{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D22","name":"Internal API Consistency","shortDescription":{"text":"Internal API Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D22"},{"id":"D23","name":"Boundary Type-Coupling","shortDescription":{"text":"Boundary Type-Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D23"},{"id":"D24","name":"Comment Value","shortDescription":{"text":"Comment Value"},"helpUri":"https://codehealth.canine.dev/dimensions/D24"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D33","name":"JS/npm Dependency Vulnerabilities","shortDescription":{"text":"JS/npm Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D33","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D38","name":"OSV Dependency Vulnerabilities","shortDescription":{"text":"OSV Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D38","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}}]}},"results":[{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: Shared: Shared: abstractness 0.07, instability 0.00, distance 0.93 \u2014 the shape a shared-kernel / building-block library has BY DESIGN \u2014 concrete and widely depended-on is what makes it useful, and this dimension does not penalise it (the distance is reported for completeness, not as a defect). Worth a look only if it has grown past one coherent kernel into an everything-bucket."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9a6075584bf1a071b89754c93f688530ad9c449d73224f95d418320ea318e68b"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: Entities: Entities: abstractness 0.13, instability 0.00, distance 0.88 \u2014 zone of pain \u2014 concrete and depended on by 5 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a5a8f368b65cb9adde2b754d4bbcd247f3e13ccb910d7985bd88f8801adbb8fd"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: EmailService: EmailService: abstractness 0.25, instability 0.00, distance 0.75 \u2014 zone of pain \u2014 concrete and depended on by 2 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0fd56e40c731dbd80dd0430eebb3079c0db26da902c53cc1d8f43d6222ca171f"}},{"ruleId":"D8","level":"error","message":{"text":"No automated tests: No automated tests \u2014 no test code was found in this repository. Untested code is the largest single risk to changing it safely."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3132564c6310e5d01a231f252a02d5d2f5a542c0a8fa29a14c89693f1e3df871"}},{"ruleId":"D9","level":"note","message":{"text":"No tests found: No test suite could be collected \u2014 nothing here references a test framework (Vitest, Jest, Mocha, or the runtime\u0027s built-in runner (\u0060node --test\u0060, \u0060bun test\u0060, \u0060deno test\u0060)), so there were no discoverable tests to count. Tests written as plain executables or shell/PowerShell harnesses are not collectible this way and are not scored here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c9bf64cbb5a4ae13d6bcd01fa3bc8d2879d860c73bc67f176ee3c2cecb8adce3"}},{"ruleId":"D19","level":"note","message":{"text":"The README contains only one file, so most of the project\u0027s architecture, contracts, and service references (e.g. Repository, EmailService) are not documented anywhere else.: Create a dedicated documentation directory for each major subsystem (Architecture/Docs markdown files), covering their purpose, interfaces, and usage."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":""},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3466f0f57f858df7887022b67627c25c105316f7ae3528082835a0e5a4afc399"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: QuickStart: QuickStart: 4 % XML-doc coverage (1/26)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"QuickStart/QuickStart/QuickStart.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"9f9276b96e1d173d0e06b5c5b3eac14f5491b7af20dba58437882c4ffbc5bff8"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: Contracts: Contracts: 0 % XML-doc coverage (0/6)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"QuickStart/Contracts/Contracts.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3408eec58b7438f3eca791b7038378e6f70edf5c11635b35c8d5e83971d9e4c7"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: Entities: Entities: 0 % XML-doc coverage (0/49)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"QuickStart/Entities/Entities.