{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D10","name":"Test Quality","shortDescription":{"text":"Test Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D10"},{"id":"D11","name":"Test Reliability","shortDescription":{"text":"Test Reliability"},"helpUri":"https://codehealth.canine.dev/dimensions/D11"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D23","name":"Boundary Type-Coupling","shortDescription":{"text":"Boundary Type-Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D23"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"}]}},"results":[{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): src/ModularNet.Api/Controllers/HealthChecksController.cs:71-85 | src/ModularNet.Api/Controllers/HealthChecksController.cs:101-115 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ModularNet.Api/Controllers/HealthChecksController.cs"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"d4277378a93893826957e0041d841b0c12d376db6122c099b5a96bb5279ee526"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: ModularNet.Shared: ModularNet.Shared: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and heavily depended-on, so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e277de6d0bada90c76d22267835278ff80886606a1058301bd0e7efe29762fdb"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: ModularNet.Domain: ModularNet.Domain: abstractness 0.00, instability 0.25, distance 0.75 \u2014 zone of pain \u2014 concrete and heavily depended-on, so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"857153cebca055529ff1efbe63f9370fb4bda0dc3c613a36fc5a970cb4f7854a"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO: Create URI \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ModularNet.Api/Controllers/AuthController.cs"},"region":{"startLine":70}}}],"partialFingerprints":{"codehealthFindingId/v1":"8b483959b52b08195c4c97d51e3fb4f5ed40346022c37a2f393011decf0d6ff7"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO: Create URI \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ModularNet.Api/Controllers/UsersController.cs"},"region":{"startLine":93}}}],"partialFingerprints":{"codehealthFindingId/v1":"b7a422d16d174559c3bce01a4d8ed8a657d205888d83d4bd14c6198713f61c7b"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO: We receive the providerId and the DB should be refactored to save this, plus the related userOid for that provider, as a user could use multiple providers to sign in. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ModularNet.Api/Controllers/AuthController.cs"},"region":{"startLine":205}}}],"partialFingerprints":{"codehealthFindingId/v1":"3beab435057b434ff1a89aef1549516cfaf15faf44f38b3d3e272b488dc6f94b"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO: Get these messages from DB \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ModularNet.Business/Implementations/EmailServiceManager.cs"},"region":{"startLine":126}}}],"partialFingerprints":{"codehealthFindingId/v1":"07ef071114993e91f53111b361821fedf7c9e7b894d78a3161aaf9c125948ec9"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO: Get these messages from DB \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ModularNet.Business/Implementations/EmailServiceManager.cs"},"region":{"startLine":161}}}],"partialFingerprints":{"codehealthFindingId/v1":"b7783ea356eaeb0cf78eb09c9769948cd1e04234a371b3ea1671e3c96ffc9a52"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Add these tokens in a secure place \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ModularNet.Business/Implementations/EncryptManager.cs"},"region":{"startLine":153}}}],"partialFingerprints":{"codehealthFindingId/v1":"f06285b877f5f7608f35c5ebc6fae9fdce83409c73c082215b2c1fd88631b14f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: At this point this piece of code is not needed, because all users will be registered in Firebase \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ModularNet.Business/Implementations/UsersManager.cs"},"region":{"startLine":40}}}],"partialFingerprints":{"codehealthFindingId/v1":"5d66f0b696efd69bbafcffd41b8dc293c8cc45e652345dbc726add4529668315"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO: Replicated. Set in config? Or in better place. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ModularNet.Business/Implementations/UsersSettingsManager.cs"},"region":{"startLine":24}}}],"partialFingerprints":{"codehealthFindingId/v1":"c179818604bb5ccf4e112c5fe87501d52323cb2df93ca9370f4a6206f33a99f3"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO: Replicated. Set in config? Or in better place. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ModularNet.Business/Implementations/UsersSettingsManager.cs"},"region":{"startLine":61}}}],"partialFingerprints":{"codehealthFindingId/v1":"aa9c56780910211fbbf594c77685d470c8f2d2375a687bf2642868bac214b0bc"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Time is replicated in CreateOrUpdateUserSettings \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ModularNet.Business/Implementations/UsersSettingsManager.cs"},"region":{"startLine":44}}}],"partialFingerprints":{"codehealthFindingId/v1":"d5d1d028a458ebd62b6d717d3de33f784a6fbdb79ad69ff6a9c2f2bfbfb19682"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Time is replicated in GetUserSettings \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ModularNet.Business/Implementations/UsersSettingsManager.cs"},"region":{"startLine":105}}}],"partialFingerprints":{"codehealthFindingId/v1":"add8700559ebccd32a7e61d49a0afdcd933333d063a51b24d8839851c7fe295e"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO: Create If for each environment when ready \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ModularNet.Infrastructure/Implementations/DbConnectionFactory.cs"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"96429514ca657b6fae1abd133a675378d92a9bd434719f6faa71846205b8f8c4"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO: Create If for each environment when ready \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ModularNet.Infrastructure/Implementations/RedisConnectionFactory.cs"},"region":{"startLine":49}}}],"partialFingerprints":{"codehealthFindingId/v1":"08d911428297b8b92c7d80ce1e586ab1f681ca6dedfdf301af8791ccaf456d0f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO: Refactor to have this similar to what has been done in Business \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ModularNet.Infrastructure/Implementations/SecretsRepository.cs"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"8f93de6e644266bd564174e5d44c31ea45aa2ce7317385a86f700a99f9da0788"}},{"ruleId":"D19","level":"note","message":{"text":"The architecture outline lists six layers but only Domain is fully described; Application, Business Logic, Infrastructure, Shared, and External Systems sections exist in the outline and are not shown.: Since the outline names them, do not flag as missing. The visible content is clean, so focus on the unshown gaps rather than the outlined ones."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1d425f4ac668d3c772080a5e081167caf23a34672e127dc8b8c79318c142672d"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found at common paths; consider documenting architectural decisions in Docs/ADL/ or similar."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D21","level":"note","message":{"text":"The concept of managing secrets is split between a \u0027Repository\u0027 and a \u0027Manager\u0027. One is infrastructure-level (repository), the other is business-level (manager), but both handle secret retrieval/caching.: Consider unifying the naming convention for secret management, e.g., both as Managers or both as Repositories, to reflect their distinct layers or responsibilities. (symbols: ModularNet.Infrastructure.Implementations.SecretsRepository, ModularNet.Business.Implementations.SecretsManager)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4ddf475ef93092646e394610aaeb69fbee9dc0ffa3bc97b2091921ee7cee8066"}},{"ruleId":"D21","level":"note","message":{"text":"The concept of email service operations is split between a \u0027Repository\u0027 and a \u0027Manager\u0027. One handles persistence/storage of email entities, the other handles the business logic/sending.: Ensure the distinction between \u0027Repository\u0027 (data access) and \u0027Manager\u0027 (business logic) is consistent across all similar service types. (symbols: ModularNet.Infrastructure.Implementations.EmailServiceRepository, ModularNet.Business.Implementations.EmailServiceManager)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"92ba70c8949640922a655077b73c1a0f265069b1b29c47ddbecca0eef3851bb4"}},{"ruleId":"D21","level":"note","message":{"text":"The Redis connection factory is implemented in a class named \u0027RedisConnectionFactory\u0027 but also has an interface \u0027IRedisConnectionFactory\u0027. This is standard, but the implementation class name matches the interface name exactly, which is fine, however, check if other factories follow this pattern.:  (symbols: ModularNet.Infrastructure.Implementations.RedisConnectionFactory, ModularNet.Infrastructure.Interfaces.IRedisConnectionFactory)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"28edf57e09ca0ff63fb11c979df9e808da1156379aa4569c675f8d5a5f8cc7a4"}},{"ruleId":"D23","level":"note","message":{"text":"Bounded contexts not declared: At 3428 LoC across 7 projects the codebase is large and multi-module, so explicit bounded contexts are needed. Name this codebase\u0027s bounded contexts (\u22652 module groups, e.g. per subsystem) so cross-boundary type coupling can be assessed. Declare them in \u0060.codehealth/config.yaml\u0060 at the repository root (create it if absent), mapping each context name to the namespace prefixes that belong to it \u2014 e.g. \u0060architecture:\u0060 \u2192 \u0060contexts:\u0060 \u2192 \u0060Billing: [\u0022Acme.Billing\u0022]\u0060, \u0060Catalog: [\u0022Acme.Catalog\u0022]\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1c7e276c9c682731f01819ed5378b90ca320cde1b583c90920172911598362b3"}},{"ruleId":"D27","level":"note","message":{"text":"High interface indirection: 31 % of calls go through an interface \u2014 tracing a call means resolving the implementation each hop. Prefer concrete types where there\u0027s a single implementation."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"cdce37f9abf7531f8d28e92afaa9d119cadea0ab8dd2d3958949c20b31f486ec"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dba67ba76c469257beffe8379e3f070abbcaf456ee9077d904f34e584201d1e8"}},{"ruleId":"D28","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3cdfd7beb31b791ae18dcb425e21eb157c842e7bbcd522cc330573c1a6538db1"}},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0a65b88617cd481f7f3bbb2c163ca1ad07668a1d5e7c4d40b3ceef5dd6f579c7"},"taxa":[{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dc8f19d56ec1d7e1c69cdaff8314e7579017d54ec2707ed5639fd68064819511"},"taxa":[{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":4,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}