{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}]},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D23","name":"Boundary Type-Coupling","shortDescription":{"text":"Boundary Type-Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D23"},{"id":"D24","name":"Comment Value","shortDescription":{"text":"Comment Value"},"helpUri":"https://codehealth.canine.dev/dimensions/D24"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}]},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29"},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}]},{"id":"D33","name":"JS/npm Dependency Vulnerabilities","shortDescription":{"text":"JS/npm Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D33","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}]},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D38","name":"OSV Dependency Vulnerabilities","shortDescription":{"text":"OSV Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D38","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}]},{"id":"D39","name":"IL Efficiency","shortDescription":{"text":"IL Efficiency"},"helpUri":"https://codehealth.canine.dev/dimensions/D39"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"PostHelpers.PaginateAndFilterAndSort (cyclomatic 142): PostHelpers.PaginateAndFilterAndSort has cyclomatic complexity 142 (threshold 15)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs"},"region":{"startLine":33}}}],"partialFingerprints":{"codehealthFindingId/v1":"08498c208849a35f2dd95f59a71644ed26fed0a784e6ec9628d9b48726011f18"}},{"ruleId":"D1","level":"warning","message":{"text":"Startup.Configure (cyclomatic 28): Startup.Configure has cyclomatic complexity 28 (threshold 15)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Web/Startup.cs"},"region":{"startLine":186}}}],"partialFingerprints":{"codehealthFindingId/v1":"7fda3c784a90b4ea0a8905a0049f869681af816b799f02ded3811bc2b4f746b2"}},{"ruleId":"D1","level":"warning","message":{"text":"DataContext.AddMetaData (cyclomatic 17): DataContext.AddMetaData has cyclomatic complexity 17 (threshold 15)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Persistence/DataContext.cs"},"region":{"startLine":95}}}],"partialFingerprints":{"codehealthFindingId/v1":"ac75afa2f7c89d6b4ddedbb19c10a7fbc994368b45cbe6f015acf6e3480046df"}},{"ruleId":"D2","level":"warning","message":{"text":"PostHelpers.PaginateAndFilterAndSort (cognitive 135): PostHelpers.PaginateAndFilterAndSort has cognitive complexity 135 (threshold 15)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs"},"region":{"startLine":33}}}],"partialFingerprints":{"codehealthFindingId/v1":"922be53a8e0f4779eaac1a2a41a9eac40d2bee405b4bc82d0c3e64d262efaab9"}},{"ruleId":"D2","level":"warning","message":{"text":"DataContext.AddMetaData (cognitive 30): DataContext.AddMetaData has cognitive complexity 30 (threshold 15)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Persistence/DataContext.cs"},"region":{"startLine":95}}}],"partialFingerprints":{"codehealthFindingId/v1":"9f95f071ff4aadaf1adadf665316833af1140d2130d80932be5f7e7e98479caa"}},{"ruleId":"D2","level":"warning","message":{"text":"ActivityLogger.LogActivity (cognitive 24): ActivityLogger.LogActivity has cognitive complexity 24 (threshold 15)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Infrastructure/Logger/ActivityLogger.cs"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"67460223cbcdd63cbe192229d4ec5a097b68bd1cfe6500ccdba92790a3022540"}},{"ruleId":"D2","level":"warning","message":{"text":"TusUploadUtils.TusIsFileTypeVerifiedAsync (cognitive 23): TusUploadUtils.TusIsFileTypeVerifiedAsync has cognitive complexity 23 (threshold 15)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Infrastructure/Upload/TusUploadUtils.cs"},"region":{"startLine":375}}}],"partialFingerprints":{"codehealthFindingId/v1":"e20e9cd5d292b11e5ffb8079ed2f15c588b27178c667fa5636db3e61b7e0c944"}},{"ruleId":"D2","level":"warning","message":{"text":"UploadAccessor.AddFileAsync (cognitive 22): UploadAccessor.AddFileAsync has cognitive complexity 22 (threshold 15)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Infrastructure/Upload/UploadAccessor.cs"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"a05530b759a561d6bbbd719a1c5f58003ff7f6a12e4a119ebbddd8a645666840"}},{"ruleId":"D2","level":"warning","message":{"text":"UploadAccessor.IsFileTypeVerified (cognitive 21): UploadAccessor.IsFileTypeVerified has cognitive complexity 21 (threshold 15)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Infrastructure/Upload/UploadAccessor.cs"},"region":{"startLine":350}}}],"partialFingerprints":{"codehealthFindingId/v1":"30a36ae8fbc881bb4423ddfdea135a7999bf6d556c3028ab074e18b73c2293db"}},{"ruleId":"D2","level":"warning","message":{"text":"Startup.Configure (cognitive 20): Startup.Configure has cognitive complexity 20 (threshold 15)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Web/Startup.cs"},"region":{"startLine":186}}}],"partialFingerprints":{"codehealthFindingId/v1":"c07f7c163b5ee0376b3abd320e32e82aa80a1992ca7980162f97106c632322ec"}},{"ruleId":"D2","level":"warning","message":{"text":"TusUploadUtils.DeleteTusFileAsync (cognitive 17): TusUploadUtils.DeleteTusFileAsync has cognitive complexity 17 (threshold 15)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Infrastructure/Upload/TusUploadUtils.cs"},"region":{"startLine":216}}}],"partialFingerprints":{"codehealthFindingId/v1":"cc211aa84432376b8c2fe982491dc0f2cdffb6d93e3c6c176bd6f84cca5b53e3"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: Helpers/PostHelpers.cs: FileTooLong \u2014 935 lines."