{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AXB1","name":"Runtime evidence locked \u2014 no reproducible boot","shortDescription":{"text":"Runtime evidence locked \u2014 no reproducible boot"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB1"},{"id":"ED5","name":"Idempotency","shortDescription":{"text":"Idempotency"},"helpUri":"https://codehealth.canine.dev/dimensions/ED5"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"PF1","name":"Benchmark discipline","shortDescription":{"text":"Benchmark discipline"},"helpUri":"https://codehealth.canine.dev/dimensions/PF1"},{"id":"SC1","name":"Supply-chain hygiene","shortDescription":{"text":"Supply-chain hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/SC1"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X28","name":"Index access outside its own emptiness guard","shortDescription":{"text":"Index access outside its own emptiness guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X28"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"Internals.encodeStream (cyclomatic 49): Internals.encodeStream has cyclomatic complexity 49 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":314}}}],"partialFingerprints":{"codehealthFindingId/v1":"4878f758408d31fb7eed94817c93e84c25af88b974948e172b79a3b823c95c4d"}},{"ruleId":"D1","level":"warning","message":{"text":"Internals.checkNoValidETag (cyclomatic 20): Internals.checkNoValidETag has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":139}}}],"partialFingerprints":{"codehealthFindingId/v1":"27182bfa6db5856bc4978ea387c313862f698de64890655e4796cb4cb45425d9"}},{"ruleId":"D1","level":"warning","message":{"text":"Internals.encodeFile (cyclomatic 18): Internals.encodeFile has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":230}}}],"partialFingerprints":{"codehealthFindingId/v1":"0bd60dbd1e98821a7a6294995c7e5b498a60cdf5d3c8ed9eff94b30f8b68759e"}},{"ruleId":"D1","level":"warning","message":{"text":"Internals.compress (cyclomatic 18): Internals.compress has cyclomatic complexity 18 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":469}}}],"partialFingerprints":{"codehealthFindingId/v1":"5cb05b24daffee9f097a388028a5a23feeb4d75be559bb37e374b7eb70c73bb8"}},{"ruleId":"D2","level":"warning","message":{"text":"Internals.encodeStream (cognitive 70): Internals.encodeStream has cognitive complexity 70 (threshold 15). Drivers by points: if/else 25 (43 pts), boolean chains 15, match/switch 5 (9 pts), error handling 1 (3 pts) (nesting depth added 24). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":314}}}],"partialFingerprints":{"codehealthFindingId/v1":"873754520bce2046505b9f20f8aadedfde23addab0010a47e6496ea012bee0c8"}},{"ruleId":"D2","level":"warning","message":{"text":"Internals.checkNoValidETag (cognitive 37): Internals.checkNoValidETag has cognitive complexity 37 (threshold 15). Drivers by points: if/else 10 (25 pts), match/switch 5 (9 pts), boolean chains 3 (nesting depth added 19). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":139}}}],"partialFingerprints":{"codehealthFindingId/v1":"79b892d5528eafdc275de25f3ce339581862b8133a786ebad1a9172ab08d2e68"}},{"ruleId":"D2","level":"warning","message":{"text":"Internals.encodeFile (cognitive 35): Internals.encodeFile has cognitive complexity 35 (threshold 15). Drivers by points: if/else 14 (26 pts), boolean chains 4, error handling 1 (3 pts), match/switch 1 (2 pts) (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":230}}}],"partialFingerprints":{"codehealthFindingId/v1":"e764031492a8c4eb9ecba1112b64f3722ac498149549a74b101a96eead017cc9"}},{"ruleId":"D2","level":"warning","message":{"text":"Internals.compress (cognitive 21): Internals.compress has cognitive complexity 21 (threshold 15). Drivers by points: if/else 11 (13 pts), match/switch 4 (5 pts), boolean chains 3 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":469}}}],"partialFingerprints":{"codehealthFindingId/v1":"0e1ffe610394ce1cf19d9f240b398452049463f8b9a03adc3f50a32bdbb79670"}},{"ruleId":"D2","level":"warning","message":{"text":"Internals.getFile (cognitive 16): Internals.getFile has cognitive complexity 16 (threshold 15). Drivers by points: if/else 8 (11 pts), match/switch 3, boolean chains 1, error handling 1 (nesting depth added 3). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":180}}}],"partialFingerprints":{"codehealthFindingId/v1":"5e86751653a9cd59c048312782ae54171d6690f33eebdd63701073bc345a5d13"}},{"ruleId":"D4","level":"warning","message":{"text":"Near-duplicate member pair (249 shared lines): src/Owin.Compression.Standard/CompressionModule.fs:7-565 | src/Owin.Compression/CompressionModule.fs:1-495 \u2014 These two members are variants of one another: 249 of their lines are already reported as duplicated blocks below, spread through both bodies rather than gathered into one. Read them as a single construct written twice. The repair is at the members\u0027 grain \u2014 factor the shared pipeline into one implementation the two call with their differences as parameters or as an injected step, or, where the difference is systematic (sync against async, one transport against another), generate one from the other. Extracting the individual blocks below is not the same fix: it leaves the two bodies in place and the next edit still has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":7}}}],"partialFingerprints":{"codehealthFindingId/v1":"c7cf312f21acbc5b87de19c52a94f9a1353760a8737d1237b99029386f845f65"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (31 lines \u00D7 2): src/Owin.Compression.Standard/CompressionModule.fs:66-96 | src/Owin.Compression/CompressionModule.fs:50-80 \u2014 \u0060src/Owin.Compression.Standard/CompressionModule.fs\u0060 and \u0060src/Owin.Compression/CompressionModule.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 14 separate duplicated blocks between them, totalling at least 254 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Owin.Compression.Standard/CompressionModule.fs:66\u0060 it runs out through the closing brace of the declaration holding it and carries on into the declaration that follows \u2014 the window is the tail of one member plus the head of the next, so no call can be substituted for those exact lines, and the smallest declaration that contains all of them is the type they sit in. The repeated unit is the member each site sits in: where those members\u0027 bodies are the same, move one whole member to the shared location and have the others delegate to it; where the copies are a run of near-identical overloads or wrappers that differ only in their signatures, the repetition IS the run \u2014 a one-line delegation has no helper inside it to lift \u2014 so generate the run from the set it enumerates, or accept it and keep each member\u0027s own documentation with it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":66}}}],"partialFingerprints":{"codehealthFindingId/v1":"47536763a877dfdc0f980ecb69c592b364a1d25641d4d30f6b19604283f13227"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (29 lines \u00D7 2): src/Owin.Compression.Standard/CompressionModule.fs:99-127 | src/Owin.Compression/CompressionModule.fs:84-112 \u2014 \u0060src/Owin.Compression.Standard/CompressionModule.fs\u0060 and \u0060src/Owin.Compression/CompressionModule.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 14 separate duplicated blocks between them, totalling at least 254 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":99}}}],"partialFingerprints":{"codehealthFindingId/v1":"5a8429f854ae10e6e1929a44f0b6fc24f2985649a02ebb359b4d340106fa376d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (26\u201327 lines \u00D7 2): src/Owin.Compression.Standard/CompressionModule.fs:406-431 | src/Owin.Compression/CompressionModule.fs:355-381 \u2014 \u0060src/Owin.Compression.Standard/CompressionModule.fs\u0060 and \u0060src/Owin.Compression/CompressionModule.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 14 separate duplicated blocks between them, totalling at least 254 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Owin.Compression.Standard/CompressionModule.fs:406\u0060 it runs out through the closing brace of the declaration holding it and carries on into the declaration that follows \u2014 the window is the tail of one member plus the head of the next, so no call can be substituted for those exact lines, and the smallest declaration that contains all of them is the type they sit in. The repeated unit is the member each site sits in: where those members\u0027 bodies are the same, move one whole member to the shared location and have the others delegate to it; where the copies are a run