{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D10","name":"Test Quality","shortDescription":{"text":"Test Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D10"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D37","name":"Vulnerability-disclosure Policy","shortDescription":{"text":"Vulnerability-disclosure Policy"},"helpUri":"https://codehealth.canine.dev/dimensions/D37","relationships":[{"target":{"id":"CWE-1059","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1059"]}},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P10","name":"Library API \u0026 versioning","shortDescription":{"text":"Library API \u0026 versioning"},"helpUri":"https://codehealth.canine.dev/dimensions/P10"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P2","name":"Observability","shortDescription":{"text":"Observability"},"helpUri":"https://codehealth.canine.dev/dimensions/P2"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"PF3","name":"Async \u0026 latency hygiene","shortDescription":{"text":"Async \u0026 latency hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/PF3"},{"id":"R1","name":"Type Safety","shortDescription":{"text":"Type Safety"},"helpUri":"https://codehealth.canine.dev/dimensions/R1"},{"id":"R10","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/R10"},{"id":"R11","name":"Import Boundaries","shortDescription":{"text":"Import Boundaries"},"helpUri":"https://codehealth.canine.dev/dimensions/R11"},{"id":"R2","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/R2"},{"id":"R3","name":"Large Files","shortDescription":{"text":"Large Files"},"helpUri":"https://codehealth.canine.dev/dimensions/R3"},{"id":"R4","name":"Test Coverage","shortDescription":{"text":"Test Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/R4"},{"id":"R6","name":"Tooling","shortDescription":{"text":"Tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/R6"},{"id":"R7","name":"Dead Code","shortDescription":{"text":"Dead Code"},"helpUri":"https://codehealth.canine.dev/dimensions/R7"},{"id":"R8","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/R8"},{"id":"R9","name":"Circular Imports","shortDescription":{"text":"Circular Imports"},"helpUri":"https://codehealth.canine.dev/dimensions/R9"},{"id":"S1","name":"Web-Security Posture","shortDescription":{"text":"Web-Security Posture"},"helpUri":"https://codehealth.canine.dev/dimensions/S1"},{"id":"SC1","name":"Supply-chain hygiene","shortDescription":{"text":"Supply-chain hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/SC1"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X24","name":"Document value interpolated into markup unescaped","shortDescription":{"text":"Document value interpolated into markup unescaped"},"helpUri":"https://codehealth.canine.dev/dimensions/X24"},{"id":"X25","name":"Inert configuration knob","shortDescription":{"text":"Inert configuration knob"},"helpUri":"https://codehealth.canine.dev/dimensions/X25"},{"id":"X26","name":"Unsynchronised callback handoff","shortDescription":{"text":"Unsynchronised callback handoff"},"helpUri":"https://codehealth.canine.dev/dimensions/X26"},{"id":"X29","name":"Per-element action decided by a fixed element","shortDescription":{"text":"Per-element action decided by a fixed element"},"helpUri":"https://codehealth.canine.dev/dimensions/X29"},{"id":"X32","name":"Type resolved by simple name across every loaded assembly","shortDescription":{"text":"Type resolved by simple name across every loaded assembly"},"helpUri":"https://codehealth.canine.dev/dimensions/X32"},{"id":"X6","name":"Hand-rolled structured-format parsing","shortDescription":{"text":"Hand-rolled structured-format parsing"},"helpUri":"https://codehealth.canine.dev/dimensions/X6"},{"id":"X7","name":"Silent fallback defaults","shortDescription":{"text":"Silent fallback defaults"},"helpUri":"https://codehealth.canine.dev/dimensions/X7"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"slateRemark.slateToRemark (cyclomatic 73): slateRemark.slateToRemark has cyclomatic complexity 73 (threshold 15). Of this number, 66 points are the body\u0027s own statements and 7 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/slateRemark.js"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"03eec9039ece8c7428d1cd6afdcf11234a95f69f5825db76df8a4130df0a53e4"}},{"ruleId":"D1","level":"warning","message":{"text":"slateRemark.slateToRemark (cyclomatic 71): slateRemark.slateToRemark has cyclomatic complexity 71 (threshold 15). Of this number, 65 points are the body\u0027s own statements and 6 belong to 2 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-richtext/src/serializers/slateRemark.js"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"4aa5e8056e39b313f49f17d098bdc1495836eaa48cbbf3aec2e08573eeafa8ac"}},{"ruleId":"D1","level":"warning","message":{"text":"remarkSlate.remarkToSlate (cyclomatic 46): remarkSlate.remarkToSlate has cyclomatic complexity 46 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkSlate.js"},"region":{"startLine":82}}}],"partialFingerprints":{"codehealthFindingId/v1":"b946edc15e98d3e926e9fa73176279947dffe66ffe2eda896efc4971841e0fe9"}},{"ruleId":"D1","level":"warning","message":{"text":"remarkSlate.remarkToSlate (cyclomatic 44): remarkSlate.remarkToSlate has cyclomatic complexity 44 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-richtext/src/serializers/remarkSlate.js"},"region":{"startLine":76}}}],"partialFingerprints":{"codehealthFindingId/v1":"3c6276d0fcc5691815ecc54637e1ee9cd945b9ede2708e413c3289ea1534ab89"}},{"ruleId":"D1","level":"warning","message":{"text":"config.applyDefaults (cyclomatic 40): config.applyDefaults has cyclomatic complexity 40 (threshold 15). Most of this is not in the body itself: 1 of the 40 points is its own statement and the rest belongs to one function literal inside it that branches (line 232). