{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"AC3","name":"Page structure","shortDescription":{"text":"Page structure"},"helpUri":"https://codehealth.canine.dev/dimensions/AC3"},{"id":"AC6","name":"Visual \u0026 motion safety","shortDescription":{"text":"Visual \u0026 motion safety"},"helpUri":"https://codehealth.canine.dev/dimensions/AC6"},{"id":"AC7","name":"A11y enforcement","shortDescription":{"text":"A11y enforcement"},"helpUri":"https://codehealth.canine.dev/dimensions/AC7"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"DM12","name":"Ambient inputs in the domain","shortDescription":{"text":"Ambient inputs in the domain"},"helpUri":"https://codehealth.canine.dev/dimensions/DM12"},{"id":"DM6","name":"Domain \u2194 infrastructure boundary","shortDescription":{"text":"Domain \u2194 infrastructure boundary"},"helpUri":"https://codehealth.canine.dev/dimensions/DM6"},{"id":"DM8","name":"Value-object opportunities","shortDescription":{"text":"Value-object opportunities"},"helpUri":"https://codehealth.canine.dev/dimensions/DM8"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P5","name":"DR \u0026 Backup","shortDescription":{"text":"DR \u0026 Backup"},"helpUri":"https://codehealth.canine.dev/dimensions/P5"},{"id":"R1","name":"Type Safety","shortDescription":{"text":"Type Safety"},"helpUri":"https://codehealth.canine.dev/dimensions/R1"},{"id":"R10","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/R10"},{"id":"R2","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/R2"},{"id":"R3","name":"Large Files","shortDescription":{"text":"Large Files"},"helpUri":"https://codehealth.canine.dev/dimensions/R3"},{"id":"R4","name":"Test Coverage","shortDescription":{"text":"Test Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/R4"},{"id":"R6","name":"Tooling","shortDescription":{"text":"Tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/R6"},{"id":"R7","name":"Dead Code","shortDescription":{"text":"Dead Code"},"helpUri":"https://codehealth.canine.dev/dimensions/R7"},{"id":"R8","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/R8"},{"id":"R9","name":"Circular Imports","shortDescription":{"text":"Circular Imports"},"helpUri":"https://codehealth.canine.dev/dimensions/R9"},{"id":"SC1","name":"Supply-chain hygiene","shortDescription":{"text":"Supply-chain hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/SC1"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D8","level":"error","message":{"text":"No automated tests: No automated tests \u2014 no test code was found in this repository. Untested code is the largest single risk to changing it safely. Start with the code you change most often: add a suite in a framework a runner can collect (ScalaTest, MUnit or specs2), and run it in CI so the gap cannot reopen."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3132564c6310e5d01a231f252a02d5d2f5a542c0a8fa29a14c89693f1e3df871"}},{"ruleId":"D9","level":"note","message":{"text":"No tests found: No test suite could be collected \u2014 no discoverable tests to count. If this repository does test, wiring the suite to a framework a runner can collect (ScalaTest, MUnit or specs2) is what makes it countable here; a pipeline step that invokes a runner is not evidence on its own, because a runner over an empty suite passes. Tests written as plain executables or shell/PowerShell harnesses are not collectible this way and are not scored here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c9bf64cbb5a4ae13d6bcd01fa3bc8d2879d860c73bc67f176ee3c2cecb8adce3"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no installation or build instructions: The README describes running the project locally via Docker Compose and host setup, but there are no build/run commands for sbt assembly or any mention of how to get started from an empty repo. Add a one-line \u0027To run this POC locally\u0027 line pointing at sbt assembly and docker-compose up."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1fa6bfcd5c6ae231d1b8ee99bced50b832d1f61cde9da6cbb533467b879a57db"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no usage examples: The README shows the command handler, list projector, and web server running but gives no usage examples of querying or consuming events. Add a short \u0027How to query the event store\u0027 example showing an event-sourcing query."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1355eb4e127a4bc9236772ce1c46f09510aa9286e7a06d1e47f308229df19049"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no licence statement: The license is present in the footer (MIT) but not documented as a separate License section, which is standard practice. Move the license to its own dedicated License file or add it to the README under a \u0027License\u0027 heading."