{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D22","name":"Internal API Consistency","shortDescription":{"text":"Internal API Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D22"},{"id":"D23","name":"Boundary Type-Coupling","shortDescription":{"text":"Boundary Type-Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D23"},{"id":"D24","name":"Comment Value","shortDescription":{"text":"Comment Value"},"helpUri":"https://codehealth.canine.dev/dimensions/D24"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D33","name":"JS/npm Dependency Vulnerabilities","shortDescription":{"text":"JS/npm Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D33","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D38","name":"OSV Dependency Vulnerabilities","shortDescription":{"text":"OSV Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D38","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D39","name":"IL Efficiency","shortDescription":{"text":"IL Efficiency"},"helpUri":"https://codehealth.canine.dev/dimensions/D39"}]}},"results":[{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: Todo.Contracts: Todo.Contracts: abstractness 0.00, instability 0.20, distance 0.80 \u2014 zone of pain \u2014 concrete and heavily depended-on, so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d7d9bd25b0434e1d5c9080092dee0f4008e7a1f61f065fcd520f999d1d586a09"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: BaseSpecification (LCOM4 4): BaseSpecification\u0027s methods form 4 groups that share no state and don\u0027t call each other \u2014 a sign it may have several responsibilities. Review whether it splits into focused classes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Framework/Repository/BaseSpecification.cs"},"region":{"startLine":7}}}],"partialFingerprints":{"codehealthFindingId/v1":"9cd819cf139ad9088ccf47b8cd75b03c391190bf2fba499050d820a9bcfa7ee0"}},{"ruleId":"D8","level":"error","message":{"text":"No automated tests: No automated tests \u2014 no test code was found in this repository. Untested code is the largest single risk to changing it safely."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3132564c6310e5d01a231f252a02d5d2f5a542c0a8fa29a14c89693f1e3df871"}},{"ruleId":"D9","level":"note","message":{"text":"No tests found: No test suite was found in this repository."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c9bf64cbb5a4ae13d6bcd01fa3bc8d2879d860c73bc67f176ee3c2cecb8adce3"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.EntityFrameworkCore.SqlServer: Microsoft.EntityFrameworkCore.SqlServer 5.0.4 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1bb48f233190b229ebd5b332fb00e8c5120b49cc5db84ca77e9c40b476415d80"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: EventStore.Client: EventStore.Client 21.2.0 \u2014 Legacy EventStore.Client.Grpc.Streams \u003E= 0.0.0"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7a547aa5c96ec8f0a0722d1a65dfaa1db3d67a36021ec4b877dec496d666b708"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.Extensions.Configuration.Binder: Microsoft.Extensions.Configuration.Binder 5.0.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5427c46a7399a66cba543df3b19ecf3b09281a7cf5f478c9c0110c05f5f88b5e"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.Extensions.DependencyInjection: Microsoft.Extensions.DependencyInjection 5.0.1 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4eaeceb9306993efdfbf1c62712c2a9161c7d7b8c6dae6eb8c525d120feaaaa3"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.Extensions.Configuration: Microsoft.Extensions.Configuration 5.0.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e6e8907a832761edc8cc68ed479980106d09791624fc789e84a0a611ce2fd77d"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.Extensions.Configuration.CommandLine: Microsoft.Extensions.Configuration.CommandLine 5.0.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"2ed62cac485665ab29a2a6a05c917d5857eb0392649404ecca3f33e4af9e690a"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.Extensions.Configuration.EnvironmentVariables: Microsoft.Extensions.Configuration.EnvironmentVariables 5.0.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0a5cb5ad25b6e755792bfebe4cf58a002f37bf64020e17d2dd2f981e92d8c256"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.Extensions.Configuration.Json: Microsoft.Extensions.Configuration.Json 5.0.