{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D24","name":"Comment Value","shortDescription":{"text":"Comment Value"},"helpUri":"https://codehealth.canine.dev/dimensions/D24"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"ToolHubControlView.ReadMetadataFromScript (cyclomatic 22): ToolHubControlView.ReadMetadataFromScript has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/ToolHubView/ToolHubControlView.cs"},"region":{"startLine":124}}}],"partialFingerprints":{"codehealthFindingId/v1":"ad9c1e4368aa94514859b967b1ac8a7f16fb2624fc499b0fe59941ae60f6456e"}},{"ruleId":"D1","level":"warning","message":{"text":"ToolHubItemControl.btnRun_Click (cyclomatic 21): ToolHubItemControl.btnRun_Click has cyclomatic complexity 21 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/ToolHubView/ToolHubItemControl.cs"},"region":{"startLine":117}}}],"partialFingerprints":{"codehealthFindingId/v1":"9c90efabbf3e8779b836eeb760c105059d0c248bd403aeb415be089b8ac2be1c"}},{"ruleId":"D1","level":"warning","message":{"text":"BackgroundHelper.CreateBrush (cyclomatic 17): BackgroundHelper.CreateBrush has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/Helper/BackgroundHelper.cs"},"region":{"startLine":188}}}],"partialFingerprints":{"codehealthFindingId/v1":"e33ed8852eac8ad240c8f700ac9f8371adfc6c02833b93aa7a9877f870f60a7d"}},{"ruleId":"D1","level":"warning","message":{"text":"ToolHelpers.ResolveToolPath (cyclomatic 17): ToolHelpers.ResolveToolPath has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/InstallView/ToolHelper.cs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"b2fab40037c307d4de67adcbfdda3701b09e9d19591f241212e495a1bf70c979"}},{"ruleId":"D1","level":"warning","message":{"text":"AiControlView.DoRemove (cyclomatic 16): AiControlView.DoRemove has cyclomatic complexity 16 (threshold 15). Most of this is not in the body itself: 4 of the 16 points are its own statements and the rest belongs to one function literal inside it that branches (line 83). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/Views/AiControlView.cs"},"region":{"startLine":66}}}],"partialFingerprints":{"codehealthFindingId/v1":"9727f23f54d6a2197a79dcffe3825a43cefd082c6357c90c5b209f0b80fc71d9"}},{"ruleId":"D2","level":"warning","message":{"text":"ToolHelpers.ResolveToolPath (cognitive 32): ToolHelpers.ResolveToolPath has cognitive complexity 32 (threshold 15). To reduce it, flatten the nesting: invert conditions into early returns or guard clauses so the happy path stays at one level, and lift the deepest nested block into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/InstallView/ToolHelper.cs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"6779fa46f5ae0300e5fce2e7e92c86b36d11943c9272c6ee8b5a566585571340"}},{"ruleId":"D2","level":"warning","message":{"text":"ToolHubControlView.ReadMetadataFromScript (cognitive 29): ToolHubControlView.ReadMetadataFromScript has cognitive complexity 29 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/ToolHubView/ToolHubControlView.cs"},"region":{"startLine":124}}}],"partialFingerprints":{"codehealthFindingId/v1":"d5096aaa486beb3035d6bca63dd6483bdc06ee47be63c2487f0f4252f7cde6a1"}},{"ruleId":"D2","level":"warning","message":{"text":"ToolHubItemControl.btnRun_Click (cognitive 22): ToolHubItemControl.btnRun_Click has cognitive complexity 22 (threshold 15). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/ToolHubView/ToolHubItemControl.cs"},"region":{"startLine":117}}}],"partialFingerprints":{"codehealthFindingId/v1":"b48885b52572f4a50934dcfa122424bf6286b03fb9dbae0827ed9aa956af99c7"}},{"ruleId":"D2","level":"warning","message":{"text":"AiControlView.DoRemove (cognitive 20): AiControlView.DoRemove has cognitive complexity 20 (threshold 15). Most of this is not in the body itself: 4 of the 20 points are its own statements and the rest belongs to one function literal inside it that branches (line 83). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/Views/AiControlView.cs"},"region":{"startLine":66}}}],"partialFingerprints":{"codehealthFindingId/v1":"a7d028b77153e71c1d71b5d1014d30ee971e917d11d94caf882fbe3c37fd562a"}},{"ruleId":"D2","level":"warning","message":{"text":"AdvancedControlView.RunSelectedAsync (cognitive 20): AdvancedControlView.RunSelectedAsync has cognitive complexity 20 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/InstallView/AdvancedControlView.cs"},"region":{"startLine":171}}}],"partialFingerprints":{"codehealthFindingId/v1":"1c0dd9964cbdc9ed44c6bb27388956d30546ba70b61c2a37caa9398535648445"}},{"ruleId":"D2","level":"warning","message":{"text":"DeviceControlView.btnApply_Click (cognitive 17): DeviceControlView.btnApply_Click has cognitive complexity 17 (threshold 15). