{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D10","name":"Test Quality","shortDescription":{"text":"Test Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D10"},{"id":"D11","name":"Test Reliability","shortDescription":{"text":"Test Reliability"},"helpUri":"https://codehealth.canine.dev/dimensions/D11"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D22","name":"Internal API Consistency","shortDescription":{"text":"Internal API Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D22"},{"id":"D23","name":"Boundary Type-Coupling","shortDescription":{"text":"Boundary Type-Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D23"},{"id":"D24","name":"Comment Value","shortDescription":{"text":"Comment Value"},"helpUri":"https://codehealth.canine.dev/dimensions/D24"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D39","name":"IL Efficiency","shortDescription":{"text":"IL Efficiency"},"helpUri":"https://codehealth.canine.dev/dimensions/D39"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"NSBUnitOfWork.MutateIncoming (cyclomatic 19): NSBUnitOfWork.MutateIncoming has cyclomatic complexity 19 (threshold 15). Of this number, 10 points are the body\u0027s own statements and 9 belong to one function literal inside it that branches. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.NServiceBus/Internal/NSBUnitOfWork.cs"},"region":{"startLine":18}}}],"partialFingerprints":{"codehealthFindingId/v1":"cdfab58be4f71c1c4901460f4b2f126f75259495db84e195e64e1b4f362238a4"}},{"ruleId":"D2","level":"warning","message":{"text":"EventStoreClient.CreateProjection (cognitive 28): EventStoreClient.CreateProjection has cognitive complexity 28 (threshold 15). To reduce it, flatten the nesting: invert conditions into early returns or guard clauses so the happy path stays at one level, and lift the deepest nested block into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.EventStore/Internal/EventStoreClient.cs"},"region":{"startLine":219}}}],"partialFingerprints":{"codehealthFindingId/v1":"ef24cc8c9f8fa24b3fd765449100efd3e478aaedbac65fd69364afc5650831d3"}},{"ruleId":"D2","level":"warning","message":{"text":"UnitOfWorkExecutor.Invoke (cognitive 17): UnitOfWorkExecutor.Invoke has cognitive complexity 17 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.NServiceBus/Internal/UnitOfWorkExecutor.cs"},"region":{"startLine":29}}}],"partialFingerprints":{"codehealthFindingId/v1":"468396b4952be2256c84abe32fc6801a99e126df34f0ccb4d41b9cf01dd3a7ca"}},{"ruleId":"D2","level":"warning","message":{"text":"CommandAcceptor.Invoke (cognitive 16): CommandAcceptor.Invoke has cognitive complexity 16 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.NServiceBus/Internal/CommandAcceptor.cs"},"region":{"startLine":26}}}],"partialFingerprints":{"codehealthFindingId/v1":"1dff4dcb25b38fed8198f83f9ee6a7646fe0bdb3658598c5c2851506b236c1bb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): src/Aggregates.NET.EventStore/Internal/EventStoreClient.cs:108-120 | src/Aggregates.NET.EventStore/Internal/EventStoreClient.cs:134-146 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Aggregates.NET.EventStore/Internal/EventStoreClient.cs:108\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.EventStore/Internal/EventStoreClient.cs"},"region":{"startLine":108}}}],"partialFingerprints":{"codehealthFindingId/v1":"b21d0fe985724f0c6304e6d374b0017a1d7f26f8a670f41d72b720003ab70267"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): src/Aggregates.NET/Internal/UnitOfWork.cs:152-160 | src/Aggregates.NET.NServiceBus/Internal/NSBUnitOfWork.cs:71-80 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET/Internal/UnitOfWork.cs"},"region":{"startLine":152}}}],"partialFingerprints":{"codehealthFindingId/v1":"b217f727ef01f93c0ff883528d2ae3e43ba6f58886a4971b1ad32d48d472d704"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): src/Aggregates.NET.NServiceBus/Internal/NSBMutator.cs:14-19 | src/Aggregates.NET.NServiceBus/Internal/NSBMutator.cs:25-30 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Aggregates.NET.NServiceBus/Internal/NSBMutator.cs:14\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.NServiceBus/Internal/NSBMutator.cs"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"392dc5401c75069221a3465f5d4a0836a584b8509b37ca0b180a07a937c49acc"}},{"ruleId":"D10","level":"warning","message":{"text":"No assertions: ShouldPassDefinedRule: Test method exercises code but verifies nothing \u2014 add an assertion."