of near-identical overloads or wrappers that differ only in their signatures, the repetition IS the run \u2014 a one-line delegation has no helper inside it to lift \u2014 so generate the run from the set it enumerates, or accept it and keep each member\u0027s own documentation with it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":406}}}],"partialFingerprints":{"codehealthFindingId/v1":"5ce840b1373cca05f2b30af39e806606e7549103e710e85296381bf7ee64762f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17\u201322 lines \u00D7 2): src/Owin.Compression.Standard/CompressionModule.fs:433-454 | src/Owin.Compression/CompressionModule.fs:384-400 \u2014 \u0060src/Owin.Compression.Standard/CompressionModule.fs\u0060 and \u0060src/Owin.Compression/CompressionModule.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 14 separate duplicated blocks between them, totalling at least 254 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Owin.Compression.Standard/CompressionModule.fs:433\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately. \u2605 These copies have DRIFTED, and that is worth reading before extracting anything: just after the matched lines, \u0060src/Owin.Compression/CompressionModule.fs:400\u0060 calls \u0060GZipStream\u0060 and \u0060src/Owin.Compression.Standard/CompressionModule.fs:454\u0060 does not \u2014 after which the two agree again for 5 more lines. One of those two behaviours is the intended one and the other is what a copy-paste left behind, so decide which BEFORE unifying them: extracting the shared part will silently settle it, and if the copy that skips the call is the wrong one, that bug is already live."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":433}}}],"partialFingerprints":{"codehealthFindingId/v1":"8b9e4cfd4e3c47bd6d811aab269b6f58330c9d682c3d6c5dcd02c6e99cee203b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (21 lines \u00D7 2): src/Owin.Compression.Standard/CompressionModule.fs:315-335 | src/Owin.Compression/CompressionModule.fs:270-290 \u2014 \u0060src/Owin.Compression.Standard/CompressionModule.fs\u0060 and \u0060src/Owin.Compression/CompressionModule.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 14 separate duplicated blocks between them, totalling at least 254 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":315}}}],"partialFingerprints":{"codehealthFindingId/v1":"80fe8819b3401e4a180bb45464b209811cbdd53d297e9b1326c0d45ac514075f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (19 lines \u00D7 2): src/Owin.Compression.Standard/CompressionModule.fs:337-355 | src/Owin.Compression/CompressionModule.fs:292-310 \u2014 \u0060src/Owin.Compression.Standard/CompressionModule.fs\u0060 and \u0060src/Owin.Compression/CompressionModule.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 14 separate duplicated blocks between them, totalling at least 254 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Owin.Compression.Standard/CompressionModule.fs:337\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":337}}}],"partialFingerprints":{"codehealthFindingId/v1":"5d9dad1c6b42d8a7aee0657799a02105e5970e8bed4825b99c28d96fa09dbb3a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17\u201318 lines \u00D7 2): src/Owin.Compression.Standard/CompressionModule.fs:48-64 | src/Owin.Compression/CompressionModule.fs:32-49 \u2014 \u0060src/Owin.Compression.Standard/CompressionModule.fs\u0060 and \u0060src/Owin.Compression/CompressionModule.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 14 separate duplicated blocks between them, totalling at least 254 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Owin.Compression.Standard/CompressionModule.fs:48\u0060 it runs out through the closing brace of the declaration holding it and carries on into the declaration that follows \u2014 the window is the tail of one member plus the head of the next, so no call can be substituted for those exact lines, and the smallest declaration that contains all of them is the type they sit in. The repeated unit is the member each site sits in: where those members\u0027 bodies are the same, move one whole member to the shared location and have the others delegate to it; where the copies are a run of near-identical overloads or wrappers that differ only in their signatures, the repetition IS the run \u2014 a one-line delegation has no helper inside it to lift \u2014 so generate the run from the set it enumerates, or accept it and keep each member\u0027s own documentation with it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"115841d37e237a65363cc8224e41cd3d8caa15427208398748635ab32fe3f0fe"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15\u201316 lines \u00D7 2): src/Owin.Compression.Standard/CompressionModule.fs:489-503 | src/Owin.Compression/CompressionModule.fs:438-453 \u2014 \u0060src/Owin.Compression.Standard/CompressionModule.fs\u0060 and \u0060src/Owin.Compression/CompressionModule.