{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D10","name":"Test Quality","shortDescription":{"text":"Test Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D10"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D37","name":"Vulnerability-disclosure Policy","shortDescription":{"text":"Vulnerability-disclosure Policy"},"helpUri":"https://codehealth.canine.dev/dimensions/D37","relationships":[{"target":{"id":"CWE-1059","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1059"]}},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P10","name":"Library API \u0026 versioning","shortDescription":{"text":"Library API \u0026 versioning"},"helpUri":"https://codehealth.canine.dev/dimensions/P10"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"PF3","name":"Async \u0026 latency hygiene","shortDescription":{"text":"Async \u0026 latency hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/PF3"},{"id":"R1","name":"Type Safety","shortDescription":{"text":"Type Safety"},"helpUri":"https://codehealth.canine.dev/dimensions/R1"},{"id":"R10","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/R10"},{"id":"R11","name":"Import Boundaries","shortDescription":{"text":"Import Boundaries"},"helpUri":"https://codehealth.canine.dev/dimensions/R11"},{"id":"R2","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/R2"},{"id":"R3","name":"Large Files","shortDescription":{"text":"Large Files"},"helpUri":"https://codehealth.canine.dev/dimensions/R3"},{"id":"R4","name":"Test Coverage","shortDescription":{"text":"Test Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/R4"},{"id":"R5","name":"Dependency Freshness","shortDescription":{"text":"Dependency Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/R5"},{"id":"R6","name":"Tooling","shortDescription":{"text":"Tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/R6"},{"id":"R7","name":"Dead Code","shortDescription":{"text":"Dead Code"},"helpUri":"https://codehealth.canine.dev/dimensions/R7"},{"id":"R8","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/R8"},{"id":"R9","name":"Circular Imports","shortDescription":{"text":"Circular Imports"},"helpUri":"https://codehealth.canine.dev/dimensions/R9"},{"id":"SC1","name":"Supply-chain hygiene","shortDescription":{"text":"Supply-chain hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/SC1"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X24","name":"Document value interpolated into markup unescaped","shortDescription":{"text":"Document value interpolated into markup unescaped"},"helpUri":"https://codehealth.canine.dev/dimensions/X24"},{"id":"X25","name":"Inert configuration knob","shortDescription":{"text":"Inert configuration knob"},"helpUri":"https://codehealth.canine.dev/dimensions/X25"},{"id":"X26","name":"Unsynchronised callback handoff","shortDescription":{"text":"Unsynchronised callback handoff"},"helpUri":"https://codehealth.canine.dev/dimensions/X26"},{"id":"X29","name":"Per-element action decided by a fixed element","shortDescription":{"text":"Per-element action decided by a fixed element"},"helpUri":"https://codehealth.canine.dev/dimensions/X29"},{"id":"X32","name":"Type resolved by simple name across every loaded assembly","shortDescription":{"text":"Type resolved by simple name across every loaded assembly"},"helpUri":"https://codehealth.canine.dev/dimensions/X32"},{"id":"X6","name":"Hand-rolled structured-format parsing","shortDescription":{"text":"Hand-rolled structured-format parsing"},"helpUri":"https://codehealth.canine.dev/dimensions/X6"},{"id":"X7","name":"Silent fallback defaults","shortDescription":{"text":"Silent fallback defaults"},"helpUri":"https://codehealth.canine.dev/dimensions/X7"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"messages-recv.makeMessagesRecvSocket (cyclomatic 375): messages-recv.makeMessagesRecvSocket has cyclomatic complexity 375 (threshold 15). Of this number, 25 points are the body\u0027s own statements and 350 belong to 37 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-recv.ts"},"region":{"startLine":110}}}],"partialFingerprints":{"codehealthFindingId/v1":"53a128b8432701d634a66f06238c7615020fe956f3b9b0db6f08c9e2c8926877"}},{"ruleId":"D1","level":"warning","message":{"text":"messages-send.makeMessagesSocket (cyclomatic 250): messages-send.makeMessagesSocket has cyclomatic complexity 250 (threshold 15). Most of this is not in the body itself: 3 of the 250 points are its own statements and the rest belongs to 26 function literals inside it that branch (lines 676, 241, 1328, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-send.ts"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"f361674b1d9810881491bbc7a71ef12c9d805dc815a3059c518348a6ca3179f9"}},{"ruleId":"D1","level":"warning","message":{"text":"chats.makeChatsSocket (cyclomatic 146): chats.makeChatsSocket has cyclomatic complexity 146 (threshold 15). Most of this is not in the body itself: 2 of the 146 points are its own statements and the rest belongs to 32 function literals inside it that branch (lines 1205, 583, 874, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/chats.ts"},"region":{"startLine":79}}}],"partialFingerprints":{"codehealthFindingId/v1":"0f1acef975050aeb8dfcdad51c13e9fafbce634cc6d62ac07cc17dd6d8d0953a"}},{"ruleId":"D1","level":"warning","message":{"text":"event-buffer.append (cyclomatic 109): event-buffer.append has cyclomatic complexity 109 (threshold 15). Of this number, 100 points are the body\u0027s own statements and 9 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/event-buffer.ts"},"region":{"startLine":288}}}],"partialFingerprints":{"codehealthFindingId/v1":"63fe01e0a627779f020d910b197f365e096b4db635384cd6e8eeab0c682107a8"}},{"ruleId":"D1","level":"warning","message":{"text":"socket.makeSocket (cyclomatic 105): socket.makeSocket has cyclomatic complexity 105 (threshold 15). Most of this is not in the body itself: 9 of the 105 points are its own statements and the rest belongs to 39 function literals inside it that branch (lines 589, 556, 627, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/socket.ts"},"region":{"startLine":72}}}],"partialFingerprints":{"codehealthFindingId/v1":"28ae2ab02d851ba05fb080fec964f5fee3859297dbb670ef8d7896e5a06b2dd7"}},{"ruleId":"D1","level":"warning","message":{"text":"process-message.processMessage (cyclomatic 79): process-message.processMessage has cyclomatic complexity 79 (threshold 15). Of this number, 78 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/process-message.ts"},"region":{"startLine":293}}}],"partialFingerprints":{"codehealthFindingId/v1":"34777bb532fae03f11ccfdcb09d454c5201fefa2535d2a1f2cd379e57b917119"}},{"ruleId":"D1","level":"warning","message":{"text":"(anonymous) (cyclomatic 77): (anonymous) has cyclomatic complexity 77 (threshold 15). Most of this is not in the body itself: 6 of the 77 points are its own statements and the rest belongs to 36 function items inside it that branch (AssignmentExpression::(anonymous), stringifyMessageSpecMember, Property, \u2026). Those helpers are already separate functions, so extracting the branching again is not available. To reduce it, move them out of the body to the enclosing scope, where each is measured, reviewed and tested on its own, and reduce whichever one then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"proto-extract/index.js"},"region":{"startLine":97}}}],"partialFingerprints":{"codehealthFindingId/v1":"a9da1db75f232bb88448047006a902bc6d9ea16dd1eb23cc6ea8c26f0a314129"}},{"ruleId":"D1","level":"warning","message":{"text":"messages.generateWAMessageContent (cyclomatic 73): messages.generateWAMessageContent has cyclomatic complexity 73 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages.ts"},"region":{"startLine":395}}}],"partialFingerprints":{"codehealthFindingId/v1":"cffcba489858411d5405b773fe2e1b5e943a52544ec3200c3806d18e6ff6d9ad"}},{"ruleId":"D1","level":"warning","message":{"text":"encode.encodeBinaryNodeInner (cyclomatic 69): encode.encodeBinaryNodeInner has cyclomatic complexity 69 (threshold 15). Most of this is not in the body itself: 12 of the 69 points are its own statements and the rest belongs to 13 function literals inside it that branch (lines 179, 99, 149, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WABinary/encode.ts"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"f24cdd27306efbbde33421d2bb79f15f5913206a956bef9a1bf35ac417a86cd9"}},{"ruleId":"D1","level":"warning","message":{"text":"decode.decodeDecompressedBinaryNode (cyclomatic 57): decode.decodeDecompressedBinaryNode has cyclomatic complexity 57 (threshold 15). Most of this is not in the body itself: 11 of the 57 points are its own statements and the rest belongs to 14 function literals inside it that branch (lines 193, 79, 71, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WABinary/decode.ts"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"9bd2fb6b5f3a27a7c53be87cedddae00fc1c063c3a4cd887e49771c159329c0f"}},{"ruleId":"D1","level":"warning","message":{"text":"chat-utils.processSyncAction (cyclomatic 55): chat-utils.processSyncAction has cyclomatic complexity 55 (threshold 15). Of this number, 52 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/chat-utils.ts"},"region":{"startLine":823}}}],"partialFingerprints":{"codehealthFindingId/v1":"da3c85fc818c740234ad37d26f763fc944ca29ac5ee76783966d6a7522cb6cf5"}},{"ruleId":"D1","level":"warning","message":{"text":"messages.prepareWAMessageMedia (cyclomatic 39): messages.prepareWAMessageMedia has cyclomatic complexity 39 (threshold 15). Of this number, 30 points are the body\u0027s own statements and 9 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages.ts"},"region":{"startLine":124}}}],"partialFingerprints":{"codehealthFindingId/v1":"714922198d1f0722d214f67fe2dadab1dbccb788981c88571a4cb86f99a4ff85"}},{"ruleId":"D1","level":"warning","message":{"text":"history.processHistoryMessage (cyclomatic 38): history.processHistoryMessage has cyclomatic complexity 38 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/history.ts"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"bcbd7629bff63865cf98dbd3156d5eb054cfd9d87d0587fa53d45f859480bfd0"}},{"ruleId":"D1","level":"warning","message":{"text":"chat-utils.chatModificationToAppPatch (cyclomatic 38): chat-utils.chatModificationToAppPatch has cyclomatic complexity 38 (threshold 15). Of this number, 28 points are the body\u0027s own statements and 10 belong to 2 function literals inside it that branch. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/chat-utils.ts"},"region":{"startLine":556}}}],"partialFingerprints":{"codehealthFindingId/v1":"623d1d7dff463151232731eea65430c4ae55f1e20acf5afb17fad110c5340645"}},{"ruleId":"D1","level":"warning","message":{"text":"libsignal.makeLibSignalRepository (cyclomatic 38): libsignal.makeLibSignalRepository has cyclomatic complexity 38 (threshold 15). Of this number, 28 points are the body\u0027s own statements and 10 belong to 5 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/libsignal.ts"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"687991231cacf95a0cee93b2312bdd9ad83fa227896e43aeda6d49c8da958dab"}},{"ruleId":"D1","level":"warning","message":{"text":"decode-wa-message.decodeMessageNode (cyclomatic 36): decode-wa-message.decodeMessageNode has cyclomatic complexity 36 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/decode-wa-message.ts"},"region":{"startLine":141}}}],"partialFingerprints":{"codehealthFindingId/v1":"b69ed801a9ffc6f10fa7c6d5076dcf45530fd4174e8c46472b7fb21245577f5d"}},{"ruleId":"D1","level":"warning","message":{"text":"LIDMappingStore._getLIDsForPNsImpl (cyclomatic 35): LIDMappingStore._getLIDsForPNsImpl has cyclomatic complexity 35 (threshold 15). Of this number, 31 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/lid-mapping.ts"},"region":{"startLine":134}}}],"partialFingerprints":{"codehealthFindingId/v1":"75752bf462521dc3fb2f663ce144711af2921a9459b7ec3de7f8dc38ee788e09"}},{"ruleId":"D1","level":"warning","message":{"text":"decode-wa-message.decryptMessageNode (cyclomatic 27): decode-wa-message.decryptMessageNode has cyclomatic complexity 27 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/decode-wa-message.ts"},"region":{"startLine":264}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee4425929a30d5f9a7715678d27d59546e10fa788f6a05bed39a95fb31f172d6"}},{"ruleId":"D1","level":"warning","message":{"text":"reporting-utils.extractReportingTokenContent (cyclomatic 27): reporting-utils.extractReportingTokenContent has cyclomatic complexity 27 (threshold 15). Of this number, 25 points are the body\u0027s own statements and 2 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/reporting-utils.ts"},"region":{"startLine":124}}}],"partialFingerprints":{"codehealthFindingId/v1":"b87240c4517bb56815108bc883bcd6e2454dc13e277cdd7c28e531bac07e66b9"}},{"ruleId":"D1","level":"warning","message":{"text":"auth-utils.addTransactionCapability (cyclomatic 26): auth-utils.addTransactionCapability has cyclomatic complexity 26 (threshold 15). Most of this is not in the body itself: 10 of the 26 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 218, 253, 303, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/auth-utils.ts"},"region":{"startLine":116}}}],"partialFingerprints":{"codehealthFindingId/v1":"ab5d07714d1f946c7faa81ba3f9af01012afbafad901a7cc1119e399d53ac22f"}},{"ruleId":"D1","level":"warning","message":{"text":"communities.makeCommunitiesSocket (cyclomatic 26): communities.makeCommunitiesSocket has cyclomatic complexity 26 (threshold 15). Most of this is not in the body itself: 4 of the 26 points are its own statements and the rest belongs to 11 function literals inside it that branch (lines 214, 304, 42, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/communities.ts"},"region":{"startLine":22}}}],"partialFingerprints":{"codehealthFindingId/v1":"061f5b4a72e58ea433f5ff0f5520ef6273483e3a1ce86a15e1f40a84d52cb3ac"}},{"ruleId":"D1","level":"warning","message":{"text":"event-buffer.makeEventBuffer (cyclomatic 25): event-buffer.makeEventBuffer has cyclomatic complexity 25 (threshold 15). Of this number, 17 points are the body\u0027s own statements and 8 belong to 4 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/event-buffer.ts"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"03530395ca0bc89b8c68e4b4024112d25d7e4724798a4e519516047429d27e48"}},{"ruleId":"D1","level":"warning","message":{"text":"groups.extractGroupMetadata (cyclomatic 25): groups.extractGroupMetadata has cyclomatic complexity 25 (threshold 15). Of this number, 18 points are the body\u0027s own statements and 7 belong to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/groups.ts"},"region":{"startLine":304}}}],"partialFingerprints":{"codehealthFindingId/v1":"e4ae9ea641d2985fda1cd5f0278b40d27a00cf56dfa1ccbc52f6b5829daa26d0"}},{"ruleId":"D1","level":"warning","message":{"text":"messages.generateWAMessageFromContent (cyclomatic 24): messages.generateWAMessageFromContent has cyclomatic complexity 24 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages.ts"},"region":{"startLine":682}}}],"partialFingerprints":{"codehealthFindingId/v1":"52790c041ac04fb7ab65d74739a9eb5f3f5087803b250e37b73367c64e1db511"}},{"ruleId":"D1","level":"warning","message":{"text":"noise-handler.makeNoiseHandler (cyclomatic 24): noise-handler.makeNoiseHandler has cyclomatic complexity 24 (threshold 15). Most of this is not in the body itself: 3 of the 24 points are its own statements and the rest belongs to 8 function literals inside it that branch (lines 182, 147, 230, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/noise-handler.ts"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"69bdb0ed6c5786941c5e1c86cea5f8c59c293c3359007690724a460ff49f61b5"}},{"ruleId":"D1","level":"warning","message":{"text":"messages-media.downloadEncryptedContent (cyclomatic 23): messages-media.downloadEncryptedContent has cyclomatic complexity 23 (threshold 15). Of this number, 19 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages-media.ts"},"region":{"startLine":553}}}],"partialFingerprints":{"codehealthFindingId/v1":"c4875c8de91ba728aae9ce58e979f6dbc4b3b6a06f2d1c6aafe216b06c79e96e"}},{"ruleId":"D1","level":"warning","message":{"text":"LIDMappingStore.storeLIDPNMappings (cyclomatic 20): LIDMappingStore.storeLIDPNMappings has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/lid-mapping.ts"},"region":{"startLine":30}}}],"partialFingerprints":{"codehealthFindingId/v1":"244e6be689139f29a45ad00780a2a67a5f5e86f11c17c09c2960609b58e6ef59"}},{"ruleId":"D1","level":"warning","message":{"text":"LIDMappingStore._getPNsForLIDsImpl (cyclomatic 19): LIDMappingStore._getPNsForLIDsImpl has cyclomatic complexity 19 (threshold 15). Of this number, 15 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/lid-mapping.ts"},"region":{"startLine":269}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b58ceb18fbbf4f68c24620cac6b52f67c42e90e47e2e7e8f221e686888093fd"}},{"ruleId":"D1","level":"warning","message":{"text":"signal.extractE2ESessionFromRetryReceipt (cyclomatic 17): signal.extractE2ESessionFromRetryReceipt has cyclomatic complexity 17 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/signal.ts"},"region":{"startLine":92}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee864b601a3686d77cd18b3bfd932e1e1ce7b82928cee888d8eb21276f2ca6cb"}},{"ruleId":"D1","level":"warning","message":{"text":"link-preview.getUrlInfo (cyclomatic 17): link-preview.getUrlInfo has cyclomatic complexity 17 (threshold 15). Of this number, 13 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/link-preview.ts"},"region":{"startLine":33}}}],"partialFingerprints":{"codehealthFindingId/v1":"a18be2152dfc4821098d6f459991764c62521b0e99ecab5cbbcb28b72a912a27"}},{"ruleId":"D1","level":"warning","message":{"text":"libsignal.signalStorage (cyclomatic 17): libsignal.signalStorage has cyclomatic complexity 17 (threshold 15). Most of this is not in the body itself: 1 of the 17 points is its own statement and the rest belongs to 6 function literals inside it that branch (lines 443, 490, 464, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/libsignal.ts"},"region":{"startLine":434}}}],"partialFingerprints":{"codehealthFindingId/v1":"6fcd8a7976fe420f4c68d838135f9f3cac8ada012685964d6496ece870c4e5d7"}},{"ruleId":"D1","level":"warning","message":{"text":"encode.serializeData (cyclomatic 17): encode.serializeData has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WAM/encode.ts"},"region":{"startLine":86}}}],"partialFingerprints":{"codehealthFindingId/v1":"64882f9132815efcf66af0e9e33e2b5f263cd876047ed35e7a5ede08c24d0b4a"}},{"ruleId":"D2","level":"warning","message":{"text":"messages-recv.makeMessagesRecvSocket (cognitive 484): messages-recv.makeMessagesRecvSocket has cognitive complexity 484 (threshold 15). Drivers by points: if/else 165 (280 pts), boolean chains 88, ternaries 24 (50 pts), error handling 16 (35 pts), loops 15 (22 pts), match/switch 6 (9 pts) (nesting depth added 170). Of this number, 26 points are the body\u0027s own statements and 458 belong to 37 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-recv.ts"},"region":{"startLine":110}}}],"partialFingerprints":{"codehealthFindingId/v1":"827dd459242873b592fb4dfbb4629e2e9c0e37ff08f237311c6ce7eac50d5c1c"}},{"ruleId":"D2","level":"warning","message":{"text":"messages-send.makeMessagesSocket (cognitive 350): messages-send.makeMessagesSocket has cognitive complexity 350 (threshold 15). Drivers by points: if/else 122 (183 pts), boolean chains 75, ternaries 25 (53 pts), loops 12 (21 pts), error handling 7 (18 pts) (nesting depth added 109). Most of this is not in the body itself: 2 of the 350 points are its own statements and the rest belongs to 26 function literals inside it that branch (lines 676, 241, 1328, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-send.ts"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"d42e219cbebf99208fda91ed434222b0325fcd704a136eb704ee04a72bd0da1d"}},{"ruleId":"D2","level":"warning","message":{"text":"event-buffer.append (cognitive 213): event-buffer.append has cognitive complexity 213 (threshold 15). Drivers by points: if/else 54 (140 pts), loops 17 (38 pts), boolean chains 29, ternaries 2 (5 pts), match/switch 1 (nesting depth added 110). Of this number, 197 points are the body\u0027s own statements and 16 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/event-buffer.ts"},"region":{"startLine":288}}}],"partialFingerprints":{"codehealthFindingId/v1":"7dbbc8c4ee8346126807b01d7741125ed6d0fab3241db89ea3660f16b63f7080"}},{"ruleId":"D2","level":"warning","message":{"text":"chats.makeChatsSocket (cognitive 199): chats.makeChatsSocket has cognitive complexity 199 (threshold 15). Drivers by points: if/else 79 (118 pts), boolean chains 37, ternaries 16 (25 pts), loops 9 (14 pts), error handling 2 (4 pts), match/switch 1 (nesting depth added 55). Most of this is not in the body itself: 1 of the 199 points is its own statement and the rest belongs to 32 function literals inside it that branch (lines 583, 1205, 412, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/chats.ts"},"region":{"startLine":79}}}],"partialFingerprints":{"codehealthFindingId/v1":"03cae0f458cb9f01f34c697a6681495e1500845d576b733f49d5ef9375fbfffc"}},{"ruleId":"D2","level":"warning","message":{"text":"(anonymous) (cognitive 147): (anonymous) has cognitive complexity 147 (threshold 15). Drivers by points: if/else 37 (99 pts), boolean chains 22, ternaries 5 (15 pts), loops 6 (11 pts) (nesting depth added 77). Most of this is not in the body itself: 8 of the 147 points are its own statements and the rest belongs to 36 function items inside it that branch (AssignmentExpression::(anonymous), stringifyMessageSpecMember, AssignmentExpression, \u2026). Those helpers are already separate functions, so extracting the branching again is not available. To reduce it, move them out of the body to the enclosing scope, where each is measured, reviewed and tested on its own, and reduce whichever one then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"proto-extract/index.js"},"region":{"startLine":97}}}],"partialFingerprints":{"codehealthFindingId/v1":"cdbf9568561d6f0ada3cb41d35c13e5184ae369f51a979391aba32b0aeb5aabe"}},{"ruleId":"D2","level":"warning","message":{"text":"process-message.processMessage (cognitive 130): process-message.processMessage has cognitive complexity 130 (threshold 15). Drivers by points: if/else 28 (70 pts), boolean chains 18, loops 4 (15 pts), ternaries 4 (15 pts), error handling 2 (8 pts), match/switch 2 (4 pts) (nesting depth added 72). Of this number, 126 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/process-message.ts"},"region":{"startLine":293}}}],"partialFingerprints":{"codehealthFindingId/v1":"e833c7f8f22487212cba1328f3e552d6a35375bd87d750ebf742fc4507f0207e"}},{"ruleId":"D2","level":"warning","message":{"text":"socket.makeSocket (cognitive 121): socket.makeSocket has cognitive complexity 121 (threshold 15). Drivers by points: if/else 55 (65 pts), boolean chains 30, error handling 12 (15 pts), ternaries 5 (6 pts), loops 4 (5 pts) (nesting depth added 15). Most of this is not in the body itself: 8 of the 121 points are its own statements and the rest belongs to 39 function literals inside it that branch (lines 589, 556, 327, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/socket.ts"},"region":{"startLine":72}}}],"partialFingerprints":{"codehealthFindingId/v1":"2bf20f288beb00091fab34670fbb309cdb3164d1d5e3031f0a0770481f27903e"}},{"ruleId":"D2","level":"warning","message":{"text":"messages.generateWAMessageContent (cognitive 103): messages.generateWAMessageContent has cognitive complexity 103 (threshold 15). Drivers by points: if/else 52 (80 pts), boolean chains 16, ternaries 2 (5 pts), match/switch 1 (2 pts) (nesting depth added 32). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages.ts"},"region":{"startLine":395}}}],"partialFingerprints":{"codehealthFindingId/v1":"1d7b588ab0f8b24e0ed4b16031814280e358dcf9784e7683a4c487090da3b0e0"}},{"ruleId":"D2","level":"warning","message":{"text":"LIDMappingStore._getLIDsForPNsImpl (cognitive 85): LIDMappingStore._getLIDsForPNsImpl has cognitive complexity 85 (threshold 15). Drivers by points: if/else 18 (43 pts), ternaries 8 (24 pts), loops 5 (12 pts), boolean chains 6 (nesting depth added 48). Of this number, 81 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/lid-mapping.ts"},"region":{"startLine":134}}}],"partialFingerprints":{"codehealthFindingId/v1":"b8aa9775ed07cfcdc925e069b35056bf99e1e0559183fdfa5c8da3fcbec2ab82"}},{"ruleId":"D2","level":"warning","message":{"text":"encode.encodeBinaryNodeInner (cognitive 78): encode.encodeBinaryNodeInner has cognitive complexity 78 (threshold 15). Drivers by points: if/else 39 (46 pts), boolean chains 19, loops 7 (8 pts), ternaries 3 (4 pts), match/switch 1 (nesting depth added 9). Most of this is not in the body itself: 13 of the 78 points are its own statements and the rest belongs to 13 function literals inside it that branch (lines 179, 164, 64, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WABinary/encode.ts"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"55b39d63b636cd17482a9ca5b54ca7556be32c23eafaba669ab9c6d598f52f9e"}},{"ruleId":"D2","level":"warning","message":{"text":"reporting-utils.extractReportingTokenContent (cognitive 70): reporting-utils.extractReportingTokenContent has cognitive complexity 70 (threshold 15). Drivers by points: if/else 24 (68 pts), boolean chains 1, loops 1 (nesting depth added 44). Of this number, 66 points are the body\u0027s own statements and 4 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/reporting-utils.ts"},"region":{"startLine":124}}}],"partialFingerprints":{"codehealthFindingId/v1":"759f7ab128beff72a687054c42d991958f7f5da25197888b4b64c53a645d92b4"}},{"ruleId":"D2","level":"warning","message":{"text":"chat-utils.processSyncAction (cognitive 69): chat-utils.processSyncAction has cognitive complexity 69 (threshold 15). Drivers by points: if/else 29 (35 pts), ternaries 11 (23 pts), boolean chains 11 (nesting depth added 18). Of this number, 63 points are the body\u0027s own statements and 6 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/chat-utils.ts"},"region":{"startLine":823}}}],"partialFingerprints":{"codehealthFindingId/v1":"1feb2f21ee7450ac8e28b2ea4b4fdbeb64a8c39b37f40c1da9895d193e7e2ec4"}},{"ruleId":"D2","level":"warning","message":{"text":"decode-wa-message.decryptMessageNode (cognitive 55): decode-wa-message.decryptMessageNode has cognitive complexity 55 (threshold 15). Drivers by points: if/else 11 (27 pts), ternaries 3 (10 pts), error handling 2 (7 pts), boolean chains 6, match/switch 1 (3 pts), loops 1 (2 pts) (nesting depth added 31). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/decode-wa-message.ts"},"region":{"startLine":264}}}],"partialFingerprints":{"codehealthFindingId/v1":"8345307845294986737db69cc18e714efcd6bd430865a60493aff9bcbb11d698"}},{"ruleId":"D2","level":"warning","message":{"text":"libsignal.makeLibSignalRepository (cognitive 52): libsignal.makeLibSignalRepository has cognitive complexity 52 (threshold 15). Drivers by points: if/else 23 (36 pts), boolean chains 6, loops 3 (4 pts), ternaries 2 (4 pts), error handling 1, match/switch 1 (nesting depth added 16). Of this number, 36 points are the body\u0027s own statements and 16 belong to 5 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/libsignal.ts"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"8f8024da091efeed2bbd403baba2631b3d023b9944c9ce5a19954e978bc8b650"}},{"ruleId":"D2","level":"warning","message":{"text":"history.processHistoryMessage (cognitive 49): history.processHistoryMessage has cognitive complexity 49 (threshold 15). Drivers by points: if/else 8 (23 pts), boolean chains 17, loops 4 (8 pts), match/switch 1 (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/history.ts"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"40a9e461db4fb8c140a04f9901de81a5cc5825f46bf679121904c1ec9da9859d"}},{"ruleId":"D2","level":"warning","message":{"text":"decode-wa-message.decodeMessageNode (cognitive 46): decode-wa-message.decodeMessageNode has cognitive complexity 46 (threshold 15). Drivers by points: if/else 19 (31 pts), boolean chains 9, ternaries 6 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/decode-wa-message.ts"},"region":{"startLine":141}}}],"partialFingerprints":{"codehealthFindingId/v1":"ab4584dce3cefe36d5d89d0c4c45115d716fdb1b2834caa7921295f33afadb20"}},{"ruleId":"D2","level":"warning","message":{"text":"decode.decodeDecompressedBinaryNode (cognitive 43): decode.decodeDecompressedBinaryNode has cognitive complexity 43 (threshold 15). Drivers by points: if/else 19 (20 pts), boolean chains 8, match/switch 4 (6 pts), loops 4, ternaries 2 (4 pts), error handling 1 (nesting depth added 5). Most of this is not in the body itself: 12 of the 43 points are its own statements and the rest belongs to 14 function literals inside it that branch (lines 71, 193, 55, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WABinary/decode.ts"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"73a0951817ceab68ae21599af8cd7c36c4ae2c13c4c0f91f41078827825015d0"}},{"ruleId":"D2","level":"warning","message":{"text":"messages.prepareWAMessageMedia (cognitive 39): messages.prepareWAMessageMedia has cognitive complexity 39 (threshold 15). Drivers by points: if/else 18 (24 pts), boolean chains 12, error handling 2, loops 1 (nesting depth added 6). Of this number, 29 points are the body\u0027s own statements and 10 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages.ts"},"region":{"startLine":124}}}],"partialFingerprints":{"codehealthFindingId/v1":"ad7d88940fd6036f18473e03cdcfbab1e6449f5d8e2d12e0cb7614f5481dcfac"}},{"ruleId":"D2","level":"warning","message":{"text":"communities.makeCommunitiesSocket (cognitive 37): communities.makeCommunitiesSocket has cognitive complexity 37 (threshold 15). Drivers by points: ternaries 11 (20 pts), if/else 7, boolean chains 4, loops 2 (4 pts), error handling 1 (2 pts) (nesting depth added 12). Most of this is not in the body itself: 5 of the 37 points are its own statements and the rest belongs to 11 function literals inside it that branch (lines 214, 42, 304, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/communities.ts"},"region":{"startLine":22}}}],"partialFingerprints":{"codehealthFindingId/v1":"68c1608fb6a9c33edd7650bc3ac47b245b04829643e8bad079a94897bed54ede"}},{"ruleId":"D2","level":"warning","message":{"text":"auth-utils.addTransactionCapability (cognitive 35): auth-utils.addTransactionCapability has cognitive complexity 35 (threshold 15). Drivers by points: if/else 14 (21 pts), boolean chains 6, loops 4 (5 pts), error handling 2 (3 pts) (nesting depth added 9). Most of this is not in the body itself: 13 of the 35 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 253, 218, 303, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/auth-utils.ts"},"region":{"startLine":116}}}],"partialFingerprints":{"codehealthFindingId/v1":"855bcd999619f252e9a9ca37cd3e8b21aee8fa05f3b58c6040489fc5d9033068"}},{"ruleId":"D2","level":"warning","message":{"text":"LIDMappingStore._getPNsForLIDsImpl (cognitive 30): LIDMappingStore._getPNsForLIDsImpl has cognitive complexity 30 (threshold 15). Drivers by points: if/else 9 (19 pts), boolean chains 5, loops 2 (3 pts), ternaries 3 (nesting depth added 11). Of this number, 26 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/lid-mapping.ts"},"region":{"startLine":269}}}],"partialFingerprints":{"codehealthFindingId/v1":"d1ce048c2cd749940634496036fc1ee40c0fc616a1cd74c178439b32ef446f3c"}},{"ruleId":"D2","level":"warning","message":{"text":"messages-media.downloadEncryptedContent (cognitive 30): messages-media.downloadEncryptedContent has cognitive complexity 30 (threshold 15). Drivers by points: if/else 9 (13 pts), ternaries 7 (10 pts), boolean chains 5, error handling 2 (nesting depth added 7). Of this number, 23 points are the body\u0027s own statements and 7 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages-media.ts"},"region":{"startLine":553}}}],"partialFingerprints":{"codehealthFindingId/v1":"d2c86a360f61ec3c3e55f34d1fb2f4bc26fde3f5e670f996be898d627d6d42de"}},{"ruleId":"D2","level":"warning","message":{"text":"chat-utils.chatModificationToAppPatch (cognitive 30): chat-utils.chatModificationToAppPatch has cognitive complexity 30 (threshold 15). Drivers by points: if/else 20, boolean chains 10. Of this number, 25 points are the body\u0027s own statements and 5 belong to 2 function literals inside it that branch. To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/chat-utils.ts"},"region":{"startLine":556}}}],"partialFingerprints":{"codehealthFindingId/v1":"b796a0a58598b793918d607938080f20c4fa29115c15730f2933af6a3884d022"}},{"ruleId":"D2","level":"warning","message":{"text":"event-buffer.makeEventBuffer (cognitive 30): event-buffer.makeEventBuffer has cognitive complexity 30 (threshold 15). Drivers by points: if/else 18 (25 pts), boolean chains 2, loops 2, error handling 1 (nesting depth added 7). Of this number, 21 points are the body\u0027s own statements and 9 belong to 4 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/event-buffer.ts"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"1743b907ae1fd5cd8ccccebb19c093556d092e3a31102ec1c962c20718ae1f6b"}},{"ruleId":"D2","level":"warning","message":{"text":"noise-handler.makeNoiseHandler (cognitive 29): noise-handler.makeNoiseHandler has cognitive complexity 29 (threshold 15). Drivers by points: if/else 20 (24 pts), boolean chains 2, ternaries 2, loops 1 (nesting depth added 4). Most of this is not in the body itself: 3 of the 29 points are its own statements and the rest belongs to 8 function literals inside it that branch (lines 147, 182, 230, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/noise-handler.ts"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"f205769b2481031b04831adb69aad7e89ff79edb94bf5ee73e3156b95de2f778"}},{"ruleId":"D2","level":"warning","message":{"text":"LIDMappingStore.storeLIDPNMappings (cognitive 27): LIDMappingStore.storeLIDPNMappings has cognitive complexity 27 (threshold 15). Drivers by points: if/else 10 (16 pts), loops 6 (7 pts), boolean chains 4 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/lid-mapping.ts"},"region":{"startLine":30}}}],"partialFingerprints":{"codehealthFindingId/v1":"3772da6e256710341146d95a61eac8dd2c501650317e8f1807432fc9bd8f5259"}},{"ruleId":"D2","level":"warning","message":{"text":"chat-utils.decodeSyncdMutations (cognitive 25): chat-utils.decodeSyncdMutations has cognitive complexity 25 (threshold 15). Drivers by points: if/else 7 (15 pts), error handling 2 (4 pts), ternaries 2 (4 pts), boolean chains 1, loops 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/chat-utils.ts"},"region":{"startLine":228}}}],"partialFingerprints":{"codehealthFindingId/v1":"51ba700ea1e6a69f54c6a55983e818deb26e710cd539c92c0d5b2c9b4200c628"}},{"ruleId":"D2","level":"warning","message":{"text":"groups.extractGroupMetadata (cognitive 24): groups.extractGroupMetadata has cognitive complexity 24 (threshold 15). Drivers by points: ternaries 9 (11 pts), boolean chains 8, if/else 4 (5 pts) (nesting depth added 3). Of this number, 18 points are the body\u0027s own statements and 6 belong