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"bc71d4465cafafc3df7a1b646a8cd5f9a306761b307dc199a6de8c1c35d8b21d"}},{"ruleId":"D30","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"83624e2a75b102d656da943ab10c203006d969612030d1669428c03d4067940e"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"58ba4d54a89f06bfd2b324741c6f930ac3e2094cbdad835695985e22cd951589"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"93da3b991fc1bcd6e501d1db83af4a936b0d5a84aaa1ec186eaf096c56a89726"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"65ee0319d18ed52d461f82f8557e3e4773f586ea30379512b0fd35ccef016ca7"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ab92a1628cd1667b980737ded7ccc3626ac57a21801920a558f6441bf7c0c5af"},"taxa":[{"id":"CWE-250","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-668","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c5771140cad32a54d4e2f97361ec8556c54a818639f00e1d895db392dc669b0e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e1651824ab8b742df51e3f7f819dbd9f2fa2e9822302c0b2e1dcb5777297dc1d"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"016cf99028b3aa3b309577f55d38ad0322900bc17106effec204c4f38f13789c"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5a66422d82eb38ab027764b1088113004b5f11b27de18b59cf0dec9575ea0c58"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e9632bcfa2681e91044816f193ea11b8098dacd9aa7688f2f982cdac1e43fcbb"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"92352d567ba19a06933c385a519da4be0401a394a5e0d5b3ccb3054e59391d6f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ebdf6c8f58e706da27e17ca8c8520c58e4dc21ad58ab38cc8073bccfd46aec9b"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bd516468434784f97b110903b05ff5d29b0cc3d91c0f8540e585214a8347d254"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"77517bd7935f462f3a68d08738ec545d69fa2cde0f8664a9745200d7220154c5"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"98d98a795bbddb89931a91385ce7ac249b8b62725e3669600927194ed50db873"}},{"ruleId":"D43","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ca77df8ac0ed56a2e42b0923be81cca477f3174e98a1dc599981adac6a376eef"}},{"ruleId":"AC3","level":"warning","message":{"text":"Page without a main landmark: No \u003Cmain\u003E (or role=\u0022main\u0022) means no \u0022skip to content\u0022 target and a weaker landmark map. This document\u0027s body is only the mount point \u003Cdiv id=\u0022root\u0022\u003E, so there is no content here to wrap \u2014 render the \u003Cmain\u003E from the component mounted into it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/public/index.html"},"region":{"startLine":2}}}],"partialFingerprints":{"codehealthFindingId/v1":"ccf95feef297cf300dc2f9497e4b15af07fd73149c1a51922e8e6d882ea4547b"}},{"ruleId":"AC3","level":"warning","message":{"text":"Page without a main landmark: No \u003Cmain\u003E (or role=\u0022main\u0022) means no \u0022skip to content\u0022 target and a weaker landmark map. This document\u0027s body is only the mount point \u003Cdiv id=\u0022root\u0022\u003E, so there is no content here to wrap \u2014 render the \u003Cmain\u003E from the component mounted into it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"web/src/main/resources/statics/index.html"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"df98bfd0d90d9c03a5d184e431276b1dcd17358df6331d0fd83131b9e89c94c9"}},{"ruleId":"AC7","level":"warning","message":{"text":"Accessibility enforcement below the top rung: No accessibility enforcement found \u2014 no a11y linter (eslint-plugin-jsx-a11y) and no axe/pa11y/Lighthouse in tests or CI. Start with the linter to catch issues at author time. What was searched, so you can tell an absence from a miss: the 3 markup file(s) this pass actually assessed, the linter configuration checked in beside them, and this repository\u0027s test and CI files \u2014 matched by name against the accessibility checkers this dimension carries. An audit run outside the repository, a hosted scanner, or a check whose name is not one of those, is not seen here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d46019b86eff5ddad9db289e6802ac158899e980df54c34f67722442787ead62"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"M2","level":"note","message":{"text":"No architecture diagram/doc: No C4/Structurizr/PlantUML/Mermaid/Graphviz/D2 diagram, no drawn diagram named for the architecture, no file named \u0060architecture\u0060 or \u0060design\u0060 in any markup this check reads, and nothing in the README, docs or contributor guides that announces the shape \u2014 no \u0060## Architecture\u0060 heading, no \u0022architecture overview\u0022/\u0022high-level design\u0022 phrasing, no \u0022the architecture is \u2026\u0022 introduction, no guided code tour. A shape laid out in prose that never names itself as the architecture is not visible to this check, and neither is one kept outside the repository, so this row reports the absence of a re-findable shape document \u2014 not evidence that nobody wrote the shape down."