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"303da493956bc385d32ece5ebf922ac5bebb70c39849e64e54a2d44b1c76354a"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: LoggerService: LoggerService: 0 % XML-doc coverage (0/6)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"QuickStart/LoggerService/LoggerService.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"8860058241a48c0675d70325a88f829841d3e67aa085386e575c503935f84253"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: QuickStart.Presentation: QuickStart.Presentation: 0 % XML-doc coverage (0/47)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"QuickStart/QuickStart.Presentation/QuickStart.Presentation.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"12e776d7a7c28a09c1a2780557cc8a110c546612e87c92a000d00edccaac79bc"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: Repository: Repository: 0 % XML-doc coverage (0/39)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"QuickStart/Repository/Repository.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"cb2685e0de759e201d4105064ab583958c229c78bae74bf530c2788ded25f2ba"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: Service: Service: 0 % XML-doc coverage (0/47)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"QuickStart/Service/Service.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ceb88c9ac5371279e50554a59b90e223a203475b05ae1bf9d69c35d3d003b2df"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: Service.Contracts: Service.Contracts: 0 % XML-doc coverage (0/7)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"QuickStart/Service.Contracts/Service.Contracts.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"74796d5464cdb1d7fe8afac0fdaf4668f40d9a96168018fb82db6189de0f860c"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: Shared: Shared: 0 % XML-doc coverage (0/99)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"QuickStart/Shared/Shared.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0e8e253b6fa21d2044294c26293c6fcc9b24aef82bfebae17df55972468b5ad3"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: EmailService: EmailService: 0 % XML-doc coverage (0/17)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"QuickStart/EmailService/EmailService.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a3bd0af820ed78a7da3ac81570fc99969cb720fb7caba3944cf7daf7acc123fa"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent use of \u0027Async\u0027 suffix in method names. Some methods use the standard \u0027Async\u0027 suffix (e.g., GetCustomerAsync), while others use the misspelled \u0027Aync\u0027 (e.g., GetAccountsAync).: Rename \u0027GetAccountsAync\u0027 to \u0027GetAccountsAsync\u0027 to match the standard asynchronous method naming convention used elsewhere in the codebase. (symbols: Service.AccountService.GetAccountsAync, Service.CustomerService.GetCustomerAsync, Service.AuditService.GetAuditLogsAsync, Service.CustomerService.GetAllCustomersAsync, Service.AccountService.GetAccountAsync)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"190eb0b71c3873af49362f04610d4439890b0b7907d2d71fbf5ce3c79f60446f"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent naming for update operations. Some methods use \u0027Update\u0027 (e.g., UpdateCustomerAsync), while others use \u0027Update...For...Async\u0027 (e.g., UpdateAccountForCustomerAsync).: Standardize the naming pattern for update methods. Either use \u0027Update[Entity]Async\u0027 or \u0027Update[Entity]For[Context]Async\u0027 consistently across all services. (symbols: Service.CustomerService.UpdateCustomerAsync, Service.AccountService.UpdateAccountForCustomerAsync, Service.CustomerService.UpdateCustomerAsync)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e5e668c349cff5d1517e7a70b357e14541f221d7d92200c9092b7281ee18e99d"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent use of \u0027Async\u0027 suffix for asynchronous methods. Some methods correctly use \u0027Async\u0027 (e.g., CreateCustomerAsync, GetAuditLogsAsync), while others do not (e.g., CreateRole).: Rename \u0027CreateRole\u0027 to \u0027CreateRoleAsync\u0027 to maintain consistency with other asynchronous service methods. (symbols: Service.CustomerService.CreateCustomerAsync, Service.RoleService.CreateRole, Service.AuditService.GetAuditLogsAsync)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c3626e90ef34c6199c27fce042ab765929146920917d5cbb28a057b0f308f68c"}},{"ruleId":"D22","level":"warning","message":{"text":"Inconsistent naming for \u0027get all\u0027 operations. One uses \u0027GetAccountsAync\u0027 (typo in Async) while the other uses \u0027GetAllCustomersAsync\u0027.: Rename \u0027GetAccountsAync\u0027 to \u0027GetAllAccountsAsync\u0027 to match the \u0027GetAll...