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs"},"region":{"startLine":0}}}],"partialFingerprints":{"codehealthFindingId/v1":"b356abdbb8c4f4e236f5caac9a9d226f17dce3bb001c1ad8ef25ed8fc136736b"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: PostHelpers: ClassTooLong \u2014 923 lines, 1 methods."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs"},"region":{"startLine":0}}}],"partialFingerprints":{"codehealthFindingId/v1":"f5577b9d091fd7b1833eeee2d6857d1b226e372431b19d211db14eb8df08d940"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (21 lines \u00D7 2): Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:729-749 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:784-803"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs"},"region":{"startLine":729}}}],"partialFingerprints":{"codehealthFindingId/v1":"19732c840a9e2343a297078a4e7629bc7ef5f607e6ca891136fed8c736d89d8c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (18 lines \u00D7 4): Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:483-498 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:936-951 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:1040-1056 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:1233-1250"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs"},"region":{"startLine":483}}}],"partialFingerprints":{"codehealthFindingId/v1":"6c5cd72b9ebd17b606a3c228670c7bb125281659926776c9cc4f8e4e2fb14f82"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 12): Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:71-87 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:105-121 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:139-155 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:173-189 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:207-223 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:241-257 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:275-291 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:309-325 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:343-359 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:377-393 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:411-427 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:445-461"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"554b1775dc7ac9fe39b8e7a4dbf3a2324e8bf994a5109135b3a1209c035302f8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:522-532 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:535-545"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs"},"region":{"startLine":522}}}],"partialFingerprints":{"codehealthFindingId/v1":"f5a095ce986a3a5d78ded7a7372a6a3b1c55a531e3d08b53277bc5fab33d86bb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:553-562 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:577-586"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs"},"region":{"startLine":553}}}],"partialFingerprints":{"codehealthFindingId/v1":"4c26108f3816ad1d4f57acc9a90b11323883329e3d87f9c11d3937c4b02d1c97"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:606-615 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:619-628"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs"},"region":{"startLine":606}}}],"partialFingerprints":{"codehealthFindingId/v1":"4c26108f3816ad1d4f57acc9a90b11323883329e3d87f9c11d3937c4b02d1c97"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:650-659 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:663-672"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs"},"region":{"startLine":650}}}],"partialFingerprints":{"codehealthFindingId/v1":"4c26108f3816ad1d4f57acc9a90b11323883329e3d87f9c11d3937c4b02d1c97"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:708-715 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:811-820"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs"},"region":{"startLine":708}}}],"partialFingerprints":{"codehealthFindingId/v1":"4c26108f3816ad1d4f57acc9a90b11323883329e3d87f9c11d3937c4b02d1c97"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:1077-1086 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:1090-1099"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs"},"region":{"startLine":1077}}}],"partialFingerprints":{"codehealthFindingId/v1":"4c26108f3816ad1d4f57acc9a90b11323883329e3d87f9c11d3937c4b02d1c97"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:1165-1174 