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/actions/config.ts"},"region":{"startLine":231}}}],"partialFingerprints":{"codehealthFindingId/v1":"66aa285a04bdcc35759e8610667d3f7daa33d13598da95e79e1f6d5c66fe7def"}},{"ruleId":"D1","level":"warning","message":{"text":"entryDraft.entryDraftReducer (cyclomatic 38): entryDraft.entryDraftReducer has cyclomatic complexity 38 (threshold 15). Of this number, 31 points are the body\u0027s own statements and 7 belong to 3 function literals inside it that branch. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/reducers/entryDraft.js"},"region":{"startLine":72}}}],"partialFingerprints":{"codehealthFindingId/v1":"d0656679c83d18e83e21b9c15fdab772a939d9196e44cfb0757c5137b1594ce7"}},{"ruleId":"D1","level":"warning","message":{"text":"mediaLibrary.mediaLibrary (cyclomatic 37): mediaLibrary.mediaLibrary has cyclomatic complexity 37 (threshold 15). Of this number, 30 points are the body\u0027s own statements and 7 belong to 4 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/reducers/mediaLibrary.ts"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"61e0cc05ad7f1b31cb7836c11ec12709c677435d978b6652ddebc24e35cd1f21"}},{"ruleId":"D1","level":"warning","message":{"text":"index.localGitMiddleware (cyclomatic 36): index.localGitMiddleware has cyclomatic complexity 36 (threshold 15). Most of this is not in the body itself: 1 of the 36 points is its own statement and the rest belongs to 4 function literals inside it that branch (lines 179, 331, 257, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-server/src/middlewares/localGit/index.ts"},"region":{"startLine":173}}}],"partialFingerprints":{"codehealthFindingId/v1":"268b8d2b61f08df5f1cec898a7dfbb35bb996f77b1e7db8f2f079b78c60bf285"}},{"ruleId":"D1","level":"warning","message":{"text":"withFileControl.withFileControl (cyclomatic 29): withFileControl.withFileControl has cyclomatic complexity 29 (threshold 15). Most of this is not in the body itself: 11 of the 29 points are its own statements and the rest belongs to 10 function literals inside it that branch (lines 454, 388, 397, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-file/src/withFileControl.js"},"region":{"startLine":240}}}],"partialFingerprints":{"codehealthFindingId/v1":"a75f55d5561524a1bb9cfdd46731c0ab76e831ba6175990ae5612e521bf426e1"}},{"ruleId":"D1","level":"warning","message":{"text":"remarkToSlate::convertNode (cyclomatic 28): remarkToSlate::convertNode has cyclomatic complexity 28 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkSlate.js"},"region":{"startLine":235}}}],"partialFingerprints":{"codehealthFindingId/v1":"2d524cc8547b3831b00176a83a5f29ef8b22f31144e7f226a5535476bdc174c4"}},{"ruleId":"D1","level":"warning","message":{"text":"slateToRemark::convertBlockNode (cyclomatic 26): slateToRemark::convertBlockNode has cyclomatic complexity 26 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-richtext/src/serializers/slateRemark.js"},"region":{"startLine":322}}}],"partialFingerprints":{"codehealthFindingId/v1":"67ffea01557081e0118260df3935ac6a7850c0f76d7c60012cba1d686d298b0d"}},{"ruleId":"D1","level":"warning","message":{"text":"remarkToSlate::convertNode (cyclomatic 26): remarkToSlate::convertNode has cyclomatic complexity 26 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-richtext/src/serializers/remarkSlate.js"},"region":{"startLine":229}}}],"partialFingerprints":{"codehealthFindingId/v1":"ed6aa183fd6c1c9169cb6eec68b9c078f7d92c959bcd65184300d479dbc9390e"}},{"ruleId":"D1","level":"warning","message":{"text":"slateToRemark::convertBlockNode (cyclomatic 25): slateToRemark::convertBlockNode has cyclomatic complexity 25 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/slateRemark.js"},"region":{"startLine":328}}}],"partialFingerprints":{"codehealthFindingId/v1":"4dd614c597a62af8f909430fd836eadc29a7bc4ca944b292d6c731de1129ed21"}},{"ruleId":"D1","level":"warning","message":{"text":"GitGateway.authenticate (cyclomatic 22): GitGateway.authenticate has cyclomatic complexity 22 (threshold 15). Most of this is not in the body itself: 2 of the 22 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 296, 307, 283, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-git-gateway/src/implementation.ts"},"region":{"startLine":279}}}],"partialFingerprints":{"codehealthFindingId/v1":"1da7fe51de3d4a1f930f5ce2546b19aeca77d5048bd2910952b8969b750ec20a"}},{"ruleId":"D1","level":"warning","message":{"text":"formatters.commitMessageFormatter (cyclomatic 22): formatters.commitMessageFormatter has cyclomatic complexity 22 (threshold 15). Most of this is not in the body itself: 6 of the 22 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 69, 91). