or fail validation. If that constant is the correct answer to the test rather than a stand-in for a value that could not be read, this is not a silent default: say so in a comment on the member and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Core/src/Eventuous.Shared/Meta/Metadata.cs"},"region":{"startLine":26}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7728be46e8c49820cc4d0c702dc95b8edae4ecd1360496ffc58f7000a9c9c72"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on parse failure: \u0060Dump\u0060 falls back to \u0060\u0022Failure\u0022\u0060 when \u0060r.Success\u0060 is false, with no log or throw \u2014 a malformed value silently becomes that default. Log the input or fail validation. If that constant is the correct answer to the test rather than a stand-in for a value that could not be read, this is not a silent default: say so in a comment on the member and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Experimental/src/ElasticPlayground/ResultExtensions.cs"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"ecaf1962d249f2854025c94ccd34944136a01d1c0b4755aa67ec000f70c9adbc"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-1104","guid":"4c918cb5-b2a6-6c55-9963-a44ee464305e","name":"CWE-1104","shortDescription":{"text":"CWE-1104"},"helpUri":"https://cwe.mitre.org/data/definitions/1104.html"},{"id":"CWE-1352","guid":"5257f322-5cfc-6b52-bedd-0b9a526b4c7d","name":"CWE-1352","shortDescription":{"text":"CWE-1352"},"helpUri":"https://cwe.mitre.org/data/definitions/1352.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-269","guid":"70e1f5f6-81e5-4e5a-ba40-b541c3a346e2","name":"CWE-269","shortDescription":{"text":"CWE-269"},"helpUri":"https://cwe.mitre.org/data/definitions/269.html"},{"id":"CWE-284","guid":"ebeb8e27-e906-2455-8dd6-d4d9578d0347","name":"CWE-284","shortDescription":{"text":"CWE-284"},"helpUri":"https://cwe.mitre.org/data/definitions/284.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-522","guid":"71fb233e-ce6a-ae57-9419-ef8373540b09","name":"CWE-522","shortDescription":{"text":"CWE-522"},"helpUri":"https://cwe.mitre.org/data/definitions/522.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-829","guid":"13c33925-97fb-5a5e-b40c-56d328b8a4d7","name":"CWE-829","shortDescription":{"text":"CWE-829"},"helpUri":"https://cwe.mitre.org/data/definitions/829.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":56,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}