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:1178-1187"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs"},"region":{"startLine":1165}}}],"partialFingerprints":{"codehealthFindingId/v1":"4c26108f3816ad1d4f57acc9a90b11323883329e3d87f9c11d3937c4b02d1c97"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:1209-1218 | Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs:1222-1231"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs"},"region":{"startLine":1209}}}],"partialFingerprints":{"codehealthFindingId/v1":"4c26108f3816ad1d4f57acc9a90b11323883329e3d87f9c11d3937c4b02d1c97"}},{"ruleId":"D5","level":"error","message":{"text":"Layer violation: Domain \u2192 Infrastructure: Aspian.Application.Core (Domain) references Aspian.Persistence (Infrastructure) \u2014 dependencies must point inward (Web \u2192 Application \u2192 Domain; Infrastructure implements inner interfaces, nothing depends outward on it)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"81c20e569dfe9cdb0ffab71d4cf00294810e93d164dd98368cc8879c692906aa"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: Aspian.Persistence: Aspian.Persistence: abstractness 0.00, instability 0.25, distance 0.75 \u2014 zone of pain \u2014 concrete and heavily depended-on, so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"05ea4029ea07523802f30a6a626eb0380ed5321963c91a66d45c1260297a7e60"}},{"ruleId":"D8","level":"error","message":{"text":"No automated tests: No automated tests \u2014 the solution has no test code. Untested code is the largest single risk to changing it safely."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3132564c6310e5d01a231f252a02d5d2f5a542c0a8fa29a14c89693f1e3df871"}},{"ruleId":"D9","level":"note","message":{"text":"No tests found: No test projects found in the repository."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c9bf64cbb5a4ae13d6bcd01fa3bc8d2879d860c73bc67f176ee3c2cecb8adce3"}},{"ruleId":"D12","level":"error","message":{"text":"Vulnerable: Microsoft.AspNetCore.Authentication.JwtBearer: Microsoft.AspNetCore.Authentication.JwtBearer 5.0.0 \u2014 Moderate severity. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"615a850aeaf77762c92306913bc06bc508230814202713cd5fc84d3c4c12c5d1"}},{"ruleId":"D12","level":"error","message":{"text":"Vulnerable: SixLabors.ImageSharp: SixLabors.ImageSharp 1.0.2 \u2014 High severity. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"17452a211de60c6888a5220bb4cc5875608e6a3c65238ee3c22dd16e2fd280a6"}},{"ruleId":"D12","level":"error","message":{"text":"Vulnerable: System.IdentityModel.Tokens.Jwt: System.IdentityModel.Tokens.Jwt 6.8.0 \u2014 Moderate severity. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b1aa57ff1b6d7e72651ec0fc7a5d3c72a563804fe76ce2b0617eefc6a133ac5e"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.AspNetCore.Identity.UI: Microsoft.AspNetCore.Identity.UI 5.0.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c24bf70a0f992fcda6d761ff6bcc3302a2bca2cd1799c53f91463a121c1eae9d"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.EntityFrameworkCore: Microsoft.EntityFrameworkCore 5.0.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"2927f16b9ff1747ae8c47784282b32d505c8e5e2832fc32f5e379254d6fd7af3"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.EntityFrameworkCore.Proxies: Microsoft.EntityFrameworkCore.Proxies 5.0.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f89591bc967139de1040704db5e0a763d367637aec1ab67391c39e8ccd66eeb3"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.EntityFrameworkCore.SqlServer: Microsoft.EntityFrameworkCore.SqlServer 5.0.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1bb48f233190b229ebd5b332fb00e8c5120b49cc5db84ca77e9c40b476415d80"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.AspNetCore.Identity.EntityFrameworkCore: Microsoft.AspNetCore.Identity.EntityFrameworkCore 5.0.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6cd381b0bf789c81719f890110e35f67109236489736add3fd5cae4df1fbab17"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: FluentValidation.AspNetCore: FluentValidation.AspNetCore 9.3.0 \u2014 Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c121fe39eaa15140bc3e6db44975ad976f90ca0ef505592ab96df7811261bcf1"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.AspNetCore.Authentication.JwtBearer: Microsoft.AspNetCore.Authentication.JwtBearer 5.0.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"322fa561b620b42802b9832e6562d67cfc20f97a91393f3d9b9ac66ab09bccbd"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.EntityFrameworkCore.Design: Microsoft.EntityFrameworkCore.Design 5.0.