{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AX9","name":"CQS / query purity","shortDescription":{"text":"CQS / query purity"},"helpUri":"https://codehealth.canine.dev/dimensions/AX9"},{"id":"AXB1","name":"Runtime evidence locked \u2014 no reproducible boot","shortDescription":{"text":"Runtime evidence locked \u2014 no reproducible boot"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB1"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P2","name":"Observability","shortDescription":{"text":"Observability"},"helpUri":"https://codehealth.canine.dev/dimensions/P2"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X31","name":"Test-only surface in a production module","shortDescription":{"text":"Test-only surface in a production module"},"helpUri":"https://codehealth.canine.dev/dimensions/X31"},{"id":"X32","name":"Type resolved by simple name across every loaded assembly","shortDescription":{"text":"Type resolved by simple name across every loaded assembly"},"helpUri":"https://codehealth.canine.dev/dimensions/X32"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D2","level":"warning","message":{"text":"chronicle_agent.preprocess_entries_loop (cognitive 18): chronicle_agent.preprocess_entries_loop has cognitive complexity 18 (threshold 15). Drivers by points: match/switch 6 (18 pts) (nesting depth added 12). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_agent.erl"},"region":{"startLine":1829}}}],"partialFingerprints":{"codehealthFindingId/v1":"32a6ea04eea6b3933466be1283138858ce3d3906525a652674e09170cd54661c"}},{"ruleId":"D2","level":"warning","message":{"text":"chronicle_status.failover_peer_status (cognitive 17): chronicle_status.failover_peer_status has cognitive complexity 17 (threshold 15). Drivers by points: match/switch 8 (16 pts), if/else 1 (nesting depth added 8). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_status.erl"},"region":{"startLine":338}}}],"partialFingerprints":{"codehealthFindingId/v1":"05f980ef1c074015fe3c9fd47f55d065c1b9aa9e12aff0706658dec4dd36d2aa"}},{"ruleId":"D2","level":"warning","message":{"text":"chronicle_agent.check_join_cluster (cognitive 16): chronicle_agent.check_join_cluster has cognitive complexity 16 (threshold 15). Drivers by points: match/switch 8 (16 pts) (nesting depth added 8). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_agent.erl"},"region":{"startLine":1439}}}],"partialFingerprints":{"codehealthFindingId/v1":"2efbca8fd80c5bef94a038e68aaba3e796b3e44667a8ecbaf74db3f541d65faa"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/chronicle_agent.erl: FileTooLong \u2014 2308 significant lines (blank, comment-only and punctuation-only lines excluded), declaring 218 functions. The bar is 500 significant lines; this is 1808 over it, 4.62\u00D7 the bar. In this language a module is exactly one source file, so its length cannot be moved into sibling files of the same module. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no one module has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_agent.erl"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"5e48c0eb66e4980bd5b3cb7b2af8a6196defbad2925dcbc7f25c87117d7b0103"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/chronicle_proposer.erl: FileTooLong \u2014 1626 significant lines (blank, comment-only and punctuation-only lines excluded), declaring 135 functions. The bar is 500 significant lines; this is 1126 over it, 3.25\u00D7 the bar. In this language a module is exactly one source file, so its length cannot be moved into sibling files of the same module. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no one module has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_proposer.erl"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f471d3dbb83b3fe5bb9787a4e4e45eefd58063ce9f719607f5756397ac9551d9"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/chronicle_rsm.erl: FileTooLong \u2014 1340 significant lines (blank, comment-only and punctuation-only lines excluded), declaring 125 functions. The bar is 500 significant lines; this is 840 over it, 2.68\u00D7 the bar. In this language a module is exactly one source file, so its length cannot be moved into sibling files of the same module. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no one module has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_rsm.erl"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"576d6df513fe499b76d6ff8e5bb79819e06a387cd44b05fa65f4a0d633c4e20b"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/chronicle_storage.erl: FileTooLong \u2014 1317 significant lines (blank, comment-only and punctuation-only lines excluded), declaring 132 functions. The bar is 500 significant lines; this is 817 over it, 2.63\u00D7 the bar. In this language a module is exactly one source file, so its length cannot be moved into sibling files of the same module. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no one module has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_storage.erl"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e83120dc16e78ae7fe5bf4475ed72ff434aca43dd8314add2313c6ce88215e57"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFunctions: chronicle: TooManyFunctions \u2014 65 functions. The bar is 30 functions; this is 35 over it, 2.17\u00D7 the bar. The counted members are a module\u0027s functions \u2014 a module holds no instance state, so there is no shared data to group them by and no type to move them onto. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no single module carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle.erl"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"50672919d9fd8d1cbf87aff5103344bad36787e9f37b1df20c5072d5e40c235e"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/chronicle_leader.erl: FileTooLong \u2014 1011 significant lines (blank, comment-only and punctuation-only lines excluded), declaring 114 functions. The bar is 500 significant lines; this is 511 over it, 2.02\u00D7 the bar. In this language a module is exactly one source file, so its length cannot be moved into sibling files of the same module. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no one module has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_leader.erl"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a80cf53d02bc728927ffd38dae512cb7b9a6e6c85dd7f92d59b1954359fc05da"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/chronicle_utils.erl: FileTooLong \u2014 857 significant lines (blank, comment-only and punctuation-only lines excluded), declaring 78 functions. The bar is 500 significant lines; this is 357 over it, 1.71\u00D7 the bar. In this language a module is exactly one source file, so its length cannot be moved into sibling files of the same module. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no one module has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_utils.erl"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e7480695495581b4b217c0d1663f8c46efa6ee1792d191552b2fe54fc14f20da"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFunctions: chronicle_config: TooManyFunctions \u2014 51 functions. The bar is 30 functions; this is 21 over it, 1.70\u00D7 the bar. The counted members are a module\u0027s functions \u2014 a module holds no instance state, so there is no shared data to group them by and no type to move them onto. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no single module carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_config.erl"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"09b6ce0a84140e6777c71578987b7ecc9acbfd568cde103b9245631e44282c7c"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/chronicle_kv.erl: FileTooLong \u2014 843 significant lines (blank, comment-only and punctuation-only lines excluded), declaring 106 functions. The bar is 500 significant lines; this is 343 over it, 1.69\u00D7 the bar. In this language a module is exactly one source file, so its length cannot be moved into sibling files of the same module. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no one module has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_kv.erl"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"cd9bc8da2347ee9d583975c29217df305a79434a11828f2bb75419ae946553d6"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFunctions: chronicle_config_rsm: TooManyFunctions \u2014 49 functions. The bar is 30 functions; this is 19 over it, 1.63\u00D7 the bar. The counted members are a module\u0027s functions \u2014 a module holds no instance state, so there is no shared data to group them by and no type to move them onto. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no single module carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_config_rsm.erl"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"b71a04c1b0c73dfcd5e5b83b1d0b9f2dc80435a5620825730bb057514144ceb8"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFunctions: chronicle_server: TooManyFunctions \u2014 47 functions. The bar is 30 functions; this is 17 over it, 1.57\u00D7 the bar. The counted members are a module\u0027s functions \u2014 a module holds no instance state, so there is no shared data to group them by and no type to move them onto. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no single module carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_server.erl"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"328b2fb4ca82dd44cd303e4d45d80d91994aafe30af3a8b221ca036dd3e0516f"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFunctions: chronicle_dump: TooManyFunctions \u2014 40 functions. The bar is 30 functions; this is 10 over it, 1.33\u00D7 the bar. The counted members are a module\u0027s functions \u2014 a module holds no instance state, so there is no shared data to group them by and no type to move them onto. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no single module carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/chronicle_dump/chronicle_dump.erl"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"2bd63de200c039da58261ee648a543c96c15e4e39d40633c47cbcb4bf80d018f"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFunctions: chronicle_status: TooManyFunctions \u2014 37 functions. The bar is 30 functions; this is 7 over it, 1.23\u00D7 the bar. The counted members are a module\u0027s functions \u2014 a module holds no instance state, so there is no shared data to group them by and no type to move them onto. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no single module carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_status.erl"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"85ca5ad1aafa62cc6777cf883a4463a219b66bd06dee452deb065f24d4ca1e67"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFunctions: chronicle_snapshot_mgr: TooManyFunctions \u2014 35 functions. The bar is 30 functions; this is 5 over it, 1.17\u00D7 the bar. The counted members are a module\u0027s functions \u2014 a module holds no instance state, so there is no shared data to group them by and no type to move them onto. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no single module carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_snapshot_mgr.erl"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"ffc0f571a80ae4ed8626f230202bddd78ffcbacdc96566ced306f35039fdd855"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): src/chronicle_leader.erl:801-811 | src/chronicle_leader.erl:922-932 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_leader.erl"},"region":{"startLine":801}}}],"partialFingerprints":{"codehealthFindingId/v1":"9b8e9c2669739e3ef086eb3a4b200dec23204d510e4b5f172b3a79cfaaa72127"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): src/chronicle_kv.erl:746-752 | src/chronicle_kv.erl:756-763 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_kv.erl"},"region":{"startLine":746}}}],"partialFingerprints":{"codehealthFindingId/v1":"9b74a5d3bb76796bf8a5e5fbe32d4b228f796a367c2c36777868fc55be7ff233"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): scripts/chronicle_dump/chronicle_dump.erl:70-74 | scripts/chronicle_dump/chronicle_dump.erl:210-214 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/chronicle_dump/chronicle_dump.erl"},"region":{"startLine":70}}}],"partialFingerprints":{"codehealthFindingId/v1":"6ad81fa75901c3c2c3a74946af05b96003c8ab3db5bd994158cb7a7666c9f2dd"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): src/chronicle_agent_sup.erl:29-36 | src/chronicle_secondary_restartable_sup.erl:29-33 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_agent_sup.erl"},"region":{"startLine":29}}}],"partialFingerprints":{"codehealthFindingId/v1":"d9259d4aa77096d6fe50f2639432c8ce9f347fe48c618114b7905ea8634b3f7d"}},{"ruleId":"D12","level":"warning","message":{"text":"Unbounded dependency requirement: chronicle: Runtime dependency \u0060chronicle\u0060 is declared in examples/chronicled/rebar.config as a bare name with no version requirement, so \u0060rebar3\u0060 is free to resolve ANY release of it \u2014 including the next major one, which can break the build without a line changing in this repository. Give it a bounded requirement (e.g. \u0060{chronicle, \u0022~\u003E 1.0\u0022}\u0060)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a46a9aa7ff5affcc5528248632510e297a24ab39407632d698b7ac9dc2bc7509"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: reconsider the strategy \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_sup.erl"},"region":{"startLine":30}}}],"partialFingerprints":{"codehealthFindingId/v1":"b6ae4b0d13c018f84f365f081dbcbe2306eb987d8f1dd24ba77779516fc373eb"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: reconsider the strategy \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_secondary_sup.erl"},"region":{"startLine":66}}}],"partialFingerprints":{"codehealthFindingId/v1":"e4e171eaa71978155347cdba0e60a84547aeeed1934287d2d41768df7a22cc85"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: reconsider the strategy \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_rsm_sup.erl"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"35f385779634a87e812baf7cf5b57fba9bf73db02cb00097de8fdd7ead7abf3c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: revise shutdown specifications \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_sup.erl"},"region":{"startLine":36}}}],"partialFingerprints":{"codehealthFindingId/v1":"420d25201757bfef8e48f0cf8e7257d17068d8b6874286bbd59c078ea7afb8fe"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: revise shutdown specifications \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_secondary_sup.erl"},"region":{"startLine":77}}}],"partialFingerprints":{"codehealthFindingId/v1":"acb1a22acbba18ba38fa0bb5ba34f41bb48360b2ba75ec203e14902724595b1d"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: In many respects log entry handlers duplicate the code in functions \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_storage.erl"},"region":{"startLine":406}}}],"partialFingerprints":{"codehealthFindingId/v1":"c25bb3a16bb5dc95d2649fadb7e97ebaec78d6c083355a125ed772bf101a174a"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: move managing of this metadata to chronicle_storage \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_storage.erl"},"region":{"startLine":1109}}}],"partialFingerprints":{"codehealthFindingId/v1":"2a5ca5400c7693812114461d8b24a23eb102a33d32cc33e012a8834de359d02a"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: make this optional \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_single_rsm_sup.erl"},"region":{"startLine":32}}}],"partialFingerprints":{"codehealthFindingId/v1":"6761dcc55763e072427a6e94cead139d27df99fc726e1761ef57a37fdc24c125"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: reconsider the decision to have proposer run in a separate process \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_server.erl"},"region":{"startLine":43}}}],"partialFingerprints":{"codehealthFindingId/v1":"9b3e41bb6f0e7576b90c7a9d1d91e5fc21dcb0688876312025ef581f599dc228"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: this