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/lib/formatters.ts"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"04cc7eac71c9a333aa83a7459a35cfad03c5858efee3450a2ecd51fdf32a7ba2"}},{"ruleId":"D1","level":"warning","message":{"text":"EditorToolbar.renderWorkflowControls (cyclomatic 22): EditorToolbar.renderWorkflowControls has cyclomatic complexity 22 (threshold 15). Of this number, 21 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/Editor/EditorToolbar.js"},"region":{"startLine":599}}}],"partialFingerprints":{"codehealthFindingId/v1":"052ca49d9a4290ebc7dd84eeef7479e0235eae4f90daf3fe45f68f1ea9a29b6b"}},{"ruleId":"D1","level":"warning","message":{"text":"renderWorkflowStatusControls::renderWorkflowControls (cyclomatic 22): renderWorkflowStatusControls::renderWorkflowControls has cyclomatic complexity 22 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/Editor/EditorToolbar.js"},"region":{"startLine":599}}}],"partialFingerprints":{"codehealthFindingId/v1":"d1ee11abed79ff3a4083074fed9ea07324008308ab646f0ab8c488450e1485f9"}},{"ruleId":"D1","level":"warning","message":{"text":"Backend.persistEntry (cyclomatic 21): Backend.persistEntry has cyclomatic complexity 21 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/backend.ts"},"region":{"startLine":1246}}}],"partialFingerprints":{"codehealthFindingId/v1":"314bcd3faaeeec92f537dd71447bbe4291a20b2d740536b7e9bf091064857fa6"}},{"ruleId":"D1","level":"warning","message":{"text":"MediaLibraryModal.MediaLibraryModal (cyclomatic 20): MediaLibraryModal.MediaLibraryModal has cyclomatic complexity 20 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/MediaLibrary/MediaLibraryModal.js"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"2998427af7a7c61d703682bb10f1ce5404787e93a787884bca0d792e72cccbe0"}},{"ruleId":"D1","level":"warning","message":{"text":"Toolbar.render (cyclomatic 20): Toolbar.render has cyclomatic complexity 20 (threshold 15). Of this number, 19 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/Toolbar.js"},"region":{"startLine":105}}}],"partialFingerprints":{"codehealthFindingId/v1":"9648b03d1618af6978fa1da357f45594eb76bb01e8abed29f6f11b049352bd80"}},{"ruleId":"D1","level":"warning","message":{"text":"remarkShortcodes.createInlineShortcodeTokenizer (cyclomatic 20): remarkShortcodes.createInlineShortcodeTokenizer has cyclomatic complexity 20 (threshold 15). Of this number, 10 points are the body\u0027s own statements and 10 belong to 3 function literals inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkShortcodes.js"},"region":{"startLine":88}}}],"partialFingerprints":{"codehealthFindingId/v1":"3a5e7c5eae1c85e89ce03ffa1ed99b5ec21c26c8bfa437d61e12133c0334055b"}},{"ruleId":"D1","level":"warning","message":{"text":"GitHub.constructor (cyclomatic 18): GitHub.constructor has cyclomatic complexity 18 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-github/src/implementation.tsx"},"region":{"startLine":99}}}],"partialFingerprints":{"codehealthFindingId/v1":"010f8c80f77854572ad6bec031f89ed0816e2572c14b7477282f737452ecc64d"}},{"ruleId":"D1","level":"warning","message":{"text":"GitLab.constructor (cyclomatic 18): GitLab.constructor has cyclomatic complexity 18 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-gitlab/src/implementation.ts"},"region":{"startLine":93}}}],"partialFingerprints":{"codehealthFindingId/v1":"9d554be238b0b724a1058123200353af8dcd292e25282117afb947ab6e35922b"}},{"ruleId":"D1","level":"warning","message":{"text":"InlineShortcode.InlineShortcode (cyclomatic 17): InlineShortcode.InlineShortcode has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/components/InlineShortcode.js"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"a495b566921359d97ea50819068ce31100740c04464e3ef625345fa0a8304723"}},{"ruleId":"D1","level":"warning","message":{"text":"withLists (cyclomatic 17): withLists has cyclomatic complexity 17 (threshold 15). Most of this is not in the body itself: 2 of the 17 points are its own statements and the rest belongs to 5 function items inside it that branch (normalizeNode, isListItem::match, isListItem, \u2026). Those helpers are already separate functions, so extracting the branching again is not available. To reduce it, move them out of the body to the enclosing scope, where each is measured, reviewed and tested on its own, and reduce whichever one then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/plugins/lists/withLists.js"},"region":{"startLine":7}}}],"partialFingerprints":{"codehealthFindingId/v1":"f213db61279f200b848e2db6e332439f260958a9c804d47af5328c9277a9f935"}},{"ruleId":"D1","level":"warning","message":{"text":"BitbucketBackend.constructor (cyclomatic 16): BitbucketBackend.constructor has cyclomatic complexity 16 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-bitbucket/src/implementation.ts"},"region":{"startLine":95}}}],"partialFingerprints":{"codehealthFindingId/v1":"dd4fb0adbc8d58488ea76c3aeed197423bb6a42ca2c8ef259304453980b08890"}},{"ruleId":"D1","level":"warning","message":{"text":"EditorControl.render (cyclomatic 16): EditorControl.render has cyclomatic complexity 16 (threshold 15). Most of this is not in the body itself: 4 of the 16 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 251, 272). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/Editor/EditorControlPane/EditorControl.js"},"region":{"startLine":197}}}],"partialFingerprints":{"codehealthFindingId/v1":"61c3c560aa8f0e27d08b41f6af480b816b5a1fc13059e103de9a402d42b5e6bf"}},{"ruleId":"D1","level":"warning","message":{"text":"PKCEAuthenticationPage.normalizeClaimsToUser (cyclomatic 16): PKCEAuthenticationPage.normalizeClaimsToUser has cyclomatic complexity 16 (threshold 15). Most of this is not in the body itself: 1 of the 16 points is its own statement and the rest belongs to one function literal inside it that branches (line 19). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-ui-auth/src/PKCEAuthenticationPage.js"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"9ddd7f4688dba7a8eee99cfbc9b6c8bc64a6e4dd3a9dcfcdb974f429623c7f90"}},{"ruleId":"D1","level":"warning","message":{"text":"remarkRehypeShortcodes.remarkToRehypeShortcodes (cyclomatic 16): remarkRehypeShortcodes.remarkToRehypeShortcodes has cyclomatic complexity 16 (threshold 15). Of this number, 11 points are the body\u0027s own statements and 5 belong to one function literal inside it that branches. To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkRehypeShortcodes.js"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"137261b5db9002dc78f0f96c7b4a05a81e81aa3fdcd11c168c12927eb9190b33"}},{"ruleId":"D1","level":"warning","message":{"text":"withHtml.deserialize (cyclomatic 16): withHtml.deserialize has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/plugins/html/withHtml.js"},"region":{"startLine":75}}}],"partialFingerprints":{"codehealthFindingId/v1":"c3f71e4bd7a1d25c1c2ef94cc55b87d7a0852fc7dbf0fe2a40d923cd187e05b0"}},{"ruleId":"D2","level":"warning","message":{"text":"config.applyDefaults (cognitive 69): config.applyDefaults has cognitive complexity 69 (threshold 15). Drivers by points: if/else 25 (51 pts), boolean chains 14, loops 2 (4 pts) (nesting depth added 28). Most of this is not in the body itself: 0 of the 69 points are its own statements and the rest belongs to one function literal inside it that branches (line 232). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/actions/config.ts"},"region":{"startLine":231}}}],"partialFingerprints":{"codehealthFindingId/v1":"b5310dc17a7726d74f7091d854e6b7a0681ed5066dbd6bb20cf989e51e573aa5"}},{"ruleId":"D2","level":"warning","message":{"text":"slateRemark.slateToRemark (cognitive 62): slateRemark.slateToRemark has cognitive complexity 62 (threshold 15). Drivers by points: if/else 18 (31 pts), ternaries 9 (14 pts), boolean chains 9, match/switch 5, loops 2 (3 pts) (nesting depth added 19). Of this number, 59 points are the body\u0027s own statements and 3 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/slateRemark.js"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"44eae19c19fc8e0218788af45e904dd8a675ce323b7ab6a20b4359bc01404034"}},{"ruleId":"D2","level":"warning","message":{"text":"slateRemark.slateToRemark (cognitive 62): slateRemark.slateToRemark has cognitive complexity 62 (threshold 15). Drivers by points: if/else 18 (31 pts), ternaries 9 (14 pts), boolean chains 9, match/switch 5, loops 2 (3 pts) (nesting depth added 19). Of this number, 59 points are the body\u0027s own statements and 3 belong to 2 function literals inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-richtext/src/serializers/slateRemark.js"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"adec2b8e51245372d771677342f60e402dc290d563d009692ece01afc284f9a0"}},{"ruleId":"D2","level":"warning","message":{"text":"index.localGitMiddleware (cognitive 36): index.localGitMiddleware has cognitive complexity 36 (threshold 15). Drivers by points: if/else 11 (19 pts), ternaries 3 (9 pts), boolean chains 6, error handling 1, match/switch 1 (nesting depth added 14). Most of this is not in the body itself: 0 of the 36 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 179, 331, 257, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-server/src/middlewares/localGit/index.ts"},"region":{"startLine":173}}}],"partialFingerprints":{"codehealthFindingId/v1":"d20dad1de613c05ecdb4dc59575956b630603b9601023e62757ece76d1298e54"}},{"ruleId":"D2","level":"warning","message":{"text":"mediaLibrary.mediaLibrary (cognitive 35): mediaLibrary.mediaLibrary has cognitive complexity 35 (threshold 15). Drivers by points: if/else 12 (22 pts), boolean chains 6, ternaries 3 (6 pts), match/switch 1 (nesting depth added 13). Of this number, 24 points are the body\u0027s own statements and 11 belong to 4 function literals inside it that branch. The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/reducers/mediaLibrary.ts"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"3cb6f7c26d0ee390daa18702722784879a5328c9929d6320090b2764365819e7"}},{"ruleId":"D2","level":"warning","message":{"text":"createInlineShortcodeTokenizer (cognitive 30): createInlineShortcodeTokenizer has cognitive complexity 30 (threshold 15). Drivers by points: if/else 12 (19 pts), boolean chains 5, ternaries 2 (4 pts), error handling 1 (2 pts) (nesting depth added 10). Most of this is not in the body itself: 0 of the 30 points are its own statements and the rest belongs to 5 function items inside it that branch (locateInlineShortcode::(anonymous), tokenizeInlineShortcode, (anonymous), \u2026). Those helpers are already separate functions, so extracting the branching again is not available. To reduce it, move them out of the body to the enclosing scope, where each is measured, reviewed and tested on its own, and reduce whichever one then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkShortcodes.js"},"region":{"startLine":88}}}],"partialFingerprints":{"codehealthFindingId/v1":"1ea55ea27275247ab29f19814b5f773187ac490f8cdb984fa04b7ce905b2de94"}},{"ruleId":"D2","level":"warning","message":{"text":"withFileControl.withFileControl (cognitive 29): withFileControl.withFileControl has cognitive complexity 29 (threshold 15). Drivers by points: ternaries 11 (12 pts), if/else 10, boolean chains 7 (nesting depth added 1). Most of this is not in the body itself: 10 of the 29 points are its own statements and the rest belongs to 10 function literals inside it that branch (lines 454, 388, 397, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-file/src/withFileControl.js"},"region":{"startLine":240}}}],"partialFingerprints":{"codehealthFindingId/v1":"12682946c6eae00be954827470b2c5186dc82ba1f1bc7c0908906eef85b5dcbd"}},{"ruleId":"D2","level":"warning","message":{"text":"GitGateway.authenticate (cognitive 26): GitGateway.authenticate has cognitive complexity 26 (threshold 15). Drivers by points: if/else 14 (18 pts), boolean chains 4, ternaries 2 (4 pts) (nesting depth added 6). Most of this is not in the body itself: 2 of the 26 points are its own statements and the rest belongs to 4 function literals inside it that branch (lines 296, 307, 283, \u2026). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-git-gateway/src/implementation.ts"},"region":{"startLine":279}}}],"partialFingerprints":{"codehealthFindingId/v1":"9323184d596328df30dbeeb60439818cc9ad4bc4931b7b7e092d74701a19f8e8"}},{"ruleId":"D2","level":"warning","message":{"text":"API.uploadFiles (cognitive 25): API.uploadFiles has cognitive complexity 25 (threshold 15). Drivers by points: if/else 9 (11 pts), ternaries 2 (7 pts), loops 2 (4 pts), boolean chains 2, error handling 1 (nesting depth added 9). Of this number, 22 points are the body\u0027s own statements and 3 belong to one function literal inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-bitbucket/src/API.ts"},"region":{"startLine":429}}}],"partialFingerprints":{"codehealthFindingId/v1":"5b890b4d4742f6863a1796f70d3943098760968c181c18f8e05132a205ca8147"}},{"ruleId":"D2","level":"warning","message":{"text":"NotesPollingManager.checkCurrentIssue (cognitive 23): NotesPollingManager.checkCurrentIssue has cognitive complexity 23 (threshold 15). Drivers by points: if/else 10 (20 pts), boolean chains 2, error handling 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-lib-util/src/notesPolling.ts"},"region":{"startLine":315}}}],"partialFingerprints":{"codehealthFindingId/v1":"82752dbf8cf75708734e667e23210871518e6f13b6c2654ea4bc8e316e6f9a1b"}},{"ruleId":"D2","level":"warning","message":{"text":"insertShortcode.insertShortcode (cognitive 23): insertShortcode.insertShortcode has cognitive complexity 23 (threshold 15). Drivers by points: if/else 7 (12 pts), ternaries 3 (5 pts), boolean chains 3, error handling 1 (3 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/plugins/shortcodes/insertShortcode.js"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"937224d52d78b7df0b395e7e339e2c496042174c5ca92c8faad42fa7c2f78e4e"}},{"ruleId":"D2","level":"warning","message":{"text":"API.requestWithBackoff (cognitive 22): API.requestWithBackoff has cognitive complexity 22 (threshold 15). Drivers by points: if/else 7 (11 pts), ternaries 2 (7 pts), boolean chains 3, error handling 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-lib-util/src/API.ts"},"region":{"startLine":63}}}],"partialFingerprints":{"codehealthFindingId/v1":"dec230fa8929ed885dc73574ba1723d8d26eb62e52bb192f8f0a1efdfd2878c0"}},{"ruleId":"D2","level":"warning","message":{"text":"remarkSlate.remarkToSlate (cognitive 22): remarkSlate.remarkToSlate has cognitive complexity 22 (threshold 15). Drivers by points: ternaries 9 (14 pts), if/else 4, boolean chains 2, match/switch 2 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkSlate.js"},"region":{"startLine":82}}}],"partialFingerprints":{"codehealthFindingId/v1":"2d6d0fbea172c89f33651ba8095638d54403a7ddb06e05c20c63d69859bd458d"}},{"ruleId":"D2","level":"warning","message":{"text":"GraphQLAPI.mutate (cognitive 20): GraphQLAPI.mutate has cognitive complexity 20 (threshold 15). Drivers by points: if/else 4 (9 pts), boolean chains 6, error handling 2 (5 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-github/src/GraphQLAPI.ts"},"region":{"startLine":153}}}],"partialFingerprints":{"codehealthFindingId/v1":"b861a06a378e3fe9c83d4eed06505ef2e4d4784f5507d5086d970f4fff2086be"}},{"ruleId":"D2","level":"warning","message":{"text":"configSchema.validateConfig (cognitive 20): configSchema.validateConfig has cognitive complexity 20 (threshold 15). Drivers by points: if/else 8 (15 pts), boolean chains 3, match/switch 1 (2 pts) (nesting depth added 8). Most of this is not in the body itself: 2 of the 20 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 434, 470, 473). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/constants/configSchema.js"},"region":{"startLine":424}}}],"partialFingerprints":{"codehealthFindingId/v1":"44c88d9e063dfeafed3a41f2d491dbe0ca669435fe6deb3ca314999cda5766e7"}},{"ruleId":"D2","level":"warning","message":{"text":"entries.evaluateFolder (cognitive 20): entries.evaluateFolder has cognitive complexity 20 (threshold 15). Drivers by points: if/else 9 (20 pts) (nesting depth added 11). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/reducers/entries.ts"},"region":{"startLine":669}}}],"partialFingerprints":{"codehealthFindingId/v1":"4fb3da21b85e93a0fc958605bfc8aea611297e93cac23bc442351e15c2d7164f"}},{"ruleId":"D2","level":"warning","message":{"text":"Backend.persistEntry (cognitive 20): Backend.persistEntry has cognitive complexity 20 (threshold 15). Drivers by points: if/else 9 (11 pts), boolean chains 8, ternaries 1 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/backend.ts"},"region":{"startLine":1246}}}],"partialFingerprints":{"codehealthFindingId/v1":"82ef505ea78854d95750ad04413755aa155350711415962eac76d649a6c75e3a"}},{"ruleId":"D2","level":"warning","message":{"text":"remarkSlate.remarkToSlate (cognitive 20): remarkSlate.remarkToSlate has cognitive complexity 20 (threshold 15). Drivers by points: ternaries 8 (12 pts), if/else 4, boolean chains 2, match/switch 2 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-richtext/src/serializers/remarkSlate.js"},"region":{"startLine":76}}}],"partialFingerprints":{"codehealthFindingId/v1":"5296f93ed8fa783fe214137317b892e92041a187d8023664f79c714b89c8e0ef"}},{"ruleId":"D2","level":"warning","message":{"text":"publish-packages.main (cognitive 20): publish-packages.main has cognitive complexity 20 (threshold 15). Drivers by points: if/else 9 (12 pts), loops 4 (7 pts), boolean chains 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/publish-packages.mjs"},"region":{"startLine":212}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee25910e1a69bd86e5679fd06ff2dd6f221288af98fe7a551c36f1901de5e925"}},{"ruleId":"D2","level":"warning","message":{"text":"InlineShortcode.InlineShortcode (cognitive 19): InlineShortcode.InlineShortcode has cognitive complexity 19 (threshold 15). Drivers by points: boolean chains 8, if/else 5 (6 pts), ternaries 3, error handling 1 (2 pts) (nesting depth added 2). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/components/InlineShortcode.js"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"2a969451c85b5cce700b0e1f5ac1f4f0562cd6027f0d4abc2d9f7d9465b076bd"}},{"ruleId":"D2","level":"warning","message":{"text":"withHtml.deserialize (cognitive 19): withHtml.deserialize has cognitive complexity 19 (threshold 15). Drivers by points: if/else 12 (16 pts), loops 1 (2 pts), boolean chains 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/plugins/html/withHtml.js"},"region":{"startLine":75}}}],"partialFingerprints":{"codehealthFindingId/v1":"e56d25516fcd8f27f2c97838d00da75d63a7afa7de0a6d7b17ce88a4bc557f1f"}},{"ruleId":"D2","level":"warning","message":{"text":"render (cognitive 19): render has cognitive complexity 19 (threshold 15). Drivers by points: boolean chains 15, ternaries 4. Of this number, 16 points are the body\u0027s own statements and 3 belong to 14 function items inside it that branch. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/Toolbar.js"},"region":{"startLine":105}}}],"partialFingerprints":{"codehealthFindingId/v1":"d3035ec38092daf6686bde6306d7d12db8d0b9ca40ea7b2d28603ec0e529e1fc"}},{"ruleId":"D2","level":"warning","message":{"text":"API.listFiles (cognitive 18): API.listFiles has cognitive complexity 18 (threshold 15). Drivers by points: if/else 6 (10 pts), boolean chains 4, ternaries 3, error handling 1 (nesting depth added 4). Most of this is not in the body itself: 7 of the 18 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 407, 425). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-forgejo/src/API.ts"},"region":{"startLine":384}}}],"partialFingerprints":{"codehealthFindingId/v1":"eca93678b92887dc2c8c656081a2311b089a36844efd31b684f67bd6967e30a2"}},{"ruleId":"D2","level":"warning","message":{"text":"GitHub.constructor (cognitive 18): GitHub.constructor has cognitive complexity 18 (threshold 15). Drivers by points: boolean chains 13, if/else 4 (5 pts) (nesting depth added 1). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-github/src/implementation.tsx"},"region":{"startLine":99}}}],"partialFingerprints":{"codehealthFindingId/v1":"f3dcf4e4c9c658b93d379534dd43aa66f163c0dcd519160a6bfafef928597055"}},{"ruleId":"D2","level":"warning","message":{"text":"formatters.commitMessageFormatter (cognitive 18): formatters.commitMessageFormatter has cognitive complexity 18 (threshold 15). Drivers by points: boolean chains 8, if/else 5 (6 pts), match/switch 2, ternaries 1 (2 pts) (nesting depth added 2). Most of this is not in the body itself: 7 of the 18 points are its own statements and the rest belongs to 2 function literals inside it that branch (lines 69, 91). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/lib/formatters.ts"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"3354a6aea9b61645e9de602967902d2dc5094f0ad10dcbcb122c0c25e46335e6"}},{"ruleId":"D2","level":"warning","message":{"text":"mediaLibrary.persistMedia (cognitive 18): mediaLibrary.persistMedia has cognitive complexity 18 (threshold 15). Drivers by points: if/else 10 (12 pts), error handling 2 (3 pts), boolean chains 2, loops 1 (nesting depth added 3). Most of this is not in the body itself: 0 of the 18 points are its own statements and the rest belongs to one function literal inside it that branches (line 268). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/actions/mediaLibrary.ts"},"region":{"startLine":266}}}],"partialFingerprints":{"codehealthFindingId/v1":"2fcc1efcae01ad8196cbb48a1dae65202292986340519834fd73e7a8416fdfd5"}},{"ruleId":"D2","level":"warning","message":{"text":"entries.createEmptyDraftData (cognitive 18): entries.createEmptyDraftData has cognitive complexity 18 (threshold 15). Drivers by points: if/else 6 (9 pts), ternaries 2 (6 pts), boolean chains 3 (nesting depth added 7). Most of this is not in the body itself: 0 of the 18 points are its own statements and the rest belongs to one function literal inside it that branches (line 857). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/actions/entries.ts"},"region":{"startLine":852}}}],"partialFingerprints":{"codehealthFindingId/v1":"a55ec3818b13eb3147da9979aca28fbfc75c5357a955d625b58053134a18c1d7"}},{"ruleId":"D2","level":"warning","message":{"text":"EditorToolbar.renderWorkflowControls (cognitive 18): EditorToolbar.renderWorkflowControls has cognitive complexity 18 (threshold 15). Drivers by points: boolean chains 11, ternaries 5 (7 pts) (nesting depth added 2). Of this number, 17 points are the body\u0027s own statements and 1 belongs to one function literal inside it that branches. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/Editor/EditorToolbar.js"},"region":{"startLine":599}}}],"partialFingerprints":{"codehealthFindingId/v1":"c0da7c0c7406d8c6a6e82b8aad36de61fef9d82b06db4b9dd98293b09eba78c2"}},{"ruleId":"D2","level":"warning","message":{"text":"renderWorkflowStatusControls::renderWorkflowControls (cognitive 18): renderWorkflowStatusControls::renderWorkflowControls has cognitive complexity 18 (threshold 15). Drivers by points: boolean chains 12, ternaries 5, other 1. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/Editor/EditorToolbar.js"},"region":{"startLine":599}}}],"partialFingerprints":{"codehealthFindingId/v1":"65db5f0a204ab4b373cd62f4074173c6f9bc769e61cbefa35d5f9da5fb7cd3b4"}},{"ruleId":"D2","level":"warning","message":{"text":"MediaLibraryModal (cognitive 18): MediaLibraryModal has cognitive complexity 18 (threshold 15). Drivers by points: boolean chains 15, ternaries 3. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/MediaLibrary/MediaLibraryModal.js"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"fc09b102d0e7cb1db8083796938caaa3d690a0591424677c26df2d376ec55281"}},{"ruleId":"D2","level":"warning","message":{"text":"withLists (cognitive 18): withLists has cognitive complexity 18 (threshold 15). Drivers by points: if/else 6 (9 pts), boolean chains 7, loops 1 (2 pts) (nesting depth added 4). Most of this is not in the body itself: 1 of the 18 points is its own statement and the rest belongs to 5 function items inside it that branch (normalizeNode, isListItem, isListItem::match, \u2026). Those helpers are already separate functions, so extracting the branching again is not available. To reduce it, move them out of the body to the enclosing scope, where each is measured, reviewed and tested on its own, and reduce whichever one then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/plugins/lists/withLists.js"},"region":{"startLine":7}}}],"partialFingerprints":{"codehealthFindingId/v1":"df756ce2aabd4839a596c7e1f1198fb194fffaa1302fd8f767548e2395b38fdb"}},{"ruleId":"D2","level":"warning","message":{"text":"API.hasWriteAccess (cognitive 17): API.hasWriteAccess has cognitive complexity 17 (threshold 15). Drivers by points: if/else 6 (10 pts), boolean chains 4, error handling 1 (3 pts) (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-gitlab/src/API.ts"},"region":{"startLine":324}}}],"partialFingerprints":{"codehealthFindingId/v1":"3dd0e1c97202c0a21e87571f1bba2f682620e35e27598ef08c208131ba72c783"}},{"ruleId":"D2","level":"warning","message":{"text":"entryDraft.entryDraftReducer (cognitive 17): entryDraft.entryDraftReducer has cognitive complexity 17 (threshold 15). Drivers by points: if/else 6 (11 pts), boolean chains 3, ternaries 1 (2 pts), match/switch 1 (nesting depth added 6). Most of this is not in the body itself: 4 of the 17 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 131, 195, 243). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/reducers/entryDraft.js"},"region":{"startLine":72}}}],"partialFingerprints":{"codehealthFindingId/v1":"d593deff7e0ac952364866e140326d8e2fb81fdc77bab7ac3690a85f082c49ae"}},{"ruleId":"D2","level":"warning","message":{"text":"CodeControl.handleChangeCodeMirrorProps (cognitive 17): CodeControl.handleChangeCodeMirrorProps has cognitive complexity 17 (threshold 15). Drivers by points: if/else 6 (10 pts), error handling 1 (4 pts), boolean chains 2, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-code/src/CodeControl.js"},"region":{"startLine":204}}}],"partialFingerprints":{"codehealthFindingId/v1":"f5c0c8582691891724eb8df7582e8d520d6abd31a4922682a4ca0e90188aa72d"}},{"ruleId":"D2","level":"warning","message":{"text":"remarkRehypeShortcodes.remarkToRehypeShortcodes (cognitive 17): remarkRehypeShortcodes.remarkToRehypeShortcodes has cognitive complexity 17 (threshold 15). Drivers by points: if/else 9 (11 pts), boolean chains 3, ternaries 2 (3 pts) (nesting depth added 3). Of this number, 9 points are the body\u0027s own statements and 8 belong to one function literal inside it that branches. To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkRehypeShortcodes.js"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"48b380cc3f69e7370430ddffa23c94506b48141b6f1ee7d11eafd112b3969f03"}},{"ruleId":"D2","level":"warning","message":{"text":"verify-published-packages.main (cognitive 17): verify-published-packages.main has cognitive complexity 17 (threshold 15). Drivers by points: loops 4 (8 pts), if/else 6 (7 pts), boolean chains 2 (nesting depth added 5). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/verify-published-packages.mjs"},"region":{"startLine":188}}}],"partialFingerprints":{"codehealthFindingId/v1":"e5abfe2a184fca783d1e06fcecea1d482234c35608b905fbb497b762201c1957"}},{"ruleId":"D2","level":"warning","message":{"text":"Forgejo.constructor (cognitive 16): Forgejo.constructor has cognitive complexity 16 (threshold 15). Drivers by points: boolean chains 10, if/else 5 (6 pts) (nesting depth added 1). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-forgejo/src/implementation.tsx"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"1cfb0a5b03dc7cbae6f7af5412afa4389b415b60c993f87a16b7375110451581"}},{"ruleId":"D2","level":"warning","message":{"text":"API.updateUnpublishedEntryStatus (cognitive 16): API.updateUnpublishedEntryStatus has cognitive complexity 16 (threshold 15). Drivers by points: if/else 7 (13 pts), boolean chains 3 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-github/src/API.ts"},"region":{"startLine":1194}}}],"partialFingerprints":{"codehealthFindingId/v1":"73a610e77339876da87e0184f7f9b212cca4fdd7116235eb7e5f4c1ed58f748b"}},{"ruleId":"D2","level":"warning","message":{"text":"GitLab.constructor (cognitive 16): GitLab.constructor has cognitive complexity 16 (threshold 15). Drivers by points: boolean chains 15, if/else 1. To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-gitlab/src/implementation.ts"},"region":{"startLine":93}}}],"partialFingerprints":{"codehealthFindingId/v1":"991acd4a142c925c171fb77776e6ad1deddc2655cab38b1d0db1fce85ae663a8"}},{"ruleId":"D2","level":"warning","message":{"text":"PKCEAuthenticationPage.normalizeClaimsToUser (cognitive 16): PKCEAuthenticationPage.normalizeClaimsToUser has cognitive complexity 16 (threshold 15). Drivers by points: if/else 8 (11 pts), boolean chains 5 (nesting depth added 3). Most of this is not in the body itself: 0 of the 16 points are its own statements and the rest belongs to one function literal inside it that branches (line 19). The decisions are inside the literal, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literal\u0027s work into a named function or method at the enclosing scope and have the literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-ui-auth/src/PKCEAuthenticationPage.js"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"5c7a66e8e61764605671bc907bfded073be8207b8348d48604f0c2ffc2ee03d3"}},{"ruleId":"D2","level":"warning","message":{"text":"remarkShortcodes.createShortcodeTokenizer (cognitive 16): remarkShortcodes.createShortcodeTokenizer has cognitive complexity 16 (threshold 15). Drivers by points: if/else 6 (8 pts), ternaries 2 (5 pts), error handling 1 (2 pts), boolean chains 1 (nesting depth added 6). Most of this is not in the body itself: 0 of the 16 points are its own statements and the rest belongs to 3 function literals inside it that branch (lines 34, 27, 37). The decisions are inside those literals, which nothing outside this body can call, review or test on its own, so splitting the enclosing body is not the move available here. To reduce it, lift the literals\u0027 work into a named function or method at the enclosing scope and have each literal call it, then reduce whichever part then reads as the largest."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkShortcodes.js"},"region":{"startLine":26}}}],"partialFingerprints":{"codehealthFindingId/v1":"d215fb058c4a3912642af1f66aa3d68659eeb2eb6bd29143effad0d759f2777e"}},{"ruleId":"D2","level":"warning","message":{"text":"slateToRemark::convertInlineAndTextChildren (cognitive 16): slateToRemark::convertInlineAndTextChildren has cognitive complexity 16 (threshold 15). Drivers by points: if/else 7 (13 pts), boolean chains 2, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/slateRemark.js"},"region":{"startLine":263}}}],"partialFingerprints":{"codehealthFindingId/v1":"df991f863f20db3ba7d72fef72a7912ddb4f8988c0111a5b113601fb3cd565d6"}},{"ruleId":"D2","level":"warning","message":{"text":"slateToRemark::convertInlineAndTextChildren (cognitive 16): slateToRemark::convertInlineAndTextChildren has cognitive complexity 16 (threshold 15). Drivers by points: if/else 7 (13 pts), boolean chains 2, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-richtext/src/serializers/slateRemark.js"},"region":{"startLine":257}}}],"partialFingerprints":{"codehealthFindingId/v1":"c07d2615991065fb89b7fd2fff89ac8ec01d86877ea07afe6a0f6447eaba889d"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: API: TooManyMethods \u2014 92 methods. The bar is 30 methods; this is 62 over it, 3.07\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-github/src/API.ts"},"region":{"startLine":232}}}],"partialFingerprints":{"codehealthFindingId/v1":"98cb88045f5252e7059360d1d86cfdd0e187c83ca36d81f81b121d57271446da"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/API.ts: FileTooLong \u2014 1293 significant lines (blank, comment-only and punctuation-only lines excluded), about 86% of them inside a single declaration: API (232-1979). The bar is 500 significant lines; this is 793 over it, 2.59\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-github/src/API.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"db53081b7af85b72b9865914bbacb5485b78e14125403b9ed5a96f493b4a15fb"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: index.localGitMiddleware: FunctionTooLong \u2014 localGitMiddleware runs 228 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 128 over it, 2.28\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-server/src/middlewares/localGit/index.ts"},"region":{"startLine":173}}}],"partialFingerprints":{"codehealthFindingId/v1":"5d3d67dccd95ee5f15208b16c96821a4c596be967eef58ded5d4de8a8bcd2a7e"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: EditorInterface.render: MethodTooLong \u2014 render runs 217 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 117 over it, 2.17\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/Editor/EditorInterface.js"},"region":{"startLine":259}}}],"partialFingerprints":{"codehealthFindingId/v1":"b6b5e8a97c2fc01b03b5553e1eb706480effc75e080b13f829b8ba692fcd1f8b"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: slateRemark.slateToRemark: FunctionTooLong \u2014 slateToRemark runs 206 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 106 over it, 2.06\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/slateRemark.js"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"3633473fe8073b38992eb16acf9824c1a49f1e4a0c511a625656f8279545dfd1"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/backend.ts: FileTooLong \u2014 1029 significant lines (blank, comment-only and punctuation-only lines excluded), about 73% of them inside a single declaration