{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D7","name":"Architectural Integrity","shortDescription":{"text":"Architectural Integrity"},"helpUri":"https://codehealth.canine.dev/dimensions/D7"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D10","name":"Test Quality","shortDescription":{"text":"Test Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D10"},{"id":"D11","name":"Test Reliability","shortDescription":{"text":"Test Reliability"},"helpUri":"https://codehealth.canine.dev/dimensions/D11"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13"},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D22","name":"Internal API Consistency","shortDescription":{"text":"Internal API Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D22"},{"id":"D23","name":"Boundary Type-Coupling","shortDescription":{"text":"Boundary Type-Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D23"},{"id":"D24","name":"Comment Value","shortDescription":{"text":"Comment Value"},"helpUri":"https://codehealth.canine.dev/dimensions/D24"},{"id":"D25","name":"ADR Conformance","shortDescription":{"text":"ADR Conformance"},"helpUri":"https://codehealth.canine.dev/dimensions/D25"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28"},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29"},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30"},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31"},{"id":"D32","name":"Data Compliance (PII/GDPR)","shortDescription":{"text":"Data Compliance (PII/GDPR)"},"helpUri":"https://codehealth.canine.dev/dimensions/D32"},{"id":"D33","name":"JS/npm Dependency Vulnerabilities","shortDescription":{"text":"JS/npm Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D33"},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36"},{"id":"D37","name":"Vulnerability-disclosure Policy","shortDescription":{"text":"Vulnerability-disclosure Policy"},"helpUri":"https://codehealth.canine.dev/dimensions/D37"},{"id":"D38","name":"OSV Dependency Vulnerabilities","shortDescription":{"text":"OSV Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D38"}]}},"results":[{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (27 lines \u00D7 2): src/AuditService/AuditService.Api/ConfigureServices.cs:33-59 | src/ExpenseService/ExpenseService.Api/ConfigureServices.cs:33-59"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/AuditService/AuditService.Api/ConfigureServices.cs"},"region":{"startLine":33}}}],"partialFingerprints":{"codehealthFindingId/v1":"2bf5c494a53dd4ea397447f4eaa21dfbe0ccb73e53779fe032c626dea58a3d93"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: ExpenseTracker.Contracts: ExpenseTracker.Contracts: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and heavily depended-on, so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ca34f04d7bef04acd4dbfcc5a3174ce5ee28cd3c2de6c48f3b1025ea3407cdb6"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: ExpenseTracker.Application: ExpenseTracker.Application: abstractness 0.00, instability 0.10, distance 0.90 \u2014 zone of pain \u2014 concrete and heavily depended-on, so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a494a3ac25d2057026dff0f25c4077f1df4b76eb87ed9484ff26bd98e2c46f7c"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: ApiExceptionFilterAttribute (LCOM4 5): ApiExceptionFilterAttribute\u0027s methods form 5 groups that share no state and don\u0027t call each other \u2014 a sign it may have several responsibilities. Review whether it splits into focused classes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ExpenseTracker/ExpenseTracker.Api/Filters/ApiExceptionFilterAttribute.cs"},"region":{"startLine":8}}}],"partialFingerprints":{"codehealthFindingId/v1":"daa75f65ebe3003f5b4e156f5c75444498fb7c9fbcc7e6b3255a7926e08e0e2d"}},{"ruleId":"D7","level":"note","message":{"text":"No checkable ADRs to assess: No architecture decision records were found and the project graph is acyclic, so architectural integrity could not be assessed. Add ADRs (with \u0060enforcement: analyzer|test\u0060) to make the architecture\u0027s rules checkable."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9bfa095522c5f2e53a7c1c0405fd8830d318409a6fb74f4288bab05aaf716e52"}},{"ruleId":"D8","level":"warning","message":{"text":"Coverage not measured: The test suite couldn\u0027t be built/run in-image and no coverage report is committed, so line coverage was not measured \u2014 and it is EXCLUDED from the score rather than scored on a LoC-ratio proxy. Commit the Cobertura/OpenCover/lcov report your CI already produces (anywhere in the repo), or make the suite runnable in-image, and real coverage will be measured."