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.UnitTests/Common/Entity.cs"},"region":{"startLine":126}}}],"partialFingerprints":{"codehealthFindingId/v1":"5b5e540315a9457991bb1cb7bcc32851865b8ae2273d0f3fdeefac780de5f590"}},{"ruleId":"D10","level":"warning","message":{"text":"No assertions: ShouldGetAStringHash: Test method exercises code but verifies nothing \u2014 add an assertion."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.UnitTests/Common/Extensions/String.cs"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"0d518e88d4bd2cc2f65d09dceb52fd0faf466e6a1c57433880a7da200fc50ebf"}},{"ruleId":"D10","level":"warning","message":{"text":"No assertions: ShouldCreateIdFromString: Test method exercises code but verifies nothing \u2014 add an assertion."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.UnitTests/Common/Id.cs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"3773f77a01206af3ae4f5fb941ef13f225d2b3cd3cbab8b1cf990454d0cc9f9b"}},{"ruleId":"D10","level":"warning","message":{"text":"No assertions: ShouldCreateIdFromGuid: Test method exercises code but verifies nothing \u2014 add an assertion."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.UnitTests/Common/Id.cs"},"region":{"startLine":15}}}],"partialFingerprints":{"codehealthFindingId/v1":"5ed6b7f45c6a6b45aa7fefc7a40e524365c68e49f46a5dc34af355c351ec74ec"}},{"ruleId":"D10","level":"warning","message":{"text":"No assertions: ShouldCreateIdFromLong: Test method exercises code but verifies nothing \u2014 add an assertion."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.UnitTests/Common/Id.cs"},"region":{"startLine":22}}}],"partialFingerprints":{"codehealthFindingId/v1":"8d0f64ba0b89d7a41dbdce105f033557fae4fcaae5f448a29b2dc754cb8a456a"}},{"ruleId":"D10","level":"error","message":{"text":"No assertions (empty test): ShouldWriteOutgoingHeaders: Test method has an empty body \u2014 it asserts nothing and exercises no code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.UnitTests/NServiceBus/NSBUnitOfWork.cs"},"region":{"startLine":22}}}],"partialFingerprints":{"codehealthFindingId/v1":"51668cbd0848e1f319e9067176c2993d1f83dfb414d937f611c7d7770a1ed9b7"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: xunit: xunit 2.6.6 \u2014 Legacy \u2014 the publisher\u0027s replacement is \u0060xunit.v3\u0060; migrate the reference to it."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d37c8c0e8046c9e8358e976373216abfb78e9fdef63ed53d3edcaa7d2238edcd"}},{"ruleId":"D16","level":"warning","message":{"text":"dormant codebase \u2014 no living knowledge left to concentrate: All 45 significant source file(s) were last meaningfully changed so long ago that no living knowledge remains \u2014 nothing since has been substantial enough to re-establish ownership (a broad, mechanical sweep that touches many files shallowly does not count, and neither does no activity at all). There is no concentration to measure, so the bus factor is not scored. This is not a clean bill: nobody currently holds working knowledge of this code (see D34 Knowledge Freshness)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"569d55ea5cb0330f13c125b289d07e5abdfcceac947a2c2645277937942e7d5f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // Todo: when implementing another eventstore, dont copy this, do it a better way \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.EventStore/ESConfigure.cs"},"region":{"startLine":94}}}],"partialFingerprints":{"codehealthFindingId/v1":"8ce1333c1ee5267faff1d6bea88229ca9c077464021563ffb53a749737791f72"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: the client will eventually have \u0022emit\u0022 option"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.EventStore/Internal/EventStoreClient.cs"},"region":{"startLine":232}}}],"partialFingerprints":{"codehealthFindingId/v1":"51ae77dbaae27e1073ee640f634bd9762a2fd23dd1ad0e5c21b1ed5f077504d6"}},{"ruleId":"D17","level":"error","message":{"text":"EmptyCatchBlock: empty catch block \u2014 the error is discarded with nothing recorded, so a failure here leaves no trace anywhere. Narrow the catch to the exception you actually expect, record it through whatever this codebase already uses to report problems, or \u2014 where swallowing really is correct, as it often is on a teardown/dispose path where throwing would mask the original failure \u2014 write down WHY in a comment on the catch. The comment has to give the reason: a note that only restates the swallow (\u0022ignored\u0022, \u0022do nothing\u0022) is read as no explanation at all and leaves this row in place. Any of the three makes the decision reviewable; all three clear this row."