{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D10","name":"Test Quality","shortDescription":{"text":"Test Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D10"},{"id":"D11","name":"Test Reliability","shortDescription":{"text":"Test Reliability"},"helpUri":"https://codehealth.canine.dev/dimensions/D11"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D24","name":"Comment Value","shortDescription":{"text":"Comment Value"},"helpUri":"https://codehealth.canine.dev/dimensions/D24"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D39","name":"IL Efficiency","shortDescription":{"text":"IL Efficiency"},"helpUri":"https://codehealth.canine.dev/dimensions/D39"}]}},"results":[{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Contract: TooManyMethods \u2014 1653 significant lines (blank, comment-only and punctuation-only lines excluded), 641 methods, declared across 18 files: Validations/DecimalValidationContract.cs (96), Validations/DoubleValidationContract.cs (96), Validations/FloatValidationContract.cs (96), Validations/IntValidationContract.cs (96), \u002B14 more file(s). The type holds no instance state, so there is no shared data to group its members by. To reduce it, split it by area instead: give each cohesive family of members its own smaller type, so no one type has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flunt/Validations/DecimalValidationContract.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b2b1c9eea6ef09ac52cc43b642040e0dbe4f840f5c9e1b2174663e313f0ad702"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: FluntErrorMessages: TooManyMethods \u2014 71 significant lines (blank, comment-only and punctuation-only lines excluded), 35 methods. The type holds no instance state, so there is no shared data to group its members by. To reduce it, split it by area instead: give each cohesive family of members its own smaller type, so no one type has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flunt/Localization/FluntErrorMessages.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"256f9040dbedbd958080c47e03895047e71bc2af93a00656f74be2a8b36ea705"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: MSTest.TestAdapter: MSTest.TestAdapter 2.2.10 \u2014 Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ee87da37b644f339f553a0b6c3bf2f114f23a951f9421d14ed870e71f7ad60e3"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: MSTest.TestFramework: MSTest.TestFramework 2.2.10 \u2014 Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b69cdd194a49be37271a696938cb22ebf3e9388aead8d7b5e3d69a29082d5e0d"}},{"ruleId":"D16","level":"warning","message":{"text":"dormant codebase \u2014 no living knowledge left to concentrate: All 15 significant source file(s) were last meaningfully changed so long ago that no living knowledge remains \u2014 nothing since has been substantial enough to re-establish ownership (a broad, mechanical sweep that touches many files shallowly does not count, and neither does no activity at all). There is no concentration to measure, so the bus factor is not scored. This is not a clean bill: nobody currently holds working knowledge of this code (see D34 Knowledge Freshness)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"569d55ea5cb0330f13c125b289d07e5abdfcceac947a2c2645277937942e7d5f"}},{"ruleId":"D17","level":"warning","message":{"text":"Dead code: Order: NamedType Order \u2014 no references found in solution."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flunt.Samples/Entities/Order.cs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"86385912fed7d9df097d585e8561ac590c3446342290ed5a01f98dcfac9b9d42"}},{"ruleId":"D17","level":"warning","message":{"text":"Dead code: OrderLine: NamedType OrderLine \u2014 no references found in solution."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flunt.Samples/Entities/OrderLine.cs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"e26e11ee189e1dfebf06855499e71fbee78ead2fc3ddc25776df612561beafc4"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found at common paths; consider documenting architectural decisions in Docs/ADL/ or similar."