{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D22","name":"Internal API Consistency","shortDescription":{"text":"Internal API Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D22"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AX9","name":"CQS / query purity","shortDescription":{"text":"CQS / query purity"},"helpUri":"https://codehealth.canine.dev/dimensions/AX9"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"ES1","name":"Fold determinism","shortDescription":{"text":"Fold determinism"},"helpUri":"https://codehealth.canine.dev/dimensions/ES1"},{"id":"ES2","name":"Immutable events","shortDescription":{"text":"Immutable events"},"helpUri":"https://codehealth.canine.dev/dimensions/ES2"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P2","name":"Observability","shortDescription":{"text":"Observability"},"helpUri":"https://codehealth.canine.dev/dimensions/P2"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"P7","name":"Outbound HTTP resilience","shortDescription":{"text":"Outbound HTTP resilience"},"helpUri":"https://codehealth.canine.dev/dimensions/P7"},{"id":"PF3","name":"Async \u0026 latency hygiene","shortDescription":{"text":"Async \u0026 latency hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/PF3"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"alvr_server_core::connection::connection_pipeline (cyclomatic 87): alvr_server_core::connection::connection_pipeline has cyclomatic complexity 87 (threshold 15). Of this number, 86 points are the body\u0027s own statements and 1 belongs to one function item inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/connection.rs"},"region":{"startLine":555}}}],"partialFingerprints":{"codehealthFindingId/v1":"938be4c7a2cd1f8909e094ef7403b705b361d74762be87717c209fbf9c2c3427"}},{"ruleId":"D1","level":"warning","message":{"text":"alvr_server_core::input_mapping::automatic_bindings (cyclomatic 67): alvr_server_core::input_mapping::automatic_bindings has cyclomatic complexity 67 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/input_mapping.rs"},"region":{"startLine":243}}}],"partialFingerprints":{"codehealthFindingId/v1":"64847d47766b847d055f8d9bda313cbd963a1f949f8f8c24a37719915c781e77"}},{"ruleId":"D1","level":"warning","message":{"text":"DataSources::new (cyclomatic 59): DataSources::new has cyclomatic complexity 59 (threshold 15). Of this number, 58 points are the body\u0027s own statements and 1 belongs to one function item inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/data_sources.rs"},"region":{"startLine":129}}}],"partialFingerprints":{"codehealthFindingId/v1":"f7bf6cf191b1664fad261f4633c3209029183a36c4c0c2954a1dd6dbf8ef3078"}},{"ruleId":"D1","level":"warning","message":{"text":"alvr_server_openvr::props::set_device_openvr_props (cyclomatic 55): alvr_server_openvr::props::set_device_openvr_props has cyclomatic complexity 55 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_openvr/src/props.rs"},"region":{"startLine":196}}}],"partialFingerprints":{"codehealthFindingId/v1":"96842b1665745ca7235aa1ec6894f4e025fa0cb8ab2e95627968e0590c86738e"}},{"ruleId":"D1","level":"warning","message":{"text":"alvr_client_core::connection::connection_pipeline (cyclomatic 53): alvr_client_core::connection::connection_pipeline has cyclomatic complexity 53 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_core/src/connection.rs"},"region":{"startLine":124}}}],"partialFingerprints":{"codehealthFindingId/v1":"e7d71f7339227ccc5c52fcdf638c987fcb12a0264e0d1a8a8f9680d6867f857a"}},{"ruleId":"D1","level":"warning","message":{"text":"alvr_client_openxr::entry_point (cyclomatic 49): alvr_client_openxr::entry_point has cyclomatic complexity 49 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/lib.rs"},"region":{"startLine":160}}}],"partialFingerprints":{"codehealthFindingId/v1":"460844c6ef7f034be9d9ebf454531e556b126fb6da6fdbc1cf7db3f6716d3caa"}},{"ruleId":"D1","level":"warning","message":{"text":"alvr_server_openvr::spawn_event_loop (cyclomatic 39): alvr_server_openvr::spawn_event_loop has cyclomatic complexity 39 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_openvr/src/lib.rs"},"region":{"startLine":233}}}],"partialFingerprints":{"codehealthFindingId/v1":"8180018fbcad63beaae583cb4e46380c0cd910a3df57ba4bdcf57330a719d06b"}},{"ruleId":"D1","level":"warning","message":{"text":"Dashboard::ui (cyclomatic 38): Dashboard::ui has cyclomatic complexity 38 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/mod.rs"},"region":{"startLine":145}}}],"partialFingerprints":{"codehealthFindingId/v1":"21257cfc79a4eae15b8497732b21daee8d5681e923b79d73e4d661d333e66251"}},{"ruleId":"D1","level":"warning","message":{"text":"alvr_xtask::main (cyclomatic 37): alvr_xtask::main has cyclomatic complexity 37 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/xtask/src/main.rs"},"region":{"startLine":164}}}],"partialFingerprints":{"codehealthFindingId/v1":"0f73ecf4a6af7b5c38d359bea31928953401e5aaaa14ba03fcf8f349778ffd3d"}},{"ruleId":"D1","level":"warning","message":{"text":"alvr_server_openvr::props::serial_number (cyclomatic 27): alvr_server_openvr::props::serial_number has cyclomatic complexity 27 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_openvr/src/props.rs"},"region":{"startLine":118}}}],"partialFingerprints":{"codehealthFindingId/v1":"d9be4b9c3b08e7e16fd0f1e0c6540ecd88b37e4f101fe868a6afe855c878acd4"}},{"ruleId":"D1","level":"warning","message":{"text":"alvr_server_core::connection::handshake_loop (cyclomatic 25): alvr_server_core::connection::handshake_loop has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/connection.rs"},"region":{"startLine":289}}}],"partialFingerprints":{"codehealthFindingId/v1":"0f521281b51de8f0bf38ea05535e7b0c9e8fc0fe7eaed500e0c7f65708be35bd"}},{"ruleId":"D1","level":"warning","message":{"text":"InteractionContext::select_sources (cyclomatic 23): InteractionContext::select_sources has cyclomatic complexity 23 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/interaction.rs"},"region":{"startLine":503}}}],"partialFingerprints":{"codehealthFindingId/v1":"87c03b5221111f7a728f31ad4ca0c74ace8132eebf317857c9489a7d9e101ed9"}},{"ruleId":"D1","level":"warning","message":{"text":"EyeTrackedFoveation::update (cyclomatic 23): EyeTrackedFoveation::update has cyclomatic complexity 23 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_openvr/src/foveated_encoding.rs"},"region":{"startLine":45}}}],"partialFingerprints":{"codehealthFindingId/v1":"10c7f5c865ea5371f8ca777f83f6464afcc843258d39ae0048bce1fe8d3adbe0"}},{"ruleId":"D1","level":"warning","message":{"text":"Launcher::ui (cyclomatic 22): Launcher::ui has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/launcher/src/ui.rs"},"region":{"startLine":282}}}],"partialFingerprints":{"codehealthFindingId/v1":"b7b62a7f03fd22db9b367f287d127f2d2b3cfe8f7aba16b7b35b2e3ed1b90c09"}},{"ruleId":"D1","level":"warning","message":{"text":"alvr_server_core::tracking::tracking_loop (cyclomatic 22): alvr_server_core::tracking::tracking_loop has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/tracking/mod.rs"},"region":{"startLine":282}}}],"partialFingerprints":{"codehealthFindingId/v1":"99112cc09a628bcc2ce342388f94925ceebcfe62c3237338dcd2da9f7622d440"}},{"ruleId":"D1","level":"warning","message":{"text":"alvr_server_core::input_mapping::map_button_pair_automatic (cyclomatic 21): alvr_server_core::input_mapping::map_button_pair_automatic has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/input_mapping.rs"},"region":{"startLine":143}}}],"partialFingerprints":{"codehealthFindingId/v1":"4da5d270fb5b123504908f79ce71a1306a16a951bbd1e184597e3c6252096a51"}},{"ruleId":"D1","level":"warning","message":{"text":"alvr_audio::receive_samples_loop (cyclomatic 19): alvr_audio::receive_samples_loop has cyclomatic complexity 19 (threshold 15). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/audio/src/lib.rs"},"region":{"startLine":377}}}],"partialFingerprints":{"codehealthFindingId/v1":"8ca864f58d69b6b36e683037e407dd0290b752f060e0835fa1fe56262846db1d"}},{"ruleId":"D1","level":"warning","message":{"text":"alvr_server_core::tracking::body::extract_default_trackers (cyclomatic 19): alvr_server_core::tracking::body::extract_default_trackers has cyclomatic complexity 19 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/tracking/body.rs"},"region":{"startLine":143}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a748d69f0e979af3370f9c59b724620d1638ecef670c1831cd8c583c6b44913"}},{"ruleId":"D1","level":"warning","message":{"text":"alvr_client_core::video_decoder::android::decoder_lifecycle (cyclomatic 18): alvr_client_core::video_decoder::android::decoder_lifecycle has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_core/src/video_decoder/android.rs"},"region":{"startLine":193}}}],"partialFingerprints":{"codehealthFindingId/v1":"c282a93dda18625c252871be111f5fe2041273da331b666e88ca5aa326a774ef"}},{"ruleId":"D1","level":"warning","message":{"text":"alvr_client_openxr::stream::stream_input_loop (cyclomatic 18): alvr_client_openxr::stream::stream_input_loop has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/stream.rs"},"region":{"startLine":529}}}],"partialFingerprints":{"codehealthFindingId/v1":"b9cfd1bc71a76b1e80a20b4f5da6c50dbe6a53bc70a6d895cc7aab249ad3db96"}},{"ruleId":"D1","level":"warning","message":{"text":"LobbyRenderer::render (cyclomatic 18): LobbyRenderer::render has cyclomatic complexity 18 (threshold 15). Of this number, 16 points are the body\u0027s own statements and 2 belong to one function item inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/graphics/src/lobby.rs"},"region":{"startLine":403}}}],"partialFingerprints":{"codehealthFindingId/v1":"bb5f0b1f541305a036eb012ee6cf71031bad0d9950ad0e1ef1fe13f7d9c544b1"}},{"ruleId":"D1","level":"warning","message":{"text":"ServerSessionManager::update_client_connections (cyclomatic 18): ServerSessionManager::update_client_connections has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_io/src/lib.rs"},"region":{"startLine":194}}}],"partialFingerprints":{"codehealthFindingId/v1":"c94cb11c9990272bbc42885c050b147259553e525606f908a44ac97370ddcd83"}},{"ruleId":"D1","level":"warning","message":{"text":"alvr_session::extrapolate_session_settings_from_session_settings (cyclomatic 18): alvr_session::extrapolate_session_settings_from_session_settings has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/session/src/lib.rs"},"region":{"startLine":155}}}],"partialFingerprints":{"codehealthFindingId/v1":"555df4cb61d98618aa251db538c92b564042dbc8b9cc57a0b0fa92a1919b9d60"}},{"ruleId":"D1","level":"warning","message":{"text":"InteractionContext::new (cyclomatic 17): InteractionContext::new has cyclomatic complexity 17 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/interaction.rs"},"region":{"startLine":201}}}],"partialFingerprints":{"codehealthFindingId/v1":"025fdf2fdfa093bbc6b75f90ad53e5346512ccafa41f5c91e80c3289db1a726e"}},{"ruleId":"D1","level":"warning","message":{"text":"SetupWizard::ui (cyclomatic 17): SetupWizard::ui has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/components/setup_wizard.rs"},"region":{"startLine":68}}}],"partialFingerprints":{"codehealthFindingId/v1":"a0ee53259eab388020b4de0ef5b41122089604fbf6d2ba7480e7804cc096217a"}},{"ruleId":"D1","level":"warning","message":{"text":"alvr_client_openxr::interaction::get_hand_data (cyclomatic 16): alvr_client_openxr::interaction::get_hand_data has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/interaction.rs"},"region":{"startLine":784}}}],"partialFingerprints":{"codehealthFindingId/v1":"7ed5ab3f309988d35dbc9b41ba505d40097375335a7e03d0655f1979c361ff46"}},{"ruleId":"D1","level":"warning","message":{"text":"DevicesTab::ui (cyclomatic 16): DevicesTab::ui has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/components/devices.rs"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"3ba699ff1a16564404cf0c375d6d1ec5437b9cdd2b7d76dac4822e2f94ac0f3f"}},{"ruleId":"D1","level":"warning","message":{"text":"ButtonMappingManager::map_button (cyclomatic 16): ButtonMappingManager::map_button has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/input_mapping.rs"},"region":{"startLine":645}}}],"partialFingerprints":{"codehealthFindingId/v1":"5e25cc5728eaa22cc09a16138bab411016d5724ef90242a36e19ba7ab5572719"}},{"ruleId":"D1","level":"warning","message":{"text":"FaceTrackingSink::send_tracking (cyclomatic 16): FaceTrackingSink::send_tracking has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/tracking/face.rs"},"region":{"startLine":54}}}],"partialFingerprints":{"codehealthFindingId/v1":"8be2fe730b27b6a46cb7a83b4d500cc125d0d75c8fa83075e58d18da1621a610"}},{"ruleId":"D1","level":"warning","message":{"text":"alvr_server_core::connection::compute_restart_settings_hash (cyclomatic 16): alvr_server_core::connection::compute_restart_settings_hash has cyclomatic complexity 16 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/connection.rs"},"region":{"startLine":97}}}],"partialFingerprints":{"codehealthFindingId/v1":"b3fccab621de17795328eec04cea6328f7079b85f1e5b113a333889bfd95949a"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_server_core::connection::connection_pipeline (cognitive 152): alvr_server_core::connection::connection_pipeline has cognitive complexity 152 (threshold 15). Drivers by points: if/else 71 (118 pts), match/switch 7 (14 pts), loops 10 (13 pts), boolean chains 7 (nesting depth added 57). Of this number, 151 points are the body\u0027s own statements and 1 belongs to one function item inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/connection.rs"},"region":{"startLine":555}}}],"partialFingerprints":{"codehealthFindingId/v1":"3c5905692a7fa11a1c2d4278ddaa148b86d53845f759379578beb5c43341759c"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_client_openxr::entry_point (cognitive 101): alvr_client_openxr::entry_point has cognitive complexity 101 (threshold 15). Drivers by points: if/else 25 (70 pts), match/switch 6 (20 pts), loops 4 (9 pts), boolean chains 2 (nesting depth added 64). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/lib.rs"},"region":{"startLine":160}}}],"partialFingerprints":{"codehealthFindingId/v1":"67f9c1b3d12feed46c584ab497d7ee2826c6817ecc9e02c91b5a6f30ec08f707"}},{"ruleId":"D2","level":"warning","message":{"text":"DataSources::new (cognitive 94): DataSources::new has cognitive complexity 94 (threshold 15). Drivers by points: if/else 26 (71 pts), match/switch 3 (11 pts), loops 6 (9 pts), boolean chains 3 (nesting depth added 56). Of this number, 89 points are the body\u0027s own statements and 5 belong to one function item inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/data_sources.rs"},"region":{"startLine":129}}}],"partialFingerprints":{"codehealthFindingId/v1":"3b024c892cd6379610f7da4baa3be42e9b810c936ecb69aa2672826cdc642404"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_server_openvr::props::set_device_openvr_props (cognitive 87): alvr_server_openvr::props::set_device_openvr_props has cognitive complexity 87 (threshold 15). Drivers by points: if/else 32 (73 pts), loops 2 (5 pts), match/switch 2 (5 pts), boolean chains 4 (nesting depth added 47). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_openvr/src/props.rs"},"region":{"startLine":196}}}],"partialFingerprints":{"codehealthFindingId/v1":"53412ee8522d417ad6d8d3a1d66ed21bb79d9f40b220c2838d899b1de42a97d0"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_server_openvr::spawn_event_loop (cognitive 84): alvr_server_openvr::spawn_event_loop has cognitive complexity 84 (threshold 15). Drivers by points: if/else 24 (62 pts), loops 3 (9 pts), match/switch 3 (8 pts), boolean chains 5 (nesting depth added 49). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_openvr/src/lib.rs"},"region":{"startLine":233}}}],"partialFingerprints":{"codehealthFindingId/v1":"574982b73ef215d52807e4f806617d83182530322d948374b822d6f4db05879f"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_client_core::connection::connection_pipeline (cognitive 79): alvr_client_core::connection::connection_pipeline has cognitive complexity 79 (threshold 15). Drivers by points: if/else 27 (50 pts), loops 9 (13 pts), match/switch 6 (12 pts), boolean chains 4 (nesting depth added 33). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_core/src/connection.rs"},"region":{"startLine":124}}}],"partialFingerprints":{"codehealthFindingId/v1":"21c3b2b36a3f95a39e8719420a0a5c89f44f0c4d0735bb1e3f7426c67caac752"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_server_core::input_mapping::automatic_bindings (cognitive 79): alvr_server_core::input_mapping::automatic_bindings has cognitive complexity 79 (threshold 15). Drivers by points: if/else 49 (62 pts), boolean chains 17 (nesting depth added 13). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/input_mapping.rs"},"region":{"startLine":243}}}],"partialFingerprints":{"codehealthFindingId/v1":"3485a177bec8b5493fc47e2754fd92036df17a9eedd31765a9e33ddb16b06248"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_server_core::connection::handshake_loop (cognitive 57): alvr_server_core::connection::handshake_loop has cognitive complexity 57 (threshold 15). Drivers by points: if/else 12 (31 pts), match/switch 4 (11 pts), loops 5 (10 pts), boolean chains 5 (nesting depth added 31). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/connection.rs"},"region":{"startLine":289}}}],"partialFingerprints":{"codehealthFindingId/v1":"d01365ffa1bf87153178e9acd71612fea7b99c5fa95f974fbe0285f0ebb72694"}},{"ruleId":"D2","level":"warning","message":{"text":"Dashboard::ui (cognitive 55): Dashboard::ui has cognitive complexity 55 (threshold 15). Drivers by points: if/else 17 (35 pts), match/switch 4 (11 pts), loops 4 (7 pts), boolean chains 2 (nesting depth added 28). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/mod.rs"},"region":{"startLine":145}}}],"partialFingerprints":{"codehealthFindingId/v1":"14d38fa384419744686d2dbc330f61e0bacda3520d998bec936f1adbe66941c3"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_audio::receive_samples_loop (cognitive 52): alvr_audio::receive_samples_loop has cognitive complexity 52 (threshold 15). Drivers by points: loops 7 (28 pts), if/else 9 (20 pts), boolean chains 2, match/switch 1 (2 pts) (nesting depth added 33). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/audio/src/lib.rs"},"region":{"startLine":377}}}],"partialFingerprints":{"codehealthFindingId/v1":"bb49fea7e2c3680f1b9a3e066fdfc0cdcc6b0252ec68a714c829f4ed59bf747f"}},{"ruleId":"D2","level":"warning","message":{"text":"LobbyRenderer::render (cognitive 45): LobbyRenderer::render has cognitive complexity 45 (threshold 15). Drivers by points: if/else 10 (26 pts), loops 7 (16 pts), match/switch 1 (3 pts) (nesting depth added 27). Of this number, 41 points are the body\u0027s own statements and 4 belong to one function item inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/graphics/src/lobby.rs"},"region":{"startLine":403}}}],"partialFingerprints":{"codehealthFindingId/v1":"ec7f1b7550cbdb0daed93bbe25a4315ad4c19c6abdf9a710f5da5f8b05598878"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_server_core::tracking::tracking_loop (cognitive 43): alvr_server_core::tracking::tracking_loop has cognitive complexity 43 (threshold 15). Drivers by points: if/else 15 (37 pts), boolean chains 3, match/switch 1 (2 pts), loops 1 (nesting depth added 23). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/tracking/mod.rs"},"region":{"startLine":282}}}],"partialFingerprints":{"codehealthFindingId/v1":"946bd8f0877c8cdf4e10485eae753929c90b87c1b68056697bbf7ffcc6db5723"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_xtask::main (cognitive 42): alvr_xtask::main has cognitive complexity 42 (threshold 15). Drivers by points: if/else 18 (37 pts), match/switch 2 (5 pts) (nesting depth added 22). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/xtask/src/main.rs"},"region":{"startLine":164}}}],"partialFingerprints":{"codehealthFindingId/v1":"31e4ac38fb67b8e48d9696fd4a4b7d32accd73c2cec402de461b59652927f5aa"}},{"ruleId":"D2","level":"warning","message":{"text":"EyeTrackedFoveation::update (cognitive 41): EyeTrackedFoveation::update has cognitive complexity 41 (threshold 15). Drivers by points: if/else 15 (27 pts), loops 5 (11 pts), boolean chains 3 (nesting depth added 18). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_openvr/src/foveated_encoding.rs"},"region":{"startLine":45}}}],"partialFingerprints":{"codehealthFindingId/v1":"6a29a243fdab435ea129c66bfb6455385440152a2318dda9ddb2059c5b7ccc09"}},{"ruleId":"D2","level":"warning","message":{"text":"InteractionContext::select_sources (cognitive 38): InteractionContext::select_sources has cognitive complexity 38 (threshold 15). Drivers by points: if/else 17 (31 pts), boolean chains 4, match/switch 1 (3 pts) (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/interaction.rs"},"region":{"startLine":503}}}],"partialFingerprints":{"codehealthFindingId/v1":"3e3184497339533ac1963d82573943330aba3cf8b396fa81602f83b1d5aa9277"}},{"ruleId":"D2","level":"warning","message":{"text":"Control::ui (cognitive 37): Control::ui has cognitive complexity 37 (threshold 15). Drivers by points: if/else 14 (33 pts), loops 3 (4 pts) (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/components/settings_controls/dictionary.rs"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"b6cf9f9b277268f468442a1b953e74bc128de6d11550bc62eb22dd99ec229a82"}},{"ruleId":"D2","level":"warning","message":{"text":"Launcher::ui (cognitive 37): Launcher::ui has cognitive complexity 37 (threshold 15). Drivers by points: if/else 9 (22 pts), match/switch 5 (11 pts), loops 2 (3 pts), boolean chains 1 (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/launcher/src/ui.rs"},"region":{"startLine":282}}}],"partialFingerprints":{"codehealthFindingId/v1":"7931d4396b6d0ac0a76fc67528ca56c4a8f4753da36bd04fc4528e6d63efead9"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_server_core::input_mapping::map_button_pair_automatic (cognitive 37): alvr_server_core::input_mapping::map_button_pair_automatic has cognitive complexity 37 (threshold 15). Drivers by points: if/else 17 (31 pts), boolean chains 6 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/input_mapping.rs"},"region":{"startLine":143}}}],"partialFingerprints":{"codehealthFindingId/v1":"7d53a67953ec67f6b3fc85038e1ff633eaf1dcf77a89c22c32c23f94c6f02d69"}},{"ruleId":"D2","level":"warning","message":{"text":"ButtonMappingManager::map_button (cognitive 30): ButtonMappingManager::map_button has cognitive complexity 30 (threshold 15). Drivers by points: if/else 10 (20 pts), loops 2 (5 pts), match/switch 1 (3 pts), boolean chains 2 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/input_mapping.rs"},"region":{"startLine":645}}}],"partialFingerprints":{"codehealthFindingId/v1":"25adc21e461d254bba495f3358540e552316caa30763d0273f5292840198dad8"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_server_openvr::props::serial_number (cognitive 26): alvr_server_openvr::props::serial_number has cognitive complexity 26 (threshold 15). Drivers by points: if/else 17 (20 pts), match/switch 2 (5 pts), boolean chains 1 (nesting depth added 6). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_openvr/src/props.rs"},"region":{"startLine":118}}}],"partialFingerprints":{"codehealthFindingId/v1":"672e85309a02d1ae1343f85a64d806991e8bc65d522c785b46f4ead9f22360cc"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_client_openxr::interaction::get_hand_data (cognitive 25): alvr_client_openxr::interaction::get_hand_data has cognitive complexity 25 (threshold 15). Drivers by points: if/else 13 (20 pts), boolean chains 5 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/interaction.rs"},"region":{"startLine":784}}}],"partialFingerprints":{"codehealthFindingId/v1":"97638c9ae1f1bbea4ba2e3ba88fa827816df828d68ef7b75ba6dc13069238b1e"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_client_openxr::stream::stream_input_loop (cognitive 24): alvr_client_openxr::stream::stream_input_loop has cognitive complexity 24 (threshold 15). Drivers by points: if/else 10 (17 pts), boolean chains 6, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/stream.rs"},"region":{"startLine":529}}}],"partialFingerprints":{"codehealthFindingId/v1":"54ce7e1b03541abd206d8898afa6bfad0ae3f8cab8e2d5476eecb91647710b7e"}},{"ruleId":"D2","level":"warning","message":{"text":"DevicesTab::ui (cognitive 24): DevicesTab::ui has cognitive complexity 24 (threshold 15). Drivers by points: if/else 13 (19 pts), boolean chains 3, loops 1 (2 pts) (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/components/devices.rs"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"d40349f7650600017dbf5e8196b7a2ebe9a203202ae5cb88c5c0299a3e832dcb"}},{"ruleId":"D2","level":"warning","message":{"text":"Control::ui (cognitive 24): Control::ui has cognitive complexity 24 (threshold 15). Drivers by points: if/else 12 (22 pts), loops 1 (2 pts) (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/components/settings_controls/section.rs"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"8bf5d37171aaa3bbad84bfd4fdac6b00da981722cb13b27dc6a81d7f32b10d66"}},{"ruleId":"D2","level":"warning","message":{"text":"HandGestureManager::is_gesture_active (cognitive 24): HandGestureManager::is_gesture_active has cognitive complexity 24 (threshold 15). Drivers by points: if/else 13 (22 pts), boolean chains 2 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/hand_gestures.rs"},"region":{"startLine":366}}}],"partialFingerprints":{"codehealthFindingId/v1":"d4e582cbf57538b7f5098d9820f708f0e7121bf2ca8cf6fd9b1c4e8bb356b958"}},{"ruleId":"D2","level":"warning","message":{"text":"ServerCoreContext::send_video_nal (cognitive 24): ServerCoreContext::send_video_nal has cognitive complexity 24 (threshold 15). Drivers by points: if/else 10 (22 pts), boolean chains 2 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/lib.rs"},"region":{"startLine":396}}}],"partialFingerprints":{"codehealthFindingId/v1":"a459cdec7832d47444ef92754d2ba403e3dd89e5f086454ec345028a1ac37803"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_dashboard::steamvr_launcher::linux_steamvr::linux_encoder_checks (cognitive 23): alvr_dashboard::steamvr_launcher::linux_steamvr::linux_encoder_checks has cognitive complexity 23 (threshold 15). Drivers by points: match/switch 3 (10 pts), if/else 3 (8 pts), loops 2 (5 pts) (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/steamvr_launcher/linux_steamvr.rs"},"region":{"startLine":232}}}],"partialFingerprints":{"codehealthFindingId/v1":"9395dc223acfab7989cc88cb50e2dd23b6f55893e8c937d098368b9a185ba6b5"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_server_core::tracking::body::extract_default_trackers (cognitive 23): alvr_server_core::tracking::body::extract_default_trackers has cognitive complexity 23 (threshold 15). Drivers by points: if/else 17 (22 pts), match/switch 1 (nesting depth added 5). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/tracking/body.rs"},"region":{"startLine":143}}}],"partialFingerprints":{"codehealthFindingId/v1":"1d8cc59c76e278dec744238549b4d24dfffe0a7e51bdbb33d9184b48a6bc3c58"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_client_core::video_decoder::android::decoder_lifecycle (cognitive 22): alvr_client_core::video_decoder::android::decoder_lifecycle has cognitive complexity 22 (threshold 15). Drivers by points: if/else 7 (13 pts), match/switch 4 (7 pts), loops 2 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_core/src/video_decoder/android.rs"},"region":{"startLine":193}}}],"partialFingerprints":{"codehealthFindingId/v1":"1c3e94abf2312e913dcc2c2a691b7f7496dbb003e700d667859b233002ad1937"}},{"ruleId":"D2","level":"warning","message":{"text":"WiredConnection::setup (cognitive 21): WiredConnection::setup has cognitive complexity 21 (threshold 15). Drivers by points: if/else 9 (16 pts), match/switch 1 (4 pts), loops 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/adb/src/lib.rs"},"region":{"startLine":32}}}],"partialFingerprints":{"codehealthFindingId/v1":"ead2e6cc8879d9e71bc706882dfe257d17dc362955907516b47b76aad19d7771"}},{"ruleId":"D2","level":"warning","message":{"text":"Launcher::launch_steamvr (cognitive 21): Launcher::launch_steamvr has cognitive complexity 21 (threshold 15). Drivers by points: if/else 13 (20 pts), boolean chains 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/steamvr_launcher/mod.rs"},"region":{"startLine":130}}}],"partialFingerprints":{"codehealthFindingId/v1":"bb605ea5a0c5c7c09aeba7143f11b4d611a22c42a38519775db355da1f54c664"}},{"ruleId":"D2","level":"warning","message":{"text":"Control::ui (cognitive 20): Control::ui has cognitive complexity 20 (threshold 15). Drivers by points: if/else 12 (17 pts), boolean chains 2, match/switch 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/components/settings_controls/number.rs"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"71862485bb6c558dc8d1f61099cb5c1bab3195f20ded94f558ec1b54444924df"}},{"ruleId":"D2","level":"warning","message":{"text":"Control::update_session_settings (cognitive 20): Control::update_session_settings has cognitive complexity 20 (threshold 15). Drivers by points: if/else 3 (10 pts), loops 3 (6 pts), match/switch 1 (4 pts) (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/components/settings_controls/presets/higher_order_choice.rs"},"region":{"startLine":94}}}],"partialFingerprints":{"codehealthFindingId/v1":"a7b801b1d68e262cb0b82bb494de0d99d5ab1e83f9e71905ac0cc0baacda3e99"}},{"ruleId":"D2","level":"warning","message":{"text":"Control::ui (cognitive 20): Control::ui has cognitive complexity 20 (threshold 15). Drivers by points: if/else 8 (16 pts), loops 3 (4 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/components/settings_controls/vector.rs"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"043a68122eb779fe34d347161edf46b5bcdab62841defd026a2b8197085577fb"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_dashboard::steamvr_launcher::linux_steamvr::linux_gpu_checks (cognitive 20): alvr_dashboard::steamvr_launcher::linux_steamvr::linux_gpu_checks has cognitive complexity 20 (threshold 15). Drivers by points: if/else 10 (14 pts), boolean chains 3, match/switch 2 (3 pts) (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/steamvr_launcher/linux_steamvr.rs"},"region":{"startLine":113}}}],"partialFingerprints":{"codehealthFindingId/v1":"c0445489e9dc92535b9910a5055d00ef7478126cf6e1e09396e0da32c93d33d2"}},{"ruleId":"D2","level":"warning","message":{"text":"BitrateManager::get_encoder_params (cognitive 20): BitrateManager::get_encoder_params has cognitive complexity 20 (threshold 15). Drivers by points: if/else 10 (17 pts), boolean chains 2, match/switch 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/bitrate.rs"},"region":{"startLine":150}}}],"partialFingerprints":{"codehealthFindingId/v1":"7dabdc9b5345a911308f7f9fc02860828ea7c25642eb7d9a858f0415ef0cdfb9"}},{"ruleId":"D2","level":"warning","message":{"text":"FaceTrackingSink::send_tracking (cognitive 20): FaceTrackingSink::send_tracking has cognitive complexity 20 (threshold 15). Drivers by points: if/else 8 (15 pts), match/switch 3 (5 pts) (nesting depth added 9). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/tracking/face.rs"},"region":{"startLine":54}}}],"partialFingerprints":{"codehealthFindingId/v1":"de54cba24a1d4f059a4ce71d7b56d1b34c9f43ec2d9cfe41c42b258def6f65c4"}},{"ruleId":"D2","level":"warning","message":{"text":"ServerSessionManager::update_client_connections (cognitive 20): ServerSessionManager::update_client_connections has cognitive complexity 20 (threshold 15). Drivers by points: if/else 9 (17 pts), boolean chains 2, match/switch 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_io/src/lib.rs"},"region":{"startLine":194}}}],"partialFingerprints":{"codehealthFindingId/v1":"df474334a774b9155bc803bb4647a1439d8bfc189585cfce3b634375dda587cf"}},{"ruleId":"D2","level":"warning","message":{"text":"WelcomeSocket::recv_all (cognitive 19): WelcomeSocket::recv_all has cognitive complexity 19 (threshold 15). Drivers by points: if/else 6 (15 pts), match/switch 1 (2 pts), boolean chains 1, loops 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/sockets.rs"},"region":{"startLine":22}}}],"partialFingerprints":{"codehealthFindingId/v1":"82cb569d678e16e8189cf4f4b8d7e186ab55b550c79d1ca1735c09e1cf6f4f89"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_session::extrapolate_session_settings_from_session_settings (cognitive 19): alvr_session::extrapolate_session_settings_from_session_settings has cognitive complexity 19 (threshold 15). Drivers by points: if/else 9 (15 pts), match/switch 2 (4 pts) (nesting depth added 8). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/session/src/lib.rs"},"region":{"startLine":155}}}],"partialFingerprints":{"codehealthFindingId/v1":"27601e72dbf67177fac8568ad69164c9419891257cdadeb2213415993b83ee5c"}},{"ruleId":"D2","level":"warning","message":{"text":"Control::ui (cognitive 18): Control::ui has cognitive complexity 18 (threshold 15). Drivers by points: if/else 12 (17 pts), boolean chains 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/components/settings_controls/choice.rs"},"region":{"startLine":101}}}],"partialFingerprints":{"codehealthFindingId/v1":"4bda6e73b532b06639838591f208f89a66ca55b0122c9daf81b97ae3c9b04776"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_audio::record_audio_blocking (cognitive 17): alvr_audio::record_audio_blocking has cognitive complexity 17 (threshold 15). Drivers by points: if/else 10 (11 pts), boolean chains 4, loops 1 (2 pts) (nesting depth added 2). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/audio/src/lib.rs"},"region":{"startLine":249}}}],"partialFingerprints":{"codehealthFindingId/v1":"00f2a9a42892d4923b62f1fb10c900de9eea17311dd25a58a26f2775c19b8fe1"}},{"ruleId":"D2","level":"warning","message":{"text":"SetupWizard::ui (cognitive 17): SetupWizard::ui has cognitive complexity 17 (threshold 15). Drivers by points: if/else 11 (16 pts), match/switch 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/components/setup_wizard.rs"},"region":{"startLine":68}}}],"partialFingerprints":{"codehealthFindingId/v1":"366d37ac6b62dce2636f5951d5356b85bafdcdf918203139401118ce3ec7e2a5"}},{"ruleId":"D2","level":"warning","message":{"text":"TrackingManager::report_device_motions (cognitive 16): TrackingManager::report_device_motions has cognitive complexity 16 (threshold 15). Drivers by points: if/else 8 (15 pts), loops 1 (nesting depth added 7). Of this number, 12 points are the body\u0027s own statements and 4 belong to one function item inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/tracking/mod.rs"},"region":{"startLine":116}}}],"partialFingerprints":{"codehealthFindingId/v1":"d023cceb008ea6df09dace7f0def1b033b58994b7257922b6bb46cb65867e0e1"}},{"ruleId":"D2","level":"warning","message":{"text":"alvr_server_core::logging_backend::init_logging (cognitive 16): alvr_server_core::logging_backend::init_logging has cognitive complexity 16 (threshold 15). Drivers by points: if/else 11, boolean chains 4, match/switch 1. Of this number, 15 points are the body\u0027s own statements and 1 belongs to one function item inside it that branches. To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/logging_backend.rs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"0296a28fd87c8e272649b45b156742c87fc5cc56dcc8fd18c18316b62d7b868c"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: alvr_server_core::connection::connection_pipeline: FunctionTooLong \u2014 alvr_server_core::connection::connection_pipeline runs 670 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 570 over it, 6.70\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/connection.rs"},"region":{"startLine":555}}}],"partialFingerprints":{"codehealthFindingId/v1":"ad1e93691bd8e1ab75b1e7507268dc1619aa5cc977b9dfd151ace15df21628ce"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: alvr_server_openvr::props::set_device_openvr_props: FunctionTooLong \u2014 alvr_server_openvr::props::set_device_openvr_props runs 346 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 246 over it, 3.46\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_openvr/src/props.rs"},"region":{"startLine":196}}}],"partialFingerprints":{"codehealthFindingId/v1":"58ab9223133a7043bee6bd84907f5d4ab3703857aa3c24bc253cb52cb767ddd6"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: alvr_client_openxr::entry_point: FunctionTooLong \u2014 alvr_client_openxr::entry_point runs 339 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 239 over it, 3.39\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/lib.rs"},"region":{"startLine":160}}}],"partialFingerprints":{"codehealthFindingId/v1":"c92e7d9805e3d4495c16fe98868382983677ce0089bf40e8352f1fdcd4a97e38"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: alvr_client_core::connection::connection_pipeline: FunctionTooLong \u2014 alvr_client_core::connection::connection_pipeline runs 322 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 222 over it, 3.22\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_core/src/connection.rs"},"region":{"startLine":124}}}],"partialFingerprints":{"codehealthFindingId/v1":"273a417bdca6f396798cfde8f3e840e5d1966a48a64da2ae8ca3403dd5b817e0"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: DataSources.new: MethodTooLong \u2014 new runs 268 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 168 over it, 2.68\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/data_sources.rs"},"region":{"startLine":129}}}],"partialFingerprints":{"codehealthFindingId/v1":"77f215cc834fa85d50c46cb0337357dc470c1c2952012ec500bed33f467217c0"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: alvr_server_core::input_mapping::automatic_bindings: FunctionTooLong \u2014 alvr_server_core::input_mapping::automatic_bindings runs 253 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 153 over it, 2.53\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/input_mapping.rs"},"region":{"startLine":243}}}],"partialFingerprints":{"codehealthFindingId/v1":"66dcf607e04643f0b27d39237a93a5e187c29145b9743241cdbb6ede72c307fb"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: InteractionContext.new: MethodTooLong \u2014 new runs 218 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 118 over it, 2.18\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/interaction.rs"},"region":{"startLine":201}}}],"partialFingerprints":{"codehealthFindingId/v1":"fee8956fb333930297a173aad638154902b8bef45f556124f3bd2a60d7068ce9"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/connection.rs: FileTooLong \u2014 1074 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 574 over it, 2.15\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/connection.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"649b108c35205e2d9aebf0c7ef84e9e1d5659515e503567e7d7881a400b1c2eb"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: HandGestureManager.get_active_gestures: MethodTooLong \u2014 get_active_gestures runs 210 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 110 over it, 2.10\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/hand_gestures.rs"},"region":{"startLine":102}}}],"partialFingerprints":{"codehealthFindingId/v1":"474b1b03dc068c5046d113138423934f4b0b92bfbf5c7d4f9291b4562abd5d4e"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: alvr_server_openvr::spawn_event_loop: FunctionTooLong \u2014 alvr_server_openvr::spawn_event_loop runs 204 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 104 over it, 2.04\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_openvr/src/lib.rs"},"region":{"startLine":233}}}],"partialFingerprints":{"codehealthFindingId/v1":"aed38343ccef47c20691f89df98b2f1906199e82655164ef33bb44cbbe7b59ff"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: alvr_session::extrapolate_session_settings_from_session_settings: FunctionTooLong \u2014 alvr_session::extrapolate_session_settings_from_session_settings runs 173 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 73 over it, 1.73\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/session/src/lib.rs"},"region":{"startLine":155}}}],"partialFingerprints":{"codehealthFindingId/v1":"0973746be13d2acbc440279a1d2b9085ce7f57900e0360acdc2c9b813dbad5c5"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: alvr_server_core::tracking::tracking_loop: FunctionTooLong \u2014 alvr_server_core::tracking::tracking_loop runs 171 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 71 over it, 1.71\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/tracking/mod.rs"},"region":{"startLine":282}}}],"partialFingerprints":{"codehealthFindingId/v1":"0223b0fe894301f3876d7267da719b50fa89b23fd71abd73e6301eee8dda9b15"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: LobbyRenderer.render: MethodTooLong \u2014 render runs 168 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 68 over it, 1.68\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/graphics/src/lobby.rs"},"region":{"startLine":403}}}],"partialFingerprints":{"codehealthFindingId/v1":"27f111ff7275f35e660e625dc23b7e877ba1a5ce299fbd92701e967ef2160aea"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: alvr_server_core::connection::compute_restart_settings_hash: FunctionTooLong \u2014 alvr_server_core::connection::compute_restart_settings_hash runs 163 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 63 over it, 1.63\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/connection.rs"},"region":{"startLine":97}}}],"partialFingerprints":{"codehealthFindingId/v1":"cff89f648999506c7162c0d0ba589c03cea3983b58dc3543acf6c1d39b6f7199"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/interaction.rs: FileTooLong \u2014 793 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 293 over it, 1.59\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/interaction.