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.EventStore/Internal/EventStoreClient.cs"},"region":{"startLine":243}}}],"partialFingerprints":{"codehealthFindingId/v1":"ece94a0c7adfe89e108f3d7a377091137d2c95af0692c65a69162c39aed4ab9c"}},{"ruleId":"D17","level":"error","message":{"text":"EmptyCatchBlock: empty catch block \u2014 the error is discarded with nothing recorded, so a failure here leaves no trace anywhere. Narrow the catch to the exception you actually expect, record it through whatever this codebase already uses to report problems, or \u2014 where swallowing really is correct, as it often is on a teardown/dispose path where throwing would mask the original failure \u2014 write down WHY in a comment on the catch. The comment has to give the reason: a note that only restates the swallow (\u0022ignored\u0022, \u0022do nothing\u0022) is read as no explanation at all and leaves this row in place. Any of the three makes the decision reviewable; all three clear this row."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.EventStore/Internal/EventStoreClient.cs"},"region":{"startLine":252}}}],"partialFingerprints":{"codehealthFindingId/v1":"55c895293144388f92bf6223f645c84b2f0e9f6ab2a4fc2ca930d7a1ce316aa6"}},{"ruleId":"D17","level":"error","message":{"text":"EmptyCatchBlock: empty catch block \u2014 the error is discarded with nothing recorded, so a failure here leaves no trace anywhere. Narrow the catch to the exception you actually expect, record it through whatever this codebase already uses to report problems, or \u2014 where swallowing really is correct, as it often is on a teardown/dispose path where throwing would mask the original failure \u2014 write down WHY in a comment on the catch. The comment has to give the reason: a note that only restates the swallow (\u0022ignored\u0022, \u0022do nothing\u0022) is read as no explanation at all and leaves this row in place. Any of the three makes the decision reviewable; all three clear this row."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.NServiceBus/Internal/NServiceBusMessaging.cs"},"region":{"startLine":40}}}],"partialFingerprints":{"codehealthFindingId/v1":"e911188366a17729b57bd5fe46afca2ffebd8def28851ae0abc512d536c0916b"}},{"ruleId":"D17","level":"error","message":{"text":"EmptyCatchBlock: empty catch block \u2014 the error is discarded with nothing recorded, so a failure here leaves no trace anywhere. Narrow the catch to the exception you actually expect, record it through whatever this codebase already uses to report problems, or \u2014 where swallowing really is correct, as it often is on a teardown/dispose path where throwing would mask the original failure \u2014 write down WHY in a comment on the catch. The comment has to give the reason: a note that only restates the swallow (\u0022ignored\u0022, \u0022do nothing\u0022) is read as no explanation at all and leaves this row in place. Any of the three makes the decision reviewable; all three clear this row."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.NServiceBus/Internal/NServiceBusMessaging.cs"},"region":{"startLine":55}}}],"partialFingerprints":{"codehealthFindingId/v1":"9e53898449476ff48bfa25759a4254b960a204196885cea931f30b68ec4b17cb"}},{"ruleId":"D17","level":"error","message":{"text":"EmptyCatchBlock: empty catch block \u2014 the error is discarded with nothing recorded, so a failure here leaves no trace anywhere. Narrow the catch to the exception you actually expect, record it through whatever this codebase already uses to report problems, or \u2014 where swallowing really is correct, as it often is on a teardown/dispose path where throwing would mask the original failure \u2014 write down WHY in a comment on the catch. The comment has to give the reason: a note that only restates the swallow (\u0022ignored\u0022, \u0022do nothing\u0022) is read as no explanation at all and leaves this row in place. Any of the three makes the decision reviewable; all three clear this row."