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"850b9f153c77a5793f5d5069b8fdb21271e771530a49ed4db0d0ee2d4b39335f"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: System.IdentityModel.Tokens.Jwt: System.IdentityModel.Tokens.Jwt 6.8.0 \u2014 Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5e25a2addd53321a5f56d70917c9cacbd45ad10a65768c7f7d77713591bd3d37"}},{"ruleId":"D16","level":"note","message":{"text":"Small-team knowledge concentration: 0 file(s) are concentrated to one author \u2014 the ambient state with 2 active author(s), not 0 separate risks. The signal becomes meaningful as ownership spreads; no per-file action implied now."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"8aa75b6daa18f1b578387fa04036c50b3163d47f957c8f5601bf083ed4489b0c"}},{"ruleId":"D17","level":"warning","message":{"text":"CommentedOutCode: 3 consecutive commented-code lines"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Application.Core/AttachmentServices/AdminServices/Download.cs"},"region":{"startLine":45}}}],"partialFingerprints":{"codehealthFindingId/v1":"fb8f1ddbc5c5c29c89eb349b7a21a01fde8dcb42c956bd76bf342193a2441ab2"}},{"ruleId":"D17","level":"warning","message":{"text":"CommentedOutCode: 5 consecutive commented-code lines"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Web/Areas/Admin/API/v1/Controllers/AttachmentsController.cs"},"region":{"startLine":68}}}],"partialFingerprints":{"codehealthFindingId/v1":"490ec34ecdf3c6756fbce95b8c9895c1c0cf9a532103fa3ae424d662baa71245"}},{"ruleId":"D17","level":"warning","message":{"text":"Dead code: TusIsFileTypeVerifiedAsync: Method TusIsFileTypeVerifiedAsync \u2014 no references found in solution."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Infrastructure/Upload/TusUploadUtils.cs"},"region":{"startLine":375}}}],"partialFingerprints":{"codehealthFindingId/v1":"8e6e37ac0f48ab8eb282ba73140d3a4d1ad57ec42e89fc131e7fe597d0269805"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found at common paths; consider documenting architectural decisions in Docs/ADL/ or similar."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D23","level":"note","message":{"text":"Bounded contexts not declared: At 10983 LoC spread over 5 projects the codebase is large and multi-module, so explicit bounded contexts are needed. Declare architecture.contexts (\u22652) in config to assess cross-boundary type coupling."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1c7e276c9c682731f01819ed5378b90ca320cde1b583c90920172911598362b3"}},{"ruleId":"D24","level":"note","message":{"text":"redundant comment: \u0022AdminOnly Policy\u0022 \u2014 weak keep; add WHY it is AdminOnly rather than public"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Web/Startup.cs"},"region":{"startLine":120}}}],"partialFingerprints":{"codehealthFindingId/v1":"f351f84387c60d9de8aa3f5b1d7fd63d954e08e6aa81587b18ef172e16c1ae0b"}},{"ruleId":"D24","level":"note","message":{"text":"redundant comment: \u0022Admin services\u0022 \u2014 delete; repeated across claim/policy types, no intent"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Domain/UserModel/Policy/AspianCoreClaimValue.cs"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"0d9cc2e1918ef2b3445c4c4f5a2e7772fb1704752923d4625e60c023d587b005"}},{"ruleId":"D30","level":"error","message":{"text":"Critical CVE: System.Drawing.Common 4.7.0: System.Drawing.Common 4.7.0 (transitive) has a Critical advisory; affects 4 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1f79a595d62add568feda19f54d04fdad0273f072ae213a4e4ad714127a8a2fe"}},{"ruleId":"D30","level":"error","message":{"text":"Critical CVE: System.Text.Encodings.Web 4.3.0: System.Text.Encodings.Web 4.3.0 (transitive) has a Critical advisory; affects 3 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"743d3b6abf9fa39b4d97e7d2b7d228ae096a0194ad8a05c8df42d1c969a7433f"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: Microsoft.Data.SqlClient 2.0.1: Microsoft.Data.SqlClient 2.0.1 (transitive) has a High advisory; affects 4 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"30d58bfb3c5b5381b099fe7c7213473404221cdaeb03235cb29287f6c9f0bb44"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: Newtonsoft.Json 10.0.1: Newtonsoft.Json 10.0.1 (transitive) has a High advisory; affects 3 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c285e2b79f70af256277e99c077e8ccf9280f25f8414c2ccfb6fecd6ab647ec6"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: System.Net.Http 4.3.0: System.Net.Http 4.3.0 (transitive) has a High advisory; affects 4 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7cf85abffe732f2645ef95a624d6badc26f0263616284d6a4cc46ca8e983031d"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: System.Text.RegularExpressions 4.3.0: System.Text.RegularExpressions 4.3.0 (transitive) has a High advisory; affects 4 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b96b7173c4377d5bea4d6fd7b52323631c631c44172b743bec6f266c10a4e538"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: AutoMapper 10.1.0: AutoMapper 10.1.0 (transitive) has a High advisory; affects 3 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a5a29c7f91c27e65224f49b40953185306eb8e0d265149fbbd4a79c0ef9bdf4f"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: Microsoft.AspNetCore.Http 1.1.1: Microsoft.AspNetCore.Http 1.1.1 (transitive) has a High advisory; affects 3 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"2f7d0bbb0c4a983ec59d39e36dc06817899227c4581a9fafca54f5ca1eba84d6"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: System.Text.Encodings.Web 4.3.0: System.Text.Encodings.Web 4.3.0 (transitive) has a High advisory; affects 3 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f0bd2fc9967a477fa624463b237367cf22c25890a3c6dc23b0c54f1a1506334a"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: System.Text.Encodings.Web 4.3.0: System.Text.Encodings.Web 4.3.0 (transitive) has a High advisory; affects 3 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f0bd2fc9967a477fa624463b237367cf22c25890a3c6dc23b0c54f1a1506334a"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: SixLabors.ImageSharp 1.0.2: SixLabors.ImageSharp 1.0.2 (transitive) has a High advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9b6287c37366cd4f870cae5fbb74078fee5124681cc899821e2140c09c274c1e"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: SixLabors.ImageSharp 1.0.2: SixLabors.ImageSharp 1.0.2 (transitive) has a High advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9b6287c37366cd4f870cae5fbb74078fee5124681cc899821e2140c09c274c1e"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: SixLabors.ImageSharp 1.0.2: SixLabors.ImageSharp 1.0.2 (transitive) has a High advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9b6287c37366cd4f870cae5fbb74078fee5124681cc899821e2140c09c274c1e"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: Microsoft.Data.SqlClient 2.0.1: Microsoft.Data.SqlClient 2.0.1 (transitive) has a Medium advisory; affects 4 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b636c797e667abc99114d8220722f875ade9271729ede99cfa215fdf96631226"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: Microsoft.IdentityModel.JsonWebTokens 5.6.0: Microsoft.IdentityModel.JsonWebTokens 5.6.0 (transitive) has a Medium advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"486e2d43aa26452cff8350614c638572e2f6b2144e4c21c889261cc491fda68e"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: System.IdentityModel.Tokens.Jwt 5.6.0: System.IdentityModel.Tokens.Jwt 5.6.0 (transitive) has a Medium advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f279c68f84071f768f46e3141c2a4f2b2892ba451ad501390510048f64b35f49"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: System.Text.Encodings.Web 4.3.0: System.Text.Encodings.Web 4.3.0 (transitive) has a Medium advisory; affects 3 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f444962051c5b46a5ddd6aa43d058f51966699daf25af0e822c0bdd2303da4f5"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: System.Text.Encodings.Web 4.3.0: System.Text.Encodings.Web 4.3.0 (transitive) has a Medium advisory; affects 3 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f444962051c5b46a5ddd6aa43d058f51966699daf25af0e822c0bdd2303da4f5"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: Microsoft.AspNetCore.Authentication.JwtBearer 5.0.0: Microsoft.AspNetCore.Authentication.JwtBearer 5.0.0 (direct) has a Medium advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b97a28c99dc7494683c2553ab542d203ff35a83ed86d53e933d04b7f288d3739"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: Microsoft.IdentityModel.JsonWebTokens 6.8.0: Microsoft.IdentityModel.JsonWebTokens 6.8.0 (transitive) has a Medium advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0d9eec6fa3579d9bfbc2acea0c4ea50af890d1da3d401368bce67e90fc79514a"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: SixLabors.ImageSharp 1.0.2: SixLabors.ImageSharp 1.0.2 (transitive) has a Medium advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"52b708c62ffa4dfba01237b70f3cef5129febc3b89ab394cb2d81e4380073a2f"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: SixLabors.ImageSharp 1.0.2: SixLabors.ImageSharp 1.0.2 (transitive) has a Medium advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"52b708c62ffa4dfba01237b70f3cef5129febc3b89ab394cb2d81e4380073a2f"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: SixLabors.ImageSharp 1.0.2: SixLabors.ImageSharp 1.0.2 (transitive) has a Medium advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"52b708c62ffa4dfba01237b70f3cef5129febc3b89ab394cb2d81e4380073a2f"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: SixLabors.ImageSharp 1.0.2: SixLabors.ImageSharp 1.0.2 (transitive) has a Medium advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"52b708c62ffa4dfba01237b70f3cef5129febc3b89ab394cb2d81e4380073a2f"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: System.IdentityModel.Tokens.Jwt 6.8.0: System.IdentityModel.Tokens.Jwt 6.8.0 (transitive) has a Medium advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6263a56fe3a70af87a269967837af0dd5b722c97091869d8433487b538f5d47f"}},{"ruleId":"D34","level":"error","message":{"text":"Orphaned knowledge: No living knowledge remains for this large file \u2014 its last meaningful change has decayed away; if it breaks, no one currently understands it. Schedule a read-through / add characterisation tests before it bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Persistence/Seed.