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 14 separate duplicated blocks between them, totalling at least 254 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Owin.Compression.Standard/CompressionModule.fs:489\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":489}}}],"partialFingerprints":{"codehealthFindingId/v1":"58a7cbe57680e30611c8936a9e8d3c5299d6040990883e990ded49b2634d2d2e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): src/Owin.Compression.Standard/CompressionModule.fs:282-295 | src/Owin.Compression/CompressionModule.fs:241-254 \u2014 \u0060src/Owin.Compression.Standard/CompressionModule.fs\u0060 and \u0060src/Owin.Compression/CompressionModule.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 14 separate duplicated blocks between them, totalling at least 254 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":282}}}],"partialFingerprints":{"codehealthFindingId/v1":"1d4b003320d0a897dc5903f40b54f86ba6439b7f3c27b649753bbfb4914f3a7b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13\u201314 lines \u00D7 2): src/Owin.Compression.Standard/CompressionModule.fs:455-467 | src/Owin.Compression/CompressionModule.fs:403-416 \u2014 \u0060src/Owin.Compression.Standard/CompressionModule.fs\u0060 and \u0060src/Owin.Compression/CompressionModule.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 14 separate duplicated blocks between them, totalling at least 254 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Owin.Compression.Standard/CompressionModule.fs:455\u0060 it runs out through the closing brace of the declaration holding it \u2014 the window is that declaration\u0027s tail, not a fragment that begins part-way through something, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it. \u2605 These copies have DRIFTED, and that is worth reading before extracting anything: just before the matched lines, \u0060src/Owin.Compression.Standard/CompressionModule.fs:451\u0060 calls \u0060BrotliStream\u0060 and \u0060src/Owin.Compression/CompressionModule.fs:400\u0060 does not \u2014 after which the two agree again for 2 more lines. One of those two behaviours is the intended one and the other is what a copy-paste left behind, so decide which BEFORE unifying them: extracting the shared part will silently settle it, and if the copy that skips the call is the wrong one, that bug is already live."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":455}}}],"partialFingerprints":{"codehealthFindingId/v1":"fd06325f3b2bcc819b5c1c6d5dafbad1a93ee4e2149796c5cc4c726da38585bb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): src/Owin.Compression.Standard/CompressionModule.fs:357-369 | src/Owin.Compression/CompressionModule.fs:312-324 \u2014 \u0060src/Owin.Compression.Standard/CompressionModule.fs\u0060 and \u0060src/Owin.Compression/CompressionModule.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 14 separate duplicated blocks between them, totalling at least 254 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":357}}}],"partialFingerprints":{"codehealthFindingId/v1":"16ba60930a60c7fb5646c4089973605f0725669b04a038a09a5ff68b2b5c2682"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11\u201312 lines \u00D7 2): src/Owin.Compression.Standard/CompressionModule.fs:269-279 | src/Owin.Compression/CompressionModule.fs:227-238 \u2014 \u0060src/Owin.Compression.Standard/CompressionModule.fs\u0060 and \u0060src/Owin.Compression/CompressionModule.