is going to wake up the process needlessly \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_rsm_sup.erl"},"region":{"startLine":40}}}],"partialFingerprints":{"codehealthFindingId/v1":"0539bcbeccdf84a9cd68344488ac237cc700992732e770a0a108c12415228355"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: deal with {error, no_rsm} \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_rsm.erl"},"region":{"startLine":1519}}}],"partialFingerprints":{"codehealthFindingId/v1":"75be505b1e6853c3072347174b1b7391fe45390b1037cabe4aa7ac95de5e25f7"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: reconsider what\u0027s needed and what\u0027s not needed here \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_proposer.erl"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"95fd98a801c04065a6f85f2de486152e67089bd85397b61b8d465933f15b8022"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: handle the latter case better \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_proposer.erl"},"region":{"startLine":603}}}],"partialFingerprints":{"codehealthFindingId/v1":"3d44023f356fc738a3f85b4e8924ac2d40b478181a0238b07b84c58070ae0428"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: right now when this function is called we replicate the proposal in \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_proposer.erl"},"region":{"startLine":1330}}}],"partialFingerprints":{"codehealthFindingId/v1":"1f7660502062cb01e6f60f4d7f3d8937bdc1e14269d513ef244479ed283a8a29"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: demonitor_agents() is needed to make sure that if there are any \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_proposer.erl"},"region":{"startLine":1699}}}],"partialFingerprints":{"codehealthFindingId/v1":"b6243ecc01be86a22f96e7eabffd7c0277d53cf326749b2eafba0404fb6e190d"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: consider triggerring catchup even if we\u0027ve got all the \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_proposer.erl"},"region":{"startLine":1758}}}],"partialFingerprints":{"codehealthFindingId/v1":"5e67458c3d876c651315ff16267cc6872d5aca743c48c331eadc327564b41e22"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: consider using a different data structure for pending entries \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_proposer.erl"},"region":{"startLine":1781}}}],"partialFingerprints":{"codehealthFindingId/v1":"2279c48f4453fa887edcc97d7689ca32430f971cd052ffc8ecd585a860a221f7"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: preallocate log when possible and use fdatasync instead of sync. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_log.erl"},"region":{"startLine":100}}}],"partialFingerprints":{"codehealthFindingId/v1":"8f339636e28954fd8c70780357acd4667a6d710b3bbc1a714e61b7cb535409e0"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: This is a temprorary kludge making ns_server\u0027s life a bit \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_kv.erl"},"region":{"startLine":578}}}],"partialFingerprints":{"codehealthFindingId/v1":"afc4f624101bc6d6fa160a0072d44312251e40189baaf75f3aa1d86f0b551f5a"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: I could actually check that whoever\u0027s writing is the owner of the \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_ets.erl"},"region":{"startLine":36}}}],"partialFingerprints":{"codehealthFindingId/v1":"b815e4155f6085eec77e437fe9c3402f98501b48f0853c80847df2d9a1b06c43"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: figure out what to do with replicas \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_config.erl"},"region":{"startLine":147}}}],"partialFingerprints":{"codehealthFindingId/v1":"915a535a0a6c51c6b57c18d305fe5a66a277b6ee2184b83fec1e456049bd71b6"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: check more state invariants \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_agent.erl"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"64ae0e647a706a86ac5ec1f5256cb4d8047c9bb25a31909712eea6db53189ef9"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: change it to use committed config \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_agent.erl"},"region":{"startLine":242}}}],"partialFingerprints":{"codehealthFindingId/v1":"470b37ac64fdb198d4132d220f4bb36d7016d369da9f318dbee40e5c0973e1c6"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: avoid O(NumberOfStateMachines * NumberOfEntries) complexity. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_agent.erl"},"region":{"startLine":363}}}],"partialFingerprints":{"codehealthFindingId/v1":"255e4b7ac78e008ea6a58e4a6591e2f45baf9a837c49210131ca7da529744be6"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: consider simply skipping the position check for this case \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_agent.erl"},"region":{"startLine":842}}}],"partialFingerprints":{"codehealthFindingId/v1":"9a7a941333b79c78f35f9ddc74d730296ddbd7160b551a53a5b2ed0985b1f034"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: It\u0027s pretty wasteful to publish this on every change when most \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_agent.erl"},"region":{"startLine":883}}}],"partialFingerprints":{"codehealthFindingId/v1":"bc6378a40acc5876ae9fa9e100b6cf787570e5884224f36d933198440e429c30"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: this extreme coupling between the two processes is \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_agent.erl"},"region":{"startLine":1490}}}],"partialFingerprints":{"codehealthFindingId/v1":"3a330c47d999e564458854f5bdae481d3b19a8a26e2c5483cded6bbb48b0b38e"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: in-progress snapshots might need to be canceled if any of the \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_agent.erl"},"region":{"startLine":1662}}}],"partialFingerprints":{"codehealthFindingId/v1":"394ee81f9991ef6159a16222e4983007d730679b26ee87520a82343db9ec1e92"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: it should be enough to compare histories and \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_agent.erl"},"region":{"startLine":1849}}}],"partialFingerprints":{"codehealthFindingId/v1":"0472d36496c4ce5d4dc7261877d74e5a74a6ccdb7a993b207d297f6968d3af1e"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_agent.erl"},"region":{"startLine":2334}}}],"partialFingerprints":{"codehealthFindingId/v1":"a4ec79fc67626e41c46f36126147e9b770c5ee6c2b00db6152dfc2c1e3a2486f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: depending on specifics of how RSM deletions are handled, \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_agent.erl"},"region":{"startLine":2647}}}],"partialFingerprints":{"codehealthFindingId/v1":"01b86d3b2458307c85275a3853485852d11368e34f53b9d6b47150de5cf96dc6"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: currently a hefty timeout is required here because nodeup events \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"test/chronicle_tests.erl"},"region":{"startLine":528}}}],"partialFingerprints":{"codehealthFindingId/v1":"25fb907baaf885d54b00b83f935ddfa9620ff278fecef347027dc017f3328c72"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no installation or build instructions: The \u0027Build\u0027 section is real but the only build command shown is \u0060rebar3 as examples compile\u0060 and no install instructions are given. Add a one-line install instruction for rebar3 (or an alternative tool) so new contributors can get started without reading the entire shell block."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"examples/chronicled/README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"673ddb440be567bd97916f75ee5d86887429eee7473ccecdd456da28e9266c78"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found. No recognised ADR directory (\u0060docs/adr/\u0060, \u0060docs/decisions/\u0060, \u0060adr/\u0060, \u0060docs/rfcs/\u0060, an \u0060ADR0001/\u0060 folder, or their siblings) exists anywhere in this tree. What was searched, so you can tell an empty log from a search that missed one: every directory under the tree (build output, dependencies and VCS metadata excepted), for a document that is either any non-index page inside a recognised ADR directory, whatever its name and however deeply nested (\u0060docs/adr/use-postgres.md\u0060, \u0060docs/adr/2024/0001-x.md\u0060); or a file anywhere whose name is ADR-shaped (\u00600001-use-postgres.md\u0060, \u0060adr-012-caching.md\u0060); or, when neither turned anything up, a document carrying the decision-record signature (an \u0022Architecture Decision Record\u0022 heading, or Status / Context / Decision / Consequences as section headings). A decision log that clears none of these \u2014 unnumbered files outside any recognised directory, without those headings \u2014 is not seen by this check and this row is then wrong. If that is your case, say so rather than renaming anything; otherwise, consider recording architectural decisions in \u0060docs/adr/\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D26","level":"note","message":{"text":"Projects may be oversized for their cohesion: 1 of 1 project(s) overshoot their size bounds, lowering Project Cohesion to 0.0/10. The most over is \u0060(repository root)\u0060 (14344 LoC, 243 public types across 2 directories). Review these for cohesion \u2014 draw the boundary inside the module first (group each responsibility into its own package or directory and keep the cross-boundary members non-public), since splitting a published package moves types between packages and breaks consumers."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d5a94650dc74886a0f1f08eb9fb6775f1fc395279ef7e901c970c9d26f767a72"}},{"ruleId":"D34","level":"note","message":{"text":"Dormant codebase: 21 of 27 significant files have no living knowledge \u2014 the codebase as a whole is dormant, not 21 separate risks. Counted over 27 of the 33 production source files in this repository: the rest are under the ~2,400-byte size floor this dimension measures over. Re-engage owners or document before change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4c69f1e54b7dd6fe9029dd02df6ba8f8145b789f2f18dbdaa086c40ded49dba6"}},{"ruleId":"D34","level":"note","message":{"text":"Most significant orphaned file: One of the orphaned files carrying the most lost knowledge \u2014 ranked by size weighted by the file\u0027s role in the codebase, the same weighting behind the score above, so core code outranks equally large plumbing. A reasonable place to start a read-through before the aggregate risk above bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_agent.erl"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"7906cee3beb21b7bf385aaa7398a83fed020fdf7bc37f899ec0dba70f2d762fb"}},{"ruleId":"D34","level":"note","message":{"text":"Most