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b663d7afc9a23807f748995aee1955acd4107860e37231b42ad12aeccc2ad178"}},{"ruleId":"D34","level":"error","message":{"text":"Orphaned knowledge: No living knowledge remains for this large file \u2014 its last meaningful change has decayed away; if it breaks, no one currently understands it. Schedule a read-through / add characterisation tests before it bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Application.Core/PostServices/AdminServices/Helpers/PostHelpers.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"aaeba196ac5435c0d4e7b218d6644d281156813c005f454e31f07f59dfc7b30d"}},{"ruleId":"D34","level":"error","message":{"text":"Orphaned knowledge: No living knowledge remains for this large file \u2014 its last meaningful change has decayed away; if it breaks, no one currently understands it. Schedule a read-through / add characterisation tests before it bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Web/Startup.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"5f07b682d4ee6ad7edaca8e1bfad04889b789abcff7f2d7030dcd20a6e248864"}},{"ruleId":"D34","level":"note","message":{"text":"Further orphaned files (smaller): 3 smaller file(s) also have no living knowledge \u2014 folded into the freshness score and metrics rather than listed individually (6 orphaned of 6 analysed files in total)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ce861fd78f6935114d3a342cb90ad25870f984e1042954fcbbe27c0e23be3658"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: App.tsx \u2194 PostList.tsx: \u0060client/src/app/layout/App.tsx\u0060 (context layout) and \u0060client/src/components/aspian-core/post/postList/PostList.tsx\u0060 (context components) live in DIFFERENT modules yet change together 64% of the time (7 shared commits) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/src/app/layout/App.tsx"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a60ab0ae7e38c9f5730c7899b4b196469ad70cbfefa544d26c5078b676d8c4df"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: agent.ts \u2194 PostList.tsx: \u0060client/src/app/api/aspian-core/agent.ts\u0060 and \u0060client/src/components/aspian-core/post/postList/PostList.tsx\u0060 change together 80% of the time (8 shared commits) with no explicit dependency \u2014 a hidden/logical coupling. If they belong together, co-locate them; if not, break the coupling."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/src/app/api/aspian-core/agent.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a6d3f2d7133a15e5908425439038b61f7abb610e0b239d16bbe45c992e7e6874"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: AttachmentsController.cs \u2194 UploadAccessor.cs: \u0060Aspian.Web/Areas/Admin/API/v1/Controllers/AttachmentsController.cs\u0060 and \u0060Infrastructure/Upload/UploadAccessor.cs\u0060 change together 70% of the time (7 shared commits) with no explicit dependency \u2014 a hidden/logical coupling. If they belong together, co-locate them; if not, break the coupling."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Web/Areas/Admin/API/v1/Controllers/AttachmentsController.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c569b2359c9ea14da6cb87c8050c62ced0052a804071fea5a624bf2852d9a6d4"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: agent.ts \u2194 App.tsx: \u0060client/src/app/api/aspian-core/agent.ts\u0060 and \u0060client/src/app/layout/App.tsx\u0060 change together 50% of the time (5 shared commits) with no explicit dependency \u2014 a hidden/logical coupling. If they belong together, co-locate them; if not, break the coupling."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/src/app/api/aspian-core/agent.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0525923be3c8c90410b10b2035396b83526ea78c7c042b9a23b6859f04862ddf"}},{"ruleId":"D38","level":"error","message":{"text":"Critical CVE: [GHSA redacted]: @babel/traverse: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a549f6e1c227fcd9228f236394b30b5f8eaa8ac535a36eb17fdf2d592afe7d9a"}},{"ruleId":"D38","level":"error","message":{"text":"Critical CVE: [GHSA redacted]: cipher-base: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"dae041abfc6080753a6b75b461e86a4c8b4a47de8a91649087cb9086ed556782"}},{"ruleId":"D38","level":"error","message":{"text":"Critical CVE: [GHSA redacted]: elliptic: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"38d9a59fd0d2c50ae10cfe24e7d6f96649636e15f19474d4d82bdec9876c5645"}},{"ruleId":"D38","level":"error","message":{"text":"Critical CVE: [GHSA redacted]: eventsource: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"4c77ff9e6175e308ae7bdca56e6d8b353439ffe52b9bd66c01cd7b60043fdecd"}},{"ruleId":"D38","level":"error","message":{"text":"Critical