{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D23","name":"Boundary Type-Coupling","shortDescription":{"text":"Boundary Type-Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D23"},{"id":"D24","name":"Comment Value","shortDescription":{"text":"Comment Value"},"helpUri":"https://codehealth.canine.dev/dimensions/D24"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"}]}},"results":[{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: FBaseApi: FBaseApi: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and heavily depended-on, so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e6fbb5697810e9676a8b3c18ebbae1e7ace0bdb18f663b7b4f16d5c65675ea40"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: FConfig: FConfig: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and heavily depended-on, so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ea8266c96ccba4e70c4c3bce2fb3c3d5b312d8c0facb13ba30e172a7c48ad145"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: FA2: FA2: abstractness 0.00, instability 0.12, distance 0.88 \u2014 zone of pain \u2014 concrete and heavily depended-on, so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a98f8e0e5ea1d08905286a0ce4389e88504fc979ebf6fd0c4463284f391c2a11"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: FA3: FA3: abstractness 0.00, instability 0.12, distance 0.88 \u2014 zone of pain \u2014 concrete and heavily depended-on, so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"55e175860625db5d743a41630c9d89bf26ca17fd819806f7000929460dc5eab2"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: FA4: FA4: abstractness 0.00, instability 0.12, distance 0.88 \u2014 zone of pain \u2014 concrete and heavily depended-on, so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a20e6a3d7fe1cf0cabe6c8f7173f87a352d4f012ab9252fad5bc870827c467be"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: FA1: FA1: abstractness 0.01, instability 0.12, distance 0.87 \u2014 zone of pain \u2014 concrete and heavily depended-on, so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9e1e5e9c4a2e6d48a4e2309f44e174b7779fbe13b42edceec04fc74598509157"}},{"ruleId":"D8","level":"note","message":{"text":"No tests \u2014 template/sample: This repo declares itself a template / kata / sample; tests are deferred to the application built from it, so coverage is not scored here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e5ca94717741d80f619caad143078fae4342c89e6107210846d2f8d1d28343db"}},{"ruleId":"D9","level":"note","message":{"text":"No tests found: No test suite was found in this repository."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c9bf64cbb5a4ae13d6bcd01fa3bc8d2879d860c73bc67f176ee3c2cecb8adce3"}},{"ruleId":"D16","level":"warning","message":{"text":"single-maintainer \u2014 knowledge-concentration (bus factor) risk: single-maintainer \u2014 knowledge-concentration (bus factor) risk (1 author(s) across 369 commit(s) sampled)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b4b49d961df742f0e507f4cc5c8094fb077ba0391a27fd015d18320865187719"}},{"ruleId":"D21","level":"note","message":{"text":"The term \u0027HttpResponseMapper\u0027 is used for classes that appear to handle HTTP responses or mapping, but the naming is inconsistent with the broader codebase which uses \u0027Response\u0027 or \u0027Dto\u0027 for response models. More critically, some mappers implement \u0027Init\u0027 while others implement \u0027Get\u0027, suggesting different responsibilities or patterns for the same concept.: Standardize on \u0027ResponseMapper\u0027 or \u0027ResponseDto\u0027 for all classes handling HTTP response mapping. (symbols: F13.Mapper.HttpResponseMapper, F20.Mapper.HttpResponseMapper.Init(), F12.Mapper.HttpResponseMapper.Init(), F10.Mapper.HttpResponseMapper.Init(), F3.Mapper.HttpResponseMapper.Get(...), F6.Mapper.HttpResponseMapper.Get(...))