to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/groups.ts"},"region":{"startLine":304}}}],"partialFingerprints":{"codehealthFindingId/v1":"ef596896f210fc8ea2394863068e040a09c3be343572f4ac852e235050705932"}},{"ruleId":"D2","level":"warning","message":{"text":"messages.generateWAMessageFromContent (cognitive 23): messages.generateWAMessageFromContent has cognitive complexity 23 (threshold 15). Drivers by points: boolean chains 11, if/else 6 (9 pts), ternaries 2 (3 pts) (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages.ts"},"region":{"startLine":682}}}],"partialFingerprints":{"codehealthFindingId/v1":"6dd12e6e90a47bfbeeec1672f3614311c7d2f4c34a276bb4f9cc76e2ff2f3b5e"}},{"ruleId":"D2","level":"warning","message":{"text":"encode.serializeData (cognitive 21): encode.serializeData has cognitive complexity 21 (threshold 15). Drivers by points: if/else 13 (16 pts), boolean chains 5 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WAM/encode.ts"},"region":{"startLine":86}}}],"partialFingerprints":{"codehealthFindingId/v1":"78ae6ca12eac55ad62f1f173e75f244a0402a5a8e69389518370ccaba1e49dcc"}},{"ruleId":"D2","level":"warning","message":{"text":"libsignal.signalStorage (cognitive 20): libsignal.signalStorage has cognitive complexity 20 (threshold 15). Drivers by points: if/else 8 (10 pts), boolean chains 5, ternaries 2 (4 pts), error handling 1 (nesting depth added 4). Most of this is not in the body itself: 0 of the 20 points are its own statements and the rest belongs to 6 function literals inside it that branch (lines 443, 490, 464, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/libsignal.ts"},"region":{"startLine":434}}}],"partialFingerprints":{"codehealthFindingId/v1":"16e2b158c74029e4c9df0c86b8665e650e599960adaff089337575a862dffb8a"}},{"ruleId":"D2","level":"warning","message":{"text":"index.extractAllExpressions (cognitive 20): index.extractAllExpressions has cognitive complexity 20 (threshold 15). Drivers by points: if/else 6 (10 pts), loops 4 (10 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"proto-extract/index.js"},"region":{"startLine":10}}}],"partialFingerprints":{"codehealthFindingId/v1":"633857f2f64cf5448edfa1102674e0dc6b6ad971c45a53639cd6784c0ace98ba"}},{"ruleId":"D2","level":"warning","message":{"text":"process-message.storeTcTokensFromHistorySync (cognitive 19): process-message.storeTcTokensFromHistorySync has cognitive complexity 19 (threshold 15). Drivers by points: ternaries 3 (7 pts), if/else 4 (6 pts), boolean chains 2, error handling 1 (2 pts), loops 2 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/process-message.ts"},"region":{"startLine":60}}}],"partialFingerprints":{"codehealthFindingId/v1":"c88f674c869c12761c22102d4f0917474daa4ef5011df1aef222bcdc7205476b"}},{"ruleId":"D2","level":"warning","message":{"text":"link-preview.getUrlInfo (cognitive 18): link-preview.getUrlInfo has cognitive complexity 18 (threshold 15). Drivers by points: if/else 8 (10 pts), boolean chains 4, error handling 2 (4 pts) (nesting depth added 4). Of this number, 14 points are the body\u0027s own statements and 4 belong to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/link-preview.ts"},"region":{"startLine":33}}}],"partialFingerprints":{"codehealthFindingId/v1":"f5e614a777f125f049c6f947ce4fb6df3260c07b06898ee6b40d88ec9aa754e9"}},{"ruleId":"D2","level":"warning","message":{"text":"messages-media.encryptedStream (cognitive 17): messages-media.encryptedStream has cognitive complexity 17 (threshold 15). Drivers by points: if/else 6 (11 pts), error handling 2 (3 pts), boolean chains 1, loops 1, ternaries 1 (nesting depth added 6). Of this number, 16 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages-media.ts"},"region":{"startLine":385}}}],"partialFingerprints":{"codehealthFindingId/v1":"ea4f8f01f2c6bb06145f2ae62021d65fdf7c4632ff55eb259188cd35fa8bdba3"}},{"ruleId":"D2","level":"warning","message":{"text":"signal.extractDeviceJids (cognitive 17): signal.extractDeviceJids has cognitive complexity 17 (threshold 15). Drivers by points: if/else 3 (9 pts), boolean chains 5, loops 2 (3 pts) (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/signal.ts"},"region":{"startLine":181}}}],"partialFingerprints":{"codehealthFindingId/v1":"7a52a4bdc2b325eb357feb2a085101037f1a08daf42c20f32f454836345be6bf"}},{"ruleId":"D2","level":"warning","message":{"text":"chat-utils.decodePatches (cognitive 17): chat-utils.decodePatches has cognitive complexity 17 (threshold 15). Drivers by points: if/else 5 (13 pts), error handling 1 (2 pts), boolean chains 1, loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/chat-utils.ts"},"region":{"startLine":479}}}],"partialFingerprints":{"codehealthFindingId/v1":"05576a029c9f2298e5809767d3e0320fba852478f08b2cfeb9dec415e478d48f"}},{"ruleId":"D2","level":"warning","message":{"text":"tc-token-utils.storeTcTokensFromIqResult (cognitive 17): tc-token-utils.storeTcTokensFromIqResult has cognitive complexity 17 (threshold 15). Drivers by points: if/else 5 (9 pts), ternaries 2 (4 pts), boolean chains 3, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/tc-token-utils.ts"},"region":{"startLine":178}}}],"partialFingerprints":{"codehealthFindingId/v1":"5cdab06ed38dea50a5d9047df3965c8df0c4389f4bf44c52b99bd3a20864344f"}},{"ruleId":"D2","level":"warning","message":{"text":"use-multi-file-auth-state.useMultiFileAuthState (cognitive 16): use-multi-file-auth-state.useMultiFileAuthState has cognitive complexity 16 (threshold 15). Drivers by points: if/else 4 (5 pts), error handling 3, loops 2 (3 pts), ternaries 1 (3 pts), boolean chains 2 (nesting depth added 4). Most of this is not in the body itself: 5 of the 16 points are its own statements and the rest belongs to 5 function literals inside it that branch (lines 118, 106, 50, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/use-multi-file-auth-state.ts"},"region":{"startLine":33}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b279235efeeaf65d0a7a2e470b790fb2148b3907e1f5022fed748004f9a380c"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: messages-recv.makeMessagesRecvSocket: FunctionTooLong \u2014 makeMessagesRecvSocket runs 1354 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 1254 over it, 13.54\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-recv.ts"},"region":{"startLine":110}}}],"partialFingerprints":{"codehealthFindingId/v1":"7d10aaba98647fd6311eb535960b0250cec120565d6004249412f8bfc67637cc"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: messages-send.makeMessagesSocket: FunctionTooLong \u2014 makeMessagesSocket runs 883 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 783 over it, 8.83\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-send.ts"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"25e24b37e7ea782ec533970c87c59fe35047e7d0757754a9ed8517acb61a2005"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: chats.makeChatsSocket: FunctionTooLong \u2014 makeChatsSocket runs 864 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 764 over it, 8.64\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/chats.ts"},"region":{"startLine":79}}}],"partialFingerprints":{"codehealthFindingId/v1":"68406aad36f5c6213a0d32b42038b44d56835831dce1b18b54ec02d53658f862"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: socket.makeSocket: FunctionTooLong \u2014 makeSocket runs 698 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 598 over it, 6.98\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/socket.ts"},"region":{"startLine":72}}}],"partialFingerprints":{"codehealthFindingId/v1":"ea19fa646bd69f8f8f7b2d4ec597d99037a0125127024cd7e0b544d4245a2cfa"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: Socket/messages-recv.ts: FileTooLong \u2014 1454 significant lines (blank, comment-only and punctuation-only lines excluded), about 93% of them inside a single declaration: makeMessagesRecvSocket (110-2174). The bar is 500 significant lines; this is 954 over it, 2.91\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-recv.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"bb5b89e7247fe23f64da0bc0793845df0df2bfbb0403c471890156e30eecda0d"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: business.makeBusinessSocket: FunctionTooLong \u2014 makeBusinessSocket runs 252 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 152 over it, 2.52\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/business.ts"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"123bba8e2fc1f7e595af82412e8c01e3ebe2ec76fde798e5431ddc2e3054fb43"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: communities.makeCommunitiesSocket: FunctionTooLong \u2014 makeCommunitiesSocket runs 249 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 149 over it, 2.49\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/communities.ts"},"region":{"startLine":22}}}],"partialFingerprints":{"codehealthFindingId/v1":"fe12347c32dbdd8d88e0dc28c766b7cb81ab9dc5cae1bbda521562135b9892e1"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: event-buffer.append: FunctionTooLong \u2014 append runs 237 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 137 over it, 2.37\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/event-buffer.ts"},"region":{"startLine":288}}}],"partialFingerprints":{"codehealthFindingId/v1":"69981d6363f82c9dc4e580c9d39785f6ef0639982a16f1f0c6c3412c67e0dadf"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: libsignal.makeLibSignalRepository: FunctionTooLong \u2014 makeLibSignalRepository runs 224 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 124 over it, 2.24\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/libsignal.ts"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"174d4ecbc2a81f18391281017a91cb4778ed5bcd229b233aa28bec5de79c6769"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: messages.generateWAMessageContent: FunctionTooLong \u2014 generateWAMessageContent runs 203 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 103 over it, 2.03\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages.ts"},"region":{"startLine":395}}}],"partialFingerprints":{"codehealthFindingId/v1":"3f6652525854dbde1fe3215d1e73388b7bdc1f140816b53e1fceda666b034bb3"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: chat-utils.chatModificationToAppPatch: FunctionTooLong \u2014 chatModificationToAppPatch runs 198 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 98 over it, 1.98\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/chat-utils.ts"},"region":{"startLine":556}}}],"partialFingerprints":{"codehealthFindingId/v1":"df9e3a9cebd86a3dd9e6bc87b6cc86303d8441a3000027b1b79b483403d06b37"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: Socket/messages-send.ts: FileTooLong \u2014 954 significant lines (blank, comment-only and punctuation-only lines excluded), about 93% of them inside a single declaration: makeMessagesSocket (73-1419). The bar is 500 significant lines; this is 454 over it, 1.91\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-send.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a3a69285f3b749f6ddcee1f7a19649017a5e1f530c2756ea1628bf4cef1f5fc3"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: Socket/chats.ts: FileTooLong \u2014 937 significant lines (blank, comment-only and punctuation-only lines excluded), about 92% of them inside a single declaration: makeChatsSocket (79-1533). The bar is 500 significant lines; this is 437 over it, 1.87\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/chats.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"4240cecbd3c744d4da807dc0ecd259b72a70d67516fc6186338f01216a6673a1"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: groups.makeGroupsSocket: FunctionTooLong \u2014 makeGroupsSocket runs 173 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 73 over it, 1.73\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/groups.ts"},"region":{"startLine":18}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7b2428870660d1872995f747a5787895e51fec188e1594be4d8df0d5f5f2166"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: Socket/socket.ts: FileTooLong \u2014 764 significant lines (blank, comment-only and punctuation-only lines excluded), about 91% of them inside a single declaration: makeSocket (72-1190). The bar is 500 significant lines; this is 264 over it, 1.53\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/socket.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ddce14fde8dafa5a856959ec04691bb0afbcdc84340e44cd6f794770407237d2"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: chat-utils.processSyncAction: FunctionTooLong \u2014 processSyncAction runs 148 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 48 over it, 1.48\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/chat-utils.ts"},"region":{"startLine":823}}}],"partialFingerprints":{"codehealthFindingId/v1":"93f89016adb0973e368d012539d896c432923f9e7151e4759294660a7298b332"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: Utils/messages.ts: FileTooLong \u2014 735 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 235 over it, 1.47\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"35918126c9bd9ecb75a737e02baf9969132756e7d8bfacbbc025b3d2ad2f2e9e"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: Utils/chat-utils.ts: FileTooLong \u2014 707 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 207 over it, 1.41\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/chat-utils.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"2397c1090071ab36759a036a49f659eb2d78f7e0adb498e9cd1995aee2035bbe"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: messages.prepareWAMessageMedia: FunctionTooLong \u2014 prepareWAMessageMedia runs 136 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 36 over it, 1.36\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages.ts"},"region":{"startLine":124}}}],"partialFingerprints":{"codehealthFindingId/v1":"81a879d8fde9c090d22ce4d645a9dfe426e5d9359b6c5e06b9ef6ebf8d7ce3c2"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: Utils/messages-media.ts: FileTooLong \u2014 648 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 148 over it, 1.30\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages-media.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ef873af47e220ce89bed957ffb5ff0eedee24ebb4fdc5a0b8af80e22fe8a3a25"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: event-buffer.makeEventBuffer: FunctionTooLong \u2014 makeEventBuffer runs 117 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 17 over it, 1.17\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/event-buffer.ts"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"df4f7fd7e804fa97c2c529dad714b2171bccf7d8dc1ecf0354fd60c8537607c8"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: newsletter.makeNewsletterSocket: FunctionTooLong \u2014 makeNewsletterSocket runs 114 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 14 over it, 1.14\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/newsletter.ts"},"region":{"startLine":44}}}],"partialFingerprints":{"codehealthFindingId/v1":"09a8ca7e253d9f75bd15c0176d1196be6c01a2c9bbbe13573cac36f2aab4ff0c"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: Utils/process-message.ts: FileTooLong \u2014 518 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 18 over it, 1.04\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/process-message.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ed514ae3e9abb15f5eacd2355b95a7415fdc4dcc7c8a9edf83105fdb9346f12f"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: USyncUser (LCOM4 7): USyncUser\u0027s methods fall into 7 groups that share no field and call none of each other, against a bar of more than 3 for this run (LCOM4, configurable \u2014 your repository\u0027s bar is the one quoted here). Each group is a set of methods reachable from one another through shared fields or direct calls, so 7 groups means the type has that many internally-connected clusters with nothing tying them together. Types whose shape makes a high count expected \u2014 and which would otherwise dominate this list \u2014 are excluded before this row is raised, so this is a genuine split candidate rather than a metric reading. It is still a shape, not a defect: confirm the groups match responsibilities you can name before splitting."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WAUSync/USyncUser.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"6acc66ecf0267315ff68491c3857b4e8b329365df8cd5931b424759f808fdd9b"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: USyncQuery (LCOM4 4): USyncQuery\u0027s methods fall into 4 groups that share no field and call none of each other, against a bar of more than 3 for this run (LCOM4, configurable \u2014 your repository\u0027s bar is the one quoted here). Each group is a set of methods reachable from one another through shared fields or direct calls, so 4 groups means the type has that many internally-connected clusters with nothing tying them together. Types whose shape makes a high count expected \u2014 and which would otherwise dominate this list \u2014 are excluded before this row is raised, so this is a genuine split candidate rather than a metric reading. It is still a shape, not a defect: confirm the groups match responsibilities you can name before splitting."