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 14 separate duplicated blocks between them, totalling at least 254 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":269}}}],"partialFingerprints":{"codehealthFindingId/v1":"2aa017099fd19e091751ec6d6bf084552fa2aec1e17839facb6df9926bf43a0e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): src/Owin.Compression.Standard/CompressionModule.fs:195-203 | src/Owin.Compression/CompressionModule.fs:165-173 \u2014 \u0060src/Owin.Compression.Standard/CompressionModule.fs\u0060 and \u0060src/Owin.Compression/CompressionModule.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 14 separate duplicated blocks between them, totalling at least 254 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":195}}}],"partialFingerprints":{"codehealthFindingId/v1":"8fa1a45d760698e04f1ec5466501ce18112a3f0a9f569daa57c16d8a7c7e7d04"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): src/Owin.Compression.Standard/CompressionModule.fs:231-239 | src/Owin.Compression/CompressionModule.fs:202-210 \u2014 \u0060src/Owin.Compression.Standard/CompressionModule.fs\u0060 and \u0060src/Owin.Compression/CompressionModule.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 14 separate duplicated blocks between them, totalling at least 254 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Owin.Compression.Standard/CompressionModule.fs:231\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":231}}}],"partialFingerprints":{"codehealthFindingId/v1":"447fef36871834105e4856bfd98eff5be5cfad89dcd997f2a8c84952b6ba236b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7\u20138 lines \u00D7 2): src/Owin.Compression.Standard/CompressionModule.fs:250-257 | src/Owin.Compression.Standard/CompressionModule.fs:375-381 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression.Standard/CompressionModule.fs"},"region":{"startLine":250}}}],"partialFingerprints":{"codehealthFindingId/v1":"c616905413ab11f6d0b7b83b156cb0a012b417a7f13764ab1429fdb8fc61e28d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): src/Owin.Compression/CompressionModule.fs:217-224 | src/Owin.Compression/CompressionModule.fs:330-336 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Owin.Compression/CompressionModule.fs"},"region":{"startLine":217}}}],"partialFingerprints":{"codehealthFindingId/v1":"e2900236185a3c62c6acd7ba3917d6eafe0f908d3cfe0f3eabb9de33b7e3d900"}},{"ruleId":"D8","level":"warning","message":{"text":"Coverage not measured \u2014 no coverage collector is wired up: Coverage NOT MEASURED: \u0060--collect:\u0022XPlat Code Coverage\u0022\u0060 names a data collector that ships in the \u0060coverlet.collector\u0060 package, and this repository wires up none \u2014 no test project references it and no runsettings declares one. The absence of coverage here is therefore not evidence about the suite or about our analyzer environment: without a collector, \u0060--collect\u0060 produces nothing even from a suite that builds and passes. Add a \u0060coverlet.collector\u0060 PackageReference to the test project(s) (or commit the Cobertura/OpenCover/lcov report your CI produces) and real coverage will be measured. It is excluded from the score rather than counted as a near-zero defect."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"62e63e619c28f057e129f2997c965d32a457366a9ce18ca019ffb6bdfba85c99"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no installation or build instructions: There are no installation/build/usage instructions for Owin.Compression in the README. Add an Install section covering NuGet package reference, project .csproj dependency, and a one-line build command."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1fa6bfcd5c6ae231d1b8ee99bced50b832d1f61cde9da6cbb533467b879a57db"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no usage examples: There are no usage examples or invocation commands for Owin.Compression in the README. Add a short Usage section showing how to add the module to an OWIN Selfhost pipeline and a test case."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1355eb4e127a4bc9236772ce1c46f09510aa9286e7a06d1e47f308229df19049"}},{"ruleId":"D27","level":"note","message":{"text":"Scattered collaborators: 93 % of calls cross a namespace and only 20 % of collaborators are co-located \u2014 group each feature\u0027s code into a vertical slice so a call\u0027s collaborators sit together."