{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D22","name":"Internal API Consistency","shortDescription":{"text":"Internal API Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D22"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AX9","name":"CQS / query purity","shortDescription":{"text":"CQS / query purity"},"helpUri":"https://codehealth.canine.dev/dimensions/AX9"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"ES1","name":"Fold determinism","shortDescription":{"text":"Fold determinism"},"helpUri":"https://codehealth.canine.dev/dimensions/ES1"},{"id":"ES2","name":"Immutable events","shortDescription":{"text":"Immutable events"},"helpUri":"https://codehealth.canine.dev/dimensions/ES2"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P10","name":"Library API \u0026 versioning","shortDescription":{"text":"Library API \u0026 versioning"},"helpUri":"https://codehealth.canine.dev/dimensions/P10"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P2","name":"Observability","shortDescription":{"text":"Observability"},"helpUri":"https://codehealth.canine.dev/dimensions/P2"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"P7","name":"Outbound HTTP resilience","shortDescription":{"text":"Outbound HTTP resilience"},"helpUri":"https://codehealth.canine.dev/dimensions/P7"},{"id":"PF1","name":"Benchmark discipline","shortDescription":{"text":"Benchmark discipline"},"helpUri":"https://codehealth.canine.dev/dimensions/PF1"},{"id":"PF3","name":"Async \u0026 latency hygiene","shortDescription":{"text":"Async \u0026 latency hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/PF3"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X32","name":"Type resolved by simple name across every loaded assembly","shortDescription":{"text":"Type resolved by simple name across every loaded assembly"},"helpUri":"https://codehealth.canine.dev/dimensions/X32"},{"id":"X6","name":"Hand-rolled structured-format parsing","shortDescription":{"text":"Hand-rolled structured-format parsing"},"helpUri":"https://codehealth.canine.dev/dimensions/X6"},{"id":"X7","name":"Silent fallback defaults","shortDescription":{"text":"Silent fallback defaults"},"helpUri":"https://codehealth.canine.dev/dimensions/X7"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"Gateway::inbound (cyclomatic 57): Gateway::inbound has cyclomatic complexity 57 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":646}}}],"partialFingerprints":{"codehealthFindingId/v1":"a5efe2fd03e0100e1cd85b462155ae5e6ac7e82049ef5fefa96d8b8c65f841f3"}},{"ruleId":"D1","level":"warning","message":{"text":"Inbound::inbound (cyclomatic 47): Inbound::inbound has cyclomatic complexity 47 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/src/inbound.rs"},"region":{"startLine":80}}}],"partialFingerprints":{"codehealthFindingId/v1":"f340d21bfe51dfa1a09b08c559c5c298dd365181a4179489f211956cd167564d"}},{"ruleId":"D1","level":"warning","message":{"text":"Primary::propose_batch (cyclomatic 43): Primary::propose_batch has cyclomatic complexity 43 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/primary.rs"},"region":{"startLine":455}}}],"partialFingerprints":{"codehealthFindingId/v1":"93e891f0ffead66a79927441bd470a9e56638aed5ebe7fccf237ab667b71b9b2"}},{"ruleId":"D1","level":"warning","message":{"text":"Start::parse_node (cyclomatic 34): Start::parse_node has cyclomatic complexity 34 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/start.rs"},"region":{"startLine":775}}}],"partialFingerprints":{"codehealthFindingId/v1":"886bec20fc1a88b8463a143359cea52e27592d3393f0043936f52ef387ed53a8"}},{"ruleId":"D1","level":"warning","message":{"text":"Primary::start_handlers (cyclomatic 33): Primary::start_handlers has cyclomatic complexity 33 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/primary.rs"},"region":{"startLine":1326}}}],"partialFingerprints":{"codehealthFindingId/v1":"c5a80f71ed103cb267520e841ad6ba8e62dd48935f9f173608b68e0161b1a4a1"}},{"ruleId":"D1","level":"warning","message":{"text":"BFT::commit_leader_certificate (cyclomatic 26): BFT::commit_leader_certificate has cyclomatic complexity 26 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/bft.rs"},"region":{"startLine":595}}}],"partialFingerprints":{"codehealthFindingId/v1":"54b6356828483bdd876f3c2b3b121e37a1c13fcba92abdadc903c15c9589d466"}},{"ruleId":"D1","level":"warning","message":{"text":"Sync::try_sync_storage_with_block (cyclomatic 23): Sync::try_sync_storage_with_block has cyclomatic complexity 23 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/sync/mod.rs"},"region":{"startLine":805}}}],"partialFingerprints":{"codehealthFindingId/v1":"a2c74ab36c8cea08d1e69882ee0872ca015516ea75a3f7822a0a3f1d3c3f73d1"}},{"ruleId":"D1","level":"warning","message":{"text":"Primary::process_batch_propose_from_peer (cyclomatic 22): Primary::process_batch_propose_from_peer has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/primary.rs"},"region":{"startLine":828}}}],"partialFingerprints":{"codehealthFindingId/v1":"8ec1f20f69fd42183747af08642711d8fe74516866cf7be85cc1ad83eb347c93"}},{"ruleId":"D1","level":"warning","message":{"text":"Node::perform_auto_checkpoints (cyclomatic 21): Node::perform_auto_checkpoints has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/node.rs"},"region":{"startLine":379}}}],"partialFingerprints":{"codehealthFindingId/v1":"d26c1a97a235a2afad3764a02b974deb1f305084d2bfd266a48604e874e6f138"}},{"ruleId":"D1","level":"warning","message":{"text":"Gateway::perform_handshake (cyclomatic 20): Gateway::perform_handshake has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":1590}}}],"partialFingerprints":{"codehealthFindingId/v1":"e78c0014a5f4da35d76f997bec2f14d0663e9ba73e9305a27127f31b6f2557da"}},{"ruleId":"D1","level":"warning","message":{"text":"BlockSync::prepare_block_requests (cyclomatic 20): BlockSync::prepare_block_requests has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/block_sync.rs"},"region":{"startLine":973}}}],"partialFingerprints":{"codehealthFindingId/v1":"339e09f37fdd1ebe05782a416e56dbc8d0049e0c00168961fa2cfe40e07d75ef"}},{"ruleId":"D1","level":"warning","message":{"text":"Account::parse (cyclomatic 17): Account::parse has cyclomatic complexity 17 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/account.rs"},"region":{"startLine":114}}}],"partialFingerprints":{"codehealthFindingId/v1":"d28d98956a989158a7aa9787f14e172f340dcae1fcf2f6aba7061bc92a0aabfa"}},{"ruleId":"D1","level":"warning","message":{"text":"Developer::handle_transaction (cyclomatic 17): Developer::handle_transaction has cyclomatic complexity 17 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/developer/mod.rs"},"region":{"startLine":424}}}],"partialFingerprints":{"codehealthFindingId/v1":"64c08d91c66e048a289edf73d878479cb696e2f1cab21d218b881e39ddaaddde"}},{"ruleId":"D1","level":"warning","message":{"text":"Storage::sync_certificate_with_block (cyclomatic 17): Storage::sync_certificate_with_block has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/helpers/storage.rs"},"region":{"startLine":872}}}],"partialFingerprints":{"codehealthFindingId/v1":"1746e2db68c37ce9b42c59222d608691e8f11e6c1e999e53ae29fba1f0f89f4b"}},{"ruleId":"D1","level":"warning","message":{"text":"Start::parse_development (cyclomatic 16): Start::parse_development has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/start.rs"},"region":{"startLine":533}}}],"partialFingerprints":{"codehealthFindingId/v1":"ab022a3eb954957638daca7d6236b6579d5044f789bc129987011f1def9c4d9e"}},{"ruleId":"D2","level":"warning","message":{"text":"Primary::propose_batch (cognitive 84): Primary::propose_batch has cognitive complexity 84 (threshold 15). Drivers by points: if/else 26 (63 pts), match/switch 4 (10 pts), boolean chains 6, loops 3 (5 pts) (nesting depth added 45). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/primary.rs"},"region":{"startLine":455}}}],"partialFingerprints":{"codehealthFindingId/v1":"e63f5f7b3f7f46fcd40fe8d908112e2a3996b623531bf970eaec71c2f44bfbbd"}},{"ruleId":"D2","level":"warning","message":{"text":"Gateway::inbound (cognitive 70): Gateway::inbound has cognitive complexity 70 (threshold 15). Drivers by points: if/else 25 (50 pts), match/switch 7 (14 pts), loops 2 (4 pts), boolean chains 2 (nesting depth added 34). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":646}}}],"partialFingerprints":{"codehealthFindingId/v1":"0717de5300f03a947b8b851cd68396f10b439eefa1419cb1fb8198097dd4262e"}},{"ruleId":"D2","level":"warning","message":{"text":"Inbound::inbound (cognitive 64): Inbound::inbound has cognitive complexity 64 (threshold 15). Drivers by points: if/else 18 (33 pts), match/switch 16 (30 pts), boolean chains 1 (nesting depth added 29). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/src/inbound.rs"},"region":{"startLine":80}}}],"partialFingerprints":{"codehealthFindingId/v1":"5279d301def0d8787cc708c68857919ad2da4874237c45a4bf42e8bcfe3d8c96"}},{"ruleId":"D2","level":"warning","message":{"text":"Primary::start_handlers (cognitive 63): Primary::start_handlers has cognitive complexity 63 (threshold 15). Drivers by points: if/else 18 (43 pts), loops 12 (15 pts), match/switch 2 (4 pts), boolean chains 1 (nesting depth added 30). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/primary.rs"},"region":{"startLine":1326}}}],"partialFingerprints":{"codehealthFindingId/v1":"87cc73cc3369cf95e15670c8b69f6e120f3ed72c65fffc18997c1982be6448a6"}},{"ruleId":"D2","level":"warning","message":{"text":"BFT::commit_leader_certificate (cognitive 58): BFT::commit_leader_certificate has cognitive complexity 58 (threshold 15). Drivers by points: if/else 11 (29 pts), loops 7 (15 pts), match/switch 4 (13 pts), boolean chains 1 (nesting depth added 35). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/bft.rs"},"region":{"startLine":595}}}],"partialFingerprints":{"codehealthFindingId/v1":"5363112e95bc10b6bb5276aa87a3f2ad16acfb5ae889e2f36d6479e20436965a"}},{"ruleId":"D2","level":"warning","message":{"text":"Start::parse_node (cognitive 44): Start::parse_node has cognitive complexity 44 (threshold 15). Drivers by points: if/else 25 (33 pts), match/switch 5 (6 pts), boolean chains 4, loops 1 (nesting depth added 9). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/start.rs"},"region":{"startLine":775}}}],"partialFingerprints":{"codehealthFindingId/v1":"cce120f76ae6855e618ab1e0c481d5309b598ba2daf70c8fcd26c517aa709e32"}},{"ruleId":"D2","level":"warning","message":{"text":"Node::perform_auto_checkpoints (cognitive 40): Node::perform_auto_checkpoints has cognitive complexity 40 (threshold 15). Drivers by points: if/else 13 (28 pts), loops 3 (5 pts), match/switch 2 (5 pts), boolean chains 2 (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/node.rs"},"region":{"startLine":379}}}],"partialFingerprints":{"codehealthFindingId/v1":"b637da77b2f77b2dfd634e07c45f05a544c194d736a4bf34189f98b62a82e16d"}},{"ruleId":"D2","level":"warning","message":{"text":"BlockSync::prepare_block_requests (cognitive 40): BlockSync::prepare_block_requests has cognitive complexity 40 (threshold 15). Drivers by points: if/else 18 (30 pts), loops 4 (8 pts), boolean chains 2 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/block_sync.rs"},"region":{"startLine":973}}}],"partialFingerprints":{"codehealthFindingId/v1":"8a945bf8fae238e7c2ce674fc92de406cf3e19bf7927e2575a47444669b31646"}},{"ruleId":"D2","level":"warning","message":{"text":"Sync::sync_storage_with_ledger_at_bootup (cognitive 37): Sync::sync_storage_with_ledger_at_bootup has cognitive complexity 37 (threshold 15). Drivers by points: loops 9 (27 pts), if/else 4 (9 pts), boolean chains 1 (nesting depth added 23). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/sync/mod.rs"},"region":{"startLine":347}}}],"partialFingerprints":{"codehealthFindingId/v1":"03ea907101c3229d0f7e65b2f989046cfea4b852079f4f520b85c5a6ce9ff9e7"}},{"ruleId":"D2","level":"warning","message":{"text":"Start::parse_development (cognitive 33): Start::parse_development has cognitive complexity 33 (threshold 15). Drivers by points: if/else 13 (22 pts), loops 3 (9 pts), boolean chains 2 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/start.rs"},"region":{"startLine":533}}}],"partialFingerprints":{"codehealthFindingId/v1":"7a77ef2b6511ee6d747c2422ac5563da9da7b06a205cb5a63c8b5b1030399054"}},{"ruleId":"D2","level":"warning","message":{"text":"snarkos_node_cdn::blocks::download_block_bundles (cognitive 33): snarkos_node_cdn::blocks::download_block_bundles has cognitive complexity 33 (threshold 15). Drivers by points: if/else 4 (12 pts), loops 4 (11 pts), match/switch 2 (10 pts) (nesting depth added 23). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/cdn/src/blocks.rs"},"region":{"startLine":328}}}],"partialFingerprints":{"codehealthFindingId/v1":"e6a88307dca1aaaea71aa2158940e277c0d40916cafe12442a5c7eafa3a11d43"}},{"ruleId":"D2","level":"warning","message":{"text":"Gateway::perform_handshake (cognitive 31): Gateway::perform_handshake has cognitive complexity 31 (threshold 15). Drivers by points: if/else 16 (25 pts), boolean chains 3, match/switch 2 (3 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":1590}}}],"partialFingerprints":{"codehealthFindingId/v1":"729ef8f818934be5941c6b2f510619c5a865d971656701363e0741ec0ebd4b36"}},{"ruleId":"D2","level":"warning","message":{"text":"Sync::try_sync_storage_with_block (cognitive 29): Sync::try_sync_storage_with_block has cognitive complexity 29 (threshold 15). Drivers by points: loops 6 (12 pts), if/else 7 (11 pts), match/switch 3 (4 pts), boolean chains 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/sync/mod.rs"},"region":{"startLine":805}}}],"partialFingerprints":{"codehealthFindingId/v1":"721da6b365e20e71bb79ca23cfb57e81e06196aa50d3441ddde2eb76cbb01271"}},{"ruleId":"D2","level":"warning","message":{"text":"BFTPersistentStorage::remove_transmissions (cognitive 29): BFTPersistentStorage::remove_transmissions has cognitive complexity 29 (threshold 15). Drivers by points: if/else 7 (20 pts), match/switch 3 (8 pts), loops 1 (nesting depth added 18). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/storage-service/src/persistent.rs"},"region":{"startLine":227}}}],"partialFingerprints":{"codehealthFindingId/v1":"33ca9cc07c28a64e613eca2a407804201b368a587e9ab1a5b8bda160ef124094"}},{"ruleId":"D2","level":"warning","message":{"text":"Client::initialize_solution_verification (cognitive 28): Client::initialize_solution_verification has cognitive complexity 28 (threshold 15). Drivers by points: if/else 7 (20 pts), match/switch 1 (4 pts), loops 2 (3 pts), boolean chains 1 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/client/mod.rs"},"region":{"startLine":332}}}],"partialFingerprints":{"codehealthFindingId/v1":"c33f235d5df8f0ac58bc6475e211f3bff02a84075dc6b0aa85801568754f365b"}},{"ruleId":"D2","level":"warning","message":{"text":"Developer::handle_transaction (cognitive 27): Developer::handle_transaction has cognitive complexity 27 (threshold 15). Drivers by points: match/switch 7 (17 pts), if/else 7 (10 pts) (nesting depth added 13). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/developer/mod.rs"},"region":{"startLine":424}}}],"partialFingerprints":{"codehealthFindingId/v1":"77180dcadb77620a3e5c4a2888ee7e622349281bafe50e9aa0114a34e07d3827"}},{"ruleId":"D2","level":"warning","message":{"text":"Primary::process_batch_propose_from_peer (cognitive 27): Primary::process_batch_propose_from_peer has cognitive complexity 27 (threshold 15). Drivers by points: if/else 18 (24 pts), boolean chains 2, match/switch 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/primary.rs"},"region":{"startLine":828}}}],"partialFingerprints":{"codehealthFindingId/v1":"910cceb2ea8e37c99cd8a3f5ab81b3f22d22857f9144bd33cdc8add4c21f3369"}},{"ruleId":"D2","level":"warning","message":{"text":"Sync::try_advancing_block_synchronization_inner (cognitive 27): Sync::try_advancing_block_synchronization_inner has cognitive complexity 27 (threshold 15). Drivers by points: if/else 10 (17 pts), match/switch 2 (6 pts), loops 2 (4 pts) (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/sync/mod.rs"},"region":{"startLine":509}}}],"partialFingerprints":{"codehealthFindingId/v1":"c2824d489f140402927c3dcf3a38099ed483b83aa5a1e9c10433880e96d9e260"}},{"ruleId":"D2","level":"warning","message":{"text":"Storage::sync_certificate_with_block (cognitive 25): Storage::sync_certificate_with_block has cognitive complexity 25 (threshold 15). Drivers by points: if/else 14 (20 pts), boolean chains 2, match/switch 1 (2 pts), loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/helpers/storage.rs"},"region":{"startLine":872}}}],"partialFingerprints":{"codehealthFindingId/v1":"4ad8d22ec53c7a649aa1cc5cf76af212e1226ba359037cd70aa4164ef64a9675"}},{"ruleId":"D2","level":"warning","message":{"text":"Storage::check_batch_header (cognitive 24): Storage::check_batch_header has cognitive complexity 24 (threshold 15). Drivers by points: if/else 11 (21 pts), loops 1 (2 pts), boolean chains 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/helpers/storage.rs"},"region":{"startLine":492}}}],"partialFingerprints":{"codehealthFindingId/v1":"db435d6cf7865f78bf4c1a0e0447a688aa06d9b14152e71ac5bb67748e8d738c"}},{"ruleId":"D2","level":"warning","message":{"text":"BootstrapClient::perform_handshake (cognitive 24): BootstrapClient::perform_handshake has cognitive complexity 24 (threshold 15). Drivers by points: if/else 10 (20 pts), match/switch 2 (4 pts) (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/bootstrap_client/handshake.rs"},"region":{"startLine":122}}}],"partialFingerprints":{"codehealthFindingId/v1":"62738fd82369dc7bea271ce85a633215254470e2416487a316d14f112cf72d22"}},{"ruleId":"D2","level":"warning","message":{"text":"BFTPersistentStorage::insert_transmissions (cognitive 23): BFTPersistentStorage::insert_transmissions has cognitive complexity 23 (threshold 15). Drivers by points: if/else 5 (15 pts), match/switch 3 (6 pts), loops 2 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/storage-service/src/persistent.rs"},"region":{"startLine":134}}}],"partialFingerprints":{"codehealthFindingId/v1":"7a229749ec4257c0081bc6a4c6ec54189850f3b6bf04864b8e6ef4e26b75fcfe"}},{"ruleId":"D2","level":"warning","message":{"text":"Router::handshake (cognitive 22): Router::handshake has cognitive complexity 22 (threshold 15). Drivers by points: if/else 9 (18 pts), match/switch 2 (3 pts), boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/src/handshake.rs"},"region":{"startLine":86}}}],"partialFingerprints":{"codehealthFindingId/v1":"310287505a9035c7a40ee7540c59e99e8c630ebfc347fb44202f11c681fb4222"}},{"ruleId":"D2","level":"warning","message":{"text":"Client::initialize_execute_verification (cognitive 21): Client::initialize_execute_verification has cognitive complexity 21 (threshold 15). Drivers by points: if/else 4 (11 pts), loops 3 (6 pts), match/switch 1 (3 pts), boolean chains 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/client/mod.rs"},"region":{"startLine":474}}}],"partialFingerprints":{"codehealthFindingId/v1":"9b852800c4cd7cd2d09e13dddc4191d0b1b236e504f2b7a174353afb97d82626"}},{"ruleId":"D2","level":"warning","message":{"text":"BlockSync::update_peer_locators (cognitive 21): BlockSync::update_peer_locators has cognitive complexity 21 (threshold 15). Drivers by points: if/else 7 (11 pts), match/switch 3 (7 pts), loops 3 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/block_sync.rs"},"region":{"startLine":812}}}],"partialFingerprints":{"codehealthFindingId/v1":"981e98b1c43eaf60da6455910f910665ef1fb406bb85f894fb2adf9e29e126de"}},{"ruleId":"D2","level":"warning","message":{"text":"BFT::try_advance_to_next_round (cognitive 20): BFT::try_advance_to_next_round has cognitive complexity 20 (threshold 15). Drivers by points: if/else 8 (13 pts), match/switch 3 (7 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/bft.rs"},"region":{"startLine":227}}}],"partialFingerprints":{"codehealthFindingId/v1":"ff6510a0d608fd410175e49845b34476259a5796f35e93231ed5682fc8850ad2"}},{"ruleId":"D2","level":"warning","message":{"text":"Client::initialize_deploy_verification (cognitive 20): Client::initialize_deploy_verification has cognitive complexity 20 (threshold 15). Drivers by points: if/else 5 (13 pts), loops 2 (3 pts), match/switch 1 (3 pts), boolean chains 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/client/mod.rs"},"region":{"startLine":406}}}],"partialFingerprints":{"codehealthFindingId/v1":"d4d2740ec766d93fb764a63e94b0b6b41db1479012f2ac01cd69f293b7deda6d"}},{"ruleId":"D2","level":"warning","message":{"text":"BlockSync::send_block_requests (cognitive 20): BlockSync::send_block_requests has cognitive complexity 20 (threshold 15). Drivers by points: if/else 5 (9 pts), loops 4 (6 pts), match/switch 3 (5 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/block_sync.rs"},"region":{"startLine":433}}}],"partialFingerprints":{"codehealthFindingId/v1":"5064b1122e20eee3ba18b44890e462be6ec08c329aa16bce32550493db1f5a60"}},{"ruleId":"D2","level":"warning","message":{"text":"BFTMemoryService::insert_transmissions (cognitive 19): BFTMemoryService::insert_transmissions has cognitive complexity 19 (threshold 15). Drivers by points: if/else 4 (13 pts), match/switch 2 (4 pts), loops 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/storage-service/src/memory.rs"},"region":{"startLine":72}}}],"partialFingerprints":{"codehealthFindingId/v1":"5442b2ef93944b57e95ab744571cbd94ec0fd7df0394054a54f53fc10e9c7714"}},{"ruleId":"D2","level":"warning","message":{"text":"Start::check_for_old_storage_format (cognitive 18): Start::check_for_old_storage_format has cognitive complexity 18 (threshold 15). Drivers by points: if/else 10 (18 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/start.rs"},"region":{"startLine":992}}}],"partialFingerprints":{"codehealthFindingId/v1":"db22bd813786635e5d4099970c8ecc2f045c272f33840506472b18cecd146083"}},{"ruleId":"D2","level":"warning","message":{"text":"snarkos_cli::helpers::fd_check::spawn_fd_monitor (cognitive 17): snarkos_cli::helpers::fd_check::spawn_fd_monitor has cognitive complexity 17 (threshold 15). Drivers by points: if/else 5 (12 pts), match/switch 2 (4 pts), loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/helpers/fd_check.rs"},"region":{"startLine":135}}}],"partialFingerprints":{"codehealthFindingId/v1":"6b77efb3f38482a9f139703c4aa1f19421abfc0367271bbc87f011c2a6ea3d9d"}},{"ruleId":"D2","level":"warning","message":{"text":"snarkos_cli::helpers::logger::parse_log_verbosity (cognitive 17): snarkos_cli::helpers::logger::parse_log_verbosity has cognitive complexity 17 (threshold 15). Drivers by points: if/else 16, match/switch 1. To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/helpers/logger.rs"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"0543743793d25bd5a147403167205671841c8a108c1c74158a90dfc11f5d68ec"}},{"ruleId":"D2","level":"warning","message":{"text":"BFT::order_dag_with_dfs (cognitive 17): BFT::order_dag_with_dfs has cognitive complexity 17 (threshold 15). Drivers by points: if/else 4 (7 pts), match/switch 2 (7 pts), loops 2 (3 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/bft.rs"},"region":{"startLine":860}}}],"partialFingerprints":{"codehealthFindingId/v1":"70e3a71f7f47fac50725412568996f60e7019ac719eb07987e7539ca3ec443ab"}},{"ruleId":"D2","level":"warning","message":{"text":"Gateway::log_connected_validators (cognitive 17): Gateway::log_connected_validators has cognitive complexity 17 (threshold 15). Drivers by points: if/else 10 (13 pts), match/switch 2, boolean chains 1, loops 1 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":1038}}}],"partialFingerprints":{"codehealthFindingId/v1":"b33da6e36bbbf718ac3833bb3e62e902d6a88a6886c450f515656c5e96ab9cb7"}},{"ruleId":"D2","level":"warning","message":{"text":"Gateway::handle_bootstrap_peers (cognitive 17): Gateway::handle_bootstrap_peers has cognitive complexity 17 (threshold 15). Drivers by points: if/else 6 (11 pts), loops 2 (3 pts), match/switch 1 (3 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":1198}}}],"partialFingerprints":{"codehealthFindingId/v1":"d6152165f6bc3a7a009dcbeb431eb92b6c865e22a45f8900091b78af22afb9cc"}},{"ruleId":"D2","level":"warning","message":{"text":"Gateway::handle_min_connected_validators (cognitive 17): Gateway::handle_min_connected_validators has cognitive complexity 17 (threshold 15). Drivers by points: if/else 6 (12 pts), loops 1 (2 pts), match/switch 1 (2 pts), boolean chains 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":1279}}}],"partialFingerprints":{"codehealthFindingId/v1":"fee736c4f22852585a09b9eb62c00fe25d65bbbfeb491c7cb2000e509645bc11"}},{"ruleId":"D2","level":"warning","message":{"text":"Primary::add_signature_to_batch (cognitive 17): Primary::add_signature_to_batch has cognitive complexity 17 (threshold 15). Drivers by points: if/else 9 (14 pts), match/switch 2 (3 pts) (nesting depth added 6). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/primary.rs"},"region":{"startLine":1062}}}],"partialFingerprints":{"codehealthFindingId/v1":"122549a0c8c89772bc3406ac7d1314480d9ace15d3a165ac4f777d5e3cd3e546"}},{"ruleId":"D2","level":"warning","message":{"text":"Sync::run (cognitive 17): Sync::run has cognitive complexity 17 (threshold 15). Drivers by points: if/else 4 (8 pts), loops 8, boolean chains 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/sync/mod.rs"},"region":{"startLine":159}}}],"partialFingerprints":{"codehealthFindingId/v1":"2312ea3c185f3ba8a4eac4eeea0804640b51302b31f3d319c6d48ee6a57ec415"}},{"ruleId":"D2","level":"warning","message":{"text":"snarkos_node_cdn::blocks::load_blocks (cognitive 17): snarkos_node_cdn::blocks::load_blocks has cognitive complexity 17 (threshold 15). Drivers by points: if/else 7 (12 pts), loops 2 (3 pts), match/switch 2 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/cdn/src/blocks.rs"},"region":{"startLine":184}}}],"partialFingerprints":{"codehealthFindingId/v1":"a2bfbea0c7309ddbd7fd8f0d7bc4414f97adabaf90791998ca2ab27364f71f82"}},{"ruleId":"D2","level":"warning","message":{"text":"PeerPoolHandling::insert_candidate_peers (cognitive 17): PeerPoolHandling::insert_candidate_peers has cognitive complexity 17 (threshold 15). Drivers by points: if/else 7 (9 pts), match/switch 2 (4 pts), boolean chains 3, loops 1 (nesting depth added 4). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/network/src/peering.rs"},"region":{"startLine":206}}}],"partialFingerprints":{"codehealthFindingId/v1":"dee5b97b424cc064c737cac5db3bbc91348b25d08d8fff9c60387c1d1da8aec6"}},{"ruleId":"D2","level":"warning","message":{"text":"BlockSync::try_issuing_block_requests (cognitive 17): BlockSync::try_issuing_block_requests has cognitive complexity 17 (threshold 15). Drivers by points: if/else 7 (11 pts), loops 2 (5 pts), boolean chains 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/block_sync.rs"},"region":{"startLine":545}}}],"partialFingerprints":{"codehealthFindingId/v1":"0906fb03acfa9d128933a02e81c2074cae19406866ee7d814c80b2211a976ea8"}},{"ruleId":"D2","level":"warning","message":{"text":"BlockSync::insert_block_responses (cognitive 17): BlockSync::insert_block_responses has cognitive complexity 17 (threshold 15). Drivers by points: if/else 9 (16 pts), loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/block_sync.rs"},"region":{"startLine":593}}}],"partialFingerprints":{"codehealthFindingId/v1":"dc073bc31b32882a4a7814d7b242670d66cdb0f1dbcbb39d60eadccd9a84324f"}},{"ruleId":"D2","level":"warning","message":{"text":"Start::parse_genesis (cognitive 16): Start::parse_genesis has cognitive complexity 16 (threshold 15). Drivers by points: if/else 4 (6 pts), match/switch 2 (6 pts), loops 1 (3 pts), boolean chains 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/start.rs"},"region":{"startLine":634}}}],"partialFingerprints":{"codehealthFindingId/v1":"862b16ec1dbbe96f6e3ffa6057d6761ab263fbf6e92a56416676363a0f2f8f31"}},{"ruleId":"D2","level":"warning","message":{"text":"BlockSync::try_advancing_block_synchronization (cognitive 16): BlockSync::try_advancing_block_synchronization has cognitive complexity 16 (threshold 15). Drivers by points: if/else 7 (11 pts), match/switch 2 (4 pts), loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/block_sync.rs"},"region":{"startLine":682}}}],"partialFingerprints":{"codehealthFindingId/v1":"e5d01f3d04acf22f2579d3e814fba9103b24a436e6faeeefc956fec338727f21"}},{"ruleId":"D2","level":"warning","message":{"text":"BlockSync::handle_block_request_timeouts (cognitive 16): BlockSync::handle_block_request_timeouts has cognitive complexity 16 (threshold 15). Drivers by points: if/else 6 (8 pts), loops 3 (5 pts), boolean chains 3 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/block_sync.rs"},"region":{"startLine":1346}}}],"partialFingerprints":{"codehealthFindingId/v1":"88d852d224bb120a84e5d6602a959bd2f367c500c914e05d36df2f00d1e222c0"}},{"ruleId":"D2","level":"warning","message":{"text":"snarkos::snarkos::main (cognitive 16): snarkos::snarkos::main has cognitive complexity 16 (threshold 15). Drivers by points: loops 4 (7 pts), if/else 4 (6 pts), boolean chains 2, match/switch 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"snarkos/main.rs"},"region":{"startLine":74}}}],"partialFingerprints":{"codehealthFindingId/v1":"ef2901548edfb201548f769dffe54391aee704209033327cf55248f143bc7c56"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: Gateway: ClassTooLong \u2014 1009 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 50 methods, 15 blocks, lines 208-2380. The bar is 400 significant lines; this is 609 over it, 2.52\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":206}}}],"partialFingerprints":{"codehealthFindingId/v1":"cca2fc2d0262ead8a7f08d11c81eef37822aa0806995d77b41d2703c1d3d5f90"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Rest: TooManyMethods \u2014 75 methods, declared across 2 files: src/routes.rs (68), src/lib.rs (7). The bar is 30 methods; this is 45 over it, 2.50\u00D7 the bar. That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/rest/src/lib.rs"},"region":{"startLine":188}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c385f4e6d5722ecf82bb6470c4b365944b12a66887f77de5df60416f02780a9"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/gateway.rs: FileTooLong \u2014 1202 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), about 84% of them inside a single declaration: Gateway (15 blocks, 208-2380). The bar is 500 significant lines; this is 702 over it, 2.40\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c97cbab5b2e9368a6adcdf8b48b41776453e42b4c704d0227d3ac6173f11b7bf"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: Primary: ClassTooLong \u2014 941 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 40 methods, 9 blocks, lines 153-2130. The bar is 400 significant lines; this is 541 over it, 2.35\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/primary.rs"},"region":{"startLine":153}}}],"partialFingerprints":{"codehealthFindingId/v1":"1bc25c6272a0fdab33de00586d7e58e10024036e78b37932dfbe4410ed8753a4"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/primary.rs: FileTooLong \u2014 1030 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), about 91% of them inside a single declaration: Primary (9 blocks, 153-2130). The bar is 500 significant lines; this is 530 over it, 2.06\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/primary.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"72486ee21d775bf1f6135a15b6ed1a82e4fc2b0706e4d32ae0e22137322948c4"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: Gateway.inbound: MethodTooLong \u2014 inbound runs 186 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 86 over it, 1.86\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":646}}}],"partialFingerprints":{"codehealthFindingId/v1":"88a2655d642c5aed851a14ea3081d2555dc671e5ed90ea59a3bfc3f02be3330f"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: Primary.propose_batch: MethodTooLong \u2014 propose_batch runs 171 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 71 over it, 1.71\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/primary.rs"},"region":{"startLine":455}}}],"partialFingerprints":{"codehealthFindingId/v1":"346029f2abdf5c327a09353f63c7c93dbd8a367aec2324648651b6b37e609c30"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/routes.rs: FileTooLong \u2014 837 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), about 84% of them inside a single declaration: Rest (284-1686). The bar is 500 significant lines; this is 337 over it, 1.67\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/rest/src/routes.