\u0027 pattern used by CustomerService. (signatures: Task\u003CIEnumerable\u003CAccountDto\u003E\u003E IAccountService.GetAccountsAync | Task\u003CIEnumerable\u003CCustomerDto\u003E\u003E ICustomerService.GetAllCustomersAsync)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"64b00e6c07e25bde784e9ce16d055994d806d4db1169c7277b6f6b4acbc45455"}},{"ruleId":"D22","level":"warning","message":{"text":"Inconsistent naming for delete operations. One uses \u0027Delete...ForCustomer\u0027 while the other uses \u0027Delete...Async\u0027 directly.: Standardize on \u0027Delete\u0027 followed by the resource name, e.g., \u0027DeleteAccountAsync\u0027 and \u0027DeleteCustomerAsync\u0027, removing the redundant \u0027ForCustomer\u0027 qualifier. (signatures: Task IAccountService.DeleteAccountForCustomerAsync | Task ICustomerService.DeleteCustomerAsync)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"341f2b31e47cb95f425092507e3d499072f1e0ec66ce8d6666bbc7a92a4b5fab"}},{"ruleId":"D22","level":"warning","message":{"text":"Inconsistent naming for single-item retrieval. RoleService uses \u0027GetRoleById\u0027 while UserService uses \u0027GetUserById\u0027.: Standardize on \u0027GetById\u0027 or \u0027GetBy...\u0027 pattern. Since \u0027GetAll\u0027 is used elsewhere, \u0027GetById\u0027 is acceptable, but ensure all services use \u0027GetById\u0027 for single item lookups. (signatures: Task\u003CUserRoleDto\u003E IRoleService.GetRoleById(string roleId) | Task\u003CUserDto\u003E IUserService.GetUserById(string userId))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e0a355e2b6935b7be71a9b177ec7eca3ed2927c2d958e6023f1ef96f9ba764b1"}},{"ruleId":"D22","level":"warning","message":{"text":"Inconsistent method signatures for single-item retrieval. AccountService requires both customerId and id, while CustomerService only requires customerId (implying the current user\u0027s context or a different routing strategy).: Align the signature. If the route is /customers/{id}, use GetCustomerAsync(id). If it\u0027s /customers/{customerId}/accounts/{id}, keep the current signature but ensure consistency with other services regarding context parameters. (signatures: Task\u003CAccountDto\u003E IAccountService.GetAccountAsync(Guid customerId, Guid id, bool trackChanges) | Task\u003CCustomerDto\u003E ICustomerService.GetCustomerAsync(Guid customerId, bool trackChanges))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"8f286963ff8fcfcf91e120fb5a09fe7a935238fae25a92635061fbf2bf513bb2"}},{"ruleId":"D23","level":"note","message":{"text":"Bounded contexts not declared: At 2378 LoC across 10 projects the codebase is large and multi-module, so explicit bounded contexts are needed. Name this codebase\u0027s bounded contexts (\u22652 module groups, e.g. per subsystem) so cross-boundary type coupling can be assessed. Declare them in \u0060.codehealth/config.yaml\u0060 at the repository root (create it if absent), mapping each context name to the module-path or namespace prefixes that belong to it \u2014 e.g. \u0060architecture:\u0060 \u2192 \u0060contexts:\u0060 \u2192 \u0060Billing: [\u0022src/billing\u0022, \u0022Acme.Billing\u0022]\u0060, \u0060Catalog: [\u0022src/catalog\u0022, \u0022Acme.Catalog\u0022]\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1c7e276c9c682731f01819ed5378b90ca320cde1b583c90920172911598362b3"}},{"ruleId":"D24","level":"note","message":{"text":"redundant comment: \u0022log an error message or throw an exception, or both.\u0022 \u2014 delete - the \u0027or both\u0027 is already obvious from the code; the comment restates a decision that reads like boilerplate."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"QuickStart/EmailService/EmailSender.cs"},"region":{"startLine":75}}}],"partialFingerprints":{"codehealthFindingId/v1":"6e1d40903f3f8f689feeeea36eb0b95018b803b1d6764d5242dadd4e14fbeb01"}},{"ruleId":"D24","level":"note","message":{"text":"redundant comment: \u0022throw new Exception(\u0022Exception\u0022);\u0022 \u2014 delete - the exception type and message are self-evident, and this line would be flagged as \u0027throw new Exception(...)