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c2229a138db594c1847d8164307e9cef2b7abb62589ccaf72280d27a99675e33"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: StreamRenderer.new: MethodTooLong \u2014 new runs 153 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 53 over it, 1.53\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/graphics/src/stream.rs"},"region":{"startLine":65}}}],"partialFingerprints":{"codehealthFindingId/v1":"35c069f2d253fff5eb14a2a55a9f487f446489135d2dc5c0361268c453b8ffb6"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: Dashboard.ui: MethodTooLong \u2014 ui runs 145 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 45 over it, 1.45\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/mod.rs"},"region":{"startLine":145}}}],"partialFingerprints":{"codehealthFindingId/v1":"76aebe77d8ed67c1760ee4ee8a00c8a230ce7ced07a8fe0af9f3b30affb314f0"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: alvr_server_openvr::make_settings: FunctionTooLong \u2014 alvr_server_openvr::make_settings runs 141 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 41 over it, 1.41\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_openvr/src/lib.rs"},"region":{"startLine":60}}}],"partialFingerprints":{"codehealthFindingId/v1":"041423f539224eaa6b9e1f2a7d4863893c56a63f0c89e04fdfb80d9f2e1f6722"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: alvr_server_core::connection::handshake_loop: FunctionTooLong \u2014 alvr_server_core::connection::handshake_loop runs 140 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 40 over it, 1.40\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/connection.rs"},"region":{"startLine":289}}}],"partialFingerprints":{"codehealthFindingId/v1":"1a57800680d0742ba7a4f9d0e4fe45cb3fd95f567839250211a0c4697df836e8"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: StatisticsTab.draw_bitrate_graph: MethodTooLong \u2014 draw_bitrate_graph runs 130 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 30 over it, 1.30\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/components/statistics.rs"},"region":{"startLine":265}}}],"partialFingerprints":{"codehealthFindingId/v1":"cbfea67aaf34a03497915293fc15fc6ab1a456aefdc8eea19cfc786d399bbf01"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/c_api.rs: FileTooLong \u2014 642 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), declaring 45 free functions. The bar is 500 significant lines; this is 142 over it, 1.28\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_core/src/c_api.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"6190d19574e1b6e415135fd8d549bea07fffd0d9147f832a73bdcecfd8456bde"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: StreamContext.render: MethodTooLong \u2014 render runs 123 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 23 over it, 1.23\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/stream.rs"},"region":{"startLine":339}}}],"partialFingerprints":{"codehealthFindingId/v1":"8bcecc6e32626c14265f8e9350d17726850f3e75afbd156f2e444d498d7e4212"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/lib.rs: FileTooLong \u2014 608 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 108 over it, 1.22\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_openvr/src/lib.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"5a67ef9c4d5f6b5238405050b7ba6399bad0b7ccbf48456323efee6e0bdffa8d"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: StreamContext.new: MethodTooLong \u2014 new runs 112 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 12 over it, 1.12\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/stream.rs"},"region":{"startLine":101}}}],"partialFingerprints":{"codehealthFindingId/v1":"f6985a2b94c5df8853c41d85b985130912f5fb1f66e97f874a864de9b50e8363"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: Launcher.version_popup: MethodTooLong \u2014 version_popup runs 111 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 11 over it, 1.11\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/launcher/src/ui.rs"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"57a6bf4c39635d9fd3235653bd181a2fd11dd791075e27caaccce23d462d2be7"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/input_mapping.rs: FileTooLong \u2014 515 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 15 over it, 1.03\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/input_mapping.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"519b6f89561f16791af925aad923bd234f92cff563b5a3bc2251e57b1ec1a24b"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: alvr_client_openxr::interaction::get_hand_data: FunctionTooLong \u2014 alvr_client_openxr::interaction::get_hand_data runs 102 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 2 over it, 1.02\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/interaction.rs"},"region":{"startLine":784}}}],"partialFingerprints":{"codehealthFindingId/v1":"d80a21fd3a3fa9c3e087dd79a6ac2bd4c95eff7fea7d2202fddf668c8a966d20"}},{"ruleId":"D4","level":"warning","message":{"text":"Near-duplicate member pair (49 shared lines): alvr/dashboard/src/dashboard/components/settings_controls/dictionary.rs:51-196 | alvr/dashboard/src/dashboard/components/settings_controls/vector.rs:40-139 \u2014 These two members are variants of one another: 49 of their lines are already reported as duplicated blocks below, spread through both bodies rather than gathered into one. Read them as a single construct written twice. The repair is at the members\u0027 grain \u2014 factor the shared pipeline into one implementation the two call with their differences as parameters or as an injected step, or, where the difference is systematic (sync against async, one transport against another), generate one from the other. Extracting the individual blocks below is not the same fix: it leaves the two bodies in place and the next edit still has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/components/settings_controls/dictionary.rs"},"region":{"startLine":51}}}],"partialFingerprints":{"codehealthFindingId/v1":"a4f2827d59acf71fe720b80a144bf90353ab90b14246470a6cdfb038133f17e9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (21\u201324 lines \u00D7 2): alvr/dashboard/src/dashboard/components/settings_controls/dictionary.rs:62-85 | alvr/dashboard/src/dashboard/components/settings_controls/vector.rs:50-70 \u2014 before extracting anything, compare \u0060alvr/dashboard/src/dashboard/components/settings_controls/dictionary.rs\u0060 and \u0060alvr/dashboard/src/dashboard/components/settings_controls/vector.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 52 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/components/settings_controls/dictionary.rs"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c4f66d00372e2103f4adf677f021db7a29309c51fcbea6f24feb32e1c3fb00c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (19 lines \u00D7 2): alvr/sockets/src/control_socket.rs:63-81 | alvr/sockets/src/stream_socket/tcp.rs:66-84 \u2014 before extracting anything, compare \u0060alvr/sockets/src/control_socket.rs\u0060 and \u0060alvr/sockets/src/stream_socket/tcp.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 42 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/sockets/src/control_socket.rs"},"region":{"startLine":63}}}],"partialFingerprints":{"codehealthFindingId/v1":"b0ac42ef88722a30c463b0bd25c1d3d7f12bd7d96d8f81951f9c3b2e240da280"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): alvr/server_core/src/connection.rs:127-143 | alvr/server_openvr/src/lib.rs:90-106 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/connection.rs"},"region":{"startLine":127}}}],"partialFingerprints":{"codehealthFindingId/v1":"c9d9cd2e198ba40d9ef08c2da5f62c1d0dfe740bde02d9245c5a0d8761b68a5d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): alvr/dashboard/src/dashboard/components/settings_controls/dictionary.rs:98-113 | alvr/dashboard/src/dashboard/components/settings_controls/vector.rs:80-95 \u2014 before extracting anything, compare \u0060alvr/dashboard/src/dashboard/components/settings_controls/dictionary.rs\u0060 and \u0060alvr/dashboard/src/dashboard/components/settings_controls/vector.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 52 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/components/settings_controls/dictionary.rs"},"region":{"startLine":98}}}],"partialFingerprints":{"codehealthFindingId/v1":"b055ad00649abd46b3a9ec7779ea75da356557edc59691a3f23cc05168c3b4b9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): alvr/dashboard/src/dashboard/components/settings_controls/optional.rs:23-38 | alvr/dashboard/src/dashboard/components/settings_controls/switch.rs:27-42 \u2014 before extracting anything, compare \u0060alvr/dashboard/src/dashboard/components/settings_controls/optional.rs\u0060 and \u0060alvr/dashboard/src/dashboard/components/settings_controls/switch.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 30 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/components/settings_controls/optional.rs"},"region":{"startLine":23}}}],"partialFingerprints":{"codehealthFindingId/v1":"aac02906bdabd5452c15f5fc9562eef681ced331249d5d0356fe5151c080f5c3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11\u201313 lines \u00D7 2): alvr/dashboard/src/main.rs:77-87 | alvr/launcher/src/main.rs:56-68 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/main.rs"},"region":{"startLine":77}}}],"partialFingerprints":{"codehealthFindingId/v1":"d161fc2caa1573ec07a00c3782031823ef759fe78094bfdfdfaae2d000172c65"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): alvr/sockets/src/control_socket.rs:40-52 | alvr/sockets/src/stream_socket/tcp.rs:43-55 \u2014 before extracting anything, compare \u0060alvr/sockets/src/control_socket.rs\u0060 and \u0060alvr/sockets/src/stream_socket/tcp.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 42 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/sockets/src/control_socket.rs"},"region":{"startLine":40}}}],"partialFingerprints":{"codehealthFindingId/v1":"5c4f7b6a1e53ee9d1c179984590dbbdce71fb34fee1f3aa042a7edcecfe2c166"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): alvr/server_core/src/tracking/mod.rs:488-498 | alvr/server_core/src/tracking/mod.rs:516-526 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/tracking/mod.rs"},"region":{"startLine":488}}}],"partialFingerprints":{"codehealthFindingId/v1":"75f6e93615017d5f92bd180f7c9572a2e5f0601cd45659e0111148d5dae8fa66"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): alvr/server_core/src/c_api.rs:496-505 | alvr/server_openvr/src/lib.rs:588-597 \u2014 before extracting anything, compare \u0060alvr/server_core/src/c_api.rs\u0060 and \u0060alvr/server_openvr/src/lib.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 38 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/c_api.rs"},"region":{"startLine":496}}}],"partialFingerprints":{"codehealthFindingId/v1":"b4b0c2861e56e3c253cd66bc222cd8f7144c22fd4dd3c6cf54157546d4273edb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): alvr/sockets/src/control_socket.rs:23-32 | alvr/sockets/src/stream_socket/tcp.rs:26-35 \u2014 before extracting anything, compare \u0060alvr/sockets/src/control_socket.rs\u0060 and \u0060alvr/sockets/src/stream_socket/tcp.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 42 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/sockets/src/control_socket.rs"},"region":{"startLine":23}}}],"partialFingerprints":{"codehealthFindingId/v1":"a22a3ba7aa2a18de238c58f2e65f75a327558105360855ea469e9afdb6e85bb3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): alvr/client_core/src/c_api.rs:166-174 | alvr/server_core/src/c_api.rs:114-122 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_core/src/c_api.rs"},"region":{"startLine":166}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee97e0c8cdfb430cf24f5d76bce82a81172e8e45fb6956cbb90520d6c6d6f55a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): alvr/client_openxr/src/lobby.rs:151-159 | alvr/client_openxr/src/stream.rs:379-387 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/lobby.rs"},"region":{"startLine":151}}}],"partialFingerprints":{"codehealthFindingId/v1":"c84499f923a5c11994258809743bbae0073af14e2854f6761f652be8cd4e4c91"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7\u20139 lines \u00D7 2): alvr/server_openvr/src/tracking.rs:90-96 | alvr/server_openvr/src/tracking.rs:286-294 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_openvr/src/tracking.rs"},"region":{"startLine":90}}}],"partialFingerprints":{"codehealthFindingId/v1":"0e2cf91c0d701818378587f841475483c62f5f2d1c7813f098f546dea4570577"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): alvr/server_core/src/lib.rs:381-387 | alvr/server_core/src/lib.rs:448-454 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/lib.rs"},"region":{"startLine":381}}}],"partialFingerprints":{"codehealthFindingId/v1":"9d0dc0b6dff9d74016e7317e9eab05914a42ed5dcc17081db41e8a07a4647e7d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 4): alvr/server_openvr/src/tracking.rs:228-232 | alvr/server_openvr/src/tracking.rs:234-238 | alvr/server_openvr/src/tracking.rs:240-244 | alvr/server_openvr/src/tracking.rs:246-250 \u2014 all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_openvr/src/tracking.rs"},"region":{"startLine":228}}}],"partialFingerprints":{"codehealthFindingId/v1":"750743c8a364938228870bc05ca6627ecd37539dae7798a7ada571347447b2af"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (4\u20135 lines \u00D7 3): alvr/server_core/src/connection.rs:247-250 | alvr/server_core/src/connection.rs:251-255 | alvr/server_core/src/connection.rs:258-262 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/connection.rs"},"region":{"startLine":247}}}],"partialFingerprints":{"codehealthFindingId/v1":"8116c75d6cf68bd1aa1079054109c45eaffc4a703da9cd1b568a2f21e99f0ca9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): alvr/server_core/src/c_api.rs:473-484 | alvr/server_openvr/src/lib.rs:567-578 \u2014 before extracting anything, compare \u0060alvr/server_core/src/c_api.rs\u0060 and \u0060alvr/server_openvr/src/lib.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 38 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/c_api.rs"},"region":{"startLine":473}}}],"partialFingerprints":{"codehealthFindingId/v1":"1152ae333cb6adbfd334e72ba08f0c06dec69a016fabdf1d71dbbe28ecfa24cb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): alvr/server_core/src/c_api.rs:564-571 | alvr/server_openvr/src/lib.rs:694-701 \u2014 before extracting anything, compare \u0060alvr/server_core/src/c_api.rs\u0060 and \u0060alvr/server_openvr/src/lib.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 38 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/c_api.rs"},"region":{"startLine":564}}}],"partialFingerprints":{"codehealthFindingId/v1":"f148052d120571d28709ba7459e7647cea5bc04a1183dc69d1f684f65a3f9651"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): alvr/server_core/src/c_api.rs:574-581 | alvr/server_openvr/src/lib.rs:704-711 \u2014 before extracting anything, compare \u0060alvr/server_core/src/c_api.rs\u0060 and \u0060alvr/server_openvr/src/lib.