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.NServiceBus/Internal/NServiceBusMessaging.cs"},"region":{"startLine":70}}}],"partialFingerprints":{"codehealthFindingId/v1":"58245c6b75585da9135bcd2ed336faf46073bcc3695eaa16f9337014e3165df1"}},{"ruleId":"D17","level":"error","message":{"text":"EmptyCatchBlock: empty catch block \u2014 the error is discarded with nothing recorded, so a failure here leaves no trace anywhere. Narrow the catch to the exception you actually expect, record it through whatever this codebase already uses to report problems, or \u2014 where swallowing really is correct, as it often is on a teardown/dispose path where throwing would mask the original failure \u2014 write down WHY in a comment on the catch. The comment has to give the reason: a note that only restates the swallow (\u0022ignored\u0022, \u0022do nothing\u0022) is read as no explanation at all and leaves this row in place. Any of the three makes the decision reviewable; all three clear this row."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET/Internal/VersionRegistrar.cs"},"region":{"startLine":112}}}],"partialFingerprints":{"codehealthFindingId/v1":"96022bbc32a5be01adc9e624f4b754c7c0c7e6e54b59a9af2296fc3d45f146d5"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // Todo: is it necessary to ensure JSON.parse works? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.EventStore/Internal/EventStoreConsumer.cs"},"region":{"startLine":75}}}],"partialFingerprints":{"codehealthFindingId/v1":"b52cf6bb372eea9d731d6638b9086f2e01f12e8f76c09b11fc9ffebd99dbbba2"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: not sure this is needed anymore since NSb uses microsoft too now \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.NServiceBus/NSBConfigure.cs"},"region":{"startLine":149}}}],"partialFingerprints":{"codehealthFindingId/v1":"af8e8c0357db28b502c94841cb85ba36ae1eb02390ded0b6c1cbd466da429899"}},{"ruleId":"D17","level":"warning","message":{"text":"CommentedOutCode: 5 consecutive commented-code lines"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.NewtonsoftJson/Internal/JsonMessageSerializer.cs"},"region":{"startLine":68}}}],"partialFingerprints":{"codehealthFindingId/v1":"f9414aad3559e9020b2d4218ecc44d1191cf7ebd42767c4d3d8117a3cdb85a2c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // Todo: this is where I would substitute the type info with a unique string to represent the object without namespaces \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.NewtonsoftJson/Internal/ResolverBinder.cs"},"region":{"startLine":78}}}],"partialFingerprints":{"codehealthFindingId/v1":"94920b4a06b93ae21f4c79f29832bdf32448b5990a813ceb58553de4cd9e1d68"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // Todo: Can use a simple duck type helper incase snapshot type != TState due to refactor or something \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET/Internal/EntityFactory.cs"},"region":{"startLine":44}}}],"partialFingerprints":{"codehealthFindingId/v1":"2b493fdbadfb0bc2a2615349e19aaa709a20e680d142028026a433f034797b8c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // Todo: creating the projection is dependant on EventStore - which defeats the purpose of the different assembly \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET/Internal/EventSubscriber.cs"},"region":{"startLine":44}}}],"partialFingerprints":{"codehealthFindingId/v1":"51574b76de6264486e11398542208f01a0921eb4bd70e42ae264a7fb1fd0ae3b"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // Todo: cheap hack NSB creates events as IEvent__impl \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET/Internal/MutateState.cs"},"region":{"startLine":51}}}],"partialFingerprints":{"codehealthFindingId/v1":"71bcb8f09c37be95f31b5dfc3b37c82292bfded19ca87c381f279e7af49ec62f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // Todo: can suport \u0022named\u0022 events with an attribute here so instead of routing based on object type \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET/Internal/MutateState.cs"},"region":{"startLine":58}}}],"partialFingerprints":{"codehealthFindingId/v1":"e09794b0be30cfa25072f15d32a0e2ceec53edb9e35bae7fcae90e6656f0bc35"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // Todo: both units of work should come from the pipeline not the container \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET/Internal/Processor.cs"},"region":{"startLine":33}}}],"partialFingerprints":{"codehealthFindingId/v1":"54e61f941499e1fdfe87de46e8be507566bb4eb52ce0b4c5b606846a574fc50c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // Todo: too many operations on this class, make a \u0022EntityWriter\u0022 contract which does event, oob, and snapshot writing \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET/Internal/Repository.cs"},"region":{"startLine":94}}}],"partialFingerprints":{"codehealthFindingId/v1":"760f10627d1bbc8f8a49a4b8deef23fdc9050373e8b2698c1702b161a0917040"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // Todo: pass parent instead of Id[]? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET/Internal/StoreEntities.cs"},"region":{"startLine":83}}}],"partialFingerprints":{"codehealthFindingId/v1":"b5e230d820486b04aee9add902ed8e9e7f1c94c09197b6ad075594032280e0b1"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // Todo: if we are to set the eventid here its important that an event is processed in the same order every retry \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET/Internal/UnitOfWork.cs"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"cef76ccc3060b7bc0a88931a5aefdd08c10452afe8f372d71a348b3c2a4a5cc3"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // Todo: If current message is an event, detect if they\u0027ve modified any entities and warn them. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET/Internal/UnitOfWork.cs"},"region":{"startLine":99}}}],"partialFingerprints":{"codehealthFindingId/v1":"46fe39854ee6d551b9422fd45da314495f0cf0a3b338f0b6cd3cb10598343788"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // Todo: what else can we put in here? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET/Internal/UnitOfWork.cs"},"region":{"startLine":120}}}],"partialFingerprints":{"codehealthFindingId/v1":"3417a40bc66acdd668923e1dd8448558ef95d02b72d86aa9823697d8c6853d4a"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // todo: with the private contract resolver is this needed? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET/State.cs"},"region":{"startLine":18}}}],"partialFingerprints":{"codehealthFindingId/v1":"cc5ed8dc92e5344469d4f5ade35c8a4399a473b1527bc1b3bacd39ebdaabc93a"}},{"ruleId":"D17","level":"warning","message":{"text":"Dead code: NSBMutator: NamedType NSBMutator \u2014 no references found in solution."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.NServiceBus/Internal/NSBMutator.cs"},"region":{"startLine":11}}}],"partialFingerprints":{"codehealthFindingId/v1":"024f39a41e002921333a9c607cbde1903c3a8677d74b8f2876a5d6c336d2d518"}},{"ruleId":"D18","level":"warning","message":{"text":"Monorepo: only 1 of 7 solutions was scored: This repository contains 7 .NET solutions, but a scan analyzes ONE. Every score, lens, and finding here reflects only \u0060Aggregates.NET.sln\u0060 \u2014 the other 6 (\u0060cake/Build.sln\u0060, \u0060samples/1. HelloWorld/HelloWorld.sln\u0060, \u0060samples/2.. Snapshots/Snapshots.sln\u0060, \u0060samples/3. Children/Children.sln\u0060, \u0060samples/4. Queries/Queries.sln\u0060, \u0060samples/5. Saga/Saga.sln\u0060) were not analyzed and are not represented in the headline. To cover them, scan each solution as its own target and group them in a Solution or Product for a portfolio roll-up. If a secondary solution is an archived or vendored tree, declare it \u2014 \u0060.gitattributes\u0060 (\u0060path/** linguist-vendored\u0060) or \u0060.editorconfig\u0060 (\u0060[path/**] generated_code = true\u0060) \u2014 to exclude it from discovery the same way generated code is."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"60e62c5f19ed3809b8c3aaea09b7c5ca33066021cf382e20dc7ad33245a1d260"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found at common paths; consider documenting architectural decisions in Docs/ADL/ or similar."