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5aad4a4530bac3928d3a065a664be89d023ecfc865f9bf79ac05754b3bffe322"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ace515990e7ee0f17b5c17e44dd168a5bdecf90804a3a3dd845cf05540978013"}},{"ruleId":"D44","level":"warning","message":{"text":"End-of-life runtime: .NET net6.0: tests/Aspnet.Core.WebAPI.Test/Aspnet.Core.WebAPI.Test.fsproj declares .NET net6.0 as this project\u0027s target framework, and .NET 6 LTS, support ended 2024-11-12. An unsupported runtime receives no security patches, so every vulnerability disclosed in it since 2024-11-12 is present and unfixable without moving off it. This is a migration rather than an upgrade: there is no newer release of a runtime that has ended."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"833052aef8fed8fff4f2fedf55a392e3e58dc048b7b988c82a469d1d41453aa6"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"M2","level":"note","message":{"text":"No architecture diagram/doc: No C4/Structurizr/PlantUML/Mermaid/Graphviz/D2 diagram, no drawn diagram named for the architecture, no file named \u0060architecture\u0060 or \u0060design\u0060 in any markup this check reads, and nothing in the README, docs or contributor guides that announces the shape \u2014 no \u0060## Architecture\u0060 heading, no \u0022architecture overview\u0022/\u0022high-level design\u0022 phrasing, no \u0022the architecture is \u2026\u0022 introduction, no guided code tour. A shape laid out in prose that never names itself as the architecture is not visible to this check, and neither is one kept outside the repository, so this row reports the absence of a re-findable shape document \u2014 not evidence that nobody wrote the shape down."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0c190e7c159d1850ee706c3ac4486e151e8a4fe169de4bf61436b9f399654f06"}},{"ruleId":"M4","level":"note","message":{"text":"README/code drift: Brotli compression only supported on .NET Standard 2.1 or higher \u2014 searched for: \u0060Brotli\u0060. Each was matched case- and separator-insensitively against file and directory NAMES anywhere in the tree, and against the CONTENTS of manifest files (package.json, *.csproj, *.props, *.slnx, *.yml, Dockerfile); the README\u0027s own prose never counts, so a claim is never refuted by merely being made. Nothing outside that search was read \u2014 a footprint living only in a submodule, in a file type not listed here, or under a name none of those terms matches is not seen, and this row is then wrong."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"343bbbd51ceb8de7a9ff88d79f7c797abf9b5921f8727b67b4d0f4f8a22c5e49"}},{"ruleId":"P1","level":"note","message":{"text":"CI test execution not evidenced: A CI pipeline exists but no test-runner invocation (your stack\u0027s test command, or a test job) was found \u2014 changes may merge without the suite running."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"860902100b1c048f49c648730bdf23459de2d8ca6af82ef0ec593ecb3995a80c"}},{"ruleId":"P3","level":"note","message":{"text":"No SAST: No static application security testing detected. For this repository\u0027s stack, add \u0060semgrep --config=auto\u0060 plus gitleaks for committed secrets (F# is not a CodeQL language and has no language-specific SAST engine) as a CI step. What was searched, so you can tell an absence from a miss: the 310 CI workflow file(s) in this repository, and the scanner and linter configuration checked in beside them. A scan that runs outside CI, one configured in your forge\u0027s web UI rather than in a committed file, or a tool whose name is none of those this check carries, is not seen \u2014 if that is your case the row is wrong, and saying so is more useful than adding a second scanner."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6e54424179c892f03ef2fd003130ac4bd43f39bbf3b1ca0a0143e25acb80ec87"}},{"ruleId":"SC1","level":"warning","message":{"text":"NuGet dependencies are not locked: No packages.lock.json and no central package management \u2014 restores aren\u0027t reproducible or pinned (SSDF PW.4.4). Enable \u003CRestorePackagesWithLockFile\u003Etrue\u003C/RestorePackagesWithLockFile\u003E (commit the lockfile) or adopt Directory.Packages.props. Advisory \u2014 never scored."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0a97b4f69ccac509400ece7eedefb06d3ede0522cd4d8bcb5c068bea719545a6"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":1,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}