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9f3696799d7b14f1a205c46bd5dc91d756666f93d1f55b59943f35604e7cdee1"}},{"ruleId":"D21","level":"note","message":{"text":"There is a mix of \u0027AppRequestModel\u0027 and \u0027Request\u0027 for request models. Some modules use \u0027AppRequestModel\u0027 in the Models namespace, while others use \u0027Request\u0027 in the Presentation namespace. This creates confusion about whether these are the same concept.: Standardize on \u0027Request\u0027 for all incoming request models, or consistently use \u0027AppRequestModel\u0027 across all modules. (symbols: F1.Models.AppRequestModel, F2.Models.AppRequestModel, F3.Models.AppRequestModel, F4.Models.AppRequestModel, F5.Models.AppRequestModel, F6.Models.AppRequestModel, F11.Models.AppRequestModel, F12.Models.AppRequestModel, F13.Models.AppRequestModel, F14.Models.AppRequestModel, F15.Models.AppRequestModel, F16.Models.AppRequestModel, F17.Presentation.Request, F18.Models.AppRequestModel, F19.Models.AppRequestModel, F20.Presentation.Request, F20.Presentation.Request)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ab5cbc9660d22470b8c1a7d501b4c9c43153b31bb6811a02447ad4338afd27e6"}},{"ruleId":"D21","level":"note","message":{"text":"Response models are named inconsistently. Some use \u0027AppResponseModel\u0027 in the Models namespace, while others use \u0027Response\u0027 or \u0027BodyDto\u0027 in the Presentation namespace. This suggests a lack of consistent layering or naming convention for response objects.: Standardize on \u0027Response\u0027 or \u0027ResponseDto\u0027 for all outgoing response models, ensuring consistency across modules. (symbols: F1.Models.AppResponseModel, F2.Models.AppResponseModel, F3.Models.AppResponseModel, F4.Models.AppResponseModel, F5.Models.AppResponseModel, F6.Models.AppResponseModel, F7.Models.AppResponseModel, F8.Presentation.Response, F9.Presentation.Response.BodyDto, F10.Models.AppResponseModel, F11.Presentation.Response.BodyDto, F12.Models.AppResponseModel, F13.Models.AppResponseModel, F14.Models.AppResponseModel, F15.Models.AppResponseModel, F18.Models.AppResponseModel, F21.Models.AppResponseModel)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"2e61a2fcb4da039b3ecd0260fb75f7d242594d5cd8dc8be3c5d4f337599ec5d9"}},{"ruleId":"D21","level":"note","message":{"text":"The term \u0027RefreshTokenModel\u0027 is used in multiple modules (F1, F6), but the structure and usage might differ. Additionally, \u0027RefreshToken\u0027 is also used in FConfig.NSwagOption.DocOption.AuthOption.BearerOption.Type, which is a configuration, not a model.: Ensure \u0027RefreshTokenModel\u0027 is consistently used for the domain model, and avoid using \u0027RefreshToken\u0027 for configuration or other non-model entities. (symbols: F1.Models.RefreshTokenModel, F6.Models.RefreshTokenModel, F1.Models.RefreshTokenModel)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4065700527dd40e4449fe9dec3b40d4be6ab6b0aecc833a6fd0df9cba40ffaff"}},{"ruleId":"D21","level":"note","message":{"text":"The \u0027SetStateBag\u0027 filter is implemented in multiple modules (F5, F6, F9, F11, F14, F19, F20) with potentially different implementations. This suggests a lack of shared base class or interface for this common functionality.: Create a shared base class or interface for \u0027SetStateBag\u0027 functionality to ensure consistency and reduce duplication. (symbols: F11.Presentation.Filters.SetStateBag.SetStateBagFilter, F6.Presentation.Filters.SetStateBag.SetStateBagFilter, F9.Presentation.Filters.SetStateBag.SetStateBagFilter, F11.Presentation.Filters.SetStateBag.SetStateBagFilter, F14.Presentation.Filters.SetStateBag, F19.Presentation.Filters.SetStateBag, F5.Presentation.Filters.SetStateBag, F20.Presentation.Filters.SetStateBag)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"eaa86e6bbbe0febafe0bb6d794459d2e7c94f861aeb25eb04b05dabb8577086d"}},{"ruleId":"D23","level":"note","message":{"text":"Bounded contexts not declared: At 11543 LoC spread over 30 projects the codebase is large and multi-module, so explicit bounded contexts are needed. Name this codebase\u0027s bounded contexts (\u22652 module groups, e.g. per subsystem) so cross-boundary type coupling can be assessed. Declare them in \u0060.codehealth/config.yaml\u0060 at the repository root (create it if absent), mapping each context name to the namespace prefixes that belong to it \u2014 e.g. \u0060architecture:\u0060 \u2192 \u0060contexts:\u0060 \u2192 \u0060Billing: [\u0022Acme.Billing\u0022]\u0060, \u0060Catalog: [\u0022Acme.Catalog\u0022]\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1c7e276c9c682731f01819ed5378b90ca320cde1b583c90920172911598362b3"}},{"ruleId":"D34","level":"note","message":{"text":"Dormant codebase: 33 of 34 significant files have no living knowledge \u2014 the codebase as a whole is dormant, not 33 separate risks. Re-engage owners or document before change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4c69f1e54b7dd6fe9029dd02df6ba8f8145b789f2f18dbdaa086c40ded49dba6"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":0,"secretScannerRunsExcluded":0}}}]}