significant orphaned file: One of the orphaned files carrying the most lost knowledge \u2014 ranked by size weighted by the file\u0027s role in the codebase, the same weighting behind the score above, so core code outranks equally large plumbing. A reasonable place to start a read-through before the aggregate risk above bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_leader.erl"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"4fe65df76781bbc25e52c73777bea4a22c1b4dfafc0ebec20e0b1d012d5b3858"}},{"ruleId":"D34","level":"note","message":{"text":"Most significant orphaned file: One of the orphaned files carrying the most lost knowledge \u2014 ranked by size weighted by the file\u0027s role in the codebase, the same weighting behind the score above, so core code outranks equally large plumbing. A reasonable place to start a read-through before the aggregate risk above bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/chronicle_kv.erl"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"82ff3db258359ed337292cf6ce605bd7fb5b77de09a95c85f1438b168ba3245e"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"M2","level":"note","message":{"text":"No architecture diagram/doc: No C4/Structurizr/PlantUML/Mermaid/Graphviz/D2 diagram, no drawn diagram named for the architecture, no file named \u0060architecture\u0060 or \u0060design\u0060 in any markup this check reads, and nothing in the README, docs or contributor guides that announces the shape \u2014 no \u0060## Architecture\u0060 heading, no \u0022architecture overview\u0022/\u0022high-level design\u0022 phrasing, no \u0022the architecture is \u2026\u0022 introduction, no guided code tour. A shape laid out in prose that never names itself as the architecture is not visible to this check, and neither is one kept outside the repository, so this row reports the absence of a re-findable shape document \u2014 not evidence that nobody wrote the shape down."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0c190e7c159d1850ee706c3ac4486e151e8a4fe169de4bf61436b9f399654f06"}},{"ruleId":"M4","level":"note","message":{"text":"README/code drift: README claims Couchbase Server uses Chronicle but no project or file references it \u2014 searched for: \u0060Couchbase\u0060. Each was matched case- and separator-insensitively against file and directory NAMES anywhere in the tree, and against the CONTENTS of manifest files (package.json, *.csproj, *.props, *.slnx, *.yml, Dockerfile); the README\u0027s own prose never counts, so a claim is never refuted by merely being made. Nothing outside that search was read \u2014 a footprint living only in a submodule, in a file type not listed here, or under a name none of those terms matches is not seen, and this row is then wrong."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"bc103d14aa334c0bb1a1dabb4fdd8815a931ac16445730097ea52c0e30f24187"}},{"ruleId":"M4","level":"note","message":{"text":"README/code drift: README claims Chronicle implements Raft consensus protocol with pre-vote and exactly-once writes; evidence contains no Raft implementation \u2014 reported by the model that read the README against this repository; no term search was run for this one, so nothing here has been checked against the tree. Treat it as a reading to confirm, not as a measured contradiction: verify it against the code before acting on it, and if the footprint it describes does exist, this row is wrong."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"8c306400bac7554f13bd85dd895950a1e0399e1c018a2aa3ecb68b86dca08dc1"}},{"ruleId":"P1","level":"warning","message":{"text":"No CI pipeline: No CI workflow found (.github/workflows, azure-pipelines.yml, .gitlab-ci.yml, \u2026) \u2014 changes aren\u0027t gated by an automated build/test."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"44f01af96e50474fba2df84d95ddf4f7e1d34c29c307830b9efc9057daa6b670"}},{"ruleId":"P3","level":"note","message":{"text":"No SAST: No static application security testing detected. For this repository\u0027s stack, add dialyzer or elvis \u2014 this repository has no CI pipeline yet, so run it locally to clear the existing findings, then make it a step of the first workflow you add so a regression fails the build. What was searched, so you can tell an absence from a miss: the 0 CI workflow file(s) in this repository, and the scanner and linter configuration checked in beside them. A scan that runs outside CI, one configured in your forge\u0027s web UI rather than in a committed file, or a tool whose name is none of those this check carries, is not seen \u2014 if that is your case the row is wrong, and saying so is more useful than adding a second scanner."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6e54424179c892f03ef2fd003130ac4bd43f39bbf3b1ca0a0143e25acb80ec87"}},{"ruleId":"P6","level":"note","message":{"text":"No changelog: No CHANGELOG/HISTORY/RELEASES file \u2014 what shipped when isn\u0027t easy to reconstruct for support or audit. (Versioning/tagging makes releases traceable, but a changelog records the what.)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"dda5aa5aed8cbb292c3ef2b733bc138f614293ae6426c85e98bf31ef330d9415"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":0,"secretScannerRunsExcluded":0}}}]}