CVE: [GHSA redacted]: form-data: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1db0a42b7653cff058ed5b3609ae2ccdb701e5533d4be0dd8136050c33b055b2"}},{"ruleId":"D38","level":"error","message":{"text":"Critical CVE: [GHSA redacted]: json-schema: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3708b8986af9a77120fb816ba396cdc05b5d26fc03066d468bd01f88f88d1710"}},{"ruleId":"D38","level":"error","message":{"text":"Critical CVE: [GHSA redacted]: loader-utils: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e5508b67f7f5e4e8380ff3f5876f117145a2d2c9522b62deb00496e638041dfb"}},{"ruleId":"D38","level":"error","message":{"text":"Critical CVE: [GHSA redacted]: merge-deep: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"6a69170d2c4fa93095fb85bbf3a05fa090c391f8c7b266e304fd2fc5b7cc490a"}},{"ruleId":"D38","level":"error","message":{"text":"Critical CVE: [GHSA redacted]: minimist: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"40f15813429a92ed2d965794ff95f9b6865438cc23ac2fc748f67aa9ae33d189"}},{"ruleId":"D38","level":"error","message":{"text":"Critical CVE: [GHSA redacted]: pbkdf2: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f0ffa39bf8708b22d965285dd87b4730e25cf318915f313f8f1a91d79234556e"}},{"ruleId":"D38","level":"error","message":{"text":"Critical CVE: [GHSA redacted]: pbkdf2: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"237b7926d3fa6a3aadd8a9656d67f4d78b79127f5152b014a0f0eda497a70a71"}},{"ruleId":"D38","level":"error","message":{"text":"Critical CVE: [GHSA redacted]: sha.js: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"edcebc450d21fe6fe74f813abf716d89384ba7bdef6503352fd87a2e6149ec8c"}},{"ruleId":"D38","level":"error","message":{"text":"Critical CVE: [GHSA redacted]: shell-quote: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"35b8c5009cc18e8e797e257729902165627c0e5b0b17d6b422d8a2afbec877f3"}},{"ruleId":"D38","level":"error","message":{"text":"Critical CVE: [GHSA redacted]: shell-quote: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"5fe6b13d26f3718b32be9d56721fe8183cea3232dc739fc35afe8eb07ab53ffe"}},{"ruleId":"D38","level":"error","message":{"text":"Critical CVE: [GHSA redacted]: url-parse: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"47f79fca6bbafa5fea30dbf3cb324588f82d3d407689df2c503dab803a6f9b5e"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: ansi-html: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d08571ddf43272915401ccd463b247b943fb3bf492ffe0d11aa8d8064877d05d"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: ansi-regex: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"85a6dc43c23e900f7e6121393c8e49a3d2d76b1717a3e15a327185a692af5e9e"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: async: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"8fec74dfc3f18fb5f9f69996a444e3f8b5f01d54da3380f6b1dcea87c3ec8113"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: axios: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"fbaa7bd2946b1fa91e9bfdc71a9b8b93fa9b566008170045a5eaec3dca0a8074"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: axios: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"9f484fdc76f3d125319b149ef11737b1ffa0e7b388c2f8fcd3d09cf1a612deb8"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: axios: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"67bad9c28e3f7b44f8caf16671b4c7a29d9e251d8fbe64f320993e25104068bc"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: axios: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"35227e1d95dda39ecb2470413b762bdcd45ff885fd571ac90f88f7531ed3631b"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: axios: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"78ba32076b028b8d77757c173798eaf987c45c30562c25ad1fa9d73b0aba71bb"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: axios: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c01339b79c94608f8f4fcff279cbb2eb5fe35cf87df6a22f38252a2f7578944d"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: axios: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"01c3577c51315dc51222b40d24d960167c4a1ddb362532a2e44800756c3b8e0d"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: axios: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e7e5a8609b1bec4dcac4c2880c918da6416b69826d8af811b59d4e609af3ef53"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: axios: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"198ac7b38b8eb63809a4bb5e90c254afbf01a41423ec7f6226fc8aa96ebb05e1"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: axios: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b22703deb4a42c3a136c0762ccca9d94d59c6c1e3d44246c6e90ae0249667af6"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: axios: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f94b863c60dea0a8097f09947a71929ac74a18a0208faf85f1fdfc6f41e138e7"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: body-parser: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b9cc6fc8ebbf077d32a9bd2ea25cd26c6a76cce57a244230e708fc90961d90e4"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: braces: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a053a48da2048a147bc758ae0fc8776adb12904df2817ca6fa884137ec4fed28"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: browserify-sign: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"5b531c731d1b0a78f9a74ee3ad835810d7b2af7762998b910ead65f5ff7d83f6"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: cross-spawn: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"50f7d27b142146b94de4d4d14abbca26b7e1f33b62d197f1eff4cc84251235f0"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: decode-uri-component: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"eacd157491d11ee66566539968108e0798e9c3a11b6819d26fb4e1a0b4c30f58"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: dns-packet: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f63289185325b8dcd4c43c24ac833df9daa151af12654fe96bf05b434718f139"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: flatted: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e16184d55e91c0ef1d3fc8c16372b5de941593f11629abecd9824009783833a5"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: flatted: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"9a76e01840067f2e6cbabc2a937adb5c08f077f35c6b1eecd760936029ca9f2c"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: follow-redirects: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"27c36a8f72c66b52091a3e76da5211a208f55f6c8526aa1d876d221479750368"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: form-data: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"aa66e29cdbdfeb370670baf94ad07a70fd9c77736a656b1c7251aac1a30ed569"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: glob-parent: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a50b0b56ed59c75ff96426ad8ddfece529c2f248699ac558d4369d06509b6a94"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: http-proxy-middleware: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"9769b8ea49aab7624f799297ed3abdd82d06dfd987c21a6f17ca07d8b44994ae"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: ini: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"334cdb8eb4aca4ace5d2a596bdcd6574ad8bfeca326e8dd7cdecd8f3a9ab62bd"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: ip: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"8d36dafb144d7c84dc1343dc12dc58069f63b6a3018fb76cc6d1992073e30574"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: is-svg: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"9f0f7352e09245f9a803348c67ca2903d5ca9456693e8df9a477e984aded9c98"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: is-svg: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b4e6811dd79197c29a749ab3e3dfa341873286ba3f7afc3c18d75ebf122f5bb8"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: json5: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"25bbae50c2c9ee76c9976c051d0ea35742d813ed065f83b62f6973eadc82a930"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: loader-utils: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"547cb5f18c088fc22576508355e9d93ba6846031275e4674a230182bee73910b"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: loader-utils: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3262e09154d9b5c39c9a0eb1319283c75179b2976e374a65338d478034fc4e87"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: lodash: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b6723075e5b518b66695a9b48c089c86ec51db79d39e192522774cf0ab995228"}},{"ruleId":"D38","level":"error","message":{"text":"High CVE: [GHSA redacted]: lodash: [GHSA redacted] (in 2 lockfiles)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"client/package-lock.json"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"5200dc1fc177fc5ba363cc039736efc7709122d781aa2a1fe984ffd87ee55b59"}},{"ruleId":"D39","level":"note","message":{"text":"IL efficiency: 7 authored method(s) exceed the IL budget: 7 of 515 first-party methods compile to oversized IL bodies (\u003E 250 instructions); worst: Aspian.Application.Core.PostServices.AdminServices.DTOs.MappingProfile..ctor @ Aspian.Application.Core/PostServices/AdminServices/DTOs/MappingProfile.cs:14, 1051 IL instructions; large bodies don\u0027t JIT-inline, which pulled this dimension to 9.7/10; splitting the hottest bodies recovers the most."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Aspian.Application.Core/PostServices/AdminServices/DTOs/MappingProfile.cs"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"74992f2ca3d6a3dc99ca63c4c1c5f69a976290b5bd66f9998ebc5520c84268be"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1395","name":"Dependency on Vulnerable Third-Party Component"},{"id":"CWE-798","name":"Use of Hard-coded Credentials"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":0,"secretScannerRunsExcluded":0}}}]}