{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D38","name":"OSV Dependency Vulnerabilities","shortDescription":{"text":"OSV Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D38","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}}]}},"results":[{"ruleId":"D8","level":"error","message":{"text":"No automated tests: No automated tests \u2014 no test code was found in this repository. Untested code is the largest single risk to changing it safely."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3132564c6310e5d01a231f252a02d5d2f5a542c0a8fa29a14c89693f1e3df871"}},{"ruleId":"D9","level":"note","message":{"text":"No tests found: No test suite could be collected \u2014 nothing here references a test framework (the \u0060test\u0060 package (\u0060dart test\u0060 / \u0060flutter test\u0060)), so there were no discoverable tests to count. Tests written as plain executables or shell/PowerShell harnesses are not collectible this way and are not scored here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c9bf64cbb5a4ae13d6bcd01fa3bc8d2879d860c73bc67f176ee3c2cecb8adce3"}},{"ruleId":"D16","level":"warning","message":{"text":"single-maintainer \u2014 knowledge-concentration (bus factor) risk: single-maintainer \u2014 knowledge-concentration (bus factor) risk (1 author(s) across 210 commit(s) sampled)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b4b49d961df742f0e507f4cc5c8094fb077ba0391a27fd015d18320865187719"}},{"ruleId":"D19","level":"note","message":{"text":"The README states it \u0027is under construction\u0027 and ends with a LaunchScreenAssets README, but there is no architecture or design documentation for the app\u0027s core features (quote creation, styling, favorites, sharing) or how they interrelate.: Add an Architecture/Design doc outlining the main components (QuoteForm, QuoteModel, StyleController, FavoritesRepository), their relationships, and a wireframe of the quote-generation flow."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e9c5d4d1089b6410b8a26010c8a464d1f817913a40413a367e554e69b3e9d825"}},{"ruleId":"D34","level":"note","message":{"text":"Further orphaned files (smaller): 18 of 18 analysed file(s) have no living knowledge left \u2014 their last meaningful change has decayed away, so if one breaks, no one currently understands it (counted over production source files of roughly 100 lines or more, excluding tests, vendored, generated and example/demo trees, largest first). None is large enough to earn a read-through of its own, so this row stands in for the per-file rows rather than raising one each \u2014 largest first: lib/features/quote/presentation/widgets/quote_detail_body.dart, lib/config/theme/app_theme/text_theme.dart, lib/config/theme/dimensions.dart (and 15 more). Attach the read to the next change that touches one of them: have a second person review that change, and leave behind a short comment or test recording what the file is for, so the knowledge comes back at the cost of a change you were making anyway."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ce861fd78f6935114d3a342cb90ad25870f984e1042954fcbbe27c0e23be3658"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: bottom_nav_bar_shell.dart \u2194 screens.dart: \u0060lib/config/navigation/bottom_navigation/bottom_nav_bar_shell.dart\u0060 (context config) and \u0060lib/features/quote/presentation/screens/screens.dart\u0060 (context features) sit in DIFFERENT parts of the tree yet change together 50% of the time (6 of the 12 commits that touched the less-changed of the two, renames followed) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/config/navigation/bottom_navigation/bottom_nav_bar_shell.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ea5a5236500ac42ca58634d8b01d83024919f24048d53a8ed23cee4425811da5"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: dimensions.dart \u2194 screens.dart: \u0060lib/config/theme/dimensions.dart\u0060 (context config) and \u0060lib/features/quote/presentation/screens/screens.dart\u0060 (context features) sit in DIFFERENT parts of the tree yet change together 50% of the time (6 of the 12 commits that touched the less-changed of the two, renames followed) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/config/theme/dimensions.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b3bb027990332f0b658b18df3a1a29b6b42f81aaf3ceb373fe2501d24072888e"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: routes.dart \u2194 screens.dart: \u0060lib/config/navigation/routers/routes.dart\u0060 (context config) and \u0060lib/features/quote/presentation/screens/screens.dart\u0060 (context features) sit in DIFFERENT parts of the tree yet change together 50% of the time (6 of the 12 commits that touched the less-changed of the two, renames followed) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/config/navigation/routers/routes.