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"40f0cb186335f268b6514ae7eeb533b4e3d88d2b569dea103a38f9f72bc35a66"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Gateway: TooManyMethods \u2014 50 methods. The bar is 30 methods; this is 20 over it, 1.67\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":206}}}],"partialFingerprints":{"codehealthFindingId/v1":"c7da063b08e56a3caecd975431d15771eac22b3b50ef9a87fdea8c113ae2d75c"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: BlockSync: ClassTooLong \u2014 636 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 35 methods, 5 blocks, lines 202-1607. The bar is 400 significant lines; this is 236 over it, 1.59\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/block_sync.rs"},"region":{"startLine":202}}}],"partialFingerprints":{"codehealthFindingId/v1":"42763d48e3728837d1aecd78673e34eefbff773183703a9d45b593eda21da806"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/block_sync.rs: FileTooLong \u2014 780 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), about 82% of them inside a single declaration: BlockSync (5 blocks, 202-1607). The bar is 500 significant lines; this is 280 over it, 1.56\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/block_sync.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ecf857138f1924e6af9ab50c56cceb70ae2e755cb10db20f728f62a36f39777a"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: Primary.start_handlers: MethodTooLong \u2014 start_handlers runs 146 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 46 over it, 1.46\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/primary.rs"},"region":{"startLine":1326}}}],"partialFingerprints":{"codehealthFindingId/v1":"7965e2065581305fdb08c9bf047b01cf6c9bf5e8c96ffd4a12ec5a8138492521"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFields: Start: TooManyFields \u2014 43 stored fields beside 12 methods. The bar is 30 stored fields; this is 13 over it, 1.43\u00D7 the bar. This is width in DATA, not behaviour: every reader that takes the whole type couples to all of its fields, so a change to any one of them is a change every reader has to be checked against. To reduce it, group the fields that are read together by the same callers into a smaller type of their own, and have this one hold that type as a single member \u2014 each reader then names only the group it uses."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/start.rs"},"region":{"startLine":136}}}],"partialFingerprints":{"codehealthFindingId/v1":"da370930968a9feec26a6f2ccbb6f5e5a3a64ee27fc0beff4c4ea0fe1af7aaab"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: commands/start.rs: FileTooLong \u2014 672 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), about 74% of them inside a single declaration: Start (3 blocks, 136-1104). The bar is 500 significant lines; this is 172 over it, 1.34\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/start.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"91b1d3ebe7c7229e33502f1d51b004e67290baa0c93cc2086b5ff455c5fed58e"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Primary: TooManyMethods \u2014 40 methods. The bar is 30 methods; this is 10 over it, 1.33\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/primary.rs"},"region":{"startLine":153}}}],"partialFingerprints":{"codehealthFindingId/v1":"63d2c39d50f891269c61da744ebc65278c392a83d44a18dd459082657e035714"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: BFT.commit_leader_certificate: MethodTooLong \u2014 commit_leader_certificate runs 129 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 29 over it, 1.29\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/bft.rs"},"region":{"startLine":595}}}],"partialFingerprints":{"codehealthFindingId/v1":"a5fe4dbb16ca8bbe6c27d72d7bb5e1df2d221b774878f27344ddce522bb1c162"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: Rest.build_routes: MethodTooLong \u2014 build_routes runs 129 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 29 over it, 1.29\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/rest/src/lib.rs"},"region":{"startLine":271}}}],"partialFingerprints":{"codehealthFindingId/v1":"30effa11bc8cc96eaeadad327e72342ae591dedd0a65fdd49f596c4a909b6ba5"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: Inbound.inbound: MethodTooLong \u2014 inbound runs 126 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 26 over it, 1.26\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/src/inbound.rs"},"region":{"startLine":80}}}],"partialFingerprints":{"codehealthFindingId/v1":"e3caa5ec0e1757e6e50a7d5368ea0d882e8d5476e1e3c9cff6144bd504b73e15"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: Start: ClassTooLong \u2014 500 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 12 methods, 3 blocks, lines 136-1104. The bar is 400 significant lines; this is 100 over it, 1.25\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/start.rs"},"region":{"startLine":136}}}],"partialFingerprints":{"codehealthFindingId/v1":"77f922f45b777e711955e99cd01a87595c7b7f93427dcde4cf6a3d6b0182ed64"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: Sync: ClassTooLong \u2014 475 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 23 methods, 7 blocks, lines 81-1095. The bar is 400 significant lines; this is 75 over it, 1.19\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/sync/mod.rs"},"region":{"startLine":81}}}],"partialFingerprints":{"codehealthFindingId/v1":"198e8995cb6365c988cb97fe1305f6bfa33b5d140a2da60a3a8aa6672248f802"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: BlockSync: TooManyMethods \u2014 35 methods. The bar is 30 methods; this is 5 over it, 1.17\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/block_sync.rs"},"region":{"startLine":202}}}],"partialFingerprints":{"codehealthFindingId/v1":"138090995501baac5c3bc4902877e35edeae4625db234d6d8fddd0318fcf2a7a"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: Start.parse_node: MethodTooLong \u2014 parse_node runs 114 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 14 over it, 1.14\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/start.rs"},"region":{"startLine":775}}}],"partialFingerprints":{"codehealthFindingId/v1":"7ffc53ecfd295d36ff3fe672ee2025b893c8e9465d2034c57cc5561fd1c8116b"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: Consensus.try_advance_to_next_block: MethodTooLong \u2014 try_advance_to_next_block runs 113 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 13 over it, 1.13\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/consensus/src/lib.rs"},"region":{"startLine":594}}}],"partialFingerprints":{"codehealthFindingId/v1":"f41ef006880a8c05f104ba7eb6e655c2bf082c6c16d4a72df84c6ebbc3f384bb"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Storage: TooManyMethods \u2014 33 methods. The bar is 30 methods; this is 3 over it, 1.10\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/helpers/storage.rs"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"4c920a883d392087a31bd0020ef410cd2c5d6d8a83619774e4da6987f1a583ac"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Worker: TooManyMethods \u2014 33 methods. The bar is 30 methods; this is 3 over it, 1.10\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/worker.rs"},"region":{"startLine":53}}}],"partialFingerprints":{"codehealthFindingId/v1":"8f09e1183f1030d31c03621f0dd73ac9ff0e64023b835dd22a42b794c75fc480"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: BFT: ClassTooLong \u2014 434 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 24 methods, 8 blocks, lines 62-936. The bar is 400 significant lines; this is 34 over it, 1.09\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/bft.rs"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"16c95f73e286cfc0e9f64eb5e44bd05cddef0d35e00d0a904d6bc20c2365362c"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: sync/mod.rs: FileTooLong \u2014 513 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), about 93% of them inside a single declaration: Sync (7 blocks, 81-1095). The bar is 500 significant lines; this is 13 over it, 1.03\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/sync/mod.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"dc6465368973c3ceadf8b6d426a2e1b1b7ed39a5c198063ba1a9f4a718923b9a"}},{"ruleId":"D4","level":"warning","message":{"text":"Members sharing a duplicated core (5 members, 50\u002B identical tokens): node/rest/src/routes.rs:362-385 | node/rest/src/routes.rs:399-426 | node/rest/src/routes.rs:439-463 | node/rest/src/routes.rs:483-510 | node/rest/src/routes.rs:529-561 \u2014 These 5 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below \u2014 it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 5 times. The repair is at the members\u0027 grain \u2014 factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 5 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/rest/src/routes.rs"},"region":{"startLine":362}}}],"partialFingerprints":{"codehealthFindingId/v1":"3573fb017f8ad8efbce9ea29b4efaa5965a214f1ac45c9be13bb77eedf792197"}},{"ruleId":"D4","level":"warning","message":{"text":"Members sharing a duplicated core (4 members, 50\u002B identical tokens): node/bft/src/gateway.rs:2119-2174 | node/bft/src/gateway.rs:2187-2257 | node/router/src/handshake.rs:175-248 | node/router/src/handshake.rs:258-343 \u2014 These 4 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below \u2014 it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 4 times. The repair is at the members\u0027 grain \u2014 factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 4 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":2119}}}],"partialFingerprints":{"codehealthFindingId/v1":"22bfc5340087b40da39b2762287e974c0f29b7bc04a5a4f8ab80defb4666edde"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (26 lines \u00D7 2): cli/src/commands/account.rs:244-269 | cli/src/commands/account.rs:286-311 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/account.rs"},"region":{"startLine":244}}}],"partialFingerprints":{"codehealthFindingId/v1":"eca2c98dc5dc169461d13caa75f8b68fb41bdfe0bcffcc93512391c89661bacd"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (18 lines \u00D7 2): node/src/client/mod.rs:216-233 | node/src/validator/mod.rs:194-211 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/client/mod.rs"},"region":{"startLine":216}}}],"partialFingerprints":{"codehealthFindingId/v1":"f3c28bad368f15968cb1deeb787c66b35b1246de67024d49e247aa6a533848f1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16\u201317 lines \u00D7 2): node/consensus/src/lib.rs:611-626 | node/consensus/src/lib.rs:646-662 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/consensus/src/lib.rs"},"region":{"startLine":611}}}],"partialFingerprints":{"codehealthFindingId/v1":"afc6ef2f1ee6e6203c873d5f31daa65687535b926e53a64d2501bc60a0c30757"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14\u201315 lines \u00D7 2): node/bft/events/src/challenge_request.rs:62-75 | node/router/messages/src/challenge_request.rs:60-74 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/events/src/challenge_request.rs"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"cd5d71c2b136959ffc4391c0775c1244c4152d7d3fec985c6bf58be05a3d7652"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): node/bft/src/sync/mod.rs:203-216 | node/bft/src/worker.rs:510-523 \u2014 before extracting anything, compare \u0060node/bft/src/sync/mod.rs\u0060 and \u0060node/bft/src/worker.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 33 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/sync/mod.rs"},"region":{"startLine":203}}}],"partialFingerprints":{"codehealthFindingId/v1":"c93e51e23ecac9cfa1c3835b698d8da829ba440f8c16f290a60dbb19178506c4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): node/bft/src/gateway.rs:768-780 | node/router/src/inbound.rs:139-151 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":768}}}],"partialFingerprints":{"codehealthFindingId/v1":"9e7b7745b3e6e704c4b9fd21728520849f27fb19a088fa99598ed9a8b9cbb810"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): node/bft/src/helpers/cache.rs:216-228 | node/router/src/helpers/cache.rs:300-312 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/helpers/cache.rs"},"region":{"startLine":216}}}],"partialFingerprints":{"codehealthFindingId/v1":"7468d36b2219e854fcaa3ca4360b76d1c1ef830879e1af3c35e9c35ba8f30db9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): node/src/node.rs:138-150 | node/src/node.rs:219-231 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/node.rs"},"region":{"startLine":138}}}],"partialFingerprints":{"codehealthFindingId/v1":"a04ebd123f6d86822e38c6124789b015275aa7a0146f7c7aa77506e431053ce6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 5): node/rest/src/routes.rs:369-380 | node/rest/src/routes.rs:410-421 | node/rest/src/routes.rs:447-458 | node/rest/src/routes.rs:494-505 | node/rest/src/routes.rs:545-556 \u2014 all 5 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/rest/src/routes.rs"},"region":{"startLine":369}}}],"partialFingerprints":{"codehealthFindingId/v1":"86d68803db5c9347a3f7c682aa35509cd31d88dbfc9ccb5e819042009e46fb60"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): node/bft/src/sync/mod.rs:1017-1028 | node/bft/src/worker.rs:573-584 \u2014 before extracting anything, compare \u0060node/bft/src/sync/mod.rs\u0060 and \u0060node/bft/src/worker.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 33 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/sync/mod.rs"},"region":{"startLine":1017}}}],"partialFingerprints":{"codehealthFindingId/v1":"de7c92b982c2a5aeb61569eec3c22bc7f393e94d89c66c3e601689962c567fdf"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): node/sync/src/block_sync.rs:1328-1338 | node/sync/src/block_sync.rs:1425-1435 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/block_sync.rs"},"region":{"startLine":1328}}}],"partialFingerprints":{"codehealthFindingId/v1":"80189404af31a1f1814a3d0e2d4a4ca1731fed95777fa53f874d3140d9a50b7d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): node/sync/src/ping.rs:75-85 | node/sync/src/ping.rs:94-104 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/ping.rs"},"region":{"startLine":75}}}],"partialFingerprints":{"codehealthFindingId/v1":"a163be268bfdf7ee4fa4244b9e904181c82b025a1af5e95d7a4b94535d0a249d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 3): node/router/messages/src/helpers/codec.rs:81-89 | node/src/bootstrap_client/codec.rs:59-67 | node/src/bootstrap_client/codec.rs:75-83 \u2014 there are 3 copies across 2 file(s) \u2014 more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 3 sites; resolving a subset leaves the remainder to drift apart."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/messages/src/helpers/codec.rs"},"region":{"startLine":81}}}],"partialFingerprints":{"codehealthFindingId/v1":"451b08eff3b2ecf3a9f19e1af62c1eff53cd4bd0ec57210e522831dc80aaf2ef"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): node/bft/src/gateway.rs:2153-2161 | node/bft/src/gateway.rs:2215-2223 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":2153}}}],"partialFingerprints":{"codehealthFindingId/v1":"bcf7af31cea38af4c86aa66898f31a921bf7b9c134ab4c83eb1e734166bdba71"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): node/bft/src/gateway.rs:324-331 | node/router/src/lib.rs:179-186 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":324}}}],"partialFingerprints":{"codehealthFindingId/v1":"e28d630897290aa60b6ba8c35b87b75f564d8a051ac8d2e321361735b79ac82c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): node/bft/src/gateway.rs:2065-2072 | node/src/bootstrap_client/handshake.rs:243-250 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":2065}}}],"partialFingerprints":{"codehealthFindingId/v1":"db51c67fdde6e28bfdb70efdb4b9b4417cce21ac0e95188e38a328b41e5b2102"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): node/router/src/handshake.rs:225-232 | node/router/src/handshake.rs:289-297 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/src/handshake.rs"},"region":{"startLine":225}}}],"partialFingerprints":{"codehealthFindingId/v1":"e13fa83390e61fe77bc56b677a7d7c694ffe9a8ee28ad5ff0bfe28c559537597"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): node/tcp/src/protocols/disconnect.rs:53-60 | node/tcp/src/protocols/on_connect.rs:45-52 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/tcp/src/protocols/disconnect.rs"},"region":{"startLine":53}}}],"partialFingerprints":{"codehealthFindingId/v1":"f160c885d658e2d543b2a034f400e867b58de68245034b2019a59a8ba048185f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 4): node/bft/src/gateway.rs:2155-2162 | node/bft/src/gateway.rs:2217-2224 | node/router/src/handshake.rs:227-233 | node/router/src/handshake.rs:291-298 \u2014 there are 4 copies across 2 file(s) \u2014 more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 4 sites; resolving a subset leaves the remainder to drift apart."