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"62e63e619c28f057e129f2997c965d32a457366a9ce18ca019ffb6bdfba85c99"}},{"ruleId":"D9","level":"note","message":{"text":"Unit tests: 37 unit test method(s)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3067d72f6515925eded797ae6deb86f74d157d3bd0b8e2d3a80edaa12ea95d24"}},{"ruleId":"D9","level":"note","message":{"text":"Integration tests: 4 integration test method(s)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b8ce5913e7f0487c282aa29038cefc209006d3bfe4e8418292f03d5a2d9bc5b9"}},{"ruleId":"D9","level":"note","message":{"text":"BDD tests: 0 BDD test method(s)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"2335ff4716b8a3faefb3014515ddf9f836e46276f415e6cd56462b6bf7742991"}},{"ruleId":"D9","level":"note","message":{"text":"E2E tests: 0 end-to-end test method(s)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9a982d279a9674eceb951bedcbe3f8d344879045f8bee5f9f6f059139e0ed590"}},{"ruleId":"D10","level":"note","message":{"text":"Mock framework: Moq: ExpenseService.UnitTests references Moq."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"73fecfed0c3032ded0d3446adbea832a077888cea2ae1e5f94659577d9c5590f"}},{"ruleId":"D10","level":"note","message":{"text":"Mock framework: Moq: AuditService.UnitTests references Moq."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"73fecfed0c3032ded0d3446adbea832a077888cea2ae1e5f94659577d9c5590f"}},{"ruleId":"D14","level":"note","message":{"text":"Licenses scanned: 25 packages scanned; 3 distinct SPDX licenses."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1d29d66daec20840f6831f63c1b66b87c40390635ef3e9f728002964c77e88d4"}},{"ruleId":"D15","level":"warning","message":{"text":"git history depth insufficient: git history depth insufficient \u2014 install a full clone for reliable trend signal."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ab15c4a7c72fcad940ff795282e210fd7f3769431dab6bffd8ce9ee8f7ee13f1"}},{"ruleId":"D16","level":"warning","message":{"text":"single-maintainer \u2014 knowledge-concentration (bus factor) risk: single-maintainer \u2014 knowledge-concentration (bus factor) risk (1 author(s) across 22 commit(s) sampled)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b4b49d961df742f0e507f4cc5c8094fb077ba0391a27fd015d18320865187719"}},{"ruleId":"D18","level":"note","message":{"text":"Build did not complete in the analyzer: \u0060dotnet build\u0060 reported 2 error(s) but no C# compiler diagnostic \u2014 an SDK / target-framework / restore mismatch in the analyzer environment, not a code defect (common for an older codebase whose target framework the analyzer\u0027s SDK can\u0027t build). Solution Shape is scored on structure and is NOT capped; the C# semantic analysis loads independently and is unaffected."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e4adc356084fc62de5b75482ff17529e286737cf4f3bd564cadee2ddffa84b35"}},{"ruleId":"D18","level":"note","message":{"text":"AuditService.Api (Production): 3 .cs files, 120 LoC (93 significant)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/AuditService/AuditService.Api/AuditService.Api.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b75bb8b3d101dddeeca300fb8672a489dea308359be6a4069cd3b3699d2c8475"}},{"ruleId":"D18","level":"note","message":{"text":"AuditService.Application (Production): 5 .cs files, 81 LoC (65 significant)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/AuditService/AuditService.Application/AuditService.Application.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"5937f09b67e36dc7281669d17351d42cda1cad5f7e9daa4d3009471bab00bbce"}},{"ruleId":"D18","level":"note","message":{"text":"AuditService.Infrastructure (Production): 7 .cs files, 288 LoC (251 significant)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/AuditService/AuditService.Infrastructure/AuditService.Infrastructure.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"89c407eea1da0f114ea7fb847b715ffc0627a26917ef51d0949a40c4f70de141"}},{"ruleId":"D18","level":"note","message":{"text":"ExpenseService.Api (Production): 6 .cs files, 190 LoC (146 significant)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ExpenseService/ExpenseService.Api/ExpenseService.Api.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"137168fbb2a57a85046bf59079a3370569c5e3e119aba1f9c1a359fe7168d291"}},{"ruleId":"D18","level":"note","message":{"text":"ExpenseService.Application (Production): 12 .cs files, 379 LoC (309 significant)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ExpenseService/ExpenseService.Application/ExpenseService.Application.