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"62219dced23cdbad1cd1a2f976df020980c7a5cba70dfeeeccddb341c0281026"}},{"ruleId":"D16","level":"warning","message":{"text":"single-maintainer \u2014 knowledge-concentration (bus factor) risk: single-maintainer \u2014 knowledge-concentration (bus factor) risk (1 author(s) across 60 commit(s) sampled)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b4b49d961df742f0e507f4cc5c8094fb077ba0391a27fd015d18320865187719"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //Todo: add -2 to version as stream current version is -1. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Framework/EventStore/EventRepository.cs"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"aa2d35ada5bbcdf32d97a67585e068652096bd4b67b1438a424856e4eba36e28"}},{"ruleId":"D18","level":"note","message":{"text":"Thin analysable surface across projects: 2 project(s) carry only a thin slice of real code (e.g. \u0060Todo.BackgroundProcessor\u0060 with 36 significant line(s)). The mean analysable-surface weight is 92 %, lowering Solution Shape by about 0.6 point(s). Consolidate thin projects or grow them into substantial, well-scoped assemblies."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"dd0b92fd965c2065080f16843920964ee00f7696ea03d87cdf61aed4cd2c746a"}},{"ruleId":"D19","level":"note","message":{"text":"The configuration guide is real but it does not explain how to run the background processor or connect the web app to the event-store cluster.: Add a one-line note on starting the background processor before the web app and link to the README\u0027s \u0027Start background processor\u0027 section."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Docs/EventStore_Config.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"76f12599b935e396cba22eb157ce4d5889b423edc16c22b105d410a49e0d9560"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found at common paths; consider documenting architectural decisions in Docs/ADL/ or similar."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D21","level":"note","message":{"text":"Typo in type name \u0027TodoItemSpanshot\u0027 (missing \u0027h\u0027 in Snapshot) compared to the correct \u0027TodoItem\u0027.: Rename \u0027TodoItemSpanshot\u0027 to \u0027TodoItemSnapshot\u0027 or similar to fix the typo. (symbols: Property: Todo.Domain.DomainModels.TodoItemSpanshot.IsComplete, Property: Todo.Domain.DomainModels.TodoItem.IsComplete)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c5c1b7ae30aea2e17d7ca4940d5d45c641ab9b727b94eec34da94f285be187e6"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent casing for the same property name: \u0027isPagingEnabled\u0027 (lowercase \u0027i\u0027) vs standard PascalCase \u0027IsPagingEnabled\u0027.: Change to \u0027IsPagingEnabled\u0027 to follow C# property naming conventions. (symbols: Property: Framework.Repository.BaseSpecification\u003CT\u003E.isPagingEnabled, Property: Framework.Repository.ISpecification\u003CT\u003E.isPagingEnabled)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7f117e3f93c74510cf0ff965ba7474442ebfb92d0786dddf5cc9b60530cce251"}},{"ruleId":"D21","level":"note","message":{"text":"Typo in namespace/assembly name \u0027CommandHanders\u0027 and \u0027EventHanders\u0027 (missing \u0027l\u0027 in Handlers).: Rename namespaces/types from \u0027CommandHanders\u0027/\u0027EventHanders\u0027 to \u0027CommandHandlers\u0027/\u0027EventHandlers\u0027. (symbols: Method: Todo.Application.CommandHanders.TodoItemCommandHandler.HandleAsync, Method: Todo.Application.EventHanders.TodoItemEventHandler.HandleAsync)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ce12b451d1f1bf1dfb356d22ee63faf64e1e574adb93eff54619cb52a57e20dd"}},{"ruleId":"D22","level":"warning","message":{"text":"Redundant event types for state transitions. Having separate event types for \u0027MarkedAsComplete\u0027 and \u0027MarkedAsUnComplete\u0027 is inconsistent with the command pattern where \u0027MarkTodoItemAsComplete\u0027 and \u0027MarkTodoItemAsUnComplete\u0027 are distinct commands. However, in an event-sourced or CQRS model, it is often cleaner to have a single \u0027TodoItemStatusChanged\u0027 event with a \u0027Status\u0027 enum, or at least consistent naming. The current naming is slightly verbose but acceptable. A more significant inconsistency is the naming of the commands: \u0027MarkTodoItemAsComplete\u0027 vs \u0027MarkTodoItemAsUnComplete\u0027. The \u0027Un\u0027 prefix is less common than using a \u0027SetStatus\u0027 or \u0027UpdateStatus\u0027 command that handles both states. However, the most glaring issue is the lack of symmetry in the event types: \u0027TodoItemMarkedAsComplete\u0027 and \u0027TodoItemMarkedAsUnComplete\u0027 are parallel, but the command types use \u0027MarkTodoItemAs...