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 38 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/c_api.rs"},"region":{"startLine":574}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c47b4e335a5ce78c26bfb64bd5cbc89e9819b2146be83ec972be96767442abc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): alvr/server_core/src/tracking/body.rs:66-78 | alvr/server_core/src/tracking/vmc.rs:94-106 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/tracking/body.rs"},"region":{"startLine":66}}}],"partialFingerprints":{"codehealthFindingId/v1":"a69ce97eee59d36f218600d6c2f9d05c6f795335d731a241e2bf33db6f25917d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): alvr/dashboard/src/dashboard/components/settings_controls/dictionary.rs:174-185 | alvr/dashboard/src/dashboard/components/settings_controls/vector.rs:120-131 \u2014 before extracting anything, compare \u0060alvr/dashboard/src/dashboard/components/settings_controls/dictionary.rs\u0060 and \u0060alvr/dashboard/src/dashboard/components/settings_controls/vector.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 52 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/components/settings_controls/dictionary.rs"},"region":{"startLine":174}}}],"partialFingerprints":{"codehealthFindingId/v1":"81e72d6b28296a6750f3473cdb2ad42576b935e02f82e5688a8c8a0d258fcf3f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): alvr/dashboard/src/steamvr_launcher/mod.rs:57-65 | alvr/dashboard/src/steamvr_launcher/mod.rs:71-79 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/steamvr_launcher/mod.rs"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"9cd84bbb8cfe28d143c99e645ec34cd5fe74e44b7ea6a612669f048ce4895f6b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): alvr/dashboard/src/dashboard/components/settings_controls/optional.rs:46-54 | alvr/dashboard/src/dashboard/components/settings_controls/switch.rs:50-58 \u2014 before extracting anything, compare \u0060alvr/dashboard/src/dashboard/components/settings_controls/optional.rs\u0060 and \u0060alvr/dashboard/src/dashboard/components/settings_controls/switch.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 30 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/components/settings_controls/optional.rs"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"9250d2978d2a7a1ec7a0d32a597ff8e191d96decd1136f202a899e57c492339a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): alvr/client_core/src/connection.rs:579-586 | alvr/server_core/src/connection.rs:1502-1509 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_core/src/connection.rs"},"region":{"startLine":579}}}],"partialFingerprints":{"codehealthFindingId/v1":"09e5e643920428965a49480237f9810705a341e69a4cc4634f9befa77d680a88"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): alvr/launcher/src/actions.rs:152-159 | alvr/launcher/src/actions.rs:166-173 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/launcher/src/actions.rs"},"region":{"startLine":152}}}],"partialFingerprints":{"codehealthFindingId/v1":"2ff55cc7f535ec7824d006461741e28296beb09420bc9bd139a7c327ab07a34f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): alvr/graphics/src/staging.rs:14-21 | alvr/graphics/src/staging.rs:24-31 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/graphics/src/staging.rs"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"739df203decd1a5a5998b8c229ec09a2a96c9f271be1a9fc2cdbd7d7aff48823"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): alvr/dashboard/src/dashboard/components/settings_controls/optional.rs:56-60 | alvr/dashboard/src/dashboard/components/settings_controls/switch.rs:60-64 \u2014 before extracting anything, compare \u0060alvr/dashboard/src/dashboard/components/settings_controls/optional.rs\u0060 and \u0060alvr/dashboard/src/dashboard/components/settings_controls/switch.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 30 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/components/settings_controls/optional.rs"},"region":{"startLine":56}}}],"partialFingerprints":{"codehealthFindingId/v1":"c0df69d3734173da67066bd7df77d934d7bc840fc1316ceb5fc572969bd13530"}},{"ruleId":"D5","level":"warning","message":{"text":"Unstable project alvr_server_core: alvr_server_core has instability 0.90 with 1 dependents."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a797fc3e3d5f4283015af45893423b748b406cb92bc63d866f14bc26c6ec4d41"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: alvr_filesystem: alvr_filesystem: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and depended on by 10 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d451a440b9c7c415cd125b3f1625a59afbdb258a45d496d0515f8335524e1916"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: alvr_common: alvr_common: abstractness 0.18, instability 0.00, distance 0.82 \u2014 the shape a shared-kernel / building-block library has BY DESIGN \u2014 concrete and widely depended-on is what makes it useful, and this dimension does not penalise it (the distance is reported for completeness, not as a defect). Worth a look only if it has grown past one coherent kernel into an everything-bucket."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"dfc6df9288bcac05ae89649b84a440f2e610566899989671f300649fa824e0c8"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: alvr_packets: alvr_packets: abstractness 0.00, instability 0.18, distance 0.82 \u2014 zone of pain \u2014 concrete and depended on by 9 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3396d5fbb961020f266781bc502278163c6d3b757c86844e777cfb692f422ce5"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: alvr_session: alvr_session: abstractness 0.00, instability 0.19, distance 0.81 \u2014 zone of pain \u2014 concrete and depended on by 13 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e2878fbf0aed3552ee39e1a9f6076a8a8ae60ab2d7692a8344d140ea8a8346aa"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: alvr/server_core/src/connection.rs: alvr/server_core/src/connection.rs changed 3 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 87 in alvr_server_core::connection::connection_pipeline at line 555. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-29..2026-09-27, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-29 17:18:47 \u002B00:00\u0027 --until=\u00272026-09-27 17:18:47 \u002B00:00\u0027 --full-history --no-merges -- alvr/server_core/src/connection.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/connection.rs"},"region":{"startLine":555}}}],"partialFingerprints":{"codehealthFindingId/v1":"e2d1961f3270b7cd2e654c1c78d9e155984823819f1f9f0b0b4cefd97eb816a8"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: alvr/server_openvr/src/lib.rs: alvr/server_openvr/src/lib.rs changed 4 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 39 in alvr_server_openvr::spawn_event_loop at line 233. 1 of those changes was a fix/bug commit, and the other 3 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-29..2026-09-27, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-29 17:18:47 \u002B00:00\u0027 --until=\u00272026-09-27 17:18:47 \u002B00:00\u0027 --full-history --no-merges -- alvr/server_openvr/src/lib.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_openvr/src/lib.rs"},"region":{"startLine":233}}}],"partialFingerprints":{"codehealthFindingId/v1":"11f605e36df01f1b8f0f5a07d8af9d8dfa615d5e87473ad0ee2666d1b4071b29"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: alvr/dashboard/src/dashboard/mod.rs: alvr/dashboard/src/dashboard/mod.rs changed 2 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 38 in Dashboard::ui at line 145. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-29..2026-09-27, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-29 17:18:47 \u002B00:00\u0027 --until=\u00272026-09-27 17:18:47 \u002B00:00\u0027 --full-history --no-merges -- alvr/dashboard/src/dashboard/mod.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/mod.rs"},"region":{"startLine":145}}}],"partialFingerprints":{"codehealthFindingId/v1":"5dee70c9b5d114b28570aa3d1cbeedd35b72a34afc0692a055504de77e93f7f7"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #1: If anonymized user #1 becomes unavailable, 10 significant file(s) lose their only recent owner: alvr/dashboard/src/data_sources.rs, alvr/client_core/src/video_decoder/android.rs, alvr/graphics/src/lib.rs, alvr/server_openvr/src/tracking.rs, alvr/sockets/src/lib.rs, alvr/sockets/src/control_socket.rs, alvr/dashboard/src/dashboard/components/settings_controls/section.rs, alvr/server_core/src/logging_backend.rs (\u002B2 more). Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c37a8e7b95919b08e5473aa40af3a3ed33af5d3908aeb67be5facd52c629bd89"}},{"ruleId":"D17","level":"warning","message":{"text":"FixmeComment: // fixme: Opening pavucontrol while audio is actively streaming \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/audio/src/linux.rs"},"region":{"startLine":76}}}],"partialFingerprints":{"codehealthFindingId/v1":"12ec32c5bdd870fe0cbc0f7289603d59488c619cd58260c8d4a25564b13c347c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Would it be more correct to try to split it up over multiple datas? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/audio/src/linux.rs"},"region":{"startLine":330}}}],"partialFingerprints":{"codehealthFindingId/v1":"aa0ffcc4e5cb80de6a060927c51d13f34498c5f1fb2b2d81a42f4f5fd4425634"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: use smarter policy with EventTiming \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/audio/src/lib.rs"},"region":{"startLine":454}}}],"partialFingerprints":{"codehealthFindingId/v1":"f02a3731231375f5b266e8c0761331bc534af225698fb3e267a0586a28f5f519"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: recover data from mismatched Config signature. low priority \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_core/src/storage.rs"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"fd7a3996da2758fe6e4917dea5e1bdd2b2f3d2bdf1e9c259aa7023f6fd393342"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: the client debug groups settings should be moved client side when feasible \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_core/src/logging_backend.rs"},"region":{"startLine":40}}}],"partialFingerprints":{"codehealthFindingId/v1":"524dc474bfa3deda8857e0a9a41eadc00953049b67f121c53fc503f5958f9e97"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Don\u0027t fetch cpal sample rate, get directly from AAudio \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_core/src/connection.rs"},"region":{"startLine":160}}}],"partialFingerprints":{"codehealthFindingId/v1":"1c96072c8a26608ec5454695a4cd3752cc97453f6d965a8d40c92a23b715d0e7"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: limited range fix config \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_core/src/c_api.rs"},"region":{"startLine":726}}}],"partialFingerprints":{"codehealthFindingId/v1":"d6e46795734a0c8bb71daf6833c36e8b650d33288c4c7560474c19bd6ca6822d"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: encoding gamma config \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_core/src/c_api.rs"},"region":{"startLine":727}}}],"partialFingerprints":{"codehealthFindingId/v1":"8411af717c35b9adb0633601cef8b549a330e0254e91c83daf018050d5e9385d"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: support hands \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_core/src/c_api.rs"},"region":{"startLine":732}}}],"partialFingerprints":{"codehealthFindingId/v1":"a235c9333c78c5bd7cc45c3b21435063abbe2ceb066cf1e256ec3c480e3a423c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: add back when implementing proper phase sync \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_core/src/video_decoder/android.rs"},"region":{"startLine":132}}}],"partialFingerprints":{"codehealthFindingId/v1":"0dac2039d126210607975548100f10ec98f99de81499189725008c69e15bf591"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: find out how to use it and avoid leaking the ImageReader \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_core/src/video_decoder/android.rs"},"region":{"startLine":245}}}],"partialFingerprints":{"codehealthFindingId/v1":"b8ef2f442c00f2353699451d6484c94c9f084262506023abd7b1a0a1a11fb9d1"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Find a driver heuristic for the limited range bug instead? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/stream.rs"},"region":{"startLine":195}}}],"partialFingerprints":{"codehealthFindingId/v1":"48bc08d0fd594c93966b82fc9384fbd8b19964b4a7c2ddbaa615219e15385da1"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: add interaction? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/lobby.rs"},"region":{"startLine":11}}}],"partialFingerprints":{"codehealthFindingId/v1":"deaf41e87ca1c9eaf4a7a072c918e11b8e9d10e33c6fa397f31a7f3a6e07f606"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: switch to vulkan \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/lib.rs"},"region":{"startLine":195}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee2f0f8f63e3de6b2aea29689f79599ada7ff2ef78f589505875bfb0b2cbb8b7"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/lib.rs"},"region":{"startLine":471}}}],"partialFingerprints":{"codehealthFindingId/v1":"7dead86da3bc87677ac90ff71c7738e690198aeb8edfcd5a65c4ff3edd857c69"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: allow rendering lobby and stream layers at the same time and add cross fade \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/lib.rs"},"region":{"startLine":608}}}],"partialFingerprints":{"codehealthFindingId/v1":"9d5c79f145dffa50e0e69ddebcb03364c43a542adcac371a15a3f61a49f3449a"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: check Quest 2 \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/interaction.rs"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"0cca39e1bc9a903b5b5c583147f7095d2ca8e504897d04fc1237716889276ccd"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: check (base) Pico 4 \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/interaction.rs"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"cfad357580bb6f00e5aa919579616b93d44a1c364372d77eed5e53d27fde5eda"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: create new controller profile for quest pro and 3 \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/interaction.rs"},"region":{"startLine":220}}}],"partialFingerprints":{"codehealthFindingId/v1":"a006c3dfe64c0915c696f1b706e89c944305f790e8b85b2cdf441f035248ba11"}},{"ruleId":"D17","level":"warning","message":{"text":"HackComment: // HACK: YVR runtime seems to ignore IS_RUNNING_AT_CREATION on versions \u003C= 3.0.1 \u2014 a workaround marked in source: record what it is compensating for and what would allow its removal (the upstream fix, the API it is waiting on, the invariant it restores), so the next reader can judge whether it is still needed rather than rediscovering why it is there."