\u0027 by a naming/structure check."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"QuickStart/QuickStart.Presentation/Controllers/RoleController.cs"},"region":{"startLine":19}}}],"partialFingerprints":{"codehealthFindingId/v1":"c749932cc4414dc2b085123ad58382da46ef03deca34d1b779762dc772beb4e7"}},{"ruleId":"D24","level":"note","message":{"text":"redundant comment: \u0022analysis\u0022 \u2014 delete - restates the Task keyword; no WHY behind it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"QuickStart/Service.Contracts/IAuditService.cs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"2241fbe4d8336f6b4877afd6da0a3fb7370d9f00f1fa84a290991ab19b1e3abe"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0b0509ffd98a0017f5ad93c27f8f92d3c7b7f891bc669600373d435492257597"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bddd3411b03797b70dc6c0a061931ad2063d5cc123010759c8da9bde96974c5a"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b74ed2402a32a3483f0222438e364162079e47e69d6fc647f12c48e4e51634de"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9b1edc6c5709bced9c1610ceea5038d37f22592f9e1b77be60513c55be5f6020"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"232013a63d845603c2a626f52ada8d8ad59691f3c568e940aad78d11f17c4f7b"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d2caf9b5c80e00c41c676365028ab64c62b755afc6698e1f36b48e73de154c0f"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"80be2362a0aacfe00a8164aedf008cc9b3c5563cc99639b97baf91859f2b9485"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bfbde621f26a078c634e4ad61ac2016b508c9bc180646d254d93ca5e7bf8241d"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c7133becd7b1d410d0bf87dfd8e6055b65d66ecc17a8a4aa6c783a4d68af55bb"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f6b113ef51570b4b40f240d9d9f8db036e93f4463f7e198594f46e89843d6e11"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f738ac93aa8072c2096569dcff0c6e116bbafb2381e99aaf34d85d6d7b9bd181"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3bd86b3e583467c095980fbf0a15f614fa04426b7e48563799455ce7e3579b75"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"205d7078da243df954cfe47c75fe76e4a4f28c8d54b45e569b1fb77b22e298e0"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"261fd0fc8679f9aacc4c9438ec7a5eceba4d70551abbf5e5488f84f877a2a5a5"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a97def94b11e43b6d8ac80c4714fd5a26759b4a65229305ad7be044726b78476"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"188b683fde02453b9eb221038cd3102ab354185a4256cb19c82283c27796499c"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"afc004c9e5c9f93623402cb8b559fb9458133864413f1679cbc91d7557cdb8f2"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"59e8df727ddd1e6986e83064cb609d921de7004b7c31c6d5e7b8c520a7a2a61a"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0eec7ba46f47dc18a828546bb5d0e774587773bb083c8d59a755aae2f8a47cae"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bbe9fa7cbc7b10d3a901bf2b87d95ff32c5dbdb93909d0f4c35a8d7ebdcd8b23"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b5d644dae36f91af459c687684afd8b2428ab634279f73206a474c78b3841a03"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dc8abda1486f9b7387454483e33e5735dea369baeb278b57a34ca73bd28f5a38"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7f2d090c0bba9d2854f9ce12ee4c7894921bbb7612fafb7e47228dd6338adc0d"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4d18f07db7ae74c6ab6e90913fffd351b7eee664bb98c6e65e996ad5c6de6569"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"098baefd13594bafebd9144120130f2c3c9b4e6499f70bf9fec8ba020cd78501"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"51c1f1c4fd1344e3f2d13430ee487ea788891e1ef9eda816fab228d1a5bb232d"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"856ac20b5388d4a5d421e37f6236baf7ade9d647f152773ccbed5dc5845251a9"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0496aa1e555284ef2f2ba06d440b121da8c3744d2da6665bc3aff6faed6828f1"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"21740f630bdc7c3d793e2721c8f3bd5a9606663552f211db8dae51e0d5a1ce7a"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fcd408f4053cef38ef69235cdc29fd271cb0860277a2611cd76e794a55ccbd10"