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":2155}}}],"partialFingerprints":{"codehealthFindingId/v1":"197a8e80123c9c5392731c2dfa4d350e702630cbbd6281c2f5200289adcc0dab"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): node/bft/src/gateway.rs:2163-2169 | node/bft/src/gateway.rs:2225-2231 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":2163}}}],"partialFingerprints":{"codehealthFindingId/v1":"a4efa2f0a10154452eb5ebb751b3006de201017908a11b7f027790222303fa85"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): node/bft/src/helpers/storage.rs:933-939 | node/bft/src/helpers/storage.rs:957-963 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/helpers/storage.rs"},"region":{"startLine":933}}}],"partialFingerprints":{"codehealthFindingId/v1":"6e99858de4352dfdc347fef6668790e5adf4bf445c980ebd4a6f63eb7d2a519b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): node/bft/src/sync/mod.rs:1009-1015 | node/bft/src/worker.rs:562-568 \u2014 before extracting anything, compare \u0060node/bft/src/sync/mod.rs\u0060 and \u0060node/bft/src/worker.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 33 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/sync/mod.rs"},"region":{"startLine":1009}}}],"partialFingerprints":{"codehealthFindingId/v1":"4bc028b6bbd53a861973a4835cecc90b0154e8aaf6360486eefca5267afe6cb9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): node/src/bootstrap_client/handshake.rs:472-478 | node/src/bootstrap_client/handshake.rs:491-497 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/bootstrap_client/handshake.rs"},"region":{"startLine":472}}}],"partialFingerprints":{"codehealthFindingId/v1":"63dbaf82bcbf351af1e3e58556f76b1a4bfa5e4f3dc79e29684ea1cb22b478a9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5\u20136 lines \u00D7 3): node/bft/src/gateway.rs:2163-2167 | node/bft/src/gateway.rs:2225-2229 | node/router/src/handshake.rs:235-240 \u2014 there are 3 copies across 2 file(s) \u2014 more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 3 sites; resolving a subset leaves the remainder to drift apart."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":2163}}}],"partialFingerprints":{"codehealthFindingId/v1":"cbd7e582ab3bb1a98f5c4f47806ae6af1354b2ebe6728e6f707dd32a38615210"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): node/bft/src/gateway.rs:875-880 | node/bft/src/gateway.rs:888-893 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":875}}}],"partialFingerprints":{"codehealthFindingId/v1":"ad1438c69d558261149f45dc20c5839c12d3e8d7677f0a17286e50291546e516"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): node/bft/src/gateway.rs:2134-2139 | node/bft/src/gateway.rs:2239-2244 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":2134}}}],"partialFingerprints":{"codehealthFindingId/v1":"899c02b9a676d6c8943a181c167482203b08cc1c5d39e96a25d8f08101328093"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): node/router/src/handshake.rs:184-189 | node/router/src/handshake.rs:268-273 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/src/handshake.rs"},"region":{"startLine":184}}}],"partialFingerprints":{"codehealthFindingId/v1":"c321e9a20ef303cddc3ff6a909d3a2213fe8722a480aa5aa5910e3d3509f6188"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): node/router/src/handshake.rs:198-203 | node/router/src/handshake.rs:318-323 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/src/handshake.rs"},"region":{"startLine":198}}}],"partialFingerprints":{"codehealthFindingId/v1":"910e3773aa31742d45be756580174ed47eed2cd2fc6b81613d5e3767f4816a34"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): node/bft/src/gateway.rs:2129-2133 | node/bft/src/gateway.rs:2234-2238 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":2129}}}],"partialFingerprints":{"codehealthFindingId/v1":"228d043d5de1d9aaba1f02e8f03ce35aa70599592f795af0d779eb49b00b7c3a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): node/tcp/src/protocols/handshake.rs:52-56 | node/tcp/src/protocols/reading.rs:86-90 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/tcp/src/protocols/handshake.rs"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"2d6c31eaf1f74b41fe171785ec8e6bd0025afbefd13fdad021552db6ac0523c1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): node/bft/events/src/disconnect.rs:74-81 | node/router/messages/src/helpers/disconnect.rs:166-173 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/events/src/disconnect.rs"},"region":{"startLine":74}}}],"partialFingerprints":{"codehealthFindingId/v1":"b29db6cff431a0abc30032e589848ac4a9a9e28ba7fac4eb69d5d164acc32df6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 3): node/bft/ledger-service/src/lib.rs:52-59 | node/bft/src/helpers/mod.rs:55-62 | node/rest/src/lib.rs:566-573 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 3 call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made 3 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/ledger-service/src/lib.rs"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"f556a496a915baa963dd4a0fcb196d5d841bf0654d108a0711ff02aeab5ffa76"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): node/bft/src/gateway.rs:992-996 | node/bft/src/primary.rs:2090-2094 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":992}}}],"partialFingerprints":{"codehealthFindingId/v1":"4a0195def4016de5ef5d6d0c69851f6d91e2d42f10f937702bb14608e6acf83d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): node/bft/src/gateway.rs:2107-2111 | node/src/bootstrap_client/handshake.rs:297-301 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":2107}}}],"partialFingerprints":{"codehealthFindingId/v1":"c241f2d795886266fdc0fc676096192eed1933a517d61c89fa9bc9b0810ca258"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): node/bft/src/helpers/cache.rs:205-212 | node/router/src/helpers/cache.rs:289-296 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/helpers/cache.rs"},"region":{"startLine":205}}}],"partialFingerprints":{"codehealthFindingId/v1":"be02ace1feef94b39ede74970dd7c91c049fe4f66739355f9dfc54b860f568cb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): node/bft/src/bft.rs:332-344 | node/bft/src/bft.rs:643-655 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/bft.rs"},"region":{"startLine":332}}}],"partialFingerprints":{"codehealthFindingId/v1":"9182e50397754fa32c4f4cf546f96bd778b7ea5d80436c53f91f747b881e4fef"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): cli/src/commands/developer/deploy.rs:217-229 | cli/src/commands/developer/execute.rs:219-231 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/developer/deploy.rs"},"region":{"startLine":217}}}],"partialFingerprints":{"codehealthFindingId/v1":"fb11bdf79c299ad8b8f072d2f7690f1c1c550dd6909327739a0b953281a6db92"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): node/src/client/mod.rs:554-566 | node/src/validator/mod.rs:503-515 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/client/mod.rs"},"region":{"startLine":554}}}],"partialFingerprints":{"codehealthFindingId/v1":"8633e0cfd4063de60eac6905246f0fae8b00e3c62d7710900f76efedfc71deb5"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): node/router/src/inbound.rs:258-266 | node/router/src/inbound.rs:289-297 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/src/inbound.rs"},"region":{"startLine":258}}}],"partialFingerprints":{"codehealthFindingId/v1":"2dc55330d759f8b86c2a7a63d025be1443f68a3b801ad433618ca5fc93d10fa9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): node/cdn/src/blocks.rs:451-457 | node/cdn/src/blocks.rs:482-488 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/cdn/src/blocks.rs"},"region":{"startLine":451}}}],"partialFingerprints":{"codehealthFindingId/v1":"bfcebd5505c443de003192db488fa64f29824e601d78e0e05860f23546cbbe4e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 3): node/tcp/src/protocols/handshake.rs:52-57 | node/tcp/src/protocols/reading.rs:86-91 | node/tcp/src/protocols/writing.rs:85-90 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from all 3 call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/tcp/src/protocols/handshake.rs"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"edfff16e5ba79d66bfbcec70af4220fca9bb280761b82ad4cea35a1964a8061e"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: snarkos-account: snarkos-account: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and depended on by 6 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0d5005e1ab57eb53b4c7bec2a820adfe908f98932416ca30407ac17ae779283c"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: snarkos-node-sync-locators: snarkos-node-sync-locators: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and depended on by 4 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"2634c104d7655a743a65b2d8b18db78a07359fb6c9ffa87af161521356fc7c68"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: snarkos-utilities: snarkos-utilities: abstractness 0.17, instability 0.00, distance 0.83 \u2014 zone of pain \u2014 concrete and depended on by 8 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"738c7b54dbe36d8bbe37b77b76cc568f33181c8be00f3c3e2ea97f4cf386a616"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: snarkos-node-network: snarkos-node-network: abstractness 0.14, instability 0.13, distance 0.73 \u2014 zone of pain \u2014 concrete and depended on by 7 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5dc3370f692a9592a72956459560b9ef3f132557c6b814f6599f1a3b66aa848d"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: MockLedgerService (LCOM4 7): MockLedgerService\u0027s methods fall into 7 groups that share no field and call none of each other, against a bar of more than 3 for this run (LCOM4, configurable \u2014 your repository\u0027s bar is the one quoted here). Each group is a set of methods reachable from one another through shared fields or direct calls, so 7 groups means the type has that many internally-connected clusters with nothing tying them together. Types whose shape makes a high count expected \u2014 and which would otherwise dominate this list \u2014 are excluded before this row is raised, so this is a genuine split candidate rather than a metric reading. It is still a shape, not a defect: confirm the groups match responsibilities you can name before splitting."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/ledger-service/src/mock.rs"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"fa0619fc2cb07ddc2a73dc3f342f6b8b85a83e3fcb4cb95dbfcfae4c7efd2641"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: Storage (LCOM4 6): Storage\u0027s methods fall into 6 groups that share no field and call none of each other, against a bar of more than 3 for this run (LCOM4, configurable \u2014 your repository\u0027s bar is the one quoted here). Each group is a set of methods reachable from one another through shared fields or direct calls, so 6 groups means the type has that many internally-connected clusters with nothing tying them together. Types whose shape makes a high count expected \u2014 and which would otherwise dominate this list \u2014 are excluded before this row is raised, so this is a genuine split candidate rather than a metric reading. It is still a shape, not a defect: confirm the groups match responsibilities you can name before splitting."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/helpers/storage.rs"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"89e567f65dc69b964c9817a73c3f312d59715afe28ab497827432840384e8baf"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: Gateway (LCOM4 4): Gateway\u0027s methods fall into 4 groups that share no field and call none of each other, against a bar of more than 3 for this run (LCOM4, configurable \u2014 your repository\u0027s bar is the one quoted here). Each group is a set of methods reachable from one another through shared fields or direct calls, so 4 groups means the type has that many internally-connected clusters with nothing tying them together. Types whose shape makes a high count expected \u2014 and which would otherwise dominate this list \u2014 are excluded before this row is raised, so this is a genuine split candidate rather than a metric reading. It is still a shape, not a defect: confirm the groups match responsibilities you can name before splitting."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":206}}}],"partialFingerprints":{"codehealthFindingId/v1":"f54db211e0bee5655a8217f48d0b33053c2da8cb1a8eb051028cb9919eb1ab5f"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: Client (LCOM4 4): Client\u0027s methods fall into 4 groups that share no field and call none of each other, against a bar of more than 3 for this run (LCOM4, configurable \u2014 your repository\u0027s bar is the one quoted here). Each group is a set of methods reachable from one another through shared fields or direct calls, so 4 groups means the type has that many internally-connected clusters with nothing tying them together. Types whose shape makes a high count expected \u2014 and which would otherwise dominate this list \u2014 are excluded before this row is raised, so this is a genuine split candidate rather than a metric reading. It is still a shape, not a defect: confirm the groups match responsibilities you can name before splitting."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/client/mod.rs"},"region":{"startLine":100}}}],"partialFingerprints":{"codehealthFindingId/v1":"ae8b980fb7177155ad2e5bfcb72e5a749ec68f743a985fa780eb0e60fe89497c"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: Prover (LCOM4 4): Prover\u0027s methods fall into 4 groups that share no field and call none of each other, against a bar of more than 3 for this run (LCOM4, configurable \u2014 your repository\u0027s bar is the one quoted here). Each group is a set of methods reachable from one another through shared fields or direct calls, so 4 groups means the type has that many internally-connected clusters with nothing tying them together. Types whose shape makes a high count expected \u2014 and which would otherwise dominate this list \u2014 are excluded before this row is raised, so this is a genuine split candidate rather than a metric reading. It is still a shape, not a defect: confirm the groups match responsibilities you can name before splitting."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/prover/mod.rs"},"region":{"startLine":72}}}],"partialFingerprints":{"codehealthFindingId/v1":"ea529f032b1ad230809bfb3fa606f56e60d626c72354970f097d6917441045bb"}},{"ruleId":"D13","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3711da9e55ed9d171b214bff84970009d08cec4b445ac12196ca154dfd8a5bca"},"taxa":[{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D13","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"08c70416da7c918f7dacce2fe21996f161d9972c2521e60fdd1a75fdb806773a"},"taxa":[{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D13","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5f58987f166787656373cb131611de066c138d3142515c1f7f0af55723184323"},"taxa":[{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: node/bft/src/gateway.rs: node/bft/src/gateway.rs changed 21 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 57 in Gateway::inbound at line 646. 3 of those changes were fix/bug commits, and the other 18 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-27..2026-09-25, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-27 14:01:00 \u002B01:00\u0027 --until=\u00272026-09-25 14:01:00 \u002B01:00\u0027 --full-history --no-merges -- node/bft/src/gateway.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":646}}}],"partialFingerprints":{"codehealthFindingId/v1":"84acc0489239044c4cbc35e7876de16678af7a35e0f9607847842cf413b0f5f4"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: node/bft/src/primary.rs: node/bft/src/primary.rs changed 25 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 43 in Primary::propose_batch at line 455. 10 of those changes were fix/bug commits, and the other 15 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-27..2026-09-25, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-27 14:01:00 \u002B01:00\u0027 --until=\u00272026-09-25 14:01:00 \u002B01:00\u0027 --full-history --no-merges -- node/bft/src/primary.