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"9a3a887dbc0bff911cdab8d6a50bf92bc95a86b4bfa72e72c0bf454b433b26dc"}},{"ruleId":"D18","level":"note","message":{"text":"ExpenseService.Infrastructure (Production): 5 .cs files, 151 LoC (132 significant)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ExpenseService/ExpenseService.Infrastructure/ExpenseService.Infrastructure.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e8ab9d16b4153ecd21508202cd47e7c46d6a5739d70cd9ec578bb678debe6746"}},{"ruleId":"D18","level":"note","message":{"text":"ExpenseTracker.Application (Production): 3 .cs files, 64 LoC (51 significant)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ExpenseTracker/ExpenseTracker.Application/ExpenseTracker.Application.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"710753126e95d8a512b4946cb0919660f7ec066c088256799ec6f03057afd82b"}},{"ruleId":"D18","level":"note","message":{"text":"ExpenseTracker.Api (Production): 2 .cs files, 140 LoC (110 significant)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ExpenseTracker/ExpenseTracker.Api/ExpenseTracker.Api.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"064d589671111699c0e5654d789e8dbbb2747a74100ee39550765071aa691e27"}},{"ruleId":"D18","level":"note","message":{"text":"ExpenseService.Domain (Production): 10 .cs files, 373 LoC (285 significant)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ExpenseService/ExpenseService.Domain/ExpenseService.Domain.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"404a6523df6c738205d438fe45a42ee9eb4859e234dba3f29878d3b183ef0928"}},{"ruleId":"D18","level":"note","message":{"text":"ExpenseTracker.BuildingBlocks (Production): 5 .cs files, 65 LoC (46 significant)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ExpenseTracker/ExpenseTracker.BuildingBlocks/ExpenseTracker.BuildingBlocks.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"93c388bb694d0c9db8cc9b1f6d975845f8f8f39ab61e1622ff2d8b2136ddabbb"}},{"ruleId":"D18","level":"note","message":{"text":"AuditService.Domain (Production): 3 .cs files, 53 LoC (32 significant)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/AuditService/AuditService.Domain/AuditService.Domain.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"30de094b44a035494ba2bd50c8c6f1a39f17097ee28a516a24648ebd13d45d41"}},{"ruleId":"D18","level":"note","message":{"text":"ExpenseTracker.Contracts (Production): 6 .cs files, 109 LoC (74 significant)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ExpenseTracker/ExpenseTracker.Contracts/ExpenseTracker.Contracts.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"9b79c14a57fd9904c8bedd647183cd241ef89b9c7bcbc8b41dbb2f0fc5aa1e8b"}},{"ruleId":"D18","level":"note","message":{"text":"ExpenseService.UnitTests (Test): 12 .cs files, 560 LoC (489 significant)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/ExpenseService.UnitTests/ExpenseService.UnitTests.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f5c4512879fed78d70cded9b3dd57655f2a837643df224a26e81ea8404feb013"}},{"ruleId":"D18","level":"note","message":{"text":"AuditService.UnitTests (Test): 3 .cs files, 78 LoC (66 significant)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/AuditService.UnitTests/AuditService.UnitTests.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ecfaf64be61f5701278ee45e8b6a805abfbef1806e543adabb3e37e8bbbd307d"}},{"ruleId":"D18","level":"note","message":{"text":"AuditService.IntegrationTests (Test): 5 .cs files, 199 LoC (173 significant)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/AuditService.IntegrationTests/AuditService.IntegrationTests.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1e6bcd55c7ed14d97a3bf58e7a40a269f2ac11a1efc214f16cc4ff69ec3ba723"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: AuditService.Api: AuditService.Api: 0 % XML-doc coverage (0/6)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/AuditService/AuditService.Api/AuditService.Api.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"aee9e12c1413d32c4d926e07ac3a139947731ccb16d4bdccad04ccd99983e214"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: AuditService.Application: AuditService.Application: 0 % XML-doc coverage (0/12)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/AuditService/AuditService.Application/AuditService.Application.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"131007a92e35e127cfeeb76b8d81d9b8761c3dd2440a659aabd569c6be2bf70e"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: AuditService.Infrastructure: AuditService.Infrastructure: 0 % XML-doc coverage (0/21)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/AuditService/AuditService.Infrastructure/AuditService.Infrastructure.