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fa68304310df24ec5ddf7fb23075ece8989a5767f0d38e0396d827b8caba9b94"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f77f2b248bd4da245548c872d3bd90fba17afd3c991c763ec1aac76283752413"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bf84d0e350af5e8115a1346099427faa890326a54c901c3c28bc5b227bda5a96"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"10ff37a081dcf678b2ecf2755fc45aba3a574aec94ebe5e4307085dad72e824d"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bf5918bb4603721a15fc6c1869278993028991b57e33ec07dc8cb47cf73ba8c9"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6c41858b8933f3cdc1d7038b683853d235e3264226b9472858da601b1c0e6636"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"99e31ead6679385690ef459d1554703df0c64347b90142fe66dda712a9ed4db3"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"17eed117aa27bc8efb68807515414ec7d261135556460df8a76b08c4093a7cdd"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1dea57d46dbd83423c599a796238dcd5514727967ab5d5da78cc31e354150507"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1b63ef131eb3d88ddbe08ed0126a146c7be8b71b3db962fe3a629db1e4e49fb7"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9883ebe415dff4dbce0098d03e1157e128947b25c6ddc468b3320ef53d2235ff"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b1b9f38a4e50218cec69b958caa7a3b822c4d4ecaec6b6aaf63ac1a14146fcbc"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"69efa0efd146e3d00a98162487c12fc2c5a8e1c6b88b271c668b95054384d817"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1f69e02a18e1a0ccdffdbcd441492527d0c6c682e4c2f395fb61d4a27a0f958e"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fa7e807449f28c2fe646cc7b53d7a212a556d2d5eab9ecf048dd8b70161b362b"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6f7a16bf530aa57b13dbd6c8a37ba72fcf3dfabc4b66b9ed34ec2364ed37d443"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b3067dfa7620732fd4f5b66d93c3a825336885f4abd9fb92e04c9051f16906c3"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9ca67267e5be5bbe9e292aebd39e6b05025e6b21ab776b7b61606b9b3d45f50e"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8771af12192d7b22078f4be6dfe08d9d354adea2715eb1bda17c200dddfeadd8"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e0872554a399a9b564176b190d171fcc2b09494f0425f6b5935b29dac65b63c4"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"96232ce5a39a14639d5c5edd69cc3f5311e4447f65d25ebcb2ba75ee45ef7849"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9feb54aab45c52219cd7f8a21653b60b2c8dbf128b03d5f733b5a47df8d39cab"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bec1fa5831c761cee9db75ebd39bb0cfa74104a1d7f3e2fe85df2d8b23f41253"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"319b4d43f6c267dec0a97c7277cccf53e14c677685646474ac941b75978b21da"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4e20c4ba5c56a7b82a45fc53af39d26bf5240e5019c968f0c68629b8cded37ed"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"397d1d826534ae04711e46f7a6c68e5683b46c28858e94516d555830ff5133ab"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"39b09f2ecd022a0e8210ce006791e641f66e075abe0a398ef81ed6e4ce0b71fb"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e62a7d25977792893874ce16e61453ae554a7742893f692ac8dbc9230f50ec6"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"42850af58b24a7b9deb44663a63c39713899025491617b6b4f47875aea71bfa7"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"946d71211ec0d458d9ac77837817a858a631589c40c05c7140e7acbf63e25a7d"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3a220dec5d51d22fc992df8911ca3a16711f234e4a6db8ad1043e13b91bb433a"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"424ea61f5e78cd18df68860da70808c478942fbcc9106f90c0fc9a05b75550f1"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"af1c27b3af602bb0300d355f4404d72e6e18b120021bd20be2d3531249b3d8c6"}},{"ruleId":"D38","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c9fa43111bb294d03c28cb7c6da6b272bd8ae69493aa877b7db79f5c186e6008"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-829","guid":"13c33925-97fb-5a5e-b40c-56d328b8a4d7","name":"CWE-829","shortDescription":{"text":"CWE-829"},"helpUri":"https://cwe.mitre.org/data/definitions/829.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":64,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}