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/Views/DeviceControlView.cs"},"region":{"startLine":113}}}],"partialFingerprints":{"codehealthFindingId/v1":"b2c0a9db651cba8c9a01db0a62841b03759563c36f32d4a044169e45a169ff90"}},{"ruleId":"D2","level":"warning","message":{"text":"BackgroundHelper.CreateBrush (cognitive 16): BackgroundHelper.CreateBrush has cognitive complexity 16 (threshold 15). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/Helper/BackgroundHelper.cs"},"region":{"startLine":188}}}],"partialFingerprints":{"codehealthFindingId/v1":"0e2c7345b6335d14feeb35569ee8c2aee8b513bcd1e1130885c8a5a51c4095a1"}},{"ruleId":"D2","level":"warning","message":{"text":"UpdatesControlView.Install (cognitive 16): UpdatesControlView.Install has cognitive complexity 16 (threshold 15). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/Views/UpdatesControlView.cs"},"region":{"startLine":161}}}],"partialFingerprints":{"codehealthFindingId/v1":"a53a1e287be0e3016913515fcf1b33a4f72055c39209cea1b1ffb63fb80511bf"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 16): Flyoobe/Features/Ads/FinishSetupAds.cs:33-45 | Flyoobe/Features/Ads/PersonalizedAds.cs:32-44 | Flyoobe/Features/Ads/TipsAndSuggestions.cs:33-45 | Flyoobe/Features/Ads/WelcomeExperienceAds.cs:32-44 | Flyoobe/Features/Edge/BrowserSignin.cs:32-44 | Flyoobe/Features/Edge/DefautBrowserSetting.cs:32-44 | Flyoobe/Features/Edge/EdgeCollections.cs:32-44 | Flyoobe/Features/Edge/EdgeShoppingAssistant.cs:32-44 | Flyoobe/Features/Edge/FirstRunExperience.cs:32-44 | Flyoobe/Features/Edge/GamerMode.cs:32-44 | Flyoobe/Features/Edge/ImportOnEachLaunch.cs:32-44 | Flyoobe/Features/Edge/StartupBoost.cs:32-44 | Flyoobe/Features/Edge/TabPageQuickLinks.cs:32-44 | Flyoobe/Features/Edge/UserFeedback.cs:32-44 | Flyoobe/Features/Gaming/VisualFX.cs:38-50 | Flyoobe/Features/Privacy/PrivacyExperience.cs:33-45 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 16 call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made 16 times. Read the line range as the matched WINDOW rather than a finished unit: at \u0060Flyoobe/Features/Ads/FinishSetupAds.cs:33\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/Features/Ads/FinishSetupAds.cs"},"region":{"startLine":33}}}],"partialFingerprints":{"codehealthFindingId/v1":"50115013c3682bdb1bf3da93fdebbe0256b05c5e20997f17a445468b1a1e866e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): Flyoobe/Features/Edge/DefaultTopSites.cs:32-44 | Flyoobe/Features/Gaming/PowerThrotteling.cs:38-50 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060Flyoobe/Features/Edge/DefaultTopSites.cs:32\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/Features/Edge/DefaultTopSites.cs"},"region":{"startLine":32}}}],"partialFingerprints":{"codehealthFindingId/v1":"d1a103f782243ccd834ff2801903e2b432c9d55d74505c2ab7efe86802ab7be1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): Flyoobe/InstallView/InPlaceRepairProvider.cs:44-53 | Flyoobe/InstallView/RunSetupFromIsoProvider.cs:43-52 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060Flyoobe/InstallView/InPlaceRepairProvider.cs:44\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/InstallView/InPlaceRepairProvider.cs"},"region":{"startLine":44}}}],"partialFingerprints":{"codehealthFindingId/v1":"aefc48349e0188f6b31624d5ebc5acb1046dc36a37dccc3b5d398d374d92f5b4"}},{"ruleId":"D8","level":"error","message":{"text":"No automated tests: No automated tests \u2014 no test code was found in this repository. Untested code is the largest single risk to changing it safely."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3132564c6310e5d01a231f252a02d5d2f5a542c0a8fa29a14c89693f1e3df871"}},{"ruleId":"D9","level":"note","message":{"text":"No tests found: No test suite could be collected \u2014 nothing here references a test framework (xUnit, NUnit or MSTest), so there were no discoverable tests to count. Tests written as plain executables or shell/PowerShell harnesses are not collectible this way and are not scored here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c9bf64cbb5a4ae13d6bcd01fa3bc8d2879d860c73bc67f176ee3c2cecb8adce3"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #1: If anonymized user #1 becomes unavailable, 1 significant file(s) lose their only recent owner: Flyoobe/Helper/DonationHelper.cs. Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9333fb47b96e74e341e4c5090ed850d02ad047a6e757e20b9bd82d5ee4571e3d"}},{"ruleId":"D17","level":"error","message":{"text":"EmptyCatchBlock: empty catch block \u2014 the error is discarded with nothing recorded, so a failure here leaves no trace anywhere. Narrow the catch to the exception you actually expect, record it through whatever this codebase already uses to report problems, or \u2014 where swallowing really is correct, as it often is on a teardown/dispose path where throwing would mask the original failure \u2014 write down WHY in a comment on the catch. The comment has to give the reason: a note that only restates the swallow (\u0022ignored\u0022, \u0022do nothing\u0022) is read as no explanation at all and leaves this row in place. Any of the three makes the decision reviewable; all three clear this row."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/InstallView/AdvancedControlView.cs"},"region":{"startLine":200}}}],"partialFingerprints":{"codehealthFindingId/v1":"459191035ba46d5e3b3604aa2a20767156a577df92fd1062e75ea3c2c116f581"}},{"ruleId":"D17","level":"error","message":{"text":"EmptyCatchBlock: empty catch block \u2014 the error is discarded with nothing recorded, so a failure here leaves no trace anywhere. Narrow the catch to the exception you actually expect, record it through whatever this codebase already uses to report problems, or \u2014 where swallowing really is correct, as it often is on a teardown/dispose path where throwing would mask the original failure \u2014 write down WHY in a comment on the catch. The comment has to give the reason: a note that only restates the swallow (\u0022ignored\u0022, \u0022do nothing\u0022) is read as no explanation at all and leaves this row in place. Any of the three makes the decision reviewable; all three clear this row."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/InstallView/BootMenuInfoProvider.cs"},"region":{"startLine":74}}}],"partialFingerprints":{"codehealthFindingId/v1":"1774344474ce7e1851fe4b8fca825c6da4cfd8bd6e7826c9bdea12708a1832b0"}},{"ruleId":"D17","level":"error","message":{"text":"EmptyCatchBlock: empty catch block \u2014 the error is discarded with nothing recorded, so a failure here leaves no trace anywhere. Narrow the catch to the exception you actually expect, record it through whatever this codebase already uses to report problems, or \u2014 where swallowing really is correct, as it often is on a teardown/dispose path where throwing would mask the original failure \u2014 write down WHY in a comment on the catch. The comment has to give the reason: a note that only restates the swallow (\u0022ignored\u0022, \u0022do nothing\u0022) is read as no explanation at all and leaves this row in place. Any of the three makes the decision reviewable; all three clear this row."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/InstallView/InPlaceRepairProvider.cs"},"region":{"startLine":53}}}],"partialFingerprints":{"codehealthFindingId/v1":"9ce60404bff421306eef25fe831848994db3c7342422cb2daa3945c6661abf12"}},{"ruleId":"D17","level":"error","message":{"text":"EmptyCatchBlock: empty catch block \u2014 the error is discarded with nothing recorded, so a failure here leaves no trace anywhere. Narrow the catch to the exception you actually expect, record it through whatever this codebase already uses to report problems, or \u2014 where swallowing really is correct, as it often is on a teardown/dispose path where throwing would mask the original failure \u2014 write down WHY in a comment on the catch. The comment has to give the reason: a note that only restates the swallow (\u0022ignored\u0022, \u0022do nothing\u0022) is read as no explanation at all and leaves this row in place. Any of the three makes the decision reviewable; all three clear this row."