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/primary.rs"},"region":{"startLine":455}}}],"partialFingerprints":{"codehealthFindingId/v1":"7b5b80c75e8abf7046b4b63ea1eef957a9c1669fd44067bdb9eaed34cfcefce9"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: node/bft/src/helpers/storage.rs: node/bft/src/helpers/storage.rs changed 20 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 17 in Storage::sync_certificate_with_block at line 872. 8 of those changes were fix/bug commits, and the other 12 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-27..2026-09-25, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-27 14:01:00 \u002B01:00\u0027 --until=\u00272026-09-25 14:01:00 \u002B01:00\u0027 --full-history --no-merges -- node/bft/src/helpers/storage.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/helpers/storage.rs"},"region":{"startLine":872}}}],"partialFingerprints":{"codehealthFindingId/v1":"97ce578f95432cef7cd1ed7bf72a92478d199b5dd45ed6bdcfd2547b69bd8a11"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: node/bft/src/bft.rs: node/bft/src/bft.rs changed 7 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 26 in BFT::commit_leader_certificate at line 595. 3 of those changes were fix/bug commits, and the other 4 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-27..2026-09-25, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-27 14:01:00 \u002B01:00\u0027 --until=\u00272026-09-25 14:01:00 \u002B01:00\u0027 --full-history --no-merges -- node/bft/src/bft.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/bft.rs"},"region":{"startLine":595}}}],"partialFingerprints":{"codehealthFindingId/v1":"a28370d0c2b5adae3a5b7eeb05178e789fb6d870463f663516311af8c10c5695"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: cli/src/commands/start.rs: cli/src/commands/start.rs changed 5 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 34 in Start::parse_node at line 775. 1 of those changes was a fix/bug commit, and the other 4 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-27..2026-09-25, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-27 14:01:00 \u002B01:00\u0027 --until=\u00272026-09-25 14:01:00 \u002B01:00\u0027 --full-history --no-merges -- cli/src/commands/start.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/start.rs"},"region":{"startLine":775}}}],"partialFingerprints":{"codehealthFindingId/v1":"f6c338e4ffad0167ed72e2b94af8e99bf81bb42a4850e3c78898071e2cf6180e"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: node/src/node.rs: node/src/node.rs changed 6 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 21 in Node::perform_auto_checkpoints at line 379. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-27..2026-09-25, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-27 14:01:00 \u002B01:00\u0027 --until=\u00272026-09-25 14:01:00 \u002B01:00\u0027 --full-history --no-merges -- node/src/node.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/node.rs"},"region":{"startLine":379}}}],"partialFingerprints":{"codehealthFindingId/v1":"f1f681d9af15ddd1067bfcac52dc21df433f4ccc345900f69a9f832b1909bc2b"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: node/router/src/inbound.rs: node/router/src/inbound.rs changed 2 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 47 in Inbound::inbound at line 80. 1 of those changes was a fix/bug commit, and the other 1 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-27..2026-09-25, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-27 14:01:00 \u002B01:00\u0027 --until=\u00272026-09-25 14:01:00 \u002B01:00\u0027 --full-history --no-merges -- node/router/src/inbound.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/src/inbound.rs"},"region":{"startLine":80}}}],"partialFingerprints":{"codehealthFindingId/v1":"f04f4f35c48ef2f5f97c1c2fa8e5a18bc7daa27614d76e8fba956928ff919703"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: node/router/messages/src/helpers/codec.rs: node/router/messages/src/helpers/codec.rs changed 7 times in last 90 days and 5 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 5 (its worst body is MessageCodec::decode at line 96), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix(router): tighten MAX_PING_MESSAGE_SIZE from 16 MiB to 2 MiB\u201D; \u201Cfix(router): reject an excluded message type outright, not just oversized\u201D; \u201Cfix(router): cap the size of a Ping message\u201D; \u201Cfix(router): address review findings on the transaction overhead cap\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-06-27..2026-09-25, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-27 14:01:00 \u002B01:00\u0027 --until=\u00272026-09-25 14:01:00 \u002B01:00\u0027 --full-history --no-merges -- node/router/messages/src/helpers/codec.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/messages/src/helpers/codec.rs"},"region":{"startLine":96}}}],"partialFingerprints":{"codehealthFindingId/v1":"17f54888b6759b5ecf541dc365bacf89e1bdd7b9470e1881a95341a77957238d"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: node/router/messages/src/unconfirmed_transaction.rs: node/router/messages/src/unconfirmed_transaction.rs changed 5 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 1 (its worst body is UnconfirmedTransaction::from at line 49), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix(router): address review findings on the transaction overhead cap\u201D; \u201Cfix(router): move the transaction overhead constant next to write_le\u201D; \u201Cfix(router): account for the frame envelope in the transaction size cap\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-06-27..2026-09-25, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-27 14:01:00 \u002B01:00\u0027 --until=\u00272026-09-25 14:01:00 \u002B01:00\u0027 --full-history --no-merges -- node/router/messages/src/unconfirmed_transaction.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/messages/src/unconfirmed_transaction.rs"},"region":{"startLine":49}}}],"partialFingerprints":{"codehealthFindingId/v1":"e65a48e557a3eee59108a36aa9eea39222ca988e6defd8a560afb87d0eb548ff"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: node/bft/src/worker.rs: node/bft/src/worker.rs changed 4 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 11 (its worst body is Worker::insert_transmission_from_peer at line 365), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix: keep a transmission whose ID storage knows only as aborted\u201D; \u201Cfix(bft): scope the ready-queue cap to the worker-ping path only\u201D; \u201Cfix(bft): enforce worker capacity limit at transmission insertion\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-06-27..2026-09-25, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-27 14:01:00 \u002B01:00\u0027 --until=\u00272026-09-25 14:01:00 \u002B01:00\u0027 --full-history --no-merges -- node/bft/src/worker.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/worker.rs"},"region":{"startLine":365}}}],"partialFingerprints":{"codehealthFindingId/v1":"780345e55c22c5b60ebed73818897b1f50d09e36c089f9b2d9e4c71f7cac0ed4"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: node/src/traits.rs: node/src/traits.rs changed 3 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 4 (its worst body is NodeInterface::wait_for_signals at line 52), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix: abort the metrics exporter task on shutdown\u201D; \u201Cfix: account for other platforms in the shutdown task check\u201D; \u201Cfix: abort the FD monitor task on shutdown\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-06-27..2026-09-25, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-27 14:01:00 \u002B01:00\u0027 --until=\u00272026-09-25 14:01:00 \u002B01:00\u0027 --full-history --no-merges -- node/src/traits.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/traits.rs"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"0c754b86d45cd38ef048812a3c9969dc9029098005e63f33bddaf7b415e9831e"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #1: If anonymized user #1 becomes unavailable, 9 significant file(s) lose their only recent owner: node/network/src/noise.rs, node/bft/storage-service/src/tests.rs, node/bft/events/src/helpers/handshake.rs, node/tcp/src/helpers/connections.rs, node/bft/storage-service/src/traits.rs, node/tcp/src/protocols/disconnect.rs, node/tcp/src/helpers/config.rs, node/tcp/src/protocols/mod.rs (\u002B1 more). Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"bf21a00ea5dec53223757a27e3fb34ae38e9919ae04d5017aa8b21a78c359112"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #2: If anonymized user #2 becomes unavailable, 3 significant file(s) lose their only recent owner: node/router/messages/src/helpers/disconnect.rs, cli/src/helpers/args.rs, node/sync/src/block_sync/helpers.rs. Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4e23d2ef3bd9a470d06d77a0e742ed179fcd624b7358238b04cb6f528d9eb8f2"}},{"ruleId":"D16","level":"note","message":{"text":"Further sole-owners (lower concentration): 2 other contributor(s) are each the sole owner of a small amount of code below the off-boarding threshold \u2014 folded into the bus-factor score and metrics (15 single-owned of 141 analysed files in total, counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 141 of the 169 production source files in this repository met that bar). They are anonymized user #3 (2 file(s)), anonymized user #4 (1 file(s)) \u2014 spread or document their files in the same way, at lower priority than the named off-boarding risks above."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6eac528f2429e724e1a97ed868f79eefbcf1888dab4af9a9e673429369bb5b2f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(kaimast): remove once we upgrade the rand crate \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"account/src/lib.rs"},"region":{"startLine":189}}}],"partialFingerprints":{"codehealthFindingId/v1":"43daf76da4c958defdfc05ed4b0a5047efe875215ff7bc300c5889d848d829f2"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(kaimast): start the display earlier and show sync progress. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/start.rs"},"region":{"startLine":956}}}],"partialFingerprints":{"codehealthFindingId/v1":"ac56bb0595c81f8dd06a8ae44f81e6ad5f8ced03a0d00f3dc3f6c56566c32fe0"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(kaimast): set up a panic handler here for each worker thread once [\u0060tokio::runtime::Builder::unhandled_panic\u0060](https://docs.rs/tokio/latest/tokio/runtime/struct.Builder.html#method.unhandled_panic) is stabilized."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/start.rs"},"region":{"startLine":1095}}}],"partialFingerprints":{"codehealthFindingId/v1":"c8671ca71b18238c3a91f5631cfe41e94e202329e2853b0370ece13698775bec"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Dedup the error types. We\u0027re adding the record as valid because the endpoint failed, \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/developer/scan.rs"},"region":{"startLine":409}}}],"partialFingerprints":{"codehealthFindingId/v1":"c2af55662364438b5beb3ea30b1288139e1852f74132500638dad3043c0074ea"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO (howardwu): For mainnet - Remove this clippy lint. The CertificateResponse should not \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/events/src/lib.rs"},"region":{"startLine":94}}}],"partialFingerprints":{"codehealthFindingId/v1":"4cba9ac529faca964f50829256195cbfbb180d45aa4293da741595858676bd34"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO switch to an iteration method that doesn\u0027t require manually updating this vec if enums are added \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/events/src/disconnect.rs"},"region":{"startLine":151}}}],"partialFingerprints":{"codehealthFindingId/v1":"6a19a0d5931d26f31c68e7f8549c1c4ba9579571371c20b03a69fa6f243ab58f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO once Worker implements Debug, simplify this with \u0060unwrap_err\u0060 \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/worker.rs"},"region":{"startLine":1241}}}],"partialFingerprints":{"codehealthFindingId/v1":"0618131b6d2884493166f48a70f6c7e13ba3921c86c21f7f8cc956046becbcc3"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: /// TODO(kaimast): avoiding using an async lock here, so this can be merged with the \u0060proposed_batch\u0060, \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/primary.rs"},"region":{"startLine":177}}}],"partialFingerprints":{"codehealthFindingId/v1":"58ede8c08c2dc6e48ed62248b4e67d36ba59b0c1ce65108ec62a807da97c7820"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(ljedrz): the BatchHeader should be serialized only once in advance before being sent to non-signers. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/primary.rs"},"region":{"startLine":507}}}],"partialFingerprints":{"codehealthFindingId/v1":"405f91ba788301396450798f338ea9ad16d1c121b79a74901e906c9e5e3c014e"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: eliminate those redundant checks \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/primary.rs"},"region":{"startLine":1273}}}],"partialFingerprints":{"codehealthFindingId/v1":"17478b6f043ebfa91e8058345be52e6e9c9b4ec33d49cc631219a0221b153e12"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO (raychu86): Optimize this by parallelizing requests, but avoiding duplicated requests since certificates are likely shared across batches. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/primary.rs"},"region":{"startLine":1926}}}],"partialFingerprints":{"codehealthFindingId/v1":"a6edb61fc3a318cdf7caf84a012220fb6f63345ef31cfe7df82ff3b37fad18dd"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO (howardwu): Limit the number of open requests we send to a peer. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/primary.rs"},"region":{"startLine":2063}}}],"partialFingerprints":{"codehealthFindingId/v1":"bf8570d10a828db943a076ddbfab1c5db958e21fb00dfa9d3c23128ff779b69e"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: /// TODO(kaimast): directy multiply by constant once the \u0060const_trait_impl\u0060 feature is stable. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/lib.rs"},"region":{"startLine":69}}}],"partialFingerprints":{"codehealthFindingId/v1":"112efd99050ff922c8954e9b8cd3c4adbe644486e5150ef03c47357457f5af1a"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(kaimast): This needs more testing to ensure disconnect is the correct action. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":812}}}],"partialFingerprints":{"codehealthFindingId/v1":"9ee44a736ec208ec217e22f11ea73e6dca07053854f151285f41e6c7da1032bc"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(kaimast): This needs more testing to ensure disconnect is the correct action. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/client/router.rs"},"region":{"startLine":262}}}],"partialFingerprints":{"codehealthFindingId/v1":"14e1f4333740cbbba9170f8ccc78b8068f005056609c696679c3378da243d723"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO (howardwu): Add rate limiting checks on this event, on a per-peer basis. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":873}}}],"partialFingerprints":{"codehealthFindingId/v1":"478ee613139aabdbff8e0cb17567dcdb2988afb3651379083770d8b207add67d"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(kaimast): This can, in theory, still lead to race conditions, if we immediately reconnect to the same peer. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":1537}}}],"partialFingerprints":{"codehealthFindingId/v1":"6a7413de80566690dd3a0b509f16694874bbacd5db31fc3331bffd11ce4b2707"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO implement Debug properly and move it over to production code \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/gateway.rs"},"region":{"startLine":2450}}}],"partialFingerprints":{"codehealthFindingId/v1":"76ab4a0999d7be669288b82ea11bdaf255ffa0a1d4ec4697a0d661f8c462aa13"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Consider other metrics to track: \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/helpers/telemetry.rs"},"region":{"startLine":97}}}],"partialFingerprints":{"codehealthFindingId/v1":"ad9d03b1beea3d125ac0ff210db4a7e295041a38134a50ed2be9cfc69076dc78"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO (howardwu): We may want to use \u0060shift_remove\u0060 below, in order to align compatibility \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/helpers/storage.rs"},"region":{"startLine":816}}}],"partialFingerprints":{"codehealthFindingId/v1":"f0dd4ea6ccfe58b68382f3cab2673228f2b014b707574854dbe1655bd27db6ab"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO (howardwu): Testing with \u0027max_gc_rounds\u0027 set to \u00270\u0027 should ensure everything is cleared after insertion. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/helpers/storage.rs"},"region":{"startLine":1129}}}],"partialFingerprints":{"codehealthFindingId/v1":"0201b5d56193f86b4d3f99cf4757728bd146856c58121abe8a856ba38e60f5f9"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO (kaimast): return early here? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/helpers/dag.rs"},"region":{"startLine":145}}}],"partialFingerprints":{"codehealthFindingId/v1":"4eb81a9c776e7bad3d7b9b012f50bd6d0af62423cf5d76ebf8a1e562d3227a11"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(kaimast); only remove old certificates for specific author here? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/helpers/dag.rs"},"region":{"startLine":157}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b283bb4f4e2ecbc82a7d4e5069330efb22d2b644482e49e9388fb0927b73282"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO (kaimast): is this extra retain needed? It might be less expensive to keep the certificate and skip this additional iteration. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/helpers/dag.rs"},"region":{"startLine":169}}}],"partialFingerprints":{"codehealthFindingId/v1":"9bb9ed6f1e9e984a62169fee7237d24a5e45f8329533b7780e7faf4e6488eabb"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(kaimast): the round_start time should be based on the timestamp of the \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/primary/proposal_task.rs"},"region":{"startLine":93}}}],"partialFingerprints":{"codehealthFindingId/v1":"1984c65c8717473739ea244411582cec8223d6cc41b1bb1d25f9044d3eabd7fc"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO remove this once channels are gone \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/sync/mod.rs"},"region":{"startLine":242}}}],"partialFingerprints":{"codehealthFindingId/v1":"24a1337d7e998075a17b4e91bb258de3f718389e28fa0385039854e02f135ef9"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(kaimast): Should we remove the response here? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/sync/mod.rs"},"region":{"startLine":772}}}],"partialFingerprints":{"codehealthFindingId/v1":"cfac25d31e750c6f52216dbc4ac8a5c9b75fc24a7bfe7ea7c16a8114955c6ea9"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(kaimast): ensure there are no dangling block requests \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/sync/mod.rs"},"region":{"startLine":827}}}],"partialFingerprints":{"codehealthFindingId/v1":"18fe109730488e85c51038e68581becde05f320214506c75243d681ba68b8bcd"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO (raychu86): Consider making the timeout dynamic based on network traffic and/or the number of validators. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/sync/mod.rs"},"region":{"startLine":1040}}}],"partialFingerprints":{"codehealthFindingId/v1":"a191a6954f5329041fcccddbbe5fefb924e254be5f6b09f1007d1e16eaf0c609"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(nkls): the easiest would be to assert on the anchor or bullshark\u0027s output, once \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/tests/narwhal_e2e.rs"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"59164ee811022f2bb7e4d2f950927ce5212466acbae93806299578d7303dc44a"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(nkls): other event types, can be done as a follow up. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/tests/gateway_e2e.rs"},"region":{"startLine":92}}}],"partialFingerprints":{"codehealthFindingId/v1":"017917658bb6d31342e8794ec90d12dc9509b4297dce4d6d6e48285d42ca7249"}},{"ruleId":"D17","level":"warning","message":{"text":"FixmeComment: // FIXME(nkls): currently we can\u0027t assert on the disconnect type, the message isn\u0027t always sent \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/tests/gateway_e2e.rs"},"region":{"startLine":123}}}],"partialFingerprints":{"codehealthFindingId/v1":"c45758a7f9f2137c93e34bab2059f88edf9464220a14259c5e37c58bb037f003"}},{"ruleId":"D17","level":"warning","message":{"text":"FixmeComment: // FIXME(nkls): currently we can\u0027t assert on the disconnect type, the message isn\u0027t always sent \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/tests/gateway_e2e.rs"},"region":{"startLine":230}}}],"partialFingerprints":{"codehealthFindingId/v1":"7a58961dcca9b88b7a5e19933663e806a5aa83d7333bff34f6ffbf25c01767eb"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO (howardwu): Find a way to resolve integrity failures. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/cdn/src/blocks.rs"},"region":{"startLine":142}}}],"partialFingerprints":{"codehealthFindingId/v1":"cd08718e2faa7f8863fe33a7c36a74c8c6f2826af4d76ce71dc202d95a85bde5"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: simplify this once the duration_constructors feature is stable \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/cdn/src/blocks.rs"},"region":{"startLine":512}}}],"partialFingerprints":{"codehealthFindingId/v1":"41a80d5114205090616506624cad0784f7f6c0cfeb813e51fd8d4f2303d2da2f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(kaimast): wake up the loop after a proposal is created, not only when a block commits. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/consensus/src/lib.rs"},"region":{"startLine":536}}}],"partialFingerprints":{"codehealthFindingId/v1":"be91370e8ccc004a98ebc49d967f77fa93bbd1a3f0046fe564760f743ea4396b"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(kaimast): This should also remove any transmissions/solutions contained in the block from the mempool. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/consensus/src/lib.rs"},"region":{"startLine":703}}}],"partialFingerprints":{"codehealthFindingId/v1":"757aabdea5b283647ecdb7b296ac2194fc569faaa749ba5d016e5bd3156ab03b"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Should this be a blocking task? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/rest/src/routes.rs"},"region":{"startLine":1205}}}],"partialFingerprints":{"codehealthFindingId/v1":"440d719d8ecc67f579522d64656e3679a946a09a3d0ddce816eafea9a9b59096"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: after a release or two, we should always be expecting the version to be present, \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/messages/src/peer_response.rs"},"region":{"startLine":68}}}],"partialFingerprints":{"codehealthFindingId/v1":"1fedcc1cabe8c76d0f93c02c13a9479659ea2d80587b1f29c2ab561f8506ede6"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO switch to an iteration method that doesn\u0027t require manually updating this vec if variants are added \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/messages/src/disconnect.rs"},"region":{"startLine":65}}}],"partialFingerprints":{"codehealthFindingId/v1":"23f0ba8f0938a75f5662a572dad4324562b7ae93674c2d9c10c0a0ccd987981e"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO (howardwu): Serialize large messages once only. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/src/outbound.rs"},"region":{"startLine":37}}}],"partialFingerprints":{"codehealthFindingId/v1":"2f8bd77b6813b00007c6128156445e451e9886192b2e89594c327698ea146344"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO (howardwu): Serialize large messages once only. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/src/outbound.rs"},"region":{"startLine":65}}}],"partialFingerprints":{"codehealthFindingId/v1":"d33b134eefc2220f9b71e69527904233a7fcc4ea721d1f35e9f4087229347921"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: /// TODO (howardwu): Consider checking minimum number of validators, to exclude clients and provers. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/src/heartbeat.rs"},"region":{"startLine":87}}}],"partialFingerprints":{"codehealthFindingId/v1":"62916003d69542a4bf8b03ce71da38390d28f8d86b3b69e3da5d4dce61e43dfd"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO (howardwu): Remove this after specializing this function. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/src/heartbeat.rs"},"region":{"startLine":227}}}],"partialFingerprints":{"codehealthFindingId/v1":"14cea1b82577b6182acf7f67888ce1ed57d45394ef3de53292f62f3e5f62f3c4"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO (kaimast): Consider increasing the minimum time based on the number of failed attempts. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/src/heartbeat.rs"},"region":{"startLine":332}}}],"partialFingerprints":{"codehealthFindingId/v1":"730b48012c45910f956a664c0b85696d267ec5d8d4adb82b25c92d33cde1da20"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO =\u003E validator(0, 1, \u0026[], false, \u0026mut rng).await, \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/tests/cleanups.rs"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"eecf9d32441d61feeebc1cd42c2d1d0b46269ccfed8b4b4ba9c7d751f0387ed4"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //         // TODO (howardwu): Swap this with the official message for announcements. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/lib.rs"},"region":{"startLine":77}}}],"partialFingerprints":{"codehealthFindingId/v1":"9c4b61391a21525584ba8ea6a9562452c435f59cae278b40e72e346fb241e2ec"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: the router\u0027s handshake still uses the legacy protocol. When it is converted, dispatch \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/bootstrap_client/handshake.rs"},"region":{"startLine":213}}}],"partialFingerprints":{"codehealthFindingId/v1":"d1b079eebe2cee7fb12d247895f4d2a8b509672dd1e912a54b7517b2241a18d9"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO(kaimast): set disconnect reason based on error \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/client/router.rs"},"region":{"startLine":148}}}],"partialFingerprints":{"codehealthFindingId/v1":"e5667358c222fbaf237e04447614bc338964dc878d7c79135d760a353f620e06"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO(kaimast): should this return None instead? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/prover/router.rs"},"region":{"startLine":164}}}],"partialFingerprints":{"codehealthFindingId/v1":"12920fc4643f663340898a932c4f31a9986e459e2b9a91ad0e4ebcdc9b7b60bc"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO(kaimast): if this fails, the validator must be corrupted. Handle this with higher severity. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/validator/router.rs"},"region":{"startLine":56}}}],"partialFingerprints":{"codehealthFindingId/v1":"05226ace8f3c94c8ba9d3f5b12c8d69d255b8b094d68bac85262954b9042a08f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //         // TODO (howardwu): Switch to the iterator when DoubleEndedIterator is supported. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/validator/mod.rs"},"region":{"startLine":289}}}],"partialFingerprints":{"codehealthFindingId/v1":"d3973ffa3d1f092ea456cab670e770a1810b6d092418f5cfb851bbebea0a5975"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO (howardwu): Consider using \u0060BTreeMap::from_par_iter\u0060 if it is more performant. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/locators/src/block_locators.rs"},"region":{"startLine":108}}}],"partialFingerprints":{"codehealthFindingId/v1":"eb272a37deb797a2c08b953623782e70be88faaea6e1569069f451f749390694"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: generalize check for RECENT_INTERVAL \u003E 1, or remove this comment if we hardwire that to 1 \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/locators/src/block_locators.rs"},"region":{"startLine":216}}}],"partialFingerprints":{"codehealthFindingId/v1":"fbc66e4d967246117c56f227e0a5c24a722bd24fe8ef7cee56285e3fa84c12aa"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: generalize check for RECENT_INTERVAL \u003E 1, or remove this comment if we hardwire that to 1 \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/locators/src/block_locators.rs"},"region":{"startLine":270}}}],"partialFingerprints":{"codehealthFindingId/v1":"550413a1051058c4253d7abbd2ee8c30874bc07974754e635b85034403c9810e"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: /// TODO (kaimast): maybe keep track of the last ping too, to not trigger spam detection? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/ping.rs"},"region":{"startLine":38}}}],"partialFingerprints":{"codehealthFindingId/v1":"814238e012cd562f91ea7b12589e15287e3c4f9ad5191b0bc9b0aea40a722713"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(kaimast): base rate limits on how many requests were sent to each peer instead. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/block_sync.rs"},"region":{"startLine":78}}}],"partialFingerprints":{"codehealthFindingId/v1":"eac2f40e7c7259f1e63bcde12c9d3de1bc3f0c55f82c0097001e7f1c1901ba57"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: generalize this for RECENT_INTERVAL \u003E 1, or remove this comment if we hardwire that to 1 \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/block_sync.rs"},"region":{"startLine":414}}}],"partialFingerprints":{"codehealthFindingId/v1":"486b6a297642024fabfae820032b9398f7c752d993388e703df828fead21d68d"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(kaimast): remove this eventually. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/block_sync.rs"},"region":{"startLine":688}}}],"partialFingerprints":{"codehealthFindingId/v1":"9cd4fd354a677d8b1f756f7cfd4fbcb7bb00928c49bd6f987f461b9993e94dda"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: /// TODO (howardwu): Remove the \u0060common_ancestor\u0060 entry. But check that this is safe \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/block_sync.rs"},"region":{"startLine":915}}}],"partialFingerprints":{"codehealthFindingId/v1":"c3823fddb9dc6f0325c4025b8bd3d2d49263dd73e5565e4a19f4d2383913ac63"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: /// TODO(kaimast): remove this public function once the sync logic is fully unified \u0060BlockSync\u0060. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/block_sync.rs"},"region":{"startLine":1146}}}],"partialFingerprints":{"codehealthFindingId/v1":"fc829f7bed6d77eda500e62756c00b6da7314bc058454a11c8bd132b84f9e9c9"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Uncomment this when we have a more rigorous analysis and testing of peer banning. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/block_sync.rs"},"region":{"startLine":1442}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a99d64c37ffd56569c87478e65d87e04600f18068d8f90e480830bbecb36ae3"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO (howardwu): Change this to the highest cumulative weight for Phase 3. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/block_sync.rs"},"region":{"startLine":1476}}}],"partialFingerprints":{"codehealthFindingId/v1":"c0ab1dc5e8bff309792e37ea1279a8b9b86eb27dc53970ba1b806bc344095a33"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO (howardwu): Consider performing an integrity check on peers (to disconnect). \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/src/block_sync.rs"},"region":{"startLine":1586}}}],"partialFingerprints":{"codehealthFindingId/v1":"a63f48b50ebc71a1a79ab7b97d117d5d92c746bbf3fddd241b6c09099e227635"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: /// TODO(kaimast): (some of) these should be treated with higher severity, as they indicate a bug or corrupted state, \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/tcp/src/tcp.rs"},"region":{"startLine":94}}}],"partialFingerprints":{"codehealthFindingId/v1":"b28cb92d4d4c0a8c65f0de9612aa6b07204ada45f7441429f39621cfa8ba9285"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(nkls): maybe this first check can be dropped; though it might be best to keep just in case. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/tcp/src/tcp.rs"},"region":{"startLine":305}}}],"partialFingerprints":{"codehealthFindingId/v1":"80fdec0436ed1fcb78c2cf4176737d4d169848788eb35d9dfca49d606efff77c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(nkls): add assertions on the contents of messages. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/tests/common/test_peer.rs"},"region":{"startLine":155}}}],"partialFingerprints":{"codehealthFindingId/v1":"2017ae5a4772bcc6b716d4f787d27a68a10026da0c1e2dc6cc8ab2fa1c10eb80"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no installation or build instructions: There are no installation/build/run instructions for the node/sync/locators crate. Add a short install line (cargo add or cargo.toml import) plus how to build and run an example."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/locators/README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ea38179f6ef9a557a2b4a911498790181278af76efba71850e4389ff5626490e"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no usage examples: The README describes the BlockLocators struct and its operations but gives no usage examples. Add a one-line example showing how to construct, check, or serialize/deserialize a BlockLocators instance."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/sync/locators/README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"357c91119f984fa8ab116659f3465fd9560728526fbf942cad4f24e17c005c17"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found. No recognised ADR directory (\u0060docs/adr/\u0060, \u0060docs/decisions/\u0060, \u0060adr/\u0060, \u0060docs/rfcs/\u0060, an \u0060ADR0001/\u0060 folder, or their siblings) exists anywhere in this tree. What was searched, so you can tell an empty log from a search that missed one: every directory under the tree (build output, dependencies and VCS metadata excepted), for a document that is either any non-index page inside a recognised ADR directory, whatever its name and however deeply nested (\u0060docs/adr/use-postgres.md\u0060, \u0060docs/adr/2024/0001-x.md\u0060); or a file anywhere whose name is ADR-shaped (\u00600001-use-postgres.md\u0060, \u0060adr-012-caching.md\u0060); or, when neither turned anything up, a document carrying the decision-record signature (an \u0022Architecture Decision Record\u0022 heading, or Status / Context / Decision / Consequences as section headings). A decision log that clears none of these \u2014 unnumbered files outside any recognised directory, without those headings \u2014 is not seen by this check and this row is then wrong. If that is your case, say so rather than renaming anything; otherwise, consider recording architectural decisions in \u0060docs/adr/\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D22","level":"warning","message":{"text":"Inconsistent naming convention for data type variants. \u0027sign_bytes\u0027 uses the type name, while \u0027sign_bits\u0027 uses the pluralized type name. \u0027sign\u0027 is ambiguous as it takes a generic Field array but lacks a suffix.: Standardize to \u0027sign_bytes\u0027, \u0027sign_bits\u0027, and \u0027sign_fields\u0027 (or \u0027sign_fields\u0027, \u0027sign_bytes\u0027, \u0027sign_bits\u0027) to clearly indicate the input data type in all method names. (signatures: Account.sign(message: \u0026[Field\u003CN\u003E], rng: R): Result | Account.sign_bytes(message: \u0026[u8], rng: R): Result | Account.sign_bits(message: \u0026[bool], rng: R): Result)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"06a93b1732399a8ddefef56bc3a8e7e5cf14d668bfb3c45da9c0687bfbc5738b"}},{"ruleId":"D22","level":"warning","message":{"text":"Same inconsistency as sign: \u0027verify_bytes\u0027 vs \u0027verify_bits\u0027. The generic \u0027verify\u0027 for Fields is inconsistent with the explicit suffixes used for other types.: Rename \u0027verify\u0027 to \u0027verify_fields\u0027 to match the pattern of \u0027verify_bytes\u0027 and \u0027verify_bits\u0027. (signatures: Account.verify(message: \u0026[Field\u003CN\u003E], signature: Signature): bool | Account.verify_bytes(message: \u0026[u8], signature: Signature): bool | Account.verify_bits(message: \u0026[bool], signature: Signature): bool)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6ca730e4f426f4bff54267fe88ecc3f17618f33192a9b777f33388c836d55758"}},{"ruleId":"D22","level":"warning","message":{"text":"Duplicate function signatures with different parameter names (one named \u0027path\u0027, one \u0027_path\u0027). This suggests an overload or a copy-paste error in the API surface, which is confusing for consumers.: Remove the duplicate. If they are distinct overloads (e.g., different generic bounds not shown), ensure the signatures are distinct. If identical, keep only one. (signatures: snarkos_cli.check_parent_permissions(path: T): Result | snarkos_cli.check_parent_permissions(_path: T): Result)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0015d2934ffac030a93d95ab2b03586cadd61ee29423d10f8f83871e51666d53"}},{"ruleId":"D22","level":"warning","message":{"text":"While these are inverse operations, the naming is slightly asymmetric. \u0027get_block_height\u0027 implies getting the height of a block (given a hash), but \u0027get_block_hash\u0027 implies getting the hash of a block (given a height). This is acceptable but could be clearer.: Consider renaming to \u0027height_from_hash\u0027 and \u0027hash_from_height\u0027 for absolute clarity, or keep as is if the context is obvious. (Low severity, but noted for consistency). (signatures: LedgerService.get_block_height(hash: BlockHash): Result | LedgerService.get_block_hash(height: u32): Result)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c3d049a4044dd15826883e946e70c4f90d42a53c6fdd4bda0786dd03dc26b615"}},{"ruleId":"D22","level":"warning","message":{"text":"Inconsistent return types for \u0027contains\u0027 operations. \u0027Storage\u0027 returns a boolean, while \u0027LedgerService\u0027 returns a Result. This forces callers to handle errors differently for similar existence checks.: Standardize \u0027contains\u0027 methods to return bool if they cannot fail, or Result if they can. Given these are likely simple lookups, bool is preferred for consistency across the codebase. (signatures: Storage.contains_certificate(certificate_id: Field): bool | LedgerService.contains_certificate(certificate_id: Field): Result)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1ac5549fb987bc4813b86895526acfa0a860684ec07ca8f56f93300a64064f00"}},{"ruleId":"D22","level":"warning","message":{"text":"Two methods with similar names and signatures that check for different states of the same entity. This can be confusing.: Ensure the distinction is clear in documentation. Consider if \u0027contains_certificate\u0027 should imply \u0027unprocessed\u0027 or if a more explicit name like \u0027contains_processed_certificate\u0027 is needed. (signatures: Storage.contains_unprocessed_certificate(certificate_id: Field): bool | Storage.contains_certificate(certificate_id: Field): bool)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e57282b07931fcc8c6b5b16b69191376106cfe6a37421a39487d3db2620a23e4"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3d0220c890dc13dbc52b05c1c1e6c9aa09fb128c078403953022f6b6e49ad1bb"},"properties":{"commitSha":"2b3e779c1b1a96672d54d82b17a9051931a00509"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"12cd7b6043fdfa43551b8c6c46d6f26359adadc7debcce8233025e247b77c7fb"},"properties":{"commitSha":"2b3e779c1b1a96672d54d82b17a9051931a00509"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"49f9b2c104e41753ffa1458403fb672485e94de77951f178b01f82e22b28d1a2"},"properties":{"commitSha":"2b3e779c1b1a96672d54d82b17a9051931a00509"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b0443d4698db2d219cb909bef235a2d3ab9cdc3a424d99f8260ae6acbb8f62ae"},"properties":{"commitSha":"2b3e779c1b1a96672d54d82b17a9051931a00509"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"24ed31bf93f010574edcf388d64cdeabb603214192b5bf62400bcc983ca2bc27"},"properties":{"commitSha":"2b3e779c1b1a96672d54d82b17a9051931a00509"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"96e21c479a6311a136442fadd71f47bd4bcb6191831505a03a3b16ea14ab139a"},"properties":{"commitSha":"ebea25c4ebbec46cfafec8a8d67a3648ddb08832"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"51eebe3acbead7d2aabc6c5416bc0d7cb672bfa9d93429adffcbb2b8678935af"},"properties":{"commitSha":"7d5ad5420b8d57115ca12e9252d66e594fddfcda"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"764aeb1d7ef98cd54f9020566e1df244ec1b77fb695420117d47425e80dbacca"},"properties":{"commitSha":"6d63e9ad5eff08546f2dde9e86ba15db38aa4168"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"38082b19d79c2b5cf5ff108630203c835dc792c6e60250ec62b6701e0aed7d4b"},"properties":{"commitSha":"6d63e9ad5eff08546f2dde9e86ba15db38aa4168"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6da31c22ddfcfe19bb7b42f275020bb9c406b50142974b4a5c44f28e23c203a1"},"properties":{"commitSha":"6d63e9ad5eff08546f2dde9e86ba15db38aa4168"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1b8830ace47ddaf8d466eb68330d95a6b6f43f357289166dfb781b8fbccfe00b"},"properties":{"commitSha":"6d63e9ad5eff08546f2dde9e86ba15db38aa4168"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4caed737dfb0c397f69838198bca38143930652026021410d2a314cd3025c0d9"},"properties":{"commitSha":"6d63e9ad5eff08546f2dde9e86ba15db38aa4168"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ed5afe1564dba90cf0b13ecfb29d095be565baf35af4d8110bac5ccbb7041c42"},"properties":{"commitSha":"4592f49eb123270562a92d44bcf284ab0f373120"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"87aeb268fe2d1216fb24058a26161de925799b9f7bd463b29491032f5f5399bb"},"properties":{"commitSha":"b0efbd4e124048aa679b0892b534a154ab62437d"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b7e979b985cf4f0cfb9dfe19f42da07c71216ef27a258378e69e3402312c7cc5"},"properties":{"commitSha":"4572958c20c7eef06760620987c5147d2e1fafcc"}},{"ruleId":"D28","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3cdfd7beb31b791ae18dcb425e21eb157c842e7bbcd522cc330573c1a6538db1"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"31c659e3aa5413b447a0ac1e6fc7470f89e8e04308ea42f10d660a9ea7712c2a"},"taxa":[{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dfb3ac523c6fdbb48fbf7cf7aa218d25426cfe9571c224c39723634b2102276f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b5ccdbb4f94bf4ccf0ca287f2ad270f88200f7b47357057f8b4aaca0872fd8fb"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b0bc63adb650e8f60db6eb87dc7be4a3f48eaa8cd62bcbc37b908193d30b0ad0"},"taxa":[{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c0a97083d54255e73c43cccc3fdf818bfe2c0037e251b4a7518bc6564bc54491"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a4987d2925df1e9e16284313fa27ec64963a62aa0728d586f1ee26b244d28b9b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b5ff4535b6cef7f0b4a1c5e875f422004b597b26f6126adbf6ad8273641a45a6"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5dec74475ef441cb9ce38a9903cc2f81bcd38ef2d8cf8620101f43ad1a804c37"},"taxa":[{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d1eb810622cdbeeb79922dbe88063e7f2b31b39609e6903010f330dd86d09d64"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"076388f1f0d3e3d2bd48d54209dac090644e48308836a28163fca9e773a072b4"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7e58f76cabe74ae821b0c2f44fa7f1a0de480fc6ef6fa11ebb119b6d8bb8bb0c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"baa7add24d326677723858e5ddba38293396e0ba7c8820345cb2fcbd8a90fa73"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"64c31f373687d877d5442556624451898111b2026308d82fa264c62d154292f0"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3696c7f606d1160f562017f67f4c6919b3ec17fa795cf7fc53bc5654555a2a92"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f9976ad9cf6373713606ae7ab05bcfda2eacfc36f22323a03907e8f4fc808375"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5be03ab325ce0dd57044d4e411f1428508ecf7870bea56774afff406be2e7ce3"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"57d94ecf1e4e1b67a0a20e1126764020d74cc51d3a14b0d8b3faf921de4f9ffd"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0f8986e6b3f3a09e0cb398181e46b53cc39953a8c08c0faa27144d0a6a67e8ed"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cd25e2b83ac639dcce62732f13612d523e8aef52d4618f47fd6e8fade8bafee2"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"865c1256b0af6cac7fabd52ec1703a6840a81e82c2cc09619e5e78e47af02756"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"75369c09bb288495c1ec96550eb2aa9585bb73f2d0abcdd876376a94900b52cc"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3697f1522e19a638b7ef88b7aaf49350d5b9b08b7c831fcbc85b3c68f84dd986"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"97f8ce7f4667033a56ccb1c51fc84b6fec73b07f66f8d2f18eee07db3bb667f1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e7c0f9c8293ac4302cb0c73a803b1e600dd92aa45994f24cce64b0c3466566f9"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e8e18d2a8f20376724197f4821264a0a9f0e273d56749195409cdb6066877285"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3643ff687baaf09e4fa86f24721b381bb8ec583e4fb1bc9174a893ca376bdfb1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dcb3e35b7ceb6e066202e8b0d09947e3c69a91f2942e781ff30459e207796cd0"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4ce6a072223ebefdcaac2c4fd5578e4e09519e88c54080cc685c6ec6eb75ead8"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"73a940446f8019b2f586f4d61a4dbd7bfa91760ac661bb8099b537f723e814c8"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"94a5aac744cec20fcd4bd49e3dc733665c735fff55525a54e3d6a7e747b619c0"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"804073c83b7c7c9ae6207c56177dc02c63fff031ea3d85113c185b950c5f30f8"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"63778fa624412affc09bbae17ed4e235deee47c1e8fbbd49594e08c2f223c987"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-552","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"be9977d5d7ddb867e7f2e9fb5ad301e217dd9c03427d8e948d094761434f4502"},"properties":{"dependency":{"package":"jsonwebtoken","version":"9.3.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"da9ce41d3dc2da176b4e1aa86f2ae1a68df334c8ac5ad721abff2335197b0ec1"},"properties":{"dependency":{"package":"tracing-subscriber","version":"0.3.19","advisory":"RUSTSEC-2025-0055","aliases":["[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5922a5beeab5ac077ffb485a783ad545036e79b56239f83da38f3fb84336b113"},"properties":{"dependency":{"package":"paste","version":"1.0.15","advisory":"RUSTSEC-2024-0436","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a42ca7416279f52063a649dbc505340ffc7c7a5727193e601ae1de8d6db75e3d"},"properties":{"dependency":{"package":"fxhash","version":"0.2.1","advisory":"RUSTSEC-2025-0057","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4975822701b3b96654c82dada9bad969e348a6adefa52cd3bba1b6cfd71c3bb7"},"properties":{"dependency":{"package":"bincode","version":"1.3.3","advisory":"RUSTSEC-2025-0141","reachability":{"kind":"unknown"}}}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1692320ceb71fe33332cdc0c6936db759d4bbf5a6d1b9b223f111c4f0b50b109"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6820ec07c0135e0c87a6d0a679bc264d38644890f21f7db0d37060edee1a6d7d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D34","level":"note","message":{"text":"Orphaned files with no living knowledge: 10 of 141 analysed file(s) have no living knowledge left \u2014 their last meaningful change has decayed away, so if one breaks, no one currently understands it (counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 141 of the 169 production source files in this repository met that bar). None is large enough to earn a read-through of its own, so this row stands in for the per-file rows rather than raising one each \u2014 most significant first: account/src/lib.rs, node/router/src/writing.rs, node/bft/events/src/transmission_response.rs, cli/src/helpers/dynamic_format.rs, node/bft/src/helpers/partition.rs, node/bft/events/src/challenge_response.rs, node/bft/events/src/block_request.rs, cli/src/helpers/bech32m.rs (and 2 more). Attach the read to the next change that touches one of them: have a second person review that change, and leave behind a short comment or test recording what the file is for, so the knowledge comes back at the cost of a change you were making anyway."