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent use of \u0027Are\u0027 vs \u0027Require\u0027/\u0027Is\u0027 for equality checks. Some methods use \u0027AreEquals\u0027 (plural, present tense) while others use \u0027RequireTwo...AreNotEquals\u0027 or \u0027Requires...AreEquals\u0027 in tests, and \u0027IsNotBetween\u0027/\u0027IsGreaterOrEqualsThan\u0027 (singular, state-based) for other comparisons. The test suite mixes \u0027Are/Not\u0027 with \u0027Require/Is\u0027 prefixes.: Standardize on \u0027Is/IsNot\u0027 for validation methods (e.g., IsEquals, IsNotEquals) or \u0027Require/Ensure\u0027 for test assertions. Avoid mixing \u0027Are\u0027 (plural) with \u0027Is\u0027 (singular) for the same concept. (symbols: Flunt.Validations.Contract\u003CT\u003E.AreEquals, Flunt.Validations.Contract\u003CT\u003E.AreNotEquals)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"97af382604b9d56e2a541385f745a46780bb3995808d8b041d9bc9947e1f8b14"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent naming for less-than comparisons. Some methods use \u0027IsLowerThan\u0027 while others use \u0027IsLessThan\u0027 (if present) or \u0027IsLowerOrEqualsThan\u0027 vs \u0027IsGreaterOrEqualsThan\u0027. The term \u0027Lower\u0027 is used instead of \u0027Less\u0027, which is less common in C# for numeric comparisons (typically \u0027Less\u0027 or \u0027Greater\u0027).: Use \u0027IsLessThan\u0027 and \u0027IsLessOrEqualsThan\u0027 to align with standard C# naming conventions (e.g., \u0060Math.Min\u0060, \u0060IComparable\u0060). Or consistently use \u0027Lower\u0027 if that is the chosen domain term, but ensure \u0027Lower\u0027 is used for both \u003C and \u003C=. (symbols: Flunt.Validations.Contract\u003CT\u003E.IsLowerThan, Flunt.Validations.Contract\u003CT\u003E.IsLowerOrEqualsThan)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"dfb6044c1a3a37e124aefefcfa33350e6997b47f5b7d0a8f7ae53244650150d3"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent use of \u0027Greater\u0027 vs \u0027Lower\u0027 vs \u0027Less\u0027. The codebase uses \u0027Greater\u0027 for \u003E and \u0027Lower\u0027 for \u003C. However, \u0027Lower\u0027 is non-standard for numeric comparisons (usually \u0027Less\u0027). Additionally, \u0027IsLowerOrEqualsThan\u0027 is used, but \u0027IsGreaterOrEqualsThan\u0027 is used, showing a mix of \u0027Greater\u0027 and \u0027Lower\u0027 which are antonyms but \u0027Lower\u0027 is an unusual choice for \u0027\u003C\u0027 in this context compared to \u0027Less\u0027.: Standardize on \u0027IsLessThan\u0027/\u0027IsLessOrEqualsThan\u0027 and \u0027IsGreaterThan\u0027/\u0027IsGreaterOrEqualsThan\u0027. \u0027Less\u0027 is the standard counterpart to \u0027Greater\u0027 in C# (e.g., \u0060IComparable\u0060). If \u0027Lower\u0027 is preferred, ensure it is used consistently for all \u0027\u003C\u0027 operations. (symbols: Flunt.Validations.Contract\u003CT\u003E.IsGreaterOrEqualsThan, Flunt.Validations.Contract\u003CT\u003E.IsLowerOrEqualsThan)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9e66dc1547b9dfbbc4feab425256b7fd8c3e3f1164c5e0c02bc89ebc0b32c36d"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent naming for null checks. Some methods use \u0027IsNull\u0027/\u0027IsNotNull\u0027 while others use \u0027IsNotBetween\u0027 or \u0027IsNotMinValue\u0027. The null checks are consistent, but the non-null checks are \u0027IsNotNull\u0027 while other validations use \u0027IsNot...\u0027. This is a minor inconsistency in prefix usage (IsNotNull vs IsNot...).: Use \u0027IsNotNull\u0027 for consistency with \u0027IsNull\u0027, or change to \u0027IsNot...\u0027. Since \u0027IsNull\u0027 is used, \u0027IsNotNull\u0027 is acceptable, but ensure no other method uses \u0027IsNot...\u0027 for the same concept. (symbols: Flunt.Validations.Contract\u003CT\u003E.IsNotNull, Flunt.Validations.Contract\u003CT\u003E.IsNull)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"cb6926adee17164d0a2ac3deae09586b2437049c2f5c425fff8d123f32d823d6"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent use of \u0027Between\u0027 vs \u0027NotBetween\u0027. While this is technically correct (negation), the test methods use \u0027Requires...IsNotBetween\u0027 or \u0027Requires...IsBetween\u0027. The inconsistency is in the test layer: some tests use \u0027Requires...IsNotBetween\u0027 while others use \u0027Requires...IsBetween\u0027.: Ensure all test methods for \u0027Between\u0027 use \u0027Requires...IsNotBetween\u0027 for the negative case. The current list shows \u0027RequiresTwoFloatsAreNotEquals\u0027 vs \u0027RequiresTwoFloatsAreEquals\u0027 in tests, which is inconsistent with the \u0027Is/IsNot\u0027 pattern in the main library. (symbols: Flunt.Validations.Contract\u003CT\u003E.IsNotBetween, Flunt.Validations.Contract\u003CT\u003E.IsBetween)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5de64129739cf3ec9d3970da168e2ea86fcdfc3a33572c61b87e188b7e0f1ae3"}},{"ruleId":"D24","level":"note","message":{"text":"redundant comment: \u0022Invalid\u0022 \u2014 delete - IsCreditCard already says INVALID"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flunt.Tests/CreditCardValidationTests.cs"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"e4ffd15f85275c4a1c7d63a22969a7dd52f4979d7f56205bab16678948a2f338"}},{"ruleId":"D24","level":"note","message":{"text":"redundant comment: \u0022DateTime = StartDate will be consider between\u0022 \u2014 