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0c190e7c159d1850ee706c3ac4486e151e8a4fe169de4bf61436b9f399654f06"}},{"ruleId":"M3","level":"note","message":{"text":"No tests/ separation: No test surface was found \u2014 this check walked the tree for authored source in the languages it models (\u0060.cs\u0060, \u0060.vb\u0060, \u0060.fs\u0060, \u0060.java\u0060, \u0060.kt\u0060, \u0060.scala\u0060, \u0060.py\u0060, \u0060.php\u0060, \u0060.rb\u0060, \u0060.ex\u0060, \u0060.exs\u0060, \u0060.go\u0060, \u0060.erl\u0060, \u0060.hrl\u0060, \u0060.swift\u0060, \u0060.dart\u0060, \u0060.rs\u0060, \u0060.ts\u0060, \u0060.tsx\u0060, \u0060.mts\u0060, \u0060.cts\u0060) and found none of it test-shaped. \u2605 \u0060.js\u0060, \u0060.jsx\u0060, \u0060.mjs\u0060 and \u0060.cjs\u0060 are NOT in that walk, so a Jest or Mocha suite written in plain JavaScript is invisible to it and this row is then wrong. If that is your case, say so rather than moving anything. Otherwise there are no tests here to separate from production code, so the folder question hasn\u0027t been reached yet."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"999e0c784909c76b6346a705ee63961fe363ed1cd6a94e3f80e2ebe7820ccd5d"}},{"ruleId":"M4","level":"note","message":{"text":"README/code drift: README omits the web server project \u2014 reported by the model that read the README against this repository; no term search was run for this one, so nothing here has been checked against the tree. Treat it as a reading to confirm, not as a measured contradiction: verify it against the code before acting on it, and if the footprint it describes does exist, this row is wrong."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5db04a96723524cf9f420d5d726775b603113cdf75deb4cb19e62b76cb2f2e7d"}},{"ruleId":"M4","level":"note","message":{"text":"README/code drift: README omits the Kafka Streams processor (streamprocessor) \u2014 reported by the model that read the README against this repository; no term search was run for this one, so nothing here has been checked against the tree. Treat it as a reading to confirm, not as a measured contradiction: verify it against the code before acting on it, and if the footprint it describes does exist, this row is wrong."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d973a218dc95a38ae2736d4d74a607a6d02776a3f5c8e4c5f386eb6b3a0c7169"}},{"ruleId":"P1","level":"warning","message":{"text":"No CI pipeline: No CI workflow found (.github/workflows, azure-pipelines.yml, .gitlab-ci.yml, \u2026) \u2014 changes aren\u0027t gated by an automated build/test."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"44f01af96e50474fba2df84d95ddf4f7e1d34c29c307830b9efc9057daa6b670"}},{"ruleId":"P3","level":"note","message":{"text":"No SAST: No static application security testing detected. For this repository\u0027s stack, add scalafix or scapegoat (or \u0060semgrep --config=auto\u0060, which runs on any language) \u2014 this repository has no CI pipeline yet, so run it locally to clear the existing findings, then make it a step of the first workflow you add so a regression fails the build. What was searched, so you can tell an absence from a miss: the 0 CI workflow file(s) in this repository, and the scanner and linter configuration checked in beside them. A scan that runs outside CI, one configured in your forge\u0027s web UI rather than in a committed file, or a tool whose name is none of those this check carries, is not seen \u2014 if that is your case the row is wrong, and saying so is more useful than adding a second scanner."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6e54424179c892f03ef2fd003130ac4bd43f39bbf3b1ca0a0143e25acb80ec87"}},{"ruleId":"P4","level":"note","message":{"text":"No rollback/health safety: Deployment is orchestrated by compose, but no service declares a \u0060healthcheck:\u0060 and nothing pins a previous image to fall back to \u2014 the runtime can tell that the container is up, not that it is serving, so a bad release is harder to detect and reverse."