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ce861fd78f6935114d3a342cb90ad25870f984e1042954fcbbe27c0e23be3658"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: mock.rs \u2194 prover.rs: \u0060node/bft/ledger-service/src/mock.rs\u0060 and \u0060node/bft/ledger-service/src/prover.rs\u0060 change together 80% of the time (8 of the 10 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well, and counted over this repository\u0027s 10,000 most recent commits rather than its whole history \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking. You can check this without leaving the row: of the 8 shared commits counted here, the most recent 3 are \u0060d5b354c8\u0060 ref: set execution cost to 10 credits in \u0060MockLedger\u0060; \u00604970d1ac\u0060 Minor fixes (at that commit the files were still \u0060node/narwhal/ledger-service/src/mock.rs\u0060 and \u0060node/narwhal/ledger-service/src/prover.rs\u0060); \u00602e33fa48\u0060 Introduce get_previous_committee_for_round (at that commit the files were still \u0060node/narwhal/ledger-service/src/mock.rs\u0060 and \u0060node/narwhal/ledger-service/src/prover.rs\u0060) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/ledger-service/src/mock.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"8834d7d5f97577d9c122ca573d62224070309c01fd35561159482ff4236e10a7"}},{"ruleId":"D35","level":"warning","message":{"text":"Change-coupling hub: test_helpers.rs \u2192 router.rs, router.rs, router.rs: \u0060node/router/src/test_helpers.rs\u0060 changes together with 3 other files \u2014 \u0060node/src/client/router.rs\u0060, \u0060node/src/prover/router.rs\u0060, \u0060node/src/validator/router.rs\u0060 \u2014 none of which declares a dependency on it: one file is the hub of 3 separate couplings, not 3 unrelated pairs. Read the hub first: if the others each duplicate a part of what it does, the shared concern belongs in ONE unit and extracting it clears every edge at once; if the hub is a registry, dispatcher or barrel that must name each of them, the coupling is structural and the question is whether that list can be discovered instead of enumerated. Fixing the hub is one change; breaking the couplings one pair at a time is 3."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/router/src/test_helpers.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b772d7a4407f9db6419b901c2135a1c24cf3a4994ff759c51d9254d186b3fe2b"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling clique: deploy.rs, execute.rs, transfer_private.rs: 3 files \u2014 \u0060cli/src/commands/developer/deploy.rs\u0060, \u0060cli/src/commands/developer/execute.rs\u0060, \u0060cli/src/commands/developer/transfer_private.rs\u0060 \u2014 all change together with no explicit dependency: a fully-connected co-change clique, not 3 separate couplings. They share one concern (thin parallel siblings over a common abstraction), so extract the shared part into ONE unit and the whole clique\u0027s coupling clears at once \u2014 you do not need to break each pair individually."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/developer/deploy.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"50a2673a11e65fb68aa510d36ab0226650706156883e28335446e1fa19188654"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: memory.rs \u2194 persistent.rs: \u0060node/bft/storage-service/src/memory.rs\u0060 and \u0060node/bft/storage-service/src/persistent.rs\u0060 change together 67% of the time (14 of the 21 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well, and counted over this repository\u0027s 10,000 most recent commits rather than its whole history \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking. You can check this without leaving the row: of the 14 shared commits counted here, the most recent 3 are \u00601ece35a8\u0060 docs: address the review comments; \u006047bf742a\u0060 fix: count an already-aborted transmission ID under storage locks; \u0060ac90b6d7\u0060 refactor: remove contains_transmission \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/storage-service/src/memory.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ab3ccd843cfa676d9a56f8ddea66c0a53ce37a2666f33f79a7e005ebe12f544e"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: certificate_response.rs \u2194 storage.rs: \u0060node/bft/events/src/certificate_response.rs\u0060 and \u0060node/bft/src/helpers/storage.rs\u0060 change together 67% of the time (8 of the 12 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well, and counted over this repository\u0027s 10,000 most recent commits rather than its whole history \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 8 shared commits counted here, the most recent 3 are \u00600bcb7607\u0060 Use committee_id in tests; \u0060ce873652\u0060 Reverts election certificates; \u00603d108ca4\u0060 tests: remove author from batch signing \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/events/src/certificate_response.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"6a6b2784e84b23dd5ac4d9cff68d1b27f94ea1bfaea45177d14e71f1ed729bc6"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: mod.rs \u2194 mod.rs: \u0060node/src/client/mod.rs\u0060 and \u0060node/src/validator/mod.rs\u0060 change together 61% of the time (82 of the 135 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well, and counted over this repository\u0027s 10,000 most recent commits rather than its whole history \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 82 shared commits counted here, the most recent 3 are \u006069363e86\u0060 Remove unused and untested slipstream-plugins support.; \u00602a4fc8cf\u0060 Allow operators to limit REST verification concurrency at startup.; \u0060c1a2dcad\u0060 feat(rest): serve the \u0060history\u0060 routes from the Provable historical API \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/client/mod.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3f0754d847effd0d7b1ac8e273e46e658041ce358beadd8a471ecf820c484df7"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: ready.rs \u2194 primary.rs: \u0060node/bft/src/helpers/ready.rs\u0060 and \u0060node/bft/src/primary.rs\u0060 change together 52% of the time (25 of the 48 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well, and counted over this repository\u0027s 10,000 most recent commits rather than its whole history \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 25 shared commits counted here, the most recent 3 are \u0060a8e0a8d8\u0060 ref: improve worker draining logic; \u0060e2595c44\u0060 Revert \u0022Revert \u0022Merge pull request #3266 from AleoNet/optimize/clear-\u2026; \u006099592f43\u0060 Revert \u0022Merge pull request #3266 from AleoNet/optimize/clear-solutions\u0022 \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/src/helpers/ready.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"cc584731e5019401ea85ee7ed42463c8c33aed6584a2358a60f40eec4346b539"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: mod.rs \u2194 mod.rs: \u0060node/src/prover/mod.rs\u0060 and \u0060node/src/validator/mod.rs\u0060 change together 51% of the time (56 of the 110 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well, and counted over this repository\u0027s 10,000 most recent commits rather than its whole history \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 56 shared commits counted here, the most recent 3 are \u006062caba23\u0060 refactor: attach the Ping task to the Router; \u0060edd71893\u0060 fix: no more zombie tasks on shutdown; \u00604ec2f561\u0060 first pass at plumbing for slipstream plugins \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/prover/mod.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"90143ed92de5df78855667c4870044792ec7a3f4f7a8ee9ed1ecbb60fdf5a725"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1b213f6eedd4b140d0bc37bdf1496f72811a643f34064f12518b32e9e83bcfc7"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e17f71490e4d120a48b2b2881ab866c93b272bef2febb673a3e8e42b2c288ab"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"759dca709f1a032fb6f624ce672e6afb5558fce53ecf01fb73618c4d33923164"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eb00976a698a5d68999b7ee6d27206fd374e916853e7ff1ead5eed42386f043f"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"90f83b4fa27db32740afe9540c905f3c0499caed87f61049a8a903ecc95b41c3"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ca7d9e09d8445ab0ff26d9fb8af02cea8f9e3ebf8370318c85ba3cd724d86463"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"40ed688c2d8355a779f206c5f45af5c6a26fb4cae09f6d4109127f9351abf0ca"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1ae293ce5d00c64f9fe36fad06531a59d9923eca1c6f5991b41ebe62d4e553d0"}},{"ruleId":"D44","level":"warning","message":{"text":"End-of-life runtime: Rust 1.96: rust-toolchain.toml declares Rust 1.96 as this project\u0027s toolchain file, and Rust 1.96, superseded by 1.97 on 2026-07-09 (the Rust project patches only the current stable). An unsupported runtime receives no security patches, so every vulnerability disclosed in it since 2026-07-09 is present and unfixable without moving off it. This is a migration rather than an upgrade: there is no newer release of a runtime that has ended."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b4d8e9b51cd4b2493b326110bfe409c9598039c510d25150fcc40f653a675ac1"}},{"ruleId":"ES2","level":"error","message":{"text":"Mutable domain event: Event: \u0060Event\u0060 conforms to a domain-event contract but carries a freely-mutable \u0060pub\u0060 field. Events are immutable facts \u2014 model them with private fields (set once in the constructor) so a recorded event can never be rewritten."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/bft/events/src/lib.rs"},"region":{"startLine":97}}}],"partialFingerprints":{"codehealthFindingId/v1":"bd5523ead0805832ea0c69b1a99d49a0c8f887f654a23af419dcb3257fdf521d"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"M2","level":"note","message":{"text":"No architecture diagram/doc: No C4/Structurizr/PlantUML/Mermaid/Graphviz/D2 diagram, no drawn diagram named for the architecture, no file named \u0060architecture\u0060 or \u0060design\u0060 in any markup this check reads, and nothing in the README, docs or contributor guides that announces the shape \u2014 no \u0060## Architecture\u0060 heading, no \u0022architecture overview\u0022/\u0022high-level design\u0022 phrasing, no \u0022the architecture is \u2026\u0022 introduction, no guided code tour. A shape laid out in prose that never names itself as the architecture is not visible to this check, and neither is one kept outside the repository, so this row reports the absence of a re-findable shape document \u2014 not evidence that nobody wrote the shape down."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0c190e7c159d1850ee706c3ac4486e151e8a4fe169de4bf61436b9f399654f06"}},{"ruleId":"P4","level":"note","message":{"text":"No rollback/health safety: Deployment is orchestrated by compose, but no service declares a \u0060healthcheck:\u0060 and nothing pins a previous image to fall back to \u2014 the runtime can tell that the container is up, not that it is serving, so a bad release is harder to detect and reverse."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"db6bab8a28a2145f47e5a4e6683cda39d2ba0296c723238e8057da979ae1c706"}},{"ruleId":"P4","level":"note","message":{"text":"No release approval gate: Deployment is automated and no gate that pauses it for a human is DECLARED IN THIS REPOSITORY\u0027S PIPELINE FILES. What was read: every file under \u0060.github/workflows/\u0060, \u0060.forgejo/workflows/\u0060, \u0060.gitea/workflows/\u0060, \u0060.azuredevops/\u0060 and \u0060.azure-pipelines/\u0060, plus \u0060.gitlab-ci*\u0060 and \u0060azure-pipelines*\u0060 \u2014 with comment text stripped, so documenting a gate is not declaring one. What would have counted: GitLab\u0027s \u0060when: manual\u0060, CircleCI\u0027s \u0060type: approval\u0060, an Azure \u0060ManualValidation@\u0060 task or an \u0060approvals:\u0060 block, a Jenkins \u0060input\u0060 step, a \u0060uses:\u0060 step naming an approval action, an \u0060environment:\u0060 paired with \u0060reviewers\u0060 / \u0060required_reviewers\u0060 / \u0060protection\u0060 / \u0060wait-timer\u0060 / \u0060deployment_branch_policy\u0060, a draft-release step, a \u0060workflow_dispatch\u0060 promotion, or a release-event gate. \u2605 What this cannot see, because none of it is a file: a GitHub environment whose required reviewers are configured in repo SETTINGS, a branch protection rule, or an organisation deployment policy \u2014 all of them real, enforced gates that live outside the repository. If yours is one of those, this row is wrong and nothing in the tree could have told us. Otherwise: whatever reaches the release trigger goes to production unreviewed, so a mistaken merge or tag is live before anyone can stop it."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6c11e2dbd483b4b423b95ac61bfcc7af1d55351b28a20d2b1105b31cfe38cc60"}},{"ruleId":"P6","level":"note","message":{"text":"No changelog: No CHANGELOG/HISTORY/RELEASES file \u2014 what shipped when isn\u0027t easy to reconstruct for support or audit. (Versioning/tagging makes releases traceable, but a changelog records the what.)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"dda5aa5aed8cbb292c3ef2b733bc138f614293ae6426c85e98bf31ef330d9415"}},{"ruleId":"P7","level":"warning","message":{"text":"Outbound HTTP without resilience: \u0060ureq::post(\u0060 makes an outbound HTTP call, and nothing bounds it: no timeout, deadline, retry or circuit breaker is set for it here, and the client has no process-wide default. A slow or failing dependency will hold this service\u0027s request, thread or connection until the call gives up on its own \u2014 or never, for a client with no default timeout. 4 of the 5 files that make outbound calls are unbounded; the first 4 are listed."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/developer/mod.rs"},"region":{"startLine":305}}}],"partialFingerprints":{"codehealthFindingId/v1":"17d888ef72f7caad6ceb16bea9e9f69c65aaeb67bad6c1d95d80d5396514cfdb"}},{"ruleId":"P7","level":"warning","message":{"text":"Outbound HTTP without resilience: \u0060ureq::get(\u0060 makes an outbound HTTP call, and nothing bounds it: no timeout, deadline, retry or circuit breaker is set for it here, and the client has no process-wide default. A slow or failing dependency will hold this service\u0027s request, thread or connection until the call gives up on its own \u2014 or never, for a client with no default timeout."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cli/src/commands/developer/scan.rs"},"region":{"startLine":156}}}],"partialFingerprints":{"codehealthFindingId/v1":"010bf8c3589e5a7b0fbd953322442c212b798450619e706ec96f74b9d2d28cd8"}},{"ruleId":"P7","level":"warning","message":{"text":"Outbound HTTP without resilience: \u0060Client::builder()\u0060 makes an outbound HTTP call, and nothing bounds it: no timeout, deadline, retry or circuit breaker is set for it here, and the client has no process-wide default. A slow or failing dependency will hold this service\u0027s request, thread or connection until the call gives up on its own \u2014 or never, for a client with no default timeout."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/cdn/src/blocks.rs"},"region":{"startLine":175}}}],"partialFingerprints":{"codehealthFindingId/v1":"f241e4a4d4380d8b30925ca2f5890f275a14b726d40ac72bcd10d6d21067b925"}},{"ruleId":"P7","level":"warning","message":{"text":"Outbound HTTP without resilience: \u0060reqwest::Client::new(\u0060 makes an outbound HTTP call, and nothing bounds it: no timeout, deadline, retry or circuit breaker is set for it here, and the client has no process-wide default. A slow or failing dependency will hold this service\u0027s request, thread or connection until the call gives up on its own \u2014 or never, for a client with no default timeout."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"node/src/bootstrap_client/mod.rs"},"region":{"startLine":98}}}],"partialFingerprints":{"codehealthFindingId/v1":"cb44ed9d99973f735151aaa697accfd9c436cc26c0ea82ef8f9fba026cb22b4c"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-522","guid":"71fb233e-ce6a-ae57-9419-ef8373540b09","name":"CWE-522","shortDescription":{"text":"CWE-522"},"helpUri":"https://cwe.mitre.org/data/definitions/522.html"},{"id":"CWE-552","guid":"3492436b-eca2-9c54-9ba3-5dade427c903","name":"CWE-552","shortDescription":{"text":"CWE-552"},"helpUri":"https://cwe.mitre.org/data/definitions/552.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-829","guid":"13c33925-97fb-5a5e-b40c-56d328b8a4d7","name":"CWE-829","shortDescription":{"text":"CWE-829"},"helpUri":"https://cwe.mitre.org/data/definitions/829.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":66,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}