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/extra_extensions/passthrough_fb.rs"},"region":{"startLine":61}}}],"partialFingerprints":{"codehealthFindingId/v1":"1062d7cd2f75f220c927bef31f15c6ac5f19b4f5e5587ac64ed43c21e14f20a3"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: include actual Android package name \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/extra_extensions/body_tracking_bd.rs"},"region":{"startLine":107}}}],"partialFingerprints":{"codehealthFindingId/v1":"08e6f5019754da84b14ac5c0601ee27c6f307c10845af80d45660cfe70970c8b"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Set X-ALVR \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/data_sources_wasm.rs"},"region":{"startLine":37}}}],"partialFingerprints":{"codehealthFindingId/v1":"08f1e12499485ec97634291744cd7e91a6d6291269c3280cd35e804d9684e890"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: find a way to center both vertically and horizontally \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/mod.rs"},"region":{"startLine":199}}}],"partialFingerprints":{"codehealthFindingId/v1":"1784500a18e27a6096f40f00783dec78f3bf44e9b867e812daedff83eb6dac64"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: handle children requests \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/components/settings_controls/presets/higher_order_choice.rs"},"region":{"startLine":137}}}],"partialFingerprints":{"codehealthFindingId/v1":"f39786f495e7202483ff8f5a915ffeffbf2a7d183dea47dc88be743b182d42e9"}},{"ruleId":"D17","level":"warning","message":{"text":"FixmeComment: // fixme: on multi-gpu nvidia system will do it twice, \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/steamvr_launcher/linux_steamvr.rs"},"region":{"startLine":240}}}],"partialFingerprints":{"codehealthFindingId/v1":"6482b022aa96da7f1a156489d92f5ff79b23cc91bf04ca41ee594a3d6927424e"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: probe for AV1 when will be available in nvml-wrapper \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/steamvr_launcher/linux_steamvr.rs"},"region":{"startLine":255}}}],"partialFingerprints":{"codehealthFindingId/v1":"250e4782e168ad395b2daf0bbeb0b2a150cd80e75e444dec84d44dbf950deb6e"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: use a custom widget \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/gui_common/src/basic_components/button_group.rs"},"region":{"startLine":4}}}],"partialFingerprints":{"codehealthFindingId/v1":"87486629ce6973d6f9a994d5d307947ff8c15fbfa15afe26227f6e41eddef6e3"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: use target timestamp in nanoseconds. the dashboard needs to use the first \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/statistics.rs"},"region":{"startLine":265}}}],"partialFingerprints":{"codehealthFindingId/v1":"2a8b4244b1a8af400e68230f80955c9260183443721179952af0c02fd6fa6d74"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: check if this is still needed \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/lib.rs"},"region":{"startLine":598}}}],"partialFingerprints":{"codehealthFindingId/v1":"738bcaba27937bdd43848232da493e79852433b52a5c97953fc8d0927db1a090"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: use get_buffer and make encoder write to socket buffers directly to avoid copy \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/connection.rs"},"region":{"startLine":961}}}],"partialFingerprints":{"codehealthFindingId/v1":"3a28d485ce7f1d4c7ad4a1466f442a82e54fcb50a95e54af40a0b3bcadc8b1f0"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: Move this struct to Settings and use it for every tracked device \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/tracking/mod.rs"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"ad61e15a10b7d93c8e1ce69a0e4feb00a1e7e5428744c57516ecbed4316a7023"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: make this customizable \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/tracking/body.rs"},"region":{"startLine":123}}}],"partialFingerprints":{"codehealthFindingId/v1":"da0b8d8ae8a6becc7104bd96267053369d0bd7b29005ba02a74f33dab3bddcae"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: make this customizable \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/tracking/body.rs"},"region":{"startLine":142}}}],"partialFingerprints":{"codehealthFindingId/v1":"11002bf7381e97cdd5054e7a80a82bd80dc15ca01ef24c6f417c341c1e1a6635"}},{"ruleId":"D17","level":"warning","message":{"text":"FixmeComment: // fixme: the dashboard is doing this wrong because it is holding its own session state. If read and \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_io/src/lib.rs"},"region":{"startLine":66}}}],"partialFingerprints":{"codehealthFindingId/v1":"0ae566197fd067192877c7f6876ce6a4c29e8d457b46ae08f0307f4cf639d9a6"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: fill out more properties for headset and controllers \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_openvr/src/props.rs"},"region":{"startLine":2}}}],"partialFingerprints":{"codehealthFindingId/v1":"f5cd356ab608cdf5c96df113ee4ce7555539f62b07aad23e0e42a48ab09f987c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: add more emulation modes \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_openvr/src/props.rs"},"region":{"startLine":3}}}],"partialFingerprints":{"codehealthFindingId/v1":"31f59b6140bbfc4c651c191d0fa6ed53eda78bd772d113c8b9cd8b425ee0d4c2"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: send different HUD message for shutdown or restart \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_openvr/src/lib.rs"},"region":{"startLine":514}}}],"partialFingerprints":{"codehealthFindingId/v1":"47d1440fbbdd2090c57b5a9e300ffc8b2424ba01c2ec38706e1f44f0bac435fb"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: convert to class when storing a TcpListener \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/sockets/src/lib.rs"},"region":{"startLine":98}}}],"partialFingerprints":{"codehealthFindingId/v1":"cad05905ba5e9160e220c3307b098b431f06722bf5b859105d123aeb932f4ddd"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: find a way to skipping this allocation \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/sockets/src/stream_socket/udp.rs"},"region":{"startLine":173}}}],"partialFingerprints":{"codehealthFindingId/v1":"b21d3d68edc888cb20e81e2ad566778a60f5f51c8fbfdfc1e0571da599265bdb"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Better Android XR heuristic \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/system_info/src/lib.rs"},"region":{"startLine":127}}}],"partialFingerprints":{"codehealthFindingId/v1":"a1a75cdd31e8ca5859b16651a4976e24a1e753af2b0db88d693d9e3ba7e9284a"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: handle case where permission is rejected \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/system_info/src/android.rs"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"f73f28736db686d2b1f2d5c25141311e7433f22b8012058001b748f372d192f4"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: installer \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/xtask/src/packaging.rs"},"region":{"startLine":116}}}],"partialFingerprints":{"codehealthFindingId/v1":"52501e9bc5c2444048c076a86317bc6daeb5eaf4ea8e18e1fe3b280b36ba3147"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: add more lints \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/xtask/src/main.rs"},"region":{"startLine":141}}}],"partialFingerprints":{"codehealthFindingId/v1":"2694abfa92822b442e5a8e8c3e11a529bb69b25e4c9c4bb6293fea7bc865eba3"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found. No recognised ADR directory (\u0060docs/adr/\u0060, \u0060docs/decisions/\u0060, \u0060adr/\u0060, \u0060docs/rfcs/\u0060, an \u0060ADR0001/\u0060 folder, or their siblings) exists anywhere in this tree. What was searched, so you can tell an empty log from a search that missed one: every directory under the tree (build output, dependencies and VCS metadata excepted), for a document that is either any non-index page inside a recognised ADR directory, whatever its name and however deeply nested (\u0060docs/adr/use-postgres.md\u0060, \u0060docs/adr/2024/0001-x.md\u0060); or a file anywhere whose name is ADR-shaped (\u00600001-use-postgres.md\u0060, \u0060adr-012-caching.md\u0060); or, when neither turned anything up, a document carrying the decision-record signature (an \u0022Architecture Decision Record\u0022 heading, or Status / Context / Decision / Consequences as section headings). A decision log that clears none of these \u2014 unnumbered files outside any recognised directory, without those headings \u2014 is not seen by this check and this row is then wrong. If that is your case, say so rather than renaming anything; otherwise, consider recording architectural decisions in \u0060docs/adr/\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D22","level":"warning","message":{"text":"Inconsistent naming convention for C API conversions. Most pairs use \u0027to_capi_\u0027 and \u0027from_capi_\u0027 prefixes, but the module itself is named \u0027c_api\u0027. While this is internally consistent within the module, it differs from common Rust FFI patterns (e.g., \u0027into_*\u0027/\u0027from_*\u0027 or \u0027to_*\u0027/\u0027from_*\u0027) and creates a slight cognitive load compared to standard library conventions. More critically, the existence of both \u0060AlvrFov\u0060 (C API) and \u0060Fov\u0060 (Primitives) with identical structures suggests a lack of a unified type system for cross-boundary data, forcing manual conversion functions for every primitive type.: Consider using a macro or code generation to ensure strict symmetry in naming (e.g., \u0060into_capi\u0060/\u0060from_capi\u0060 or \u0060to_c\u0060/\u0060from_c\u0060). Alternatively, if the C API types are just wrappers, consider implementing \u0060From\u0060/\u0060Into\u0060 traits to allow idiomatic Rust conversions rather than explicit function calls, reducing API surface clutter. (signatures: alvr_common.c_api.to_capi_fov(fov: Fov): AlvrFov | alvr_common.c_api.from_capi_fov(fov: AlvrFov): Fov | alvr_common.c_api.to_capi_quat(quat: Quat): AlvrQuat | alvr_common.c_api.from_capi_quat(quat: AlvrQuat): Quat | alvr_common.c_api.to_capi_pose(pose: Pose): AlvrPose | alvr_common.c_api.from_capi_pose(pose: AlvrPose): Pose | alvr_common.c_api.to_capi_view_params(view_params: ViewParams): AlvrViewParams | alvr_common.c_api.from_capi_view_params(view_params: AlvrViewParams): ViewParams)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"436797514b75fbd82ce9fdd116434111c343b07bbf618699526bbc18062b1817"}},{"ruleId":"D22","level":"warning","message":{"text":"Redundant and confusingly named logging/error reporting functions. \u0060show_warn\u0060 and \u0060show_err\u0060 both take a \u0060Result\u0060 and return \u0060T\u0060, implying they unwrap and log. \u0060show_e\u0060 and \u0060show_e_dbg\u0060 take an error type \u0060E\u0060. The distinction between \u0060show_e\u0060 and \u0060show_e_dbg\u0060 is unclear without documentation (is it debug-only? does it include backtrace?). Similarly, the distinction between \u0060show_err\u0060 and \u0060show_e\u0060 is ambiguous: does one handle \u0060Result\u0060 and the other raw errors? If so, why not name them \u0060log_result\u0060 and \u0060log_error\u0060? The presence of \u0060_blocking\u0060 variants suggests async context, but the non-blocking variants don\u0027t specify their execution context clearly.: Unify error logging into a consistent set: \u0060log_error(Result)\u0060, \u0060log_warning(Result)\u0060, \u0060log_error_raw(Error)\u0060. Remove \u0060show_e_dbg\u0060 unless it serves a distinct, well-documented purpose (e.g., verbose backtrace). Rename \u0060show_*\u0060 to \u0060log_*\u0060 for clarity. (signatures: alvr_common.logging.show_warn(res: Result): T | alvr_common.logging.show_e(e: E) | alvr_common.logging.show_e_dbg(e: E) | alvr_common.logging.show_e_blocking(e: E) | alvr_common.logging.show_err(res: Result): T | alvr_common.logging.show_err_blocking(res: Result): T)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"8d51aefbc9a3ea897913a9c38283135782cd0c6775630de9a47c7f085d7ecb3d"}},{"ruleId":"D22","level":"warning","message":{"text":"Duplicate intent between \u0060VideoStreamingCapabilities\u0060 and \u0060ClientCapabilities\u0060. Both types contain nearly identical properties: \u0060default_view_resolution\u0060, \u0060max_view_resolution\u0060, \u0060refresh_rates\u0060, \u0060foveated_encoding\u0060, \u0060encoder_high_profile\u0060, \u0060encoder_10_bits\u0060, \u0060encoder_av1\u0060, \u0060prefer_10bit\u0060, \u0060preferred_encoding_gamma\u0060, \u0060prefer_hdr\u0060. \u0060VideoStreamingCapabilities\u0060 is used in network packets, while \u0060ClientCapabilities\u0060 is used in the core client context. This duplication increases maintenance burden and risk of desync.: Create a single \u0060StreamingCapabilities\u0060 struct that is used internally by \u0060ClientCapabilities\u0060 and serialized/deserialized for \u0060VideoStreamingCapabilities\u0060 in the packet layer. Use \u0060#[serde]\u0060 or similar attributes to handle the network representation if needed, or keep a thin wrapper if the C API requires