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e8ed7933eddf28f7be56986e2e2f4b6e0f93f377b208c6b8f857766eaa85ac20"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: text_size_selector.dart \u2194 word_spacing_selector.dart: \u0060lib/features/quote/presentation/widgets/quote_settings_widgets/text_size_selector.dart\u0060 and \u0060lib/features/quote/presentation/widgets/quote_settings_widgets/word_spacing_selector.dart\u0060 change together 67% of the time (8 of the 12 commits that touched the less-changed of the two, renames followed) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/features/quote/presentation/widgets/quote_settings_widgets/text_size_selector.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"159577c44c508361a1e34946de03416896e879de2ed0f86cc80d3a15e854a9a1"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: letter_spacing_selector.dart \u2194 text_size_selector.dart: \u0060lib/features/quote/presentation/widgets/quote_settings_widgets/letter_spacing_selector.dart\u0060 and \u0060lib/features/quote/presentation/widgets/quote_settings_widgets/text_size_selector.dart\u0060 change together 67% of the time (8 of the 12 commits that touched the less-changed of the two, renames followed) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/features/quote/presentation/widgets/quote_settings_widgets/letter_spacing_selector.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"fc011371f33e9a77e32111007d55508a937ea9b2719f6b3ac97f68edcd513865"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: letter_spacing_selector.dart \u2194 word_spacing_selector.dart: \u0060lib/features/quote/presentation/widgets/quote_settings_widgets/letter_spacing_selector.dart\u0060 and \u0060lib/features/quote/presentation/widgets/quote_settings_widgets/word_spacing_selector.dart\u0060 change together 67% of the time (8 of the 12 commits that touched the less-changed of the two, renames followed) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/features/quote/presentation/widgets/quote_settings_widgets/letter_spacing_selector.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c0d0abc718c26d3a216ce00a9605119a76d03057fe51999cd98db7904189528d"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: created_by_you_screen.dart \u2194 favorites_screen.dart: \u0060lib/features/quote/presentation/screens/created_by_you_screen.dart\u0060 and \u0060lib/features/quote/presentation/screens/favorites_screen.dart\u0060 change together 61% of the time (11 of the 18 commits that touched the less-changed of the two, renames followed) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/features/quote/presentation/screens/created_by_you_screen.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"79faa8eebded4403875c47dc0b0fb0ddbbc0a526ae83167cecd45727a1dd5bdb"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: text_font_weight_selector.dart \u2194 word_spacing_selector.dart: \u0060lib/features/quote/presentation/widgets/quote_settings_widgets/text_font_weight_selector.dart\u0060 and \u0060lib/features/quote/presentation/widgets/quote_settings_widgets/word_spacing_selector.dart\u0060 change together 58% of the time (7 of the 12 commits that touched the less-changed of the two, renames followed) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/features/quote/presentation/widgets/quote_settings_widgets/text_font_weight_selector.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"50e26310d28e0061b9f7fa6966f720d9f4093353bbd7f4a369de761d68b0ec88"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: text_align_selector.dart \u2194 word_spacing_selector.dart: \u0060lib/features/quote/presentation/widgets/quote_settings_widgets/text_align_selector.dart\u0060 and \u0060lib/features/quote/presentation/widgets/quote_settings_widgets/word_spacing_selector.dart\u0060 change together 58% of the time (7 of the 12 commits that touched the less-changed of the two, renames followed) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/features/quote/presentation/widgets/quote_settings_widgets/text_align_selector.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c96f8dc0a2cb71be674f027e5f43e13b2f08d3776fa9a9c3338e5a5998777c15"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: letter_spacing_selector.dart \u2194 text_font_weight_selector.dart: \u0060lib/features/quote/presentation/widgets/quote_settings_widgets/letter_spacing_selector.dart\u0060 and \u0060lib/features/quote/presentation/widgets/quote_settings_widgets/text_font_weight_selector.dart\u0060 change together 58% of the time (7 of the 12 commits that touched the less-changed of the two, renames followed) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/features/quote/presentation/widgets/quote_settings_widgets/letter_spacing_selector.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0811ca2d66f510e969d3d9674d85e14876f2fbbd98b50c53b6ed56c53adaff56"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":0,"secretScannerRunsExcluded":0}}}]}