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WAUSync/USyncQuery.ts"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"395d53684305b7b225c85aa17cd5d182dd158bf249487b1bd8f7c88c2ec81048"}},{"ruleId":"D10","level":"warning","message":{"text":"No assertions: alice and bob exchange messages bidirectionally: This method\u0027s body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* \u2014 so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as \u0027no assertion this check knows how to see\u0027, and if that is right, add one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/__tests__/e2e/messaging.test-e2e.ts"},"region":{"startLine":30}}}],"partialFingerprints":{"codehealthFindingId/v1":"83d5054bf858882028ad99f7b8d92a8414c25c2ef01816d8b890a860a6b099bc"}},{"ruleId":"D13","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"25fa2af995f5857e0561087a55bf122bc82f3d85b40e6d5006f13c88677b5615"},"taxa":[{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D14","level":"error","message":{"text":"Banned license: libsignal: \u0060libsignal\u0060 6.0.0 is published on registry.npmjs.org under \u0060GPL-3.0\u0060, which this policy bans, and it is a PRODUCTION dependency this repository\u0027s committed lockfile resolves \u2014 so it is installed by everything that depends on this repository, not just by its build toolchain. A package offering SEVERAL licences is a choice and is only charged when every one of them is banned. Replace the package, or record an accepted exception."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"25f970ee0e675e18382c366ae477f8e71ba046b9c1312efb9b595a80dcad47f4"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/Socket/chats.ts: src/Socket/chats.ts changed 2 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 146 in chats.makeChatsSocket at line 79. 1 of those changes was a fix/bug commit, and the other 1 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-05-06..2026-08-04, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-05-06 20:41:35 \u002B03:00\u0027 --until=\u00272026-08-04 20:41:35 \u002B03:00\u0027 --full-history --no-merges -- src/Socket/chats.ts\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/chats.ts"},"region":{"startLine":79}}}],"partialFingerprints":{"codehealthFindingId/v1":"000af71203226a5dc548278e4613f57ddaa36ad909871691e5a6f6f8616e3618"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #1: If anonymized user #1 becomes unavailable, 2 significant file(s) lose their only recent owner: src/Utils/reporting-utils.ts, src/Utils/identity-change-handler.ts. Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"40d76ab06e05995bd68140dbb49916e61942b4a14e513b038b1537fcd71e26b8"}},{"ruleId":"D16","level":"note","message":{"text":"Further sole-owners (lower concentration): 1 other contributor(s) are each the sole owner of a small amount of code below the off-boarding threshold \u2014 folded into the bus-factor score and metrics (3 single-owned of 52 analysed files in total, counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 52 of the 101 production source files in this repository met that bar). They are anonymized user #2 (1 file(s)) \u2014 spread or document their files in the same way, at lower priority than the named off-boarding risks above."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6eac528f2429e724e1a97ed868f79eefbcf1888dab4af9a9e673429369bb5b2f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: use usync to handle this entire mess \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/libsignal.ts"},"region":{"startLine":266}}}],"partialFingerprints":{"codehealthFindingId/v1":"400a63403169ca39925c0eb98db247b81cea222f95dca7c5b98cba09d95ad0f0"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: validate users, throw WARNING on no valid users \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/socket.ts"},"region":{"startLine":275}}}],"partialFingerprints":{"codehealthFindingId/v1":"8db0e6cc3250d2aa88f80042e89a680a2dfb6032efdf6a7d33aa168d48ba5da0"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: explore full length of data that whatsapp provides \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-send.ts"},"region":{"startLine":140}}}],"partialFingerprints":{"codehealthFindingId/v1":"f8727db100e50e086789e696c35998d4411a8eec3afd3539b4d61f58b937e26a"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: investigate - the idea here is that \u003Cuser\u003E should have an inline lid field with the lid being the pn equivalent \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-send.ts"},"region":{"startLine":318}}}],"partialFingerprints":{"codehealthFindingId/v1":"12c58827ea80e7f5dc5a73bfbb0064131db0bc8e9a0ed441454abe71d5349868"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: LID MAP this stuff (lid protocol will now return lid with devices) \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-send.ts"},"region":{"startLine":324}}}],"partialFingerprints":{"codehealthFindingId/v1":"a5d1b489b3d05fb03ad2f3c5650e984a555c1832c2e5edade9b09e6442091fc0"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO: for later, abstract the logic to send a Peer Message instead of just PDO - useful for App State Key Resync with phone \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-send.ts"},"region":{"startLine":504}}}],"partialFingerprints":{"codehealthFindingId/v1":"18e6d24fc58fcd644576634308de923d8885bb625c33eacb0d3d126c69f508a6"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: expand for reactions and other types \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-send.ts"},"region":{"startLine":706}}}],"partialFingerprints":{"codehealthFindingId/v1":"095300ae0a64c1b5204a428ab40d3e263af72de98006662b03ea0c8d78a6806b"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: should we rely on the cache specially if the cache is outdated and the metadata has new fields? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-send.ts"},"region":{"startLine":712}}}],"partialFingerprints":{"codehealthFindingId/v1":"158cbf2e05ad35a2e91295b8abc7a004bccfc751bc8ea7eae6712c769bf9a9fc"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: start storing group participant list \u002B addr mode in Signal \u0026 stop relying on this \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-send.ts"},"region":{"startLine":716}}}],"partialFingerprints":{"codehealthFindingId/v1":"ca3bc6417b8cceaa8394c88c8e80e94038fbd044d69939a64f181769b98c20c0"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: check out what if the sender key memory doesn\u0027t include the LID stuff now? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-send.ts"},"region":{"startLine":725}}}],"partialFingerprints":{"codehealthFindingId/v1":"fb4697bdef946b10c51fab4a3df609e801362bbad766041ca7f000d654ec53cc"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //todo: revamp all this logic \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-send.ts"},"region":{"startLine":782}}}],"partialFingerprints":{"codehealthFindingId/v1":"f0c236b87ec4f82d9db193e2dd1ba74a73722a04e66e0616c54abc08d92419dd"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: investigate if this is true \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-send.ts"},"region":{"startLine":817}}}],"partialFingerprints":{"codehealthFindingId/v1":"759388c253f2ec52f90f28c76d42f2f0b5eb1ed04155f48e27618c8887854a4f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO: CACHE \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-send.ts"},"region":{"startLine":1358}}}],"partialFingerprints":{"codehealthFindingId/v1":"fba7114cd2901396aa5aa885db975d8ed2bf7697cf1eb258495e393c25ddeb4e"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: is this really true though \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-recv.ts"},"region":{"startLine":524}}}],"partialFingerprints":{"codehealthFindingId/v1":"f3809cdb32ef1be92100955f5749c5a5a7e76137651b9c813477815a252aa847"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Support PN/LID (Here is only LID now) \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-recv.ts"},"region":{"startLine":802}}}],"partialFingerprints":{"codehealthFindingId/v1":"00348dbb4c88ff3ec7a24f0336c3b5af7475d2b34b8930d64a0c606456b363d9"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Store LID MAPPINGS \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-recv.ts"},"region":{"startLine":858}}}],"partialFingerprints":{"codehealthFindingId/v1":"7ecfddfc2a5615e83b77c7bd65c251c60c997e2519d8508d184ab9e0b95e19c2"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Store LID MAPPINGS \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/groups.ts"},"region":{"startLine":370}}}],"partialFingerprints":{"codehealthFindingId/v1":"d67daa514142b9006db689a749bebd618c9faf9219e120c034df9a444369d6bb"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: LIDMAPPING SUPPORT \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-recv.ts"},"region":{"startLine":930}}}],"partialFingerprints":{"codehealthFindingId/v1":"061c259e4065027ef0732ded3914e86ba7ac95703c42a7b499937dce9a835cc5"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: HANDLE PARTICIPANT_PN \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-recv.ts"},"region":{"startLine":1049}}}],"partialFingerprints":{"codehealthFindingId/v1":"e0945f44fadfab013a0846a9763a93df6b90cb3579c010ca78247706be89320f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: WAJIDHASH stuff proper support inhouse \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-recv.ts"},"region":{"startLine":1079}}}],"partialFingerprints":{"codehealthFindingId/v1":"c339bfb209c9c4da922352237dae71b2a8458bb2f6547501efb705d5e19018f2"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: temporary fix for crashes and issues resulting of failed msmsg decryption \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-recv.ts"},"region":{"startLine":1587}}}],"partialFingerprints":{"codehealthFindingId/v1":"a9128d64a16c5f9d9170662787e0f0cc445fd850f90e57f97f7d20de3a7d2762"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: investigate sending receipts to LIDs and not PNs \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-recv.ts"},"region":{"startLine":1751}}}],"partialFingerprints":{"codehealthFindingId/v1":"62c7c4e2dba509b73a7f8883c6da1a4a1ffa2f2fe0cc8ecf69d7d1dbf01e5601"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: investigate \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-recv.ts"},"region":{"startLine":1764}}}],"partialFingerprints":{"codehealthFindingId/v1":"32b5ecab2d9ef265f69263d4c74835bfbb0a51dabe2036c89c3ccfad16215bdb"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: investigate \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/process-message.ts"},"region":{"startLine":389}}}],"partialFingerprints":{"codehealthFindingId/v1":"2d2b668370b77c319d4c93093ebba83af867abc55c95607b4dc163aefe15ad37"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: properly parse LID / PN DATA \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/groups.ts"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"389b7ebc6be82ad8beea3ce7ec1f031728b59a92198013982fd9c2a149a37467"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: investigate if this makes any sense at all \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/communities.ts"},"region":{"startLine":393}}}],"partialFingerprints":{"codehealthFindingId/v1":"7c654a47c360fe7c75e93e27ea2373100f75ea5dbcf2dc269588e967a0af42e7"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: IMPLEMENT THE PN/LID FIELDS HERE!! \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/communities.ts"},"region":{"startLine":468}}}],"partialFingerprints":{"codehealthFindingId/v1":"54d31156a9d614193e1988be18f7e9d01d5f70b3e67ee9ccb4fb6a336097f51b"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: refactor and gain independence from Boom \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Types/State.ts"},"region":{"startLine":23}}}],"partialFingerprints":{"codehealthFindingId/v1":"652b96f7d38a6c923c31c0c30dcdad740bae04494fa0e67a8819adb4f9abfab0"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: remove out of the message key, place in WebMessageInfo \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Types/Message.ts"},"region":{"startLine":27}}}],"partialFingerprints":{"codehealthFindingId/v1":"f756fe3d972dfd8172976a0983b36cccc706e33d7c536c4aa6057074089cf44c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: refactor this mess \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Types/Events.ts"},"region":{"startLine":19}}}],"partialFingerprints":{"codehealthFindingId/v1":"a01f0cb6dacce141610e9519e5431bc9d99a3f74136da3539cb30ce013792027"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: investigate (hard set as false atm) \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/validate-connection.ts"},"region":{"startLine":82}}}],"partialFingerprints":{"codehealthFindingId/v1":"39b38350c96839ee670502fb90ba30fabd7565b48589edf7105daee022ea50c8"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: investigate inconsistencies \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/process-message.ts"},"region":{"startLine":162}}}],"partialFingerprints":{"codehealthFindingId/v1":"1434c99fd26d274446f0ecd60c171643f29e5e7de3a3e2d92dda12b7f12959e9"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: target:audit AUDIT THIS FUNCTION AGAIN \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/process-message.ts"},"region":{"startLine":170}}}],"partialFingerprints":{"codehealthFindingId/v1":"daf6c1bbf8887053a2a0d138acde1a07d080fcfc45018cb0cdb653c803bbbd3d"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: IMPLEMENT HISTORY SYNC ETC (sticker uploads etc.). \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/process-message.ts"},"region":{"startLine":463}}}],"partialFingerprints":{"codehealthFindingId/v1":"b324be071f0a79e7ad96e3e31b0b6e9ef2640f6d419810d02c672d2772c1449d"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Add other events \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/process-message.ts"},"region":{"startLine":730}}}],"partialFingerprints":{"codehealthFindingId/v1":"364acd12f8ee01a1f1f8cd1d21059e4e5343697efe1a850093f33dcbed666dc4"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: make standalone, remove getMessage reference \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/process-message.ts"},"region":{"startLine":740}}}],"partialFingerprints":{"codehealthFindingId/v1":"06cec28648bbe90c5a709e74134126acc7982e1f8757ec980e818e32d1ec45ac"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Remove entirely \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/process-message.ts"},"region":{"startLine":741}}}],"partialFingerprints":{"codehealthFindingId/v1":"97fbe69cc1a076345e19f10134f195923ee23d4207fec8323ffb7cd2480acfb0"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: add more support here \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages.ts"},"region":{"startLine":195}}}],"partialFingerprints":{"codehealthFindingId/v1":"622849cf814454ebd90bd1e076c0a3086e247b16808b3d010941b07dbbf2b229"}},{"ruleId":"D17","level":"warning","message":{"text":"HackComment: // hacky copy \u2014 a workaround marked in source: record what it is compensating for and what would allow its removal (the upstream fix, the API it is waiting on, the invariant it restores), so the next reader can judge whether it is still needed rather than rediscovering why it is there."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages.ts"},"region":{"startLine":353}}}],"partialFingerprints":{"codehealthFindingId/v1":"d04e35753f81830848cdaba202c4d9217eea0a0b8da10f6b59e9d464d3ec97a0"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO: use built-in interface and get disappearing mode info etc. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages.ts"},"region":{"startLine":478}}}],"partialFingerprints":{"codehealthFindingId/v1":"7bf45e7caabd1ee28857caa79b27f231b022b97d6144aff0b78150f1cfd9c1fd"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO: cache / use store!? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages.ts"},"region":{"startLine":479}}}],"partialFingerprints":{"codehealthFindingId/v1":"4a06ed1a08495681511e45979ed162f3a1dde103da7acf943f6a0c7f14b35669"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Add support for LIDs \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages.ts"},"region":{"startLine":700}}}],"partialFingerprints":{"codehealthFindingId/v1":"20019119f2a02a833044994f61fe6f52c14b1f12518a0bfaaf2043268d3aa763"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Add support for LIDs \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages.ts"},"region":{"startLine":760}}}],"partialFingerprints":{"codehealthFindingId/v1":"818d277dab0ad569f01abda5693467f52fdb990a0d5671a6e5c0b104001faea2"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Move entirely to sharp, removing jimp as it supports readable streams \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages-media.ts"},"region":{"startLine":136}}}],"partialFingerprints":{"codehealthFindingId/v1":"687f56cdce3d6ffcc8d51a85709c9050a663d94f7241ae6b471406c7b12fab65"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: add support \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/event-buffer.ts"},"region":{"startLine":561}}}],"partialFingerprints":{"codehealthFindingId/v1":"8b8efc634cbaaf65a7fd4e678d48a315d29078e6b540b189a4128bfcc6b1b310"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Handle hosted IDs \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/decode-wa-message.ts"},"region":{"startLine":38}}}],"partialFingerprints":{"codehealthFindingId/v1":"35289bef818e23fb02b5d51e6a2b9e5b8e19be16b52577723ed50dcb06931e43"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: remove from here and add a STUB TYPE \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/decode-wa-message.ts"},"region":{"startLine":287}}}],"partialFingerprints":{"codehealthFindingId/v1":"616eeafaa7b4a29366f54d74f28176b1f402d83423d84d2db69b34f2d06ccf58"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Handle hosted devices \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/decode-wa-message.ts"},"region":{"startLine":309}}}],"partialFingerprints":{"codehealthFindingId/v1":"20567e13bf84795ac34d4b9ce22859bb03d9841179803556763e6d0002534143"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: investigate how to implement hosted ids in this case \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WABinary/jid-utils.ts"},"region":{"startLine":56}}}],"partialFingerprints":{"codehealthFindingId/v1":"14beac143ec331d24932580e89f0970579ed04bbcb41d4278f0c014417beef3e"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: implement errors etc. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WAUSync/USyncQuery.ts"},"region":{"startLine":61}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a017faaa5de4c0a8dbe261ce2daf8580efb8e0c00d7a74c18c28d0c5e1b955e"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO: implement error backoff, refresh etc. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WAUSync/USyncQuery.ts"},"region":{"startLine":68}}}],"partialFingerprints":{"codehealthFindingId/v1":"6d93fedc38c0980696b8f86628885f21d5818126f1398c0f97c330e26cc39d63"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO: see if there are any errors in the result node \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WAUSync/USyncQuery.ts"},"region":{"startLine":69}}}],"partialFingerprints":{"codehealthFindingId/v1":"88aa4bfe1011948bb9cb8ca7d29cfea4111dd2db0e0be00df78283e702d39318"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO: implement side list \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WAUSync/USyncQuery.ts"},"region":{"startLine":100}}}],"partialFingerprints":{"codehealthFindingId/v1":"659eea784760a65dc14e79f450d4247ded339ceb9b4a4b679e36548a25a4a4f9"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO: Implement device phashing, ts and expectedTs \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WAUSync/Protocols/USyncDeviceProtocol.ts"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"ff23603afad1fcad0ff2a349e8ffaa51e53ee0822570e39dac5646ab2c7e9e3c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO: if all are not present, return null \u003C- current behavior \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WAUSync/Protocols/USyncDeviceProtocol.ts"},"region":{"startLine":36}}}],"partialFingerprints":{"codehealthFindingId/v1":"21a58a144312d64418b50b77b51f7622ae027047ff72fa8cdd20982aa2bc7280"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO: otherwise return a node w tag \u0027devices\u0027 w those as attrs \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WAUSync/Protocols/USyncDeviceProtocol.ts"},"region":{"startLine":37}}}],"partialFingerprints":{"codehealthFindingId/v1":"b5ce4781363d86ab4585925d389d26caa1b0431675ec4418d206080f63de0bb0"}},{"ruleId":"D26","level":"note","message":{"text":"Projects may be oversized for their cohesion: 1 of 2 project(s) overshoot their size bounds, lowering Project Cohesion to 0.0/10. The most over is \u0060(repository root)\u0060 (43731 LoC, 142 public types across 13 directories). Review these for cohesion \u2014 draw the boundary inside the module first (group each responsibility into its own package or directory and keep the cross-boundary members non-public), since splitting a published package moves types between packages and breaks consumers."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d5a94650dc74886a0f1f08eb9fb6775f1fc395279ef7e901c970c9d26f767a72"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d657c6d74de84083bb5bbd336f2b15abb65c5e56abe923e5a7465d016d0d5c5a"},"properties":{"commitSha":"f8a538eee293c38387c08b2ea97b22d9b61c9d55"}},{"ruleId":"D28","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3cdfd7beb31b791ae18dcb425e21eb157c842e7bbcd522cc330573c1a6538db1"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9603565aa6069e0abcf535dcde33980e7f55a15fa6af1c7abedeeffe7f52bf08"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"aeac62ac05a248923a739032d3983624555d5962ce89e8ecd033796dc901db60"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2fbb80e84aaa7e5d18fcef396e8c3e57fc3a1c67c12c52696ac4908702161662"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"897504e2c29bd666d3e71d739a4484bebc73a312c0341fd1422879e58602266e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"986956032f8efd0ae73a971a3cd56fbdb95979d4c603387e66425f4de769e05b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"872de5d59ab2c57615d1ae78f98e1bc0238074d8e58636fab9dce3d4f21cf57a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"12104b6bbe331eb564da74c0323616747ebd241a161ddd6b13fa7d99473470c7"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9914f28575ed2afc4a7f533538da7b9735649f76d7acf42954f2ad3061bb6ca1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9ed755679fe6dfda391e792dfe52299542c72440443137882d378ac3af9dfc82"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"354ce32ef9e89c9d2c859d3f860cffa78e3ff1811a27718904b2ff57e02463cd"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4440afd3ba471b064119c051b07478ca836bfc7d9567a72cccc1bfae32bcabcc"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9a666c70161ffdcccb303f7ac98bf5d4a2d5c891c542954a141768d8948b9155"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0ddbd9298ce349dc44101e812e36b43aeb937046b364ddafd9bf8cbe2569f318"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0d324a5c056f991ad4eef638064732ea12bf8309cdd5c67653d31d847557bcec"},"taxa":[{"id":"CWE-269","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"141b36e23c1fd948511092101e9a5f90e3dedec51ebe055cbb404858c5bcb6ea"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f744c580e0225d6960fd52b7605b3ea21c31cb95fcc4ae6686975e68dcbeef86"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"069436d79dc4765ffc099992ea78424da71c78292c81aaf276d6749130d908fd"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f661d4c6359ae1136934d1403c6e30ee5c0646f850f68d090e9663616db54a80"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"25bb14c2470637301f5fe9b6e411640f28a1800f03aef643600dd2613b0de6cf"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fbf7da89368ebf387222d7362ae778cc2188afae2df2126dae6eeb5ee1d02773"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"139b038b9d4b41ac3ba46e204a02d87015b7b0ed4091af2005e0f16f633aa112"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9e6671a31e85383822777f3d90baccf3fd1a110f863a1604a9eae0d630ec077d"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"77f076f91a2e04d8232dd57ece16ee336ff4e62d33ea78b5477ee1caab33f46e"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ab8d83539c5ebe567cb6deae98d392d6617f9ea4001a34a9a21fb3f393c0be8f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"51deb5f11d29da72484d112de68af7e38e0a51818f441a6e0dd487a6031a58d2"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"904b3f333838d97fde9dc807fd4560c10f8371b02ab76c0e403975727509d022"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3b05ba515a0129218f03788d09f94768f02609db43e2061d6ce787be3145aa87"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"91eab49e65020a98c730d7e350d49c7d7b063f392f0b24436c68fc410c455719"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"243750846cee1e4d90d54322ac74d60ffa1d25cf364d4ff0a212750008340012"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"73c8906a41f734a43143d1c5921a5af822aa31f6d7afcc65734ae8ee8cdc285d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"42099e15ab2fb027ae5788790f6095e66b4a61b5ca46eb90ec4c888c184ab9a9"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"396401d4837a904f8fa0c54890661ac5059945840094bd765cd856df14430f70"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bee1ecca10ff2520affdd574c36fe3ec559681a5cd419be1c9a1a17bd8f14469"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e37d8c3080d3f8e690d19a540a352f863a9d0d11f51431a4df4b2e0a9df4df9"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"43936724ce9104cbcbd3b2a6abf084db7ce16d31f0f19df8bf94c7b0c1cdc45c"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"56a00c2a871232b82bc97787799bd73f7a43ccb6d7d3ab137a356d853dacc9a5"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e0175b8d6229fb0099bd854f8596870c5b897562f3df1be422ec8f7c128c8f56"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"75a47f88c95139d014f3e4f3ab083f6bfd1b73a0beff32a62a4056dcf1393c5a"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8630c7ac6a0cefe483b018d9f11144902fcd5188d4d04b20194a731bd0cd5693"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1329","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"50f54279ac3b73d0b30df6604956a46a7b888091bbd5f02ae5e6c9efc0cfbb34"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1329","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"08a48b1a5d18dad4d44aa67da6188190ab35e4b064f1f3e46f7005b6d4d03f28"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1352","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f81de7f18ac8482964c36faa98746e0354a60f0150ffb4b717f7743153a1c12a"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1329","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"46e5cd56ae4274f38fb5b04b417af2e5fed1e1688a79b9a64ecaf5b425765409"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"802306358db31e73c4181258c4aeb10e440955e3d00a91a16283182f4041ac0d"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1352","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d558a41e1ecea5da409b22a9f962624f0a4ee1f8d65c51484534ac4042ab7655"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1352","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4915cc96879f11ca84c5ded856b545f7897b6af9621cab9f5bd7d996fec28f1f"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1352","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f6adfa6f3039e75b655c3b226255df9dcbcd14f4b43b0c7dfd6cc804755bdc42"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-552","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5044188dfc85f10da6a3e1c096c6f4cdad8cc50fdc27f76ea471eeef4362b554"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-552","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"73c6a417c00c887ecd70c03c9ab06fa7e63a67c2e087d88de8fda3c537e12d83"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1352","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b0225ae7e4051a121655972b6d89c50b7d49f8f98798df05122fafdbb3f51fa5"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1352","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"87f83ee7bafd5dfa95cedfb98c51eeba6383af150599457a0da8b67100c47c5f"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1352","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0f9291aae80ca13331a0a274469c1220076d26d4690e70903be13ef565e5e453"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1352","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bec15c78b7007dd6ed69169f948bc3ff822b8a72204454e9e65aa1fa7a6fb93f"},"taxa":[{"id":"CWE-125","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8e5e3ed970394ee6d8cc06cabd0b41ba332e6ccdc98d68bb5f964dad5f7b6984"},"taxa":[{"id":"CWE-125","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b5af76518f2e08b4a26e6f10a46573cca6a19f0d85a6112b6e5379386b88d17c"},"taxa":[{"id":"CWE-125","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"85b566ed09576211b15f16477da6d58ba6af6e57c3dec05846ebb49d7815916a"},"taxa":[{"id":"CWE-125","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fe90143711aafab7f157c08c53c663baf850c4fa93a547c8392e27a76b20fa59"},"taxa":[{"id":"CWE-125","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"03cdeb9d0a287d4f62e5b00e7aea65aee7b2c152a0995bd709ba2eb5b58aa3ff"},"taxa":[{"id":"CWE-125","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e4649caaa4c21153e63972ad075786af62678fe04ee9c35fc257ec6c14908b72"},"taxa":[{"id":"CWE-310","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e5697a90eefd746c699fe059acfd292e6953149f527d1a40cd60bc7d30d0fd85"},"properties":{"dependency":{"package":"json-schema","version":"0.2.3","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e5290fb6fe2e07c902a029b2e627c3c1beeaede8f8149ea896c872b7c5dd4cb8"},"properties":{"dependency":{"package":"form-data","version":"2.3.3","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1c9a61626e0d439eacda938bf7340276efbf3bfe3de024eb2bd43a16ebca4a59"},"properties":{"dependency":{"package":"tar","version":"7.5.14","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fa2b418ebfceed090cf4d0c18e340973864d309b70ad1f11356e789362739959"},"properties":{"dependency":{"package":"baileys","version":"0.0.0-use.local","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"28f6e6a17a23f2f262ae716ce298d9fc29bbb60fbf9082f4da7ed805e2b1e5ca"},"properties":{"dependency":{"package":"qs","version":"6.5.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"413620234360206f3ec12c572f16485e1d8eba49e759ee46aaa03eb2aaa2fce8"},"properties":{"dependency":{"package":"lodash","version":"4.17.21","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"89846c388d1345bd3d1c8d91a1876ee1bd4f599959f91271beda32e68d7e0ef0"},"properties":{"dependency":{"package":"linkify-it","version":"5.0.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1626c54f745b97160bcf3510ff10b11358af9e4eb3e90bd58fbfd47f8162e4bf"},"properties":{"dependency":{"package":"js-yaml","version":"3.14.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6f5a906de12491a44662133469417be6c392cdcbcb3405b04632b0f598202612"},"properties":{"dependency":{"package":"js-yaml","version":"4.1.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"40f2e514bd3f77ed5acdd9f95f2849c6001eb8818fb395c9fb524969d6426587"},"properties":{"dependency":{"package":"brace-expansion","version":"1.1.14","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4e29bc3cccb27117fcd2275d94545926cc0641a040ef0b74d649c5c12bc31d6f"},"properties":{"dependency":{"package":"brace-expansion","version":"2.1.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fc96b814c97b979f91b5b729319c7e4af786656b6652919c3f09c941f2547f55"},"properties":{"dependency":{"package":"undici","version":"7.24.5","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e71bcd46c5035bdf476f9a558639efbfce1ddbd75b4533dd3e54a3147dc2d597"},"properties":{"dependency":{"package":"link-preview-js","version":"3.2.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"production","file":"src/Utils/link-preview.ts","line":45}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"775e7acc0328d2696632f11082bdec0123b3b60ea654529217d47b1bf0e4751e"},"properties":{"dependency":{"package":"protobufjs-cli","version":"1.2.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"test-or-tooling","file":"package.json"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"516168152bb5dba93c5dbb03351418a2c72ea2c9ecf10f18a6ade72fa55dd0a9"},"properties":{"dependency":{"package":"browserslist","version":"4.25.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3109fe12da6c70d79185eb39354b9d91447102db38ac52ce8247c411d12173b8"},"properties":{"dependency":{"package":"ws","version":"8.18.3","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"production","file":"src/Socket/Client/websocket.ts","line":1}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"23ff8721b1719c2074f99ad4c8d944a3bf19825855bcc0f5a15c2bf7bc64f588"},"properties":{"dependency":{"package":"basic-ftp","version":"5.3.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d3322cfa69f32b8fe1e33a0f5f0f552005af75b9130c549b9d4efb8f23387821"},"properties":{"dependency":{"package":"ip-address","version":"10.2.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"330a15ae56339582fb30f322dbaf3c180ec7ea3b2c8580445f5acb89f50db699"},"properties":{"dependency":{"package":"tmp","version":"0.2.5","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"22e5e63065a908a405c75e5ad0246b40632cda439f08ac8f7d646a1135a2d364"},"properties":{"dependency":{"package":"protobufjs","version":"7.5.6","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"test-or-tooling","file":"src/__tests__/bigint-validation.test.ts","line":2}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f676dea69a1d6dc64e028474a97519e9f6a05f4a05b916af09944f094f5abd2e"},"properties":{"dependency":{"package":"protobufjs","version":"7.5.8","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"test-or-tooling","file":"src/__tests__/bigint-validation.test.ts","line":2}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b5b0a402fbd0ae1d38c5087f0f4341f57f81b4c9b75f5dbe971c27352ffc0df2"},"properties":{"dependency":{"package":"tough-cookie","version":"2.5.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ad43e76ab6bd0f911c60fb7ce41a06a9b69bce9905aa675df8099d5a97d187fa"},"properties":{"dependency":{"package":"request","version":"2.88.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"02484e3bcdfc341d4b6b3e5e7d9feebad8a010a4349295c27701d71e5f40ce63"},"properties":{"dependency":{"package":"uuid","version":"3.4.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"73b985f17f4f7358c644c18eea4e014d51c363ec76f6a0bcfea42dfe80f29593"},"properties":{"dependency":{"package":"qs","version":"6.5.3","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"42e57bd6076b1c50639213eb012779efb1eebb3a5c151c7b3f06088941dc8e22"},"properties":{"dependency":{"package":"markdown-it","version":"14.1.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"76cffb8b29a20d384f0c702ad8d0d4ba89df79914b8d5d3e5c65f8dd1d6b5582"},"properties":{"dependency":{"package":"@humanfs/node","version":"0.16.6","advisory":"[GHSA redacted]","reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"696950c1aa4ac8042480bf39cdfbb11060aa9dd830b45962f66317e71dac10ad"},"properties":{"dependency":{"package":"@babel/core","version":"7.28.