delete - the \u0027consider between\u0027 phrasing is boilerplate; remove or replace with a one-line constraint"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flunt.Tests/DateTimeValidationTests.cs"},"region":{"startLine":120}}}],"partialFingerprints":{"codehealthFindingId/v1":"48b64f9dc9a714aa59302911945290b89e57adb551e42bc1ef7c44c06e85347d"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"87deddaeb73a5cb34870da76a2c39660da033ef2fb2a7cbc64ae7a78b65fd424"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d68f7101d68f81a416c587fc75c184582e6f28ddb6e0d8e7a2fea42efc952904"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"37e9b14834e57affdb9b756398680eae2a64febdb7a3f1aedcfd421b116ae21f"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7cf85abffe732f2645ef95a624d6badc26f0263616284d6a4cc46ca8e983031d"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b96b7173c4377d5bea4d6fd7b52323631c631c44172b743bec6f266c10a4e538"}},{"ruleId":"D34","level":"error","message":{"text":"Orphaned knowledge: No living knowledge remains for this large file \u2014 its last meaningful change has decayed away; if it breaks, no one currently understands it. Schedule a read-through / add characterisation tests before it bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flunt/Validations/DecimalValidationContract.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"8767f1643fab204cafe67023b67d1a51c04d18d4131d35c96207320dbb6bb11f"}},{"ruleId":"D34","level":"error","message":{"text":"Orphaned knowledge: No living knowledge remains for this large file \u2014 its last meaningful change has decayed away; if it breaks, no one currently understands it. Schedule a read-through / add characterisation tests before it bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flunt/Validations/DoubleValidationContract.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"acbf87d59d8fa9037b26d9bd06fe20283ae61552b27093ece206da25ae9b3ed3"}},{"ruleId":"D34","level":"error","message":{"text":"Orphaned knowledge: No living knowledge remains for this large file \u2014 its last meaningful change has decayed away; if it breaks, no one currently understands it. Schedule a read-through / add characterisation tests before it bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flunt/Validations/FloatValidationContract.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d3fe96ab6788abdc3d6d04fe7a13f548682c647e0807119aa370575f2c483aa1"}},{"ruleId":"D34","level":"error","message":{"text":"Orphaned knowledge: No living knowledge remains for this large file \u2014 its last meaningful change has decayed away; if it breaks, no one currently understands it. Schedule a read-through / add characterisation tests before it bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flunt/Validations/LongValidationContract.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a257f66c7ca67eed0ba8b9e4def250107f8028ffed6d78db37ca757382d28623"}},{"ruleId":"D34","level":"error","message":{"text":"Orphaned knowledge: No living knowledge remains for this large file \u2014 its last meaningful change has decayed away; if it breaks, no one currently understands it. Schedule a read-through / add characterisation tests before it bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flunt/Validations/IntValidationContract.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c7add4dd23a7cdc2835b6dda28901183db9442304b14735e279bb2967ad1414d"}},{"ruleId":"D34","level":"note","message":{"text":"Further orphaned files (smaller): 10 smaller file(s) also have no living knowledge \u2014 folded into the freshness score and metrics rather than listed individually (15 orphaned of 15 analysed files in total, counted over production source files of roughly 100 lines or more, excluding tests, vendored, generated and example/demo trees, largest first)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ce861fd78f6935114d3a342cb90ad25870f984e1042954fcbbe27c0e23be3658"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1b213f6eedd4b140d0bc37bdf1496f72811a643f34064f12518b32e9e83bcfc7"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e17f71490e4d120a48b2b2881ab866c93b272bef2febb673a3e8e42b2c288ab"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eb00976a698a5d68999b7ee6d27206fd374e916853e7ff1ead5eed42386f043f"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"90f83b4fa27db32740afe9540c905f3c0499caed87f61049a8a903ecc95b41c3"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9658270ba49f37ed04e99ab1263b6393cd42aed8bdfb7aafd9fa1070f5491895"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d657599f6f99da1927d3377533dfc0888b34c4d84aa7d5579841fd72d0e39bce"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":11,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}