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/InstallView/RunSetupFromIsoProvider.cs"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"6a7fe97c0bd69d50c5f5f7ed82d744801d8e067d3c38bcd79bbeac294c36dc6d"}},{"ruleId":"D17","level":"error","message":{"text":"EmptyCatchBlock: empty catch block \u2014 the error is discarded with nothing recorded, so a failure here leaves no trace anywhere. Narrow the catch to the exception you actually expect, record it through whatever this codebase already uses to report problems, or \u2014 where swallowing really is correct, as it often is on a teardown/dispose path where throwing would mask the original failure \u2014 write down WHY in a comment on the catch. The comment has to give the reason: a note that only restates the swallow (\u0022ignored\u0022, \u0022do nothing\u0022) is read as no explanation at all and leaves this row in place. Any of the three makes the decision reviewable; all three clear this row."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/InstallView/ToolHelper.cs"},"region":{"startLine":55}}}],"partialFingerprints":{"codehealthFindingId/v1":"0e82698899bd99a73e091fa9b07a3bc54d3f52f16caaac0ff7999ed687b3d526"}},{"ruleId":"D17","level":"error","message":{"text":"EmptyCatchBlock: empty catch block \u2014 the error is discarded with nothing recorded, so a failure here leaves no trace anywhere. Narrow the catch to the exception you actually expect, record it through whatever this codebase already uses to report problems, or \u2014 where swallowing really is correct, as it often is on a teardown/dispose path where throwing would mask the original failure \u2014 write down WHY in a comment on the catch. The comment has to give the reason: a note that only restates the swallow (\u0022ignored\u0022, \u0022do nothing\u0022) is read as no explanation at all and leaves this row in place. Any of the three makes the decision reviewable; all three clear this row."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/InstallView/ToolHelper.cs"},"region":{"startLine":103}}}],"partialFingerprints":{"codehealthFindingId/v1":"d05ee12a9b1a5547845e3c89bb4e2aee9d89b2bb386d44064465f996da08a094"}},{"ruleId":"D18","level":"warning","message":{"text":"Monorepo: only 1 of 3 solutions was scored: This repository contains 3 .NET solutions, but a scan analyzes ONE. Every score, lens, and finding here reflects only \u0060Flyoobe.sln\u0060 \u2014 the other 2 (\u0060Flyby11-deprecated/Flyby11.sln\u0060, \u0060Flyoobe.ToolSpot-deprecated/Flyoobe.Spot.sln\u0060) were not analyzed and are not represented in the headline. To cover them, scan each solution as its own target and group them in a Solution or Product for a portfolio roll-up. If a secondary solution is an archived or vendored tree, declare it \u2014 \u0060.gitattributes\u0060 (\u0060path/** linguist-vendored\u0060) or \u0060.editorconfig\u0060 (\u0060[path/**] generated_code = true\u0060) \u2014 to exclude it from discovery the same way generated code is."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"447bb11e4227696119972b805fcb72d3ced918b47fcda508d1efcfafe347e404"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found at common paths; consider documenting architectural decisions in Docs/ADL/ or similar."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D24","level":"note","message":{"text":"redundant comment: \u0022--- Soft, clean themes ---\u0022 \u2014 delete - it restates the softness of the theme style."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Flyoobe/Helper/BackgroundHelper.cs"},"region":{"startLine":190}}}],"partialFingerprints":{"codehealthFindingId/v1":"385330c383558297f4ca0f7f5d95e2fe4c81957280f39010f61662ea28d0ed09"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"78b180c2f2c37dadb8fb7b7f9f5eb81ad3d1d4d42b9b31ee70791b8a98ebc2cf"}},{"ruleId":"D28","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3cdfd7beb31b791ae18dcb425e21eb157c842e7bbcd522cc330573c1a6538db1"}},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"09a3c8a36b0cbee7a600ab009eb07de2e24f0865128de1ec0fee27b6c34afba8"},"taxa":[{"id":"CWE-22","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D34","level":"note","message":{"text":"Dormant codebase: 43 of 44 significant files have no living knowledge \u2014 the codebase as a whole is dormant, not 43 separate risks. Re-engage owners or document before change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4c69f1e54b7dd6fe9029dd02df6ba8f8145b789f2f18dbdaa086c40ded49dba6"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-22","guid":"b68d9ca7-bdde-d057-a6cc-9f8b1e739552","name":"CWE-22","shortDescription":{"text":"CWE-22"},"helpUri":"https://cwe.mitre.org/data/definitions/22.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":3,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}