it, but avoid maintaining two separate structs with identical fields. (signatures: alvr_packets.VideoStreamingCapabilities | alvr_client_core.ClientCapabilities)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"8cc5da9d36b3b8aa6d6b6849f630c3ee08b2ded183e7bfe4877d147ddd98a250"}},{"ruleId":"D22","level":"warning","message":{"text":"Three different types represent the same negotiated streaming configuration. \u0060ClientNegotiatedStreamingConfig\u0060 is in packets, \u0060ServerNegotiatedStreamingConfig\u0060 is in server core, and \u0060AlvrNegotiatedConfig\u0060 is in the server C API. They share fields like \u0060view_resolution\u0060, \u0060refresh_rate\u0060, \u0060foveated_encoding\u0060, \u0060codec\u0060, etc. This tripartite duplication is a significant consistency issue.: Define a single \u0060NegotiatedStreamingConfig\u0060 type in a shared module (e.g., \u0060alvr_common\u0060 or \u0060alvr_packets\u0060). Derive or implement conversions to/from the C API type (\u0060AlvrNegotiatedConfig\u0060) and use the same type in the server core, possibly with a thin wrapper if server-specific logic is needed, but avoid duplicating the data structure. (signatures: alvr_packets.ClientNegotiatedStreamingConfig | alvr_server_core.ServerNegotiatedStreamingConfig | alvr_server_core.c_api.AlvrNegotiatedConfig)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3534681717fe96b30fbe19ce2db7eebebb720f4988a7796a8f14e2052353d087"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d5b8f11381d61a58459ffc7c595fd52d09c03c711894a63a9578043d2338412b"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1f3e3a96386d3cf2a09fa1b2ee086568b14149ffbb176c4b92b8ecf6af2fa512"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f017a5b412a3b50a1a1f3f4aa23d0b9b9dc462c33770fbce7f4027f0af623ef8"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e10dd1c37af22b497f72f89b2c46e91ef5c8fc9d8d3b51a11f187eb59b3d5d0b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a378eb575e3f20eca26f26f9af5fcfc839b4b37f9977c04073aa58942c61cd4f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"15ad88b38fff2e6e26a2e5c51db46b5d95f5a0ab9ae8764a426454804472d49b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9413d177ee3dfb094dc7ceb596e3a2705c4a851450d2130bbb4a0076070eb76d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e94a71402fb043503fefb1c4b58f8f88aa79c3ffe1f9f14604b914b193a36a8d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1f4038f9c29318e4cabfcfe5282a24e2b2a58c8cdd0709749bf69fc3092cd1a8"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8bab30bfa518829199ac30a51d228ff31fc51c7eb6a052fbe9d706140404f500"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"afc717790c56c5174a490483330807de3c21e4f0e762bef067d31e871bf9c6ab"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9cfa2e2b1d3dae82fc2b836f41760279dfe2491292041f8faf65dfa664abbd68"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"045562b35b2b2c227e5b0cdf3d286d2cf31f63072d8abf407d04a8619cd89e10"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6f609823f2c49c06e7f6547a010884c8d7052ca435362686845f11307313cdf8"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e298513553d5073f69a57d895847436260a2ac788ea83efab0321b79bdccb18a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f76570c69b95f93c87adfd2262e64ea6126831a8d82aeb1638e7c4cd67be9e6f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9cd22d1bd020b7cc28ecbcc930a29750814f0cbc5e476e7ee79311280a239b16"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"82a1d3520505a9453717e5ff1a0a78888be7e9ac8872aab2c122fb5ad85f7407"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cade8f36a37b9fcffcbe6aa6fe8ebe4d2b97bf0e97ce9520a5385bd2059e6e89"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1a16047de4bda85a2a3405317d207d0f41cc9878c50a9de2ef33ab42e8d7bad2"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"95875570e513e6a7fb5a2ff5965abffe0c34cd5d992e75273727a3f250415bcc"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"be5c381aa5d9ddb9e3af7a45865c3244f813717e889735b83a81a815cf867ae1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3c60416023ee11ff9e6ca4bb26321314282ecbf4604294eca963032dadaa2226"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"14d9cba49ad83efdf9cb7d4e21d32cb7c83295f6a6b30c44cc773a40154e0748"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4e0c8c5edbc266c136235b7b0441c4d25e82d4dcd050bd62a98b6125186ab636"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b5d821466fc9e712dcb84dbe9331f3a677303f781c6769ab1b9377b61a873a56"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"07bb0918b3193d108003660307af24c6244df9d1ff9e48d558182419680d8d5f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c19f7cacc92a80dafa889e39daa2f847112a2b520fceee2d5b374adafabbeef1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"364700d17e88d794efa35fa53b12121df0f54f5a134faed419bc129e0373bc0f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4fdcad890126fa48ba89a957e7fbc3ac798e80a914b33f4225f82d0fe7db9e7f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"65f942e0c9890fe4868e27c65c2bbd68fbed1677e3dcd977afe2f2a83daa6fb6"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9e8b4d4b646f533a605c295211ed01fc2f37cfe74c7fd773dafa7b7af37585a2"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3f606d1961767708a3269baf9becc29beb0188838dd5c35a5cbfdd41a9cc65dd"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5bbc2c222284890669e1d1d1cef9718c718c1ab559e26a95491e77d56c5c828a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"465f848e7b2a781c5a49f8f66966330526f09f54b0996c38b52ad1fdafbcceda"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"19ef7b650553ba6d686e0a71f723dc8898d01b3694ef36fa2a0f4063498b63ad"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d0f26c1f43d1897a29cdde427abbf72a51f3d350613d788d2abbfe0b20dc5c62"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e58a9e9a7ea1e6c3cf6985289dac08c6b37b91bfd8c15612e773688f8832b42b"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cbfc04b46dae0e7cd89976366e963ce74ec1af2fd90171c6211ed329373f4090"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9481aa6fa9c771abe710386454bf8cddd592050be0e0830e9d491b6db7f9a1f9"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bf2a06228a1134b4aa651acc0eb8521cc00ceffec89513935a4dfbbcdf41da6b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8feb12b1d093b2e84f565be6fe7cb840ff9371897e5f647e3eb022788791808b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"48d31e7879c008a01b62e44ff588a2785387685c6e85607344a60963a6e97f35"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9547ffe1fe450c6c27db818620d208444635fcb2b5e8020d78e0fe53a6e209e3"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4445dfbc2eef6be992d39b3dcc05c4bae1e7837cce35c1fd48aef885756ad3e3"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c123c72c0fbc39f5282835e6faac93c33224b1902a119d3772d8a5e2482a5067"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"89bb37b903bc30f61450a2205ec954e925681e960fc56e28dec9f39c9a5a6c25"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8e00e450452881ebfaecef0bdb6d6b4c2ca698802973930f77cbf8e905b2d285"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2b5691c5accf6d37ec58f3a779b6eeefb501fd2515c95e807c88911c6c2f87cc"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d131c32785c6d67895c6817bf9921917ceefb33faf83aef2f41038eb6e979d92"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4e366510d6d4c0ee60f02f4cb1a5aa6408a3a26dacc96182979c6e8916767a11"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d87b9e75e58350e492085394095417f7290985987c6a415f6f6b8de6de104925"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dd8c2b9a880923d4dec86420d863f6e81bf7657c845ceb51cea60fbb9d4a444f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"90b14e7f1153c67bdbeec0077e47032ef4de28e18164b38b7196e70eed379390"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7fffff1ce743d7646d8da73475ea15e203c81415c7b61b11dfb2a931e1a9bdde"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c6bf1153c56f871e455b3a39a0fdf706321d42d9ceb27e7733f3ff2cc2d3b8cc"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f58a6e4f064d10870bbd402f1a2af426694e3f3f0320902403f1a2732834aad1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f4ccd75b8478d9d2c94a6dabf443de6f09646d38782cb43c2c8fbcb40351f510"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d4981f68fe540436477e77168973db3f13f5b14a8c729c2d03f0e7de924535c0"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3577b5d460a45f2f85a34c317d2bbdc39946750e4d239c3a196c4aa170cf5403"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d60333c88b4631ae11bcb052c8b5cb98939b28cf028014d1251b9a66f227dda1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c4b1f594fb5963a033fd7314b17fd74df9a452feab4c60f17fca3b3b0b585cf5"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"80c19e0e2114d3939b325d084adfe644f297cce1094257bb6740756115cfada6"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b45720d22f4ebd6baa41095ee35c99cd00cff8ea604036e40bd5a63d92cd3639"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e8ee1e8daefe053a47a746e18a42131c85c0e592eaf8aabe28d904fddcb74a65"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8ff3afadf609a6755c1181240e03a3a424d96e89c4dc7c0e39ed489787162736"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ab8d83539c5ebe567cb6deae98d392d6617f9ea4001a34a9a21fb3f393c0be8f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"615717f8ef63fa5b551fb3286c068a0de1c1fbfe28346737d25e0ad6543ec7dc"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"962998aaa62e87a0a2f2e4ac39cf66241755e58c196b709404bfc5a5216c059b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3715dcc9123cdf97f6e2fcd2c4869fd88e7fc43ce8397594255c49f0d3cf1c44"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bc6c3511c8c7931b3942994470fd91935810288e80073b17cb8b1ce01cfd42cb"},"taxa":[{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2a0a54a489f9875c6090e9c5f7733e622c1cbe5c3c6e03ffd1dd2486eac16fc1"},"taxa":[{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b5308f9ed219ff7d361ed2b01ab7b5fa7a33b0013fcd35575e7068ccda1d2997"},"properties":{"dependency":{"package":"quinn-proto","version":"0.11.14","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","RUSTSEC-2026-0185"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0d3d2c2346bccaaa14c1bd0f0713c18ae4de849fffdc7282dbd533ab105c9398"},"properties":{"dependency":{"package":"rustls-webpki","version":"0.103.12","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","RUSTSEC-2026-0104"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5922a5beeab5ac077ffb485a783ad545036e79b56239f83da38f3fb84336b113"},"properties":{"dependency":{"package":"paste","version":"1.0.15","advisory":"RUSTSEC-2024-0436","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4975822701b3b96654c82dada9bad969e348a6adefa52cd3bba1b6cfd71c3bb7"},"properties":{"dependency":{"package":"bincode","version":"2.0.1","advisory":"RUSTSEC-2025-0141","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d469c4cdd0b2892278c4ee90c01a5a8ea4872a98733c483777e04c904cfebdfc"},"properties":{"dependency":{"package":"proc-macro-error2","version":"2.0.1","advisory":"RUSTSEC-2026-0173","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c356dafc2d2f879539349393edf47ceccc3e0771bf15e4dae816abd8594fd25c"},"properties":{"dependency":{"package":"ttf-parser","version":"0.25.1","advisory":"RUSTSEC-2026-0192","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d44a25813d8a9e18eb42fa5350a972c298292d454155c6472f091bfb670363df"},"properties":{"dependency":{"package":"rand","version":"0.8.5","advisory":"RUSTSEC-2026-0097","aliases":["[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bf9b3890cba73cd3c5d5270d1976bd1bae94596a1c510482b94fe9367ef871f2"},"properties":{"dependency":{"package":"memmap2","version":"0.9.10","advisory":"RUSTSEC-2026-0186","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1092cdc16bab90e26caa98781415518f2a1a0fec9b43d183894264e01dcc42b6"},"properties":{"dependency":{"package":"event-listener","version":"5.4.1","advisory":"RUSTSEC-2026-0221","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0b4d0bd0ea0d3a81846d91c999f1c98d63806893d9b8b2fd8c703eaa81f667a7"},"properties":{"dependency":{"package":"tar","version":"0.4.45","advisory":"[GHSA redacted]","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3093639787a794980e2927a83517926c30608d2452afa7632226b2c9805b8e34"},"properties":{"dependency":{"package":"quick-xml","version":"0.38.4","advisory":"RUSTSEC-2026-0194","aliases":["RUSTSEC-2026-0195"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"266685ae11a36fdae3438af4583cee48422bb524f9f9ae1a449b1d0f440d48f5"},"properties":{"dependency":{"package":"quick-xml","version":"0.39.2","advisory":"RUSTSEC-2026-0194","aliases":["RUSTSEC-2026-0195"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1be0220e1fa221ea274d30abdd6b4e473172e558c80e87aecee355dd31489ca8"},"properties":{"dependency":{"package":"webbrowser","version":"1.2.0","advisory":"RUSTSEC-2026-0257","aliases":["[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"80b5c22beae306eb623d7a60ec13361ab89285e1cc30fcf5b8daa2e87ffb5c69"},"properties":{"dependency":{"package":"h2","version":"0.4.13","advisory":"RUSTSEC-2026-0258","aliases":["[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3035e85b1a9c0c33df37dc333f490439b3fa52aefda24a401e2e75a177cdf778"},"properties":{"dependency":{"package":"rustls","version":"0.23.38","advisory":"RUSTSEC-2026-0285","aliases":["[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5157dc89321fb6e243cd26ba6a01a507aae9232dc8eb1781bedb36ebbdb4383d"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5fd0e8230e98fc0de7b5df1b84061fce9ab3e9fe724022333b22096211524f91"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7602aabc992cd26af3a38c3d949e0bc59bb23024ea7ca03828f4b685f5f795ee"},"taxa":[{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2c2e68719e425f4fc727ec65f629e7833febccfab76d6b278a369f83f149c033"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"41a575b8af36c35f84ceabef7e29a69d46e9c5f10bba92e21d395467a98a9598"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b8ac44333df47230c05886841919db7981cb9281c42fc32991e98c1cb0f7f635"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b87e46892d760f33bc96813831ebdc270a13144be4ded6b2d10b22a088860df3"},"taxa":[{"id":"CWE-345","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f4e8657e362c26d7744c15f4375f6cb2abf041e884eb609584b9dc675082811f"},"taxa":[{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d0ffb1679b2eba23fc750e704045461c0ca2dc88f2b1c71bde584dfd3012ef46"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f9d0613df6b942472c47f286f1555bc1d4173da1faefe53fe1b869edb4f25ea9"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3e165773e33ceb0df5907893cbd718299437cf47c1fadc5c4d682cb3f5a90311"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0edf66bc9a57e9af822553591d1029f5d996d2a7e46f4170a36fd62ee3c5d50e"}},{"ruleId":"D34","level":"note","message":{"text":"Orphaned files with no living knowledge: 3 of 98 analysed file(s) have no living knowledge left \u2014 their last meaningful change has decayed away, so if one breaks, no one currently understands it (counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 98 of the 142 production source files in this repository met that bar). None is large enough to earn a read-through of its own, so this row stands in for the per-file rows rather than raising one each \u2014 most significant first: alvr/server_core/src/tracking/vmc.rs, alvr/client_openxr/src/extra_extensions/motion_tracking_bd.rs, alvr/xtask/src/ci.rs. Attach the read to the next change that touches one of them: have a second person review that change, and leave behind a short comment or test recording what the file is for, so the knowledge comes back at the cost of a change you were making anyway."