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent naming for repository retrieval operations. Some use \u0027Get\u0027 while others use \u0027Plan\u0027 for similar retrieval/lookup operations on entities.: Standardize on \u0027Get\u0027 for retrieval operations, or \u0027Plan\u0027 if the operation is specifically about planning a query. (symbols: Aggregates.Internal.TestableRepository\u003CTEntity, TState, TParent\u003E.Plan(Aggregates.Internal.TestableId), Aggregates.Internal.TestableRepository\u003CTEntity, TState, TParent\u003E.Plan(Aggregates.Id), Aggregates.Internal.TestableRepository\u003CTEntity, TState, TParent\u003E.Get(Aggregates.Id), Aggregates.Contracts.IRepository\u003CTEntity, TParent\u003E.Get(Aggregates.Id))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"355d6dbad1b9a18e5cfd4754294d21cde67e2d387cc4abda48b6866f61881756"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent naming for verification/checking operations. Some use \u0027Check\u0027 while others use \u0027Raised\u0027 or \u0027EventChecker\u0027 for similar verification logic.: Standardize on \u0027Check\u0027 for verification methods, or \u0027Raised\u0027 if the method specifically checks for raised events. (symbols: Aggregates.Internal.TestableRepository\u003CTEntity, TState, TParent\u003E.Check(Aggregates.Id), Aggregates.IEventChecker\u003CTEntity\u003E.Raised\u003CTEvent\u003E(System.Action\u003CTEvent\u003E), Aggregates.Internal.EventChecker\u003CTEntity, TState\u003E.Check\u003CTChild\u003E(Aggregates.Id))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"007c57f9b05c541a356fa853d64fbbd49494cf190ebb0049ed6b8cd7e1fc99a1"}},{"ruleId":"D21","level":"note","message":{"text":"Duplicate method name \u0027Plan\u0027 with different parameter types (TestableId vs Id) causing ambiguity.: Rename one of the \u0027Plan\u0027 methods to reflect the difference, e.g., \u0027PlanWithTestableId\u0027. (symbols: Aggregates.Internal.TestableRepository\u003CTEntity, TState, TParent\u003E.Plan(Aggregates.Internal.TestableId), Aggregates.Internal.TestableRepository\u003CTEntity, TState, TParent\u003E.Plan(Aggregates.Id))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f4d8221866c6c4d83c7d67e5900d42e6259f55982067112fd71b6f22608e43b8"}},{"ruleId":"D21","level":"note","message":{"text":"Overloaded method \u0027Plan\u0027 exists with different parameter types, which can be confusing.: Consider renaming to \u0027PlanWithTestableId\u0027 and \u0027PlanWithId\u0027 for clarity. (symbols: Aggregates.Internal.TestableRepository\u003CTEntity, TState, TParent\u003E.Plan(Aggregates.Internal.TestableId), Aggregates.Internal.TestableRepository\u003CTEntity, TState, TParent\u003E.Plan(Aggregates.Id))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5673d46dce96198dadea7e225ccf43ddec8e1e882d7410969b30977edfc6ebbf"}},{"ruleId":"D21","level":"note","message":{"text":"The method \u0027Plan\u0027 is overloaded with different parameter types, which can be confusing.: Rename to \u0027PlanWithTestableId\u0027 and \u0027PlanWithId\u0027 for clarity. (symbols: Aggregates.Internal.TestableRepository\u003CTEntity, TState, TParent\u003E.Plan(Aggregates.Internal.TestableId), Aggregates.Internal.TestableRepository\u003CTEntity, TState, TParent\u003E.Plan(Aggregates.Id))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7f06b74717449f7ddb0d05736f17f690cc00200ae5c469d7d66d8439d566cd03"}},{"ruleId":"D22","level":"warning","message":{"text":"Inconsistent naming for retrieval operations. \u0027Get\u0027 implies a mandatory return (or exception on failure), while \u0027TryGet\u0027 implies a safe, non-throwing retrieval. However, both \u0027Get\u0027 and \u0027TryGet\u0027 in the interface return the entity (not a bool/optional), making the semantic difference between \u0027Get\u0027 and \u0027TryGet\u0027 confusing. Additionally, \u0027Get\u0027 and \u0027TryGet\u0027 have identical signatures (plus bucket), suggesting they might be redundant or one should return an optional/nullable type instead of throwing.: Standardize on \u0027Get\u0027 for mandatory retrieval and \u0027TryGet\u0027 for optional retrieval. If \u0027TryGet\u0027 still returns the entity, consider changing the return type to \u0027TEntity?