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: lid-mapping.ts \u2194 messages-send.ts: \u0060src/Signal/lid-mapping.ts\u0060 (context Signal) and \u0060src/Socket/messages-send.ts\u0060 (context Socket) sit in DIFFERENT parts of the tree yet change together 52% of the time (11 of the 21 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see. You can check this without leaving the row: of the 11 shared commits counted here, the most recent 3 are \u00603730684e\u0060 feat: add cleanup handlers to prevent memory leaks on socket close (#\u2026; \u006050d410d1\u0060 chore: lint; \u006029318cf6\u0060 chore: lint and re-organize \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/lid-mapping.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"698437817541abec85163de941f0eff8cef7e8b5d217e859471dc23f82e072e4"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: lid-mapping.ts \u2194 socket.ts: \u0060src/Signal/lid-mapping.ts\u0060 (context Signal) and \u0060src/Socket/socket.ts\u0060 (context Socket) sit in DIFFERENT parts of the tree yet change together 52% of the time (11 of the 21 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see. You can check this without leaving the row: of the 11 shared commits counted here, the most recent 3 are \u00603730684e\u0060 feat: add cleanup handlers to prevent memory leaks on socket close (#\u2026; \u006050d410d1\u0060 chore: lint; \u00607ee0b617\u0060 chore: lint \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/lid-mapping.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"38221401d65c1172a0c379cbced8c328cc562f1191b2dd3099e1c05867ee2a27"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e17f71490e4d120a48b2b2881ab866c93b272bef2febb673a3e8e42b2c288ab"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eb00976a698a5d68999b7ee6d27206fd374e916853e7ff1ead5eed42386f043f"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"90f83b4fa27db32740afe9540c905f3c0499caed87f61049a8a903ecc95b41c3"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0752d0df7434000fcabf1048e2de30a7a1a8b982b3db9a19898c4dec199856b4"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d068c977b62d9a977df1bb6f53e8b00b586c3abee955f91d715f92b8e019d624"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"01617c8618e3c4e3878dbf35ba9ff053ccec9d7cd1ea559a8db623472c13a49c"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ace515990e7ee0f17b5c17e44dd168a5bdecf90804a3a3dd845cf05540978013"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"M4","level":"note","message":{"text":"README/code drift: README claims a \u0027Sponsor\u0027 link but the evidence shows no sponsorship page \u2014 reported by the model that read the README against this repository; no term search was run for this one, so nothing here has been checked against the tree. Treat it as a reading to confirm, not as a measured contradiction: verify it against the code before acting on it, and if the footprint it describes does exist, this row is wrong."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c132b6ac6ed47a25ac40efd9cf4e053ea370f5f1aae91a33b1a5af13233d8656"}},{"ruleId":"M4","level":"note","message":{"text":"README/code drift: README claims a new guide at https://baileys.wiki but there is no such guide in the evidence \u2014 reported by the model that read the README against this repository; no term search was run for this one, so nothing here has been checked against the tree. Treat it as a reading to confirm, not as a measured contradiction: verify it against the code before acting on it, and if the footprint it describes does exist, this row is wrong."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"59f1fbec4030bf5dc51daa2786d785759ef971a1d2093136aba919fa0d45806f"}},{"ruleId":"P3","level":"note","message":{"text":"No SAST: No static application security testing detected. For this repository\u0027s stack, add CodeQL\u0027s javascript-typescript pack, \u0060semgrep --config=p/typescript\u0060, or eslint-plugin-security as a CI step. What was searched, so you can tell an absence from a miss: the 15204 CI workflow file(s) in this repository, and the scanner and linter configuration checked in beside them. A scan that runs outside CI, one configured in your forge\u0027s web UI rather than in a committed file, or a tool whose name is none of those this check carries, is not seen \u2014 if that is your case the row is wrong, and saying so is more useful than adding a second scanner."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6e54424179c892f03ef2fd003130ac4bd43f39bbf3b1ca0a0143e25acb80ec87"}},{"ruleId":"P4","level":"note","message":{"text":"No release approval gate: The release is automated and no gate that pauses it for a human is DECLARED IN THIS REPOSITORY\u0027S PIPELINE FILES. What was read: every file under \u0060.github/workflows/\u0060, \u0060.forgejo/workflows/\u0060, \u0060.gitea/workflows/\u0060, \u0060.azuredevops/\u0060 and \u0060.azure-pipelines/\u0060, plus \u0060.gitlab-ci*\u0060 and \u0060azure-pipelines*\u0060 \u2014 with comment text stripped, so documenting a gate is not declaring one. What would have counted: GitLab\u0027s \u0060when: manual\u0060, CircleCI\u0027s \u0060type: approval\u0060, an Azure \u0060ManualValidation@\u0060 task or an \u0060approvals:\u0060 block, a Jenkins \u0060input\u0060 step, a \u0060uses:\u0060 step naming an approval action, an \u0060environment:\u0060 paired with \u0060reviewers\u0060 / \u0060required_reviewers\u0060 / \u0060protection\u0060 / \u0060wait-timer\u0060 / \u0060deployment_branch_policy\u0060, a draft-release step, a \u0060workflow_dispatch\u0060 promotion, or a release-event gate. \u2605 What this cannot see, because none of it is a file: a GitHub environment whose required reviewers are configured in repo SETTINGS, a branch protection rule, or an organisation deployment policy \u2014 all of them real, enforced gates that live outside the repository. If yours is one of those, this row is wrong and nothing in the tree could have told us. Otherwise: whatever the release trigger points at is published to users unreviewed, so a mistagged or unverified commit ships and the only remedy is a follow-up release."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6c11e2dbd483b4b423b95ac61bfcc7af1d55351b28a20d2b1105b31cfe38cc60"}},{"ruleId":"P6","level":"note","message":{"text":"Changelog looks stale/thin: The changelog this check read carries 1 versioned entry, against a bar of 3. Counted as either an \u0060x.y.z\u0060 string or a version-shaped section heading (\u0060## [1.2.0]\u0060, \u0060## V14.x.x\u0060, \u0060## Updates in 8.0.x\u0060), whichever is the larger \u2014 so a log sectioned by minor series counts its sections, not its individual patch numbers. Entries recorded somewhere this check does not read \u2014 release notes generated at tag time from a generator config it did not recognise, or a log kept outside the repository \u2014 are not counted here, and this row is about what is re-findable in the tree rather than about how often you release."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c9a74c249fe67853238d9c15085f7f97d31f51bb82455046aa10c2cef82f67b8"}},{"ruleId":"PF3","level":"warning","message":{"text":"Sync-over-async blocking: \u0060main\u0060 is async and calls appendFileSync \u2014 a blocking call inside async code stalls the event loop \u2014 every other request waits for as long as it runs."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/update-version.ts"},"region":{"startLine":108}}}],"partialFingerprints":{"codehealthFindingId/v1":"d787031792bb478faa8b9aa74804cd6919edd5adc720638ceba24e4a2d9d2db8"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (153 lines \u00D7 2 locations): src/Socket/communities.ts:251 \u00B7 src/Socket/groups.ts:124 \u2014 the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/communities.ts"},"region":{"startLine":251}}}],"partialFingerprints":{"codehealthFindingId/v1":"995550bd5702bf942856182f2d773a4195ab6fa647f16c46ff8b997b884ce081"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (53 lines \u00D7 2 locations): src/Socket/communities.ts:22 \u00B7 src/Socket/groups.ts:18 \u2014 the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/communities.ts"},"region":{"startLine":22}}}],"partialFingerprints":{"codehealthFindingId/v1":"6510110f28757c32010e145e99f2bd9b0e4c2b72dec2b3845b2bc7ddefc755cf"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (34 lines \u00D7 2 locations): src/Socket/business.ts:301 \u00B7 src/Socket/business.ts:341 \u2014 all 2 copies are in the same file, and the SHAPE of this repetition could not be determined. It is not a run of declarations, a listing, a declaration header, a type body or a slice through a construct \u2014 and it was not measured as a run of executable statements either, so this row cannot tell you whether a function can stand where these lines are. Read the two spans before acting, because the move is opposite in the two cases. Where they are statements, the ordinary answer holds: give the shared part one home and call it from each site. Where they turn out to be declarations, a literal\u0027s entries, or the cases of an enumeration, there is no call site to call anything from, and collapsing them would delete what each copy pins \u2014 a shared base type, a generated set, or one exported constant each site refers to is the move instead, and sometimes the honest answer is that there is nothing to extract at all. Reported because the copies drift apart the first time only one of them is edited, which is true whichever of those they are."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/business.ts"},"region":{"startLine":301}}}],"partialFingerprints":{"codehealthFindingId/v1":"a0bb217944dcbc50129cf5508ce2516204847fc905f8f355edd6c9350678b746"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (23 lines \u00D7 2 locations): scripts/update-version.ts:36 \u00B7 scripts/update-version.ts:69 \u2014 all 2 copies are in the same file, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/update-version.ts"},"region":{"startLine":36}}}],"partialFingerprints":{"codehealthFindingId/v1":"c5fb509da9a3f4ae01f089e1849cc40dffe6e8344221d8cdb64e23e06c18c5b0"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (23 lines \u00D7 2 locations): src/Utils/process-message.ts:239 \u00B7 src/Utils/process-message.ts:269 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/process-message.ts"},"region":{"startLine":239}}}],"partialFingerprints":{"codehealthFindingId/v1":"595312e2305332303de5b6bf2721ca85dd1cf863153c0fd8b261def90f6208b0"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (21 lines \u00D7 2 locations): src/Signal/lid-mapping.ts:112 \u00B7 src/Signal/lid-mapping.ts:247 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/lid-mapping.ts"},"region":{"startLine":112}}}],"partialFingerprints":{"codehealthFindingId/v1":"f56ec79880f15de823dc40bd4fc835b7c3776201ab125374f2d8e06b1f5afe90"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2 locations): src/Socket/communities.ts:177 \u00B7 src/Socket/groups.ts:112 \u2014 the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/communities.ts"},"region":{"startLine":177}}}],"partialFingerprints":{"codehealthFindingId/v1":"39a9204f1a1d7e85791017e8b62c3aece4216ba4ad62c5229d6d48e3f574ac98"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2 locations): src/Socket/communities.ts:456 \u00B7 src/Socket/groups.ts:359 \u2014 the 2 copies are spread across 2 files, and the SHAPE of this repetition could not be determined. It is not a run of declarations, a listing, a declaration header, a type body or a slice through a construct \u2014 and it was not measured as a run of executable statements either, so this row cannot tell you whether a function can stand where these lines are. Read the two spans before acting, because the move is opposite in the two cases. Where they are statements, the ordinary answer holds: give the shared part one home and call it from each site. Where they turn out to be declarations, a literal\u0027s entries, or the cases of an enumeration, there is no call site to call anything from, and collapsing them would delete what each copy pins \u2014 a shared base type, a generated set, or one exported constant each site refers to is the move instead, and sometimes the honest answer is that there is nothing to extract at all. Reported because the copies drift apart the first time only one of them is edited, which is true whichever of those they are."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/communities.ts"},"region":{"startLine":456}}}],"partialFingerprints":{"codehealthFindingId/v1":"13995c5f2a14622dded1a9501562df9082d5b534cbde44e8b5b5545eb94e78f8"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2 locations): src/Socket/communities.ts:100 \u00B7 src/Socket/groups.ts:75 \u2014 the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/communities.ts"},"region":{"startLine":100}}}],"partialFingerprints":{"codehealthFindingId/v1":"a436b6b9beb56bc789008bdc6784882cf9fdf41514dfea622ea13608a740d929"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block with local edits (11 matched lines \u00D7 2 locations): proto-extract/index.js:133 \u00B7 proto-extract/index.js:218 \u2014 the two spans are one implementation copied and then locally edited \u2014 63 tokens are still identical, in the same order in both spans, with only local edits between them. The copies have already begun to drift, which is this row\u0027s finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters \u2014 or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"proto-extract/index.js"},"region":{"startLine":133}}}],"partialFingerprints":{"codehealthFindingId/v1":"e10d90a654f93c91541fde3ea68d312859f957947235d54ee52b15d0df1a2266"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2 locations): src/Socket/chats.ts:286 \u00B7 src/Socket/chats.ts:299 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/chats.ts"},"region":{"startLine":286}}}],"partialFingerprints":{"codehealthFindingId/v1":"5487ba3da0876508675e1e7cdb2e8829bd566f752bf6cc252509b2c2964e1188"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2 locations): src/Socket/groups.ts:369 \u00B7 src/Socket/messages-recv.ts:857 \u2014 the 2 copies are spread across 2 files, and the SHAPE of this repetition could not be determined. It is not a run of declarations, a listing, a declaration header, a type body or a slice through a construct \u2014 and it was not measured as a run of executable statements either, so this row cannot tell you whether a function can stand where these lines are. Read the two spans before acting, because the move is opposite in the two cases. Where they are statements, the ordinary answer holds: give the shared part one home and call it from each site. Where they turn out to be declarations, a literal\u0027s entries, or the cases of an enumeration, there is no call site to call anything from, and collapsing them would delete what each copy pins \u2014 a shared base type, a generated set, or one exported constant each site refers to is the move instead, and sometimes the honest answer is that there is nothing to extract at all. Reported because the copies drift apart the first time only one of them is edited, which is true whichever of those they are."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/groups.ts"},"region":{"startLine":369}}}],"partialFingerprints":{"codehealthFindingId/v1":"093404d4dc27708d691ecfa4d845acc54eafe5c4c583f3b08865cf5eb2f8908d"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2 locations): src/Socket/socket.ts:342 \u00B7 src/Socket/socket.ts:365 \u2014 all 2 copies are in the same file, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/socket.ts"},"region":{"startLine":342}}}],"partialFingerprints":{"codehealthFindingId/v1":"efc6f2a23b88dfa89db0aa30faf0dc6d87c72bc21ebf8e07ef98e1acfbed8ccf"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2 locations): src/Socket/socket.ts:415 \u00B7 src/Socket/socket.ts:683 \u2014 all 2 copies are in the same file, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/socket.ts"},"region":{"startLine":415}}}],"partialFingerprints":{"codehealthFindingId/v1":"c1fbdd0fca9152d4e07723ade65b7e746d4d29298facfafa4e3defb9a69b630d"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2 locations): src/Utils/noise-handler.ts:31 \u00B7 src/Utils/noise-handler.ts:41 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/noise-handler.ts"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"ab7fab7d011267a7de810bc89a319d03c850d41573bc69863d887ca55797c801"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2 locations): src/Utils/chat-utils.ts:452 \u00B7 src/Utils/chat-utils.ts:535 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/chat-utils.ts"},"region":{"startLine":452}}}],"partialFingerprints":{"codehealthFindingId/v1":"14909305f5eac543b6513de8f00aab65a850857b4bce080d8ede4b4f2a7f4e69"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2 locations): src/WABinary/encode.ts:147 \u00B7 src/WABinary/encode.ts:162 \u2014 all 2 copies are in the same file, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WABinary/encode.ts"},"region":{"startLine":147}}}],"partialFingerprints":{"codehealthFindingId/v1":"6d3f0b8eafaa71b4df549a4eaf9e3a72ac8d1234697d8ccfe723e9b2a502896f"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2 locations): src/WAM/encode.ts:100 \u00B7 src/WAM/encode.ts:108 \u2014 all 2 copies are in the same file, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WAM/encode.ts"},"region":{"startLine":100}}}],"partialFingerprints":{"codehealthFindingId/v1":"209d78905bd707ebc0a104fcc43ae90cc7e0b492047ea4422f10702773835577"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2 locations): src/Socket/messages-recv.ts:621 \u00B7 src/Socket/messages-recv.ts:1413 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-recv.ts"},"region":{"startLine":621}}}],"partialFingerprints":{"codehealthFindingId/v1":"6580e95aa41836b3319d89249f9aa8c3ea483e7289ed3de2880ed9dbb1b3c100"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2 locations): src/Utils/crypto.ts:87 \u00B7 src/Utils/crypto.ts:100 \u2014 all 2 copies are in the same file, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/crypto.ts"},"region":{"startLine":87}}}],"partialFingerprints":{"codehealthFindingId/v1":"04c7b53072b9f7b6a97cbc1d0a9533ca752453025127a4705f2e8fc53c644e84"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2 locations): src/Utils/chat-utils.ts:328 \u00B7 src/Utils/chat-utils.ts:451 \u2014 all 2 copies are in the same file, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/chat-utils.ts"},"region":{"startLine":328}}}],"partialFingerprints":{"codehealthFindingId/v1":"303fc5ed394d3b22ecc81c248a6412144d8729b331773c8ce6cd7dfa081a6823"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Defaults/index.ts:1 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Defaults/index.