\u0027 while the event types use \u0027TodoItemMarkedAs...\u0027. This is a minor naming convention inconsistency between commands and events.: Consider unifying the status change into a single \u0027TodoItemStatusChanged\u0027 event and a \u0027UpdateTodoItemStatus\u0027 command to reduce the number of types and improve consistency. (signatures: TodoItemMarkedAsComplete | TodoItemMarkedAsUnComplete)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"733edc58991ce68896c8ce5f2c992342a995526d2f8e6c8ada9e8a2d553fb023"}},{"ruleId":"D24","level":"note","message":{"text":"misleading comment: \u0022Apply ordering if expressions are set\u0022 \u2014 Fix - the code applies ordering only when expression-based; this comment is false and contradicts the actual logic."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Framework/Repository/SpecificationEvaluator.cs"},"region":{"startLine":26}}}],"partialFingerprints":{"codehealthFindingId/v1":"f7dcafc54f9c67ddb6b766e8fac7f2e1de10ffeeab78abeecf9eec4e80510c1a"}},{"ruleId":"D24","level":"note","message":{"text":"misleading comment: \u0022Register framework service dependecies and\u0022 \u2014 Remove - the comment repeats the container registration boilerplate, not WHY the call exists."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Modules/Todo/Todo.BackgroundProcessor/Program.cs"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"c061bbdfa05f6819ac279ecbb539c35ed1f77a3602f00ddfcd654f308e8842b0"}},{"ruleId":"D24","level":"note","message":{"text":"redundant comment: \u0022Register framework service dependecies and\u0022 \u2014 Delete - boilerplate restating ConfigureServices purpose; no WHY."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Modules/Todo/Todo.BackgroundProcessor/Program.cs"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"8d3590d8f28cec3e7886f5561aabbfe2fc861297f65b72601274ed4fe544f3de"}},{"ruleId":"D27","level":"note","message":{"text":"Scattered collaborators: 91 % of calls cross a namespace and only 45 % of collaborators are co-located \u2014 group each feature\u0027s code into a vertical slice so a call\u0027s collaborators sit together."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5aad4a4530bac3928d3a065a664be89d023ecfc865f9bf79ac05754b3bffe322"}},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b2b015098eb4e572dba2c546a9a022e114ae7318a47b949546f72aa2ade50e1b"},"taxa":[{"id":"CWE-862","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9d671725020f88400e7d8236ca53f63cfe9fc41b297b23a0299c36baad81b7fa"},"taxa":[{"id":"CWE-862","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1f79a595d62add568feda19f54d04fdad0273f072ae213a4e4ad714127a8a2fe"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"30d58bfb3c5b5381b099fe7c7213473404221cdaeb03235cb29287f6c9f0bb44"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"58c61fd9b239c2505b291f9f0b42d311bc1fbae0ccfea9c8d6841fe9eba0ba49"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b96b7173c4377d5bea4d6fd7b52323631c631c44172b743bec6f266c10a4e538"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b636c797e667abc99114d8220722f875ade9271729ede99cfa215fdf96631226"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"486e2d43aa26452cff8350614c638572e2f6b2144e4c21c889261cc491fda68e"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"19438624c5cdcef3d5c1e2851ac580bfbe3d4f14a2b62ebcd99ac2b6622b8ab3"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f279c68f84071f768f46e3141c2a4f2b2892ba451ad501390510048f64b35f49"}},{"ruleId":"D34","level":"note","message":{"text":"Further orphaned files (smaller): 5 of 5 analysed file(s) have no living knowledge left \u2014 their last meaningful change has decayed away, so if one breaks, no one currently understands it. None is large enough to schedule a dedicated read-through on its own, so they are folded into the freshness score rather than raised individually \u2014 largest first: Framework/Registrar/RegistrarService.cs, Framework/Aggregate/AggregateRepository.cs, Modules/Todo/Todo.Domain/DomainModels/TodoItem.cs (and 2 more)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ce861fd78f6935114d3a342cb90ad25870f984e1042954fcbbe27c0e23be3658"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-862","guid":"2d96ecd7-f7f1-7f55-9f3a-43bb5bafdf33","name":"CWE-862","shortDescription":{"text":"CWE-862"},"helpUri":"https://cwe.mitre.org/data/definitions/862.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":10,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}