\u0027 or \u0027Result\u003CTEntity\u003E\u0027 to clearly distinguish success/failure paths. Alternatively, if \u0027TryGet\u0027 is just a wrapper that doesn\u0027t throw, rename it to \u0027GetSafe\u0027 or similar to avoid confusion with the standard \u0027Try\u0027 pattern. (signatures: Task\u003CTEntity\u003E IRepository\u003CTEntity\u003E.Get(Id id) | Task\u003CTEntity\u003E IRepository\u003CTEntity\u003E.Get(string bucket, Id id) | Task\u003CTEntity\u003E IRepository\u003CTEntity\u003E.TryGet(Id id) | Task\u003CTEntity\u003E IRepository\u003CTEntity\u003E.TryGet(string bucket, Id id))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c4c7686a51cc6f1a26f877aeebb715ab5bbd8773dcb02ca5b5f18ed780a5f48d"}},{"ruleId":"D22","level":"warning","message":{"text":"The child entity repository interface duplicates the \u0027Get\u0027 and \u0027TryGet\u0027 naming convention but omits the \u0027bucket\u0027 parameter found in the parent interface. This creates an inconsistent API surface where the same operation (retrieval) has different parameters depending on the generic signature, which is confusing for consumers.: Align the child entity repository with the parent repository by adding the \u0027bucket\u0027 parameter to \u0027Get\u0027 and \u0027TryGet\u0027 methods, or explicitly document that child entities are scoped to a single bucket. (signatures: Task\u003CTEntity\u003E IRepository\u003CTEntity, TParent\u003E.Get(Id id) | Task\u003CTEntity\u003E IRepository\u003CTEntity, TParent\u003E.TryGet(Id id) | Task\u003CTEntity\u003E IRepository\u003CTEntity, TParent\u003E.New(Id id))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5a9117864d53ec47d82f63a2c7eecb8a1ff145498bcf78fe42e9e1893cae0c69"}},{"ruleId":"D22","level":"warning","message":{"text":"Redundant/Confusing service execution patterns. \u0027ContextExtensions.Service\u0027 and \u0027IProcessor.Process\u0027 both handle service execution. \u0027ContextExtensions\u0027 offers overloads for both direct service instances and Action\u003CT\u003E delegates, while \u0027IProcessor\u0027 also offers both. This suggests a duplication of intent: is the context extension the public API or the processor? The naming \u0027Service\u0027 vs \u0027Process\u0027 is inconsistent for the same conceptual operation.: Consolidate service execution into one primary path. If \u0027ContextExtensions\u0027 is the public API, ensure \u0027IProcessor\u0027 doesn\u0027t duplicate this functionality. Rename \u0027Service\u0027 and \u0027Process\u0027 to a unified term like \u0027Execute\u0027 or \u0027Handle\u0027 if they serve the same purpose. (signatures: Task\u003CTResponse\u003E ContextExtensions.Service\u003CTService, TResponse\u003E(IServiceContext context, TService service) | Task\u003CTResponse\u003E ContextExtensions.Service\u003CTService, TResponse\u003E(IServiceContext context, Action\u003CTService\u003E service) | Task\u003CTResponse\u003E IProcessor.Process\u003CTService, TResponse\u003E(TService service, IServiceProvider container) | Task\u003CTResponse\u003E IProcessor.Process\u003CTService, TResponse\u003E(Action\u003CTService\u003E service, IServiceProvider container))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ade5abdf66e9ba4ac398a4cd5e914a5b635f2771747dd3ba9d9d947844b85414"}},{"ruleId":"D22","level":"warning","message":{"text":"Inconsistent setup methods for event consumption. \u0027IEventSubscriber\u0027 uses \u0027Setup\u0027 for general endpoints, while \u0027IEventStoreConsumer\u0027 uses \u0027SetupProjection\u0027 and \u0027SetupChildrenProjection\u0027. This splits the concept of \u0027starting to listen\u0027 into multiple methods with different signatures and naming conventions.: Unify the entry point for starting event consumption. Use a consistent naming convention like \u0027Subscribe\u0027 or \u0027StartListening\u0027 across all consumer interfaces. (signatures: void IEventSubscriber.Setup(string endpoint, Version version) | Task IEventStoreConsumer.SetupProjection(string endpoint, Version version, Type[] eventTypes) | Task IEventStoreConsumer.SetupChildrenProjection(string endpoint, Version version))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b2fe7d290ae016ca2c1c07c778b0455135428da29c438ac0db5cc7a9658a5f1c"}},{"ruleId":"D23","level":"note","message":{"text":"Bounded contexts not declared: At 6457 LoC across 6 projects the codebase is large and multi-module, so explicit bounded contexts are needed. Name this codebase\u0027s bounded contexts (\u22652 module groups, e.g. per subsystem) so cross-boundary type coupling can be assessed. Declare them in \u0060.codehealth/config.yaml\u0060 at the repository root (create it if absent), mapping each context name to the module-path or namespace prefixes that belong to it \u2014 e.g. \u0060architecture:\u0060 \u2192 \u0060contexts:\u0060 \u2192 \u0060Billing: [\u0022src/billing\u0022, \u0022Acme.Billing\u0022]\u0060, \u0060Catalog: [\u0022src/catalog\u0022, \u0022Acme.Catalog\u0022]\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1c7e276c9c682731f01819ed5378b90ca320cde1b583c90920172911598362b3"}},{"ruleId":"D27","level":"note","message":{"text":"Scattered collaborators: 92 % of calls cross a namespace and only 42 % of collaborators are co-located \u2014 group each feature\u0027s code into a vertical slice so a call\u0027s collaborators sit together."