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"443bdcc9bc7dd2ad6389d0e422c4d1208a5d3d99593224182e096d3d58a243ea"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: ExpenseService.Api: ExpenseService.Api: 0 % XML-doc coverage (0/23)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ExpenseService/ExpenseService.Api/ExpenseService.Api.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3b6051f2bfc207d8ee76220c38643fc061d0affe81c9deaab28ab52e0b98f195"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: ExpenseService.Application: ExpenseService.Application: 0 % XML-doc coverage (0/52)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ExpenseService/ExpenseService.Application/ExpenseService.Application.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c466ef5663370ecc896647f898d1a19bb2a72cdecda2fcf72a61506964efe899"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: ExpenseService.Infrastructure: ExpenseService.Infrastructure: 0 % XML-doc coverage (0/17)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ExpenseService/ExpenseService.Infrastructure/ExpenseService.Infrastructure.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f0d70e28f55af92ea93daa1d9f654cb8f03889091f7bd34544d66e2c88b12abe"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: ExpenseTracker.Application: ExpenseTracker.Application: 0 % XML-doc coverage (0/12)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ExpenseTracker/ExpenseTracker.Application/ExpenseTracker.Application.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"7634f984019213570c1649ce6a55e2ed1ec3e2201697a982e9f14ca2da93e03a"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: ExpenseTracker.Api: ExpenseTracker.Api: 0 % XML-doc coverage (0/4)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ExpenseTracker/ExpenseTracker.Api/ExpenseTracker.Api.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"9323e9c67bc643848b7634a3b65b92d9bf802ab7ffbe6c08f652b22f8173a96c"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: ExpenseService.Domain: ExpenseService.Domain: 0 % XML-doc coverage (0/80)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ExpenseService/ExpenseService.Domain/ExpenseService.Domain.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b386dc3e7eff689af7a2552285a7672adee92bdf0d582e0f4c03456fac10f014"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: ExpenseTracker.BuildingBlocks: ExpenseTracker.BuildingBlocks: 0 % XML-doc coverage (0/12)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ExpenseTracker/ExpenseTracker.BuildingBlocks/ExpenseTracker.BuildingBlocks.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"860c5bb014a46f91375becab6ea0836096ffa8bfb195b3f0af5ac3bfa0491677"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: AuditService.Domain: AuditService.Domain: 0 % XML-doc coverage (0/20)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/AuditService/AuditService.Domain/AuditService.Domain.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f420100c183c893f4fdf8b3cb0298788c4fcab5026ddec815843eed7ad84977a"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: ExpenseTracker.Contracts: ExpenseTracker.Contracts: 0 % XML-doc coverage (0/41)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ExpenseTracker/ExpenseTracker.Contracts/ExpenseTracker.Contracts.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"902f7527cca3fa72e650df2be14d622f2691fb9a5d383ceff20e42cbb0ff66b1"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found at common paths; consider documenting architectural decisions in Docs/ADL/ or similar."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D23","level":"note","message":{"text":"Bounded contexts not declared: A codebase of this scale with 15 projects likely contains multiple distinct modules or concerns that require explicit boundary definitions to manage coupling effectively. Declare architecture.contexts (\u22652) in config to assess cross-boundary type coupling."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1c7e276c9c682731f01819ed5378b90ca320cde1b583c90920172911598362b3"}},{"ruleId":"D24","level":"note","message":{"text":"redundant comment: \u0022Add services to the container.\u0022 \u2014 Remove. This is a standard ASP.NET Core pattern; the code \u0060services.Add...\u0060 is self-explanatory."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/AuditService/AuditService.Api/Program.cs"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"4b8f42954213e855d43214a6746979a28df87290a3e5b911b14ae976f37a8a26"}},{"ruleId":"D24","level":"note","message":{"text":"redundant comment: \u0022Configure the HTTP request pipeline.\u0022 \u2014 Remove. This is a standard ASP.NET Core pattern; the code \u0060app.Use...\u0060 is self-explanatory."