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"db6bab8a28a2145f47e5a4e6683cda39d2ba0296c723238e8057da979ae1c706"}},{"ruleId":"R1","level":"warning","message":{"text":"Type Safety: 0 typed \u00B7 13 plain JS \u2014 the untyped files are client/src/actions.js, client/src/api.js, client/src/components/App.js, client/src/components/InvoiceForm.js, client/src/components/InvoicesList.js, client/src/components/InvoicesTable.js (\u002B7 more)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d00ee7953f55325a823d27e5db9657c80ca9b9861c0c0abf8fe487cd3fa586d3"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2 locations): client/src/components/InvoiceForm.js:35 \u00B7 client/src/components/InvoiceForm.js:46 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/src/components/InvoiceForm.js"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"ad6e8eef0e543a604469710119871bfb90305c0847488856ee31ac987013d48c"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2 locations): client/src/components/InvoicesList.js:5 \u00B7 client/src/components/NewInvoice.js:11 \u2014 the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/src/components/InvoicesList.js"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a6a468e32d860476c46611b17a153ac7f0c40555fc525a9581227ca8fea3050"}},{"ruleId":"R4","level":"warning","message":{"text":"Test Coverage: 0% of 13 production file(s) reachable from 0 test file(s) via the import graph \u2014 \u0027production\u0027 here is the RESIDUE: every source file left once tests, tooling, generated output, config, declarations and declaration-only modules, fixture corpora, type fixtures, behaviour-free data modules, re-export barrels, registration/constant data modules and service workers are set aside, so the percentage is taken over a smaller denominator than the workspace\u0027s file count"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"64e0e3511eb969fb4720b196e7d3799e1714077217351c3c56a27b50e3e21220"}},{"ruleId":"R6","level":"warning","message":{"text":"No lint script: test \u2713 \u00B7 lint \u2717 \u00B7 typecheck \u2717 \u2014 read from this repository\u0027s package.json scripts and corroborated against its CI workflows. A script counts when its name or command matches the step: \u0060test\u0060 for the suite, \u0060lint\u0060 or \u0060prettier\u0060 for linting, \u0060typecheck\u0060/\u0060type-check\u0060/\u0060tsc\u0060 for type checking. \u2717 therefore means no script or CI step under those names was found, NOT that the step is absent from your pipeline \u2014 a task invoked by a runner this check does not read, or named something else entirely, is not seen and is worth confirming before acting on a cross. A \u2713 means the wiring is DECLARED \u2014 a script or CI step under those names exists. It is not a statement that the step passes, or that it runs at all: nothing here installs a dependency or executes a suite."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"bc8e67e81453cf5399dd04786d18b232180426b135169175fee670bdd83ccb03"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~10 LoC): no import path from any entry point (1 application, 0 tooling, 0 test roots considered), and no other file in the scanned tree imports it \u2014 nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/src/components/Message.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ed06fd0e6bd98a4e7ce184af02acdbe93250d8d2820f896aa96863e8191c6737"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027emptyDraft\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/src/model.js"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"5199ec1c4b10be17e92c581453fe5b38bbf674075923f9bb5a1de9be9de7f572"}},{"ruleId":"R8","level":"warning","message":{"text":"Unused dependency \u0027npm\u0027: Declared in client/package.json but never imported anywhere in that package or its workspace members \u2014 no static import reaches it. Usually that is dead weight and attack surface, but two shapes are indistinguishable from source and are NOT dead: an optional or native peer that another dependency loads dynamically at runtime, and a package a build, docs or test step installs and invokes separately. Confirm which of the three this is before removing it."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"063d5be4e076392af4e7d07677076ad3dbcf0cd72763871c0a2c4947936f1002"}},{"ruleId":"SC1","level":"warning","message":{"text":"JavaScript dependencies are not locked: No package-lock.json / yarn.lock / pnpm-lock.yaml / bun.lock \u2014 JS installs aren\u0027t reproducible (SSDF PW.4.4). Commit your package manager\u0027s lockfile and install from it (\u0060npm ci\u0060, \u0060yarn --immutable\u0060, \u0060pnpm i --frozen-lockfile\u0060 or \u0060bun i --frozen-lockfile\u0060). Advisory \u2014 never scored."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"40a08798dc9f9c819eaa9f7c084938e1cf2517a9281aed2c31563d6f7d5ba90d"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-250","guid":"52ee12e8-390a-7351-b1e6-388afa694e54","name":"CWE-250","shortDescription":{"text":"CWE-250"},"helpUri":"https://cwe.mitre.org/data/definitions/250.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-668","guid":"e2cb99db-6d24-b056-b0d0-885a733ec403","name":"CWE-668","shortDescription":{"text":"CWE-668"},"helpUri":"https://cwe.mitre.org/data/definitions/668.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":16,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}