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5aad4a4530bac3928d3a065a664be89d023ecfc865f9bf79ac05754b3bffe322"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a9b844b6c8c1cd10c637ec0a93e254d503dd4fd0ae1081566e79ce9e5ec0ef8e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d68f7101d68f81a416c587fc75c184582e6f28ddb6e0d8e7a2fea42efc952904"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ac3bcaf026786b4bec9392921f4c030f96915025efa32bb45a880f8b734de1bc"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e3632e55b46df1fce32551c4d37b9305330cf39c6f8a7b19caa612bbbdf68eb3"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"43b8b9a99d4467ac226addbcecf55934ce57e0ae0a930e02d9c37bc412849f86"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4642dd55dc3bb4a6567207f90bcd79bef31f9280d0913ee9f753e5b4b1909943"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6dce551ad0772915991268b48355e7bf243d3c3769abb7d52c41656d4c955758"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7cef61eb07287f430b020c18b4ebe1bda309219c2d91d00ec31fe26ba818598e"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0ec952ada219fe5a028e3a8aa8d56d26ded08861b1152c70e1e8a6609e9450b6"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"068575b070ffb9472759a5be2e330d4c53d1995ff99ab12cb083c0e36c781f83"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7cf85abffe732f2645ef95a624d6badc26f0263616284d6a4cc46ca8e983031d"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b96b7173c4377d5bea4d6fd7b52323631c631c44172b743bec6f266c10a4e538"}},{"ruleId":"D34","level":"note","message":{"text":"Dormant codebase: 45 of 45 significant files have no living knowledge \u2014 the codebase as a whole is dormant, not 45 separate risks. Re-engage owners or document before change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4c69f1e54b7dd6fe9029dd02df6ba8f8145b789f2f18dbdaa086c40ded49dba6"}},{"ruleId":"D34","level":"note","message":{"text":"Largest orphaned file: One of the largest files with no living knowledge remaining \u2014 a reasonable place to start a read-through before the aggregate risk above bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.EventStore/Internal/EventStoreClient.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"4c84afdc011506501411b2eb1a1b255886efbf4d496c7d7bb91b9f7bd68d98e3"}},{"ruleId":"D34","level":"note","message":{"text":"Largest orphaned file: One of the largest files with no living knowledge remaining \u2014 a reasonable place to start a read-through before the aggregate risk above bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cake/Program.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"76f8110909f470e625535156e537f89881d59d8adafec02ccfbbc25c414a3407"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: MutateIncoming.cs \u2194 MutateOutgoing.cs: \u0060src/Aggregates.NET.NServiceBus/Internal/MutateIncoming.cs\u0060 and \u0060src/Aggregates.NET.NServiceBus/Internal/MutateOutgoing.cs\u0060 change together 56% of the time (9 of the 16 commits that touched the less-changed of the two, renames followed). They sit in the same directory, and in this ecosystem sibling files there normally share one namespace/package \u2014 so a direct reference between them needs no import and this pass cannot see whether one exists. Read the pair before acting: if one file only DECLARES what the other consumes (a constants/types file beside its user), the co-change is definitional and the question is whether the split earns its keep; if they duplicate structure, extract the common part into a shared function or type they both call; if neither holds, the coupling is hidden and worth breaking."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Aggregates.NET.NServiceBus/Internal/MutateIncoming.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"68637f2bcbf48aea5085518c95e015a07340c9efbfc6659e3aad77b6ab01cfd1"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":12,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}