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/AuditService/AuditService.Api/Program.cs"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"4b8f42954213e855d43214a6746979a28df87290a3e5b911b14ae976f37a8a26"}},{"ruleId":"D25","level":"note","message":{"text":"no ADRs to check: No ADRs found, so conformance can\u0027t be assessed."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5f96235c58be08aaae505ba823e9095f206fbc6a447f646e346ee9bd81a5f481"}},{"ruleId":"D30","level":"note","message":{"text":"Not applicable: the solution did not restore on the analyzer\u0027s .NET SDK (an SDK/target-framework/restore mismatch, common for an older codebase), so there was no restored dependency graph to scan for NuGet CVEs \u2014 excluded rather than scored; re-run on an SDK that can restore this solution"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"34ff807233366ca1607a49113cb8f9a094878853712c06642d2146b82741378f"}},{"ruleId":"D31","level":"error","message":{"text":"High IaC: DS-0029: \u0027apt-get\u0027 missing \u0027--no-install-recommends\u0027"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/AuditService/AuditService.Api/Dockerfile"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"98840803c9b4b3486a3fff0b93ec5096d7e12492bb774e21c9703dcf91430f0c"}},{"ruleId":"D31","level":"error","message":{"text":"High IaC: DS-0029: \u0027apt-get\u0027 missing \u0027--no-install-recommends\u0027"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ExpenseService/ExpenseService.Api/Dockerfile"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"2cfe15b938a6b4ca057fd71f5729cc6d7773f654fed0cda243b0406777c94706"}},{"ruleId":"D31","level":"note","message":{"text":"Low IaC: DS-0026: No HEALTHCHECK defined"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/AuditService/AuditService.Api/Dockerfile"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b4abce6578d5939489c115235a013e1b20660b110341187dec5dd9f91048f4af"}},{"ruleId":"D31","level":"note","message":{"text":"Low IaC: DS-0026: No HEALTHCHECK defined"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ExpenseService/ExpenseService.Api/Dockerfile"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"247f0a72fbc702a8d32f2bdfc8cb4bae879c8b54e74f80e351a086c7ceb2d3ef"}},{"ruleId":"D32","level":"note","message":{"text":"Not applicable: No PII/GDPR-handling patterns detected (p/gdpr ruleset) \u2014 no data-compliance surface to assess."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"df51e593e9b0b9805626d04fe36a3d12c504b5d7d5da30dc59b5b0f134b5753b"}},{"ruleId":"D33","level":"note","message":{"text":"Not applicable: No JS/npm manifest or lockfile found outside bin/obj (package.json, package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lockb); no JS dependencies to scan."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f46a134eeb447d8c90511e3106af3dac20b26868f5143d77eadbb96ed8f220c6"}},{"ruleId":"D34","level":"note","message":{"text":"early-stage repository \u2014 too little history to judge knowledge freshness: early-stage repository \u2014 too little history to judge knowledge freshness (22 commit(s) sampled)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"58b42e8ad1f5e125e8a2d365554e56d01e64a556b28e0c9985ff169722b7c54a"}},{"ruleId":"D35","level":"warning","message":{"text":"git history depth insufficient: git history depth insufficient \u2014 a full clone gives reliable change-coupling."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c3898c82d557f2616b569b6ad2fc4553f15857ea932e622df9e26ca46b21274a"}},{"ruleId":"D36","level":"note","message":{"text":"Not applicable: No CI/build pipeline found (.github/workflows, .gitlab-ci.yml, azure-pipelines.yml, Jenkinsfile, .circleci); there is no build to attest provenance for."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"383f97e2d2c3d8c6d4adffc68d228db0928a3a8f5c3df1214c0f646687d2dbe9"}},{"ruleId":"D37","level":"note","message":{"text":"Not applicable: No vulnerability-disclosure policy file found (SECURITY.md, .github/SECURITY.md, docs/SECURITY.md, .well-known/security.txt). A coordinated-disclosure policy may live off-repo, so this is not evidenced rather than failed."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e748a9b8b3d154964dfb621b8675d34a302dda266d0196c5d83eb8ba4071d61c"}},{"ruleId":"D38","level":"note","message":{"text":"Not applicable: No JS/npm lockfile found outside bin/obj (package-lock.json, yarn.lock, pnpm-lock.yaml, bun.lockb); nothing for OSV to scan."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6ff7301b610918095afd57ac1c89dabddab1d8fdb34c0f0d687159a5a0df0b8e"}}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":0,"secretScannerRunsExcluded":0}}}]}