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"7e1655ce490beeefb941b41a958f45235de17c0e5d6c9d8ca4640c14c03000c7"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:third-party-deep-import]: src/Signal/Group/group_cipher.ts:1 imports libsignal/src/crypto, reaching past a declared dependency\u0027s public entry into its build output \u2014 that path is the package\u0027s toolchain layout, not its API, and a minor version bump can relocate it with no semver signal. Import from the package\u0027s documented entry point instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/Group/group_cipher.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"094f2f7d564ab273ed4ac06e017891074da208965e4ff89f78e061bd641418c5"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:third-party-deep-import]: src/Signal/Group/keyhelper.ts:2 imports libsignal/src/curve, reaching past a declared dependency\u0027s public entry into its build output \u2014 that path is the package\u0027s toolchain layout, not its API, and a minor version bump can relocate it with no semver signal. Import from the package\u0027s documented entry point instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/Group/keyhelper.ts"},"region":{"startLine":2}}}],"partialFingerprints":{"codehealthFindingId/v1":"ca19df76e439e3067070f690c109ce6faed2c2d6fafca70435a0df2fcd6cf5f7"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:third-party-deep-import]: src/Signal/Group/sender-chain-key.ts:1 imports libsignal/src/crypto, reaching past a declared dependency\u0027s public entry into its build output \u2014 that path is the package\u0027s toolchain layout, not its API, and a minor version bump can relocate it with no semver signal. Import from the package\u0027s documented entry point instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/Group/sender-chain-key.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b51ea253e1606b7ffe5810a0dede5f76817a4c213b0e0a214ef87b5efe13f628"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Signal/Group/sender-key-distribution-message.ts:1 reaches into another package with a relative path (../../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/Group/sender-key-distribution-message.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"bc472dacb445bee872e5ce5267c034c495ddd07e3849afd88715c23d44e3583f"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:third-party-deep-import]: src/Signal/Group/sender-key-message.ts:1 imports libsignal/src/curve, reaching past a declared dependency\u0027s public entry into its build output \u2014 that path is the package\u0027s toolchain layout, not its API, and a minor version bump can relocate it with no semver signal. Import from the package\u0027s documented entry point instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/Group/sender-key-message.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0ba5b59e1dc27790ab4545be87ac90548c84104c3f2e22681e5b105cc94d0261"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Signal/Group/sender-key-message.ts:2 reaches into another package with a relative path (../../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/Group/sender-key-message.ts"},"region":{"startLine":2}}}],"partialFingerprints":{"codehealthFindingId/v1":"c6438bbccafa2262d1aa3121554939a31b76b0785554e0027a9e10f1ddb6d244"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:third-party-deep-import]: src/Signal/Group/sender-message-key.ts:1 imports libsignal/src/crypto, reaching past a declared dependency\u0027s public entry into its build output \u2014 that path is the package\u0027s toolchain layout, not its API, and a minor version bump can relocate it with no semver signal. Import from the package\u0027s documented entry point instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/Group/sender-message-key.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"01087433dac394ef57b956b51e1d649b583acfd16ecf8b9d2bf9d7251f81f016"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:third-party-deep-import]: src/Signal/libsignal.ts:4 imports libsignal/src/protobufs, reaching past a declared dependency\u0027s public entry into its build output \u2014 that path is the package\u0027s toolchain layout, not its API, and a minor version bump can relocate it with no semver signal. Import from the package\u0027s documented entry point instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/libsignal.ts"},"region":{"startLine":4}}}],"partialFingerprints":{"codehealthFindingId/v1":"47a0923d7ec2db15605d9ea6317b920773d54e845669350f9f438b5290976b58"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Socket/chats.ts:3 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/chats.ts"},"region":{"startLine":3}}}],"partialFingerprints":{"codehealthFindingId/v1":"db71e0609d38298b93fc9050ba6413707440bb49407c624985cf71789ba667c3"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Socket/communities.ts:1 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/communities.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"fe63053cc65056210474dba12220e82f817ebc9796fcbc4e44e7c9ec45b8269d"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Socket/groups.ts:2 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/groups.ts"},"region":{"startLine":2}}}],"partialFingerprints":{"codehealthFindingId/v1":"974dc0033c6fdb6a77ada487ac2b44b06d6a7420da196d95ce8ce8577d3b4054"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Socket/messages-recv.ts:5 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-recv.ts"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"8fb43c56a48c5239cdee0a16d4ea5dbc17270c0236dfb899accba5c0b4f15302"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Socket/messages-send.ts:3 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-send.ts"},"region":{"startLine":3}}}],"partialFingerprints":{"codehealthFindingId/v1":"d18c5cde0c21dc94176551cbde7fbdb2d2e695ecfee6cedf0a43eaa6551eb806"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Socket/socket.ts:5 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/socket.ts"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"13f2f0862388df674c88457221d2de2b4c38430693668a653ebcadcfa27ac4be"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Types/Events.ts:2 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Types/Events.ts"},"region":{"startLine":2}}}],"partialFingerprints":{"codehealthFindingId/v1":"15742337e24718b9b4ea27c4dffc82046b1c4a113817f89da9a59a8dbcc2e13f"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Types/Message.ts:3 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Types/Message.ts"},"region":{"startLine":3}}}],"partialFingerprints":{"codehealthFindingId/v1":"bc1d705ee348339e84143b46672e3be72b630fa3cac8a407664697e8401d7171"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Types/Signal.ts:1 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Types/Signal.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c1262e582f23dc1df23f17c2694a0d6dc803b9eab29f70c7d860501e5fe25f4e"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Types/Socket.ts:3 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Types/Socket.ts"},"region":{"startLine":3}}}],"partialFingerprints":{"codehealthFindingId/v1":"acfc32b5477903edeea8ddbc02d490c4cb01b2f29b4026ec5436755c6db8ccd9"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Utils/browser-utils.ts:2 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/browser-utils.ts"},"region":{"startLine":2}}}],"partialFingerprints":{"codehealthFindingId/v1":"02f0024969d66e01d5b68cb5f63a0617ad0bb43092c3f2903574377d256e4987"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Utils/chat-utils.ts:3 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/chat-utils.ts"},"region":{"startLine":3}}}],"partialFingerprints":{"codehealthFindingId/v1":"cbcb691169ebe0647ab2b1b654833388bd4f9b3cdaa88457890bb760dfe29819"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:third-party-deep-import]: src/Utils/crypto.ts:2 imports libsignal/src/curve, reaching past a declared dependency\u0027s public entry into its build output \u2014 that path is the package\u0027s toolchain layout, not its API, and a minor version bump can relocate it with no semver signal. Import from the package\u0027s documented entry point instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/crypto.ts"},"region":{"startLine":2}}}],"partialFingerprints":{"codehealthFindingId/v1":"96d725222afc2076a43766f89325fb8701d63dc01a8d749f6815bc11b9bab5b2"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Utils/decode-wa-message.ts:2 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/decode-wa-message.ts"},"region":{"startLine":2}}}],"partialFingerprints":{"codehealthFindingId/v1":"5d2c2ac9168ea1235337ba587593da7e62693566c31073da02997943c03d053a"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Utils/generics.ts:4 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/generics.ts"},"region":{"startLine":4}}}],"partialFingerprints":{"codehealthFindingId/v1":"c9af1cf2904685fe05a56af22d5ff5f16795d05746aed610f145618f4312381f"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Utils/history.ts:4 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/history.ts"},"region":{"startLine":4}}}],"partialFingerprints":{"codehealthFindingId/v1":"5b7f78a96b73c5efc0a0cb0462cb5a46a837a7b0654328dce1e62a1a229d23de"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Utils/messages-media.ts:12 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages-media.ts"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"10b29ed6d9c958a3c893e579057f2b02f653aaab9928a0b2539f9a3be34e0679"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Utils/messages.ts:5 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages.ts"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"6b3dee8cddb2da5f9abbded3a3ae852245e04e1ca9c3c8ca56177e24cc7ce86a"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Utils/noise-handler.ts:2 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/noise-handler.ts"},"region":{"startLine":2}}}],"partialFingerprints":{"codehealthFindingId/v1":"cdfd7b435ee1824ab927ef9c1090ee0e6d02cabfddb06bf84b909ccc25bc4e7a"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Utils/process-message.ts:2 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/process-message.ts"},"region":{"startLine":2}}}],"partialFingerprints":{"codehealthFindingId/v1":"65565e8685d0ec356a8f280cc41673b574ddc730a60ea1a093d8489269e5e6d5"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Utils/reporting-utils.ts:2 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/reporting-utils.ts"},"region":{"startLine":2}}}],"partialFingerprints":{"codehealthFindingId/v1":"d1b3f32ed29182883d5aef184300821044b155a3f2cc6612aa1734afd23c14be"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Utils/sync-action-utils.ts:1 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/sync-action-utils.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"dc868eaf35f0bbc57aa5025e9fdc409e89955bf03ac19818fb5afe8f1144496e"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Utils/use-multi-file-auth-state.ts:4 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/use-multi-file-auth-state.ts"},"region":{"startLine":4}}}],"partialFingerprints":{"codehealthFindingId/v1":"08c684e1ac7d34a6c2021dce442444d6cafce344b442eb09b43ba786570cc1ba"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/Utils/validate-connection.ts:3 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/validate-connection.ts"},"region":{"startLine":3}}}],"partialFingerprints":{"codehealthFindingId/v1":"66922ce3584e5d01e132b70874c83a797f1ff353b2c9b633a60e819d70bcccb7"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/WABinary/generic-utils.ts:2 reaches into another package with a relative path (../../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WABinary/generic-utils.ts"},"region":{"startLine":2}}}],"partialFingerprints":{"codehealthFindingId/v1":"ec17437361d5168dfbd285bc387a399d8b75112deddf3b177273a1be30886f3b"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:relative-cross-package]: src/index.ts:3 reaches into another package with a relative path (../WAProto/index.js) \u2014 import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/index.ts"},"region":{"startLine":3}}}],"partialFingerprints":{"codehealthFindingId/v1":"a39e5d649200ef12510bf07a8c416b85c29619d52cae5f7beb29043aca30a146"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function (anonymous) (cyclomatic 102, cognitive 151): (anonymous) has cyclomatic complexity 102 and cognitive complexity 151; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-send.ts"},"region":{"startLine":676}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b5a199342125d9611ad5bc33e5dbc3894838abf77d06d75181066e0f2ef4d9c"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function append (cyclomatic 89, cognitive 189): append has cyclomatic complexity 89 and cognitive complexity 189; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/event-buffer.ts"},"region":{"startLine":288}}}],"partialFingerprints":{"codehealthFindingId/v1":"8a96c3eb21d7f9f7c22ebfc06a5e8181528b7666eaeb4ef693b98bbecb6635f7"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function processMessage (cyclomatic 79, cognitive 131): processMessage has cyclomatic complexity 79 and cognitive complexity 131; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/process-message.ts"},"region":{"startLine":293}}}],"partialFingerprints":{"codehealthFindingId/v1":"a36832163f1afa61e2f8efa0e382eda5af6389b4643eff0c24af3f994408811b"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function generateWAMessageContent (cyclomatic 75, cognitive 114): generateWAMessageContent has cyclomatic complexity 75 and cognitive complexity 114; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages.ts"},"region":{"startLine":395}}}],"partialFingerprints":{"codehealthFindingId/v1":"e68abadf9d2b74ae6f031012950b2f5f7ee297de17883296ebfa8b876e697dc0"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function processSyncAction (cyclomatic 48, cognitive 59): processSyncAction has cyclomatic complexity 48 and cognitive complexity 59; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/chat-utils.ts"},"region":{"startLine":823}}}],"partialFingerprints":{"codehealthFindingId/v1":"c683355e293c9aaf470dab84028bf65b0fd79d36c400c0e33ecaacc95bb7a28f"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function processHistoryMessage (cyclomatic 38, cognitive 49): processHistoryMessage has cyclomatic complexity 38 and cognitive complexity 49; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/history.ts"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"f079a94e1bf2bbef50039e1d57b486519d0103644d2d6bdce5b9f08b7c7043c0"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function sendMessagesAgain (cyclomatic 36, cognitive 59): sendMessagesAgain has cyclomatic complexity 36 and cognitive complexity 59; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-recv.ts"},"region":{"startLine":1314}}}],"partialFingerprints":{"codehealthFindingId/v1":"9062d5ec6431a44b07ea9c19c3c45a658f1ff1f31d879b12ec0cb9aa10245a11"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function decodeMessageNode (cyclomatic 36, cognitive 52): decodeMessageNode has cyclomatic complexity 36 and cognitive complexity 52; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/decode-wa-message.ts"},"region":{"startLine":141}}}],"partialFingerprints":{"codehealthFindingId/v1":"7ee91a5c9bb1f656dbf94be1540899e2253bdaa5b05acb80c4c7bcf406f3214b"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function handleGroupNotification (cyclomatic 35, cognitive 22): handleGroupNotification has cyclomatic complexity 35 and cognitive complexity 22; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-recv.ts"},"region":{"startLine":801}}}],"partialFingerprints":{"codehealthFindingId/v1":"b9be2f83f3315586af8645ed7792b6a5cebec66656d5a338152a21254a80bcca"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function _getLIDsForPNsImpl (cyclomatic 31, cognitive 81): _getLIDsForPNsImpl has cyclomatic complexity 31 and cognitive complexity 81; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Signal/lid-mapping.ts"},"region":{"startLine":134}}}],"partialFingerprints":{"codehealthFindingId/v1":"a688a55e34a21cdc4710e664852854ac45b57b9c960dc6a122ddb65300e9bbec"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function handleLegacyMexNewsletterNotification (cyclomatic 31, cognitive 44): handleLegacyMexNewsletterNotification has cyclomatic complexity 31 and cognitive complexity 44; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-recv.ts"},"region":{"startLine":353}}}],"partialFingerprints":{"codehealthFindingId/v1":"16aadd38e90bfa6497331763dc7e9c021fdd36ea060d956f5a54f6efaaf2b67b"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function prepareWAMessageMedia (cyclomatic 30, cognitive 31): prepareWAMessageMedia has cyclomatic complexity 30 and cognitive complexity 31; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages.ts"},"region":{"startLine":124}}}],"partialFingerprints":{"codehealthFindingId/v1":"05ab2a965c4eb09e2f90e4bda4d61f1671f412ce9b212324e09cee2fc29e128b"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function (anonymous) (cyclomatic 29, cognitive 56): (anonymous) has cyclomatic complexity 29 and cognitive complexity 56; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-send.ts"},"region":{"startLine":245}}}],"partialFingerprints":{"codehealthFindingId/v1":"ea623afe0ab375c3786d1c12110adfdc4258caf87b06f8d3ef1851dc67c727ea"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function chatModificationToAppPatch (cyclomatic 28, cognitive 31): chatModificationToAppPatch has cyclomatic complexity 28 and cognitive complexity 31; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/chat-utils.ts"},"region":{"startLine":556}}}],"partialFingerprints":{"codehealthFindingId/v1":"88df89afc18f536c6d7994d113708fd22081bf076e802b00d6580815b39db670"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function decrypt (cyclomatic 27, cognitive 55): decrypt has cyclomatic complexity 27 and cognitive complexity 55; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/decode-wa-message.ts"},"region":{"startLine":276}}}],"partialFingerprints":{"codehealthFindingId/v1":"71a1ef9a332c3ba9bedd18f73705c9eb552f2c83ba266a9f7ce53ffa2ced1774"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function processNotification (cyclomatic 27, cognitive 26): processNotification has cyclomatic complexity 27 and cognitive complexity 26; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-recv.ts"},"region":{"startLine":1035}}}],"partialFingerprints":{"codehealthFindingId/v1":"c2e98d87220b50af436ac01dce9c15cf1bacc1773214341e8b2f208877eb77a2"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function (anonymous) (cyclomatic 26, cognitive 67): (anonymous) has cyclomatic complexity 26 and cognitive complexity 67; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/reporting-utils.ts"},"region":{"startLine":124}}}],"partialFingerprints":{"codehealthFindingId/v1":"4740454866f1dfc4ff3ee3a4931c0a02d174f612b8020307e1fe5a19a89468f3"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function (anonymous) (cyclomatic 26, cognitive 47): (anonymous) has cyclomatic complexity 26 and cognitive complexity 47; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/messages-recv.ts"},"region":{"startLine":1620}}}],"partialFingerprints":{"codehealthFindingId/v1":"ea475556b31f4e9ffbd6491a661d50b528d379add2bbaad482be5c6b56653527"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function (anonymous) (cyclomatic 25, cognitive 31): (anonymous) has cyclomatic complexity 25 and cognitive complexity 31; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Socket/chats.ts"},"region":{"startLine":1205}}}],"partialFingerprints":{"codehealthFindingId/v1":"e56da44570df132086377348ced183c712c3ad39ce808ef9a55bbc35106ea097"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function generateWAMessageFromContent (cyclomatic 24, cognitive 23): generateWAMessageFromContent has cyclomatic complexity 24 and cognitive complexity 23; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/messages.ts"},"region":{"startLine":682}}}],"partialFingerprints":{"codehealthFindingId/v1":"792a7ead524f12aa0952732665574d2f45573231d04263e8d61470f0afa7375d"}},{"ruleId":"R3","level":"warning","message":{"text":"Large Files: 15 file(s) over 400 lines (counted as significant lines \u2014 blank lines excluded \u2014 over production source only, tests excluded), largest first: src/WAM/constants.ts (22882), src/Socket/messages-recv.ts (1918), src/Socket/chats.ts (1357), src/WABinary/constants.ts (1300), src/Socket/messages-send.ts (1249), src/Socket/socket.ts (1038) (\u002B9 more)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"cecee31b569df4f07e06db732f1ca037af27b5afef9023da51f9673d931a142f"}},{"ruleId":"R4","level":"warning","message":{"text":"This test file cannot be loaded: src/__tests__/Socket/identity-change-handling.test.ts:5 imports \u0027../../WABinary\u0027, which names no file in this repository \u2014 and no rule in its .gitignore chain could cover one, so no build writes it either. The import throws as the runner collects this file, so none of its test cases run and nothing it was written to verify is verified. Restore the missing module or delete the test. It is excluded from the reachability measured above, because a file that cannot load reaches nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/__tests__/Socket/identity-change-handling.test.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"66b9dbed30fba6690f39102dbe5141558fb0109e656081ff601aaa3e1a170346"}},{"ruleId":"R4","level":"warning","message":{"text":"This test file cannot be loaded: src/__tests__/Utils/offline-node-processor.test.ts:3 imports \u0027../../WABinary\u0027, which names no file in this repository \u2014 and no rule in its .gitignore chain could cover one, so no build writes it either. The import throws as the runner collects this file, so none of its test cases run and nothing it was written to verify is verified. Restore the missing module or delete the test. It is excluded from the reachability measured above, because a file that cannot load reaches nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/__tests__/Utils/offline-node-processor.test.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"fb6f2dc69ce5a0d49e41d8cd7068d8e02e73bceb90f66a6a5d75d9a56bb95cf0"}},{"ruleId":"R4","level":"warning","message":{"text":"This test file cannot be loaded: src/__tests__/Utils/reporting-utils.test.ts:2 imports \u0027../../../WAProto\u0027, which names no file in this repository \u2014 and no rule in its .gitignore chain could cover one, so no build writes it either. The import throws as the runner collects this file, so none of its test cases run and nothing it was written to verify is verified. Restore the missing module or delete the test. It is excluded from the reachability measured above, because a file that cannot load reaches nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/__tests__/Utils/reporting-utils.test.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"58e8eacb8dbe444514460261c7588369eef068ce4763ecde246d58730a52fc2c"}},{"ruleId":"R4","level":"warning","message":{"text":"This test file cannot be loaded: src/__tests__/Utils/stanza-ack.test.ts:2 imports \u0027../../WABinary\u0027, which names no file in this repository \u2014 and no rule in its .gitignore chain could cover one, so no build writes it either. The import throws as the runner collects this file, so none of its test cases run and nothing it was written to verify is verified. Restore the missing module or delete the test. It is excluded from the reachability measured above, because a file that cannot load reaches nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/__tests__/Utils/stanza-ack.test.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"271ee87799455ec0c6b6605b8be95470fb45af3134063966e1ebf09349b5e41d"}},{"ruleId":"R4","level":"warning","message":{"text":"This test file cannot be loaded: src/__tests__/Utils/tc-token.test.ts:15 imports \u0027../../WABinary\u0027, which names no file in this repository \u2014 and no rule in its .gitignore chain could cover one, so no build writes it either. The import throws as the runner collects this file, so none of its test cases run and nothing it was written to verify is verified. Restore the missing module or delete the test. It is excluded from the reachability measured above, because a file that cannot load reaches nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/__tests__/Utils/tc-token.test.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c55534ca324f5699d0e5fda27acdd00a10caf44b07ccb6e970137f7c78021c43"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WABinary/decode.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"94ae01b33d49362c5feb1c842a2728b52b29233c14b8e79556c0bda84843405f"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WABinary/encode.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d5b067b3e856f3ae15da05b2a766770cc3564dcc817a58668a333b5f8dc89e5f"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/update-version.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"8288da80d6b80764259daec33c50424bfa5a43ca3a65331bc312e7a1c7ec846b"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WABinary/jid-utils.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"9c5a3d8d6dd25816cc37c2b1bed89f48964b55dd4efbb8669210e98d336607c2"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Types/Label.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d66429cd3da3a978acbc290bd5a2d510eff868e3e5ce5a3b88d54a6a5cd50cc0"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"engine-requirements.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"81987cf3c34419cfec868279cefc4183f76f6bc49e835ba451db77a0e19e81d8"}},{"ruleId":"R6","level":"warning","message":{"text":"The declared test suite includes a file that cannot be loaded: This repository declares test tooling, and the \u2713 above records that declaration \u2014 but src/__tests__/Socket/identity-change-handling.test.ts and 4 other test file(s) in this workspace cannot be loaded at all: it imports a module that names no file in this repository, so the runner throws while collecting it and none of its cases execute. The wiring is present and the suite it points at does not run as written, which is why the tooling tick must not be read as a statement that the tests pass. Fix the unloadable file(s) \u2014 each one is reported with its failing import under Test Coverage \u2014 then the declared script exercises what it claims to."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/__tests__/Socket/identity-change-handling.test.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"481e9193595b45b4d1b6e8a6c00b3f725bb1b6ddb88eb286577cec4e5ac79540"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~308 LoC): no import path from any entry point (6 application, 4 tooling, 35 test roots considered), and no other file in the scanned tree imports it \u2014 nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WABinary/decode.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"003b10f511cf391485d3aa5ea73392548b3c2e78a0c505dc695aec9f35e10f80"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~258 LoC): no import path from any entry point (6 application, 4 tooling, 35 test roots considered), and no other file in the scanned tree imports it \u2014 nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WABinary/encode.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d3f8623df7cca8b74832005514d946e03f14eab216b40b84c0651d3309c306ea"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~128 LoC): no import path from any entry point (6 application, 4 tooling, 35 test roots considered), but 2 in-repo import(s) from 2 other file(s) do name it (src/WABinary/decode.ts, src/WABinary/encode.ts) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WABinary/jid-utils.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"50e0e942292044e5365c2cb3f615001ed57c591fcb99062ee93a5a95001f6dea"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027LabelColor\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Types/Label.ts"},"region":{"startLine":27}}}],"partialFingerprints":{"codehealthFindingId/v1":"a01f35fba456ae4ab68f0e6d65f23732569e5e824f42f1b399bc2ad8c12ffaf7"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027getAllBinaryNodeChildren\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WABinary/generic-utils.ts"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"651d8ca49243f09563baa3ac8ea7278baf1b9ecb5f1a717f56c0bedd57259bd7"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027getBinaryNodeChildString\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WABinary/generic-utils.ts"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"0b3439e11b287f6fb2da3dab475a9cfc1f6b3b95211f30e1f9047335e4fbb4c8"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027getBinaryNodeChildUInt\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WABinary/generic-utils.ts"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"0d6e0a5be768f9250c30e83e3c60616e52a65f5e1d67666fc9d6d52ce5365212"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027assertNodeErrorFree\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WABinary/generic-utils.ts"},"region":{"startLine":66}}}],"partialFingerprints":{"codehealthFindingId/v1":"c5d6a0d140784465d6dbb079265e2afc46d175bd5aee06c4f6fe2972e2ae7328"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027reduceBinaryNodeToDictionary\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WABinary/generic-utils.ts"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"0685bcb09a8f4ff7d4d381cbdbc27285182b762f4ccca8455e6b46c36b472731"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027getBinaryNodeMessages\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WABinary/generic-utils.ts"},"region":{"startLine":90}}}],"partialFingerprints":{"codehealthFindingId/v1":"17c69a37aa761fb42cc7c5af9f2653e6b0e1c021d4fc3663fa13345b27960ddf"}},{"ruleId":"R8","level":"warning","message":{"text":"Unused dependency \u0027request-promise-core\u0027: Declared in proto-extract/package.json but never imported anywhere in that package or its workspace members \u2014 no static import reaches it. Usually that is dead weight and attack surface, but two shapes are indistinguishable from source and are NOT dead: an optional or native peer that another dependency loads dynamically at runtime, and a package a build, docs or test step installs and invokes separately. Confirm which of the three this is before removing it."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"53621d1bd116ec6ac23db4a7196273c7720b231599cdcc1b0cf9130b00d88ca8"}},{"ruleId":"R9","level":"error","message":{"text":"Import cycle (7 files): src/Defaults/index.ts \u2192 src/Signal/libsignal.ts \u2192 src/Signal/Group/index.ts \u2192 src/Signal/Group/group-session-builder.ts \u2192 src/Signal/Group/sender-key-record.ts \u2192 src/Utils/generics.ts \u2192 src/Utils/crypto.ts \u2192 src/Defaults/index.ts (one verified cycle inside a mutually-dependent group of 24 files)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Defaults/index.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"22861993528efcd9e07bfc3f2f3b5c6cb4c6b029766972731c04d60497ed6a51"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default in catch: \u0060readTcTokenIndex\u0060 swallows every exception into \u0060return []\u0060 \u2014 a data error becomes a silent behavior change with no trail. Log the failure or let it raise. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the handler or in the docstring, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Utils/tc-token-utils.ts"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"0088ddb8febc32e3b7e72b3caa19902ec0041e6a4c98927b7034c940e5c87273"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1059","guid":"a2381a08-60f6-9554-a8b8-f3018cfaaca5","name":"Insufficient Technical Documentation","shortDescription":{"text":"Insufficient Technical Documentation"},"helpUri":"https://cwe.mitre.org/data/definitions/1059.html"},{"id":"CWE-1104","guid":"4c918cb5-b2a6-6c55-9963-a44ee464305e","name":"CWE-1104","shortDescription":{"text":"CWE-1104"},"helpUri":"https://cwe.mitre.org/data/definitions/1104.html"},{"id":"CWE-125","guid":"98717707-96bf-ca5b-9568-8d1d257574c1","name":"CWE-125","shortDescription":{"text":"CWE-125"},"helpUri":"https://cwe.mitre.org/data/definitions/125.html"},{"id":"CWE-1329","guid":"f70f1c3f-4ccf-cb5e-bdd3-03ba4868d36d","name":"CWE-1329","shortDescription":{"text":"CWE-1329"},"helpUri":"https://cwe.mitre.org/data/definitions/1329.html"},{"id":"CWE-1352","guid":"5257f322-5cfc-6b52-bedd-0b9a526b4c7d","name":"CWE-1352","shortDescription":{"text":"CWE-1352"},"helpUri":"https://cwe.mitre.org/data/definitions/1352.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-269","guid":"70e1f5f6-81e5-4e5a-ba40-b541c3a346e2","name":"CWE-269","shortDescription":{"text":"CWE-269"},"helpUri":"https://cwe.mitre.org/data/definitions/269.html"},{"id":"CWE-310","guid":"97174724-2e33-8455-b7cd-5c3258d1cb8f","name":"CWE-310","shortDescription":{"text":"CWE-310"},"helpUri":"https://cwe.mitre.org/data/definitions/310.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-522","guid":"71fb233e-ce6a-ae57-9419-ef8373540b09","name":"CWE-522","shortDescription":{"text":"CWE-522"},"helpUri":"https://cwe.mitre.org/data/definitions/522.html"},{"id":"CWE-552","guid":"3492436b-eca2-9c54-9ba3-5dade427c903","name":"CWE-552","shortDescription":{"text":"CWE-552"},"helpUri":"https://cwe.mitre.org/data/definitions/552.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-829","guid":"13c33925-97fb-5a5e-b40c-56d328b8a4d7","name":"CWE-829","shortDescription":{"text":"CWE-829"},"helpUri":"https://cwe.mitre.org/data/definitions/829.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":97,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}