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ce861fd78f6935114d3a342cb90ad25870f984e1042954fcbbe27c0e23be3658"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: lobby.rs \u2194 stream.rs: \u0060alvr/client_openxr/src/lobby.rs\u0060 and \u0060alvr/client_openxr/src/stream.rs\u0060 change together 82% of the time (23 of the 28 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking. You can check this without leaving the row: of the 23 shared commits counted here, the most recent 3 are \u006032df9c70\u0060 Miscellaneous changes (#3270); \u0060a211badd\u0060 refactor: :rotating_light: Fix Rust v1.89 lints (#2972); \u00608c0a8155\u0060 Protocol cleanup (6) (#2912) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/lobby.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"5f99043e0ed3094b6ee5989da992480703369fecbcadac6ffce03a479f2f1621"}},{"ruleId":"D35","level":"warning","message":{"text":"Change-coupling hub: c_api.rs \u2192 main.rs, graphics.rs, lobby.rs, stream.rs: \u0060alvr/client_core/src/c_api.rs\u0060 changes together with 4 other files \u2014 \u0060alvr/client_mock/src/main.rs\u0060, \u0060alvr/client_openxr/src/graphics.rs\u0060, \u0060alvr/client_openxr/src/lobby.rs\u0060, \u0060alvr/client_openxr/src/stream.rs\u0060 \u2014 none of which declares a dependency on it: one file is the hub of 4 separate couplings, not 4 unrelated pairs. Read the hub first: if the others each duplicate a part of what it does, the shared concern belongs in ONE unit and extracting it clears every edge at once; if the hub is a registry, dispatcher or barrel that must name each of them, the coupling is structural and the question is whether that list can be discovered instead of enumerated. Fixing the hub is one change; breaking the couplings one pair at a time is 4."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_core/src/c_api.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"88d89061b5f3e6335799f6d8893424ff3d599330d5b5a66e1a0beee4314cf169"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: input_mapping.rs \u2194 props.rs: \u0060alvr/server_core/src/input_mapping.rs\u0060 and \u0060alvr/server_openvr/src/props.rs\u0060 change together 64% of the time (9 of the 14 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 9 shared commits counted here, the most recent 3 are \u0060669b5411\u0060 feat: Add PSVR2 Sense controller emulation (#2871); \u00604dd68f03\u0060 Add Quest 1 emulation options (#3024); \u0060097dd207\u0060 feat: Pico 4 controller emulation (#2724) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/input_mapping.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"57a2fa539bc89e306ba1d5183ac64ef857b728b19cb89438f91f7cbae25d9d2b"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: connection.rs \u2194 props.rs: \u0060alvr/server_core/src/connection.rs\u0060 and \u0060alvr/server_openvr/src/props.rs\u0060 change together 64% of the time (14 of the 22 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 14 shared commits counted here, the most recent 3 are \u0060669b5411\u0060 feat: Add PSVR2 Sense controller emulation (#2871); \u00604dd68f03\u0060 Add Quest 1 emulation options (#3024); \u0060097dd207\u0060 feat: Pico 4 controller emulation (#2724) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/connection.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"5a62e22f8529df0ceecee601f23042e4efd915c04319ddf088b35666953ef448"}},{"ruleId":"D35","level":"warning","message":{"text":"Change-coupling hub: connection.rs \u2192 mod.rs, main.rs, udp.rs: \u0060alvr/client_core/src/connection.rs\u0060 changes together with 3 other files \u2014 \u0060alvr/client_core/src/video_decoder/mod.rs\u0060, \u0060alvr/client_mock/src/main.rs\u0060, \u0060alvr/sockets/src/stream_socket/udp.rs\u0060 \u2014 none of which declares a dependency on it: one file is the hub of 3 separate couplings, not 3 unrelated pairs. Read the hub first: if the others each duplicate a part of what it does, the shared concern belongs in ONE unit and extracting it clears every edge at once; if the hub is a registry, dispatcher or barrel that must name each of them, the coupling is structural and the question is whether that list can be discovered instead of enumerated. Fixing the hub is one change; breaking the couplings one pair at a time is 3."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_core/src/connection.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"812a3671121cb9338a15a54349b3de0104d60ab4450ec94c3dea0cd6b8c76a52"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: builtin_schema.rs \u2194 settings.rs: \u0060alvr/dashboard/src/dashboard/components/settings_controls/presets/builtin_schema.rs\u0060 and \u0060alvr/session/src/settings.rs\u0060 change together 59% of the time (13 of the 22 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 13 shared commits counted here, the most recent 3 are \u0060ca2decae\u0060 feat(foveation): support runtime per-eye centers (#3385); \u0060a6af8c2d\u0060 First set of UI tweaks (#3002); \u0060971c1aeb\u0060 fix(dashboard): UIX Improvements to dashboard settings (#2840) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/dashboard/src/dashboard/components/settings_controls/presets/builtin_schema.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b5143a95c73c20653d58c968fd175b1ae5c23f8b631d6abdade8e17ba54dd51e"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: stream.rs \u2194 lobby.rs: \u0060alvr/client_openxr/src/stream.rs\u0060 and \u0060alvr/graphics/src/lobby.rs\u0060 change together 54% of the time (13 of the 24 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 13 shared commits counted here, the most recent 3 are \u006032df9c70\u0060 Miscellaneous changes (#3270); \u00609fee606d\u0060 feat: :sparkles: Send detached controller inputs to the server (#3049); \u00608c0a8155\u0060 Protocol cleanup (6) (#2912) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/stream.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ddab7b0014dd9313711a8ee48a3829410596dddad631334e6e1b1c252a9227f4"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: main.rs \u2194 lib.rs: \u0060alvr/client_mock/src/main.rs\u0060 and \u0060alvr/client_openxr/src/lib.rs\u0060 change together 50% of the time (15 of the 30 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 15 shared commits counted here, the most recent 3 are \u00608c4c483a\u0060 fix(android): batch startup permission requests (#3400); \u0060750b73ce\u0060 refactor: \u2B06\uFE0F Update dependencies (#3243); \u00603eefb9ce\u0060 feat: Refactoring around Platform (#3069) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_mock/src/main.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d4aeb1b16092c58fdb7497901694ba02af2e1a986df4d510e37043146dc65897"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: interaction.rs \u2194 face.rs: \u0060alvr/client_openxr/src/interaction.rs\u0060 and \u0060alvr/server_core/src/tracking/face.rs\u0060 change together 50% of the time (6 of the 12 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 6 shared commits counted here, the most recent 3 are \u00604e08e0ee\u0060 Protocol cleanup (5) (#2907); \u006036d7046a\u0060 refactor: Remove Pico audio visemes (#2765); \u006092c82f79\u0060 feat: Add support for Pico headsets face tracking (#2666) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/client_openxr/src/interaction.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"7a3a0f30f174fd4359f16c85eeb3ca16fa55cc8265aea887ae310aedfef523ba"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: connection.rs \u2194 hand_gestures.rs: \u0060alvr/server_core/src/connection.rs\u0060 and \u0060alvr/server_core/src/hand_gestures.rs\u0060 change together 50% of the time (5 of the 10 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking. You can check this without leaving the row: of the 5 shared commits counted here, the most recent 3 are \u006031e0d932\u0060 Support separate OpenVR hand trackers for VRChat (#2295); \u00602a159fd2\u0060 feat(server): :sparkles: Expose all tracked devices through events; r\u2026 (at that commit the files were still \u0060alvr/server/src/connection.rs\u0060 and \u0060alvr/server/src/hand_gestures.rs\u0060); \u0060b923da37\u0060 feat(server): :sparkles: Add \u0060only touch\u0060 option; refactoring (at that commit the files were still \u0060alvr/server/src/connection.rs\u0060 and \u0060alvr/server/src/hand_gestures.rs\u0060) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/server_core/src/connection.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"4fbb8834ae93855ec06460e9ff21fe71d0d69ced778819e12b5d91d8186ec4c6"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1b213f6eedd4b140d0bc37bdf1496f72811a643f34064f12518b32e9e83bcfc7"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eb00976a698a5d68999b7ee6d27206fd374e916853e7ff1ead5eed42386f043f"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"90f83b4fa27db32740afe9540c905f3c0499caed87f61049a8a903ecc95b41c3"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9658270ba49f37ed04e99ab1263b6393cd42aed8bdfb7aafd9fa1070f5491895"}},{"ruleId":"D44","level":"warning","message":{"text":"End-of-life runtime: Rust 1.97: rust-toolchain.toml declares Rust 1.97 as this project\u0027s toolchain file, and Rust 1.97, superseded by 1.98 on 2026-08-20 (the Rust project patches only the current stable). An unsupported runtime receives no security patches, so every vulnerability disclosed in it since 2026-08-20 is present and unfixable without moving off it. This is a migration rather than an upgrade: there is no newer release of a runtime that has ended."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"dcf7e9d4c69a9ce8ce9aef71946a22fd4bc9a108d597e8635468e94e0aa93368"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"M2","level":"note","message":{"text":"No architecture diagram/doc: No C4/Structurizr/PlantUML/Mermaid/Graphviz/D2 diagram, no drawn diagram named for the architecture, no file named \u0060architecture\u0060 or \u0060design\u0060 in any markup this check reads, and nothing in the README, docs or contributor guides that announces the shape \u2014 no \u0060## Architecture\u0060 heading, no \u0022architecture overview\u0022/\u0022high-level design\u0022 phrasing, no \u0022the architecture is \u2026\u0022 introduction, no guided code tour. A shape laid out in prose that never names itself as the architecture is not visible to this check, and neither is one kept outside the repository, so this row reports the absence of a re-findable shape document \u2014 not evidence that nobody wrote the shape down."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0c190e7c159d1850ee706c3ac4486e151e8a4fe169de4bf61436b9f399654f06"}},{"ruleId":"P2","level":"note","message":{"text":"Logging is not universal: Only 14/17 runnable modules use logging (modules with no entry point or server are excluded \u2014 they are libraries a runnable module hosts). Silent: \u0060alvr/launcher\u0060, \u0060alvr/vrcompositor_wrapper\u0060, \u0060alvr/xtask\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"91a94e21d6d4d0e6a2003f94505b0b02b157176f0b24c4820f3f82b4447a97fe"}},{"ruleId":"P7","level":"warning","message":{"text":"Outbound HTTP without resilience: \u0060reqwest::Client::builder(\u0060 makes an outbound HTTP call, and nothing bounds it: no timeout, deadline, retry or circuit breaker is set for it here, and the client has no process-wide default. A slow or failing dependency will hold this service\u0027s request, thread or connection until the call gives up on its own \u2014 or never, for a client with no default timeout."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"alvr/launcher/src/actions.rs"},"region":{"startLine":30}}}],"partialFingerprints":{"codehealthFindingId/v1":"a14835539fc405655e8faea6240a991f45da6bd07d899b532625d8961862e10e"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-345","guid":"d80d4b65-bbbe-b65d-958e-7ac466af18f9","name":"CWE-345","shortDescription":{"text":"CWE-345"},"helpUri":"https://cwe.mitre.org/data/definitions/345.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-522","guid":"71fb233e-ce6a-ae57-9419-ef8373540b09","name":"CWE-522","shortDescription":{"text":"CWE-522"},"helpUri":"https://cwe.mitre.org/data/definitions/522.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-829","guid":"13c33925-97fb-5a5e-b40c-56d328b8a4d7","name":"CWE-829","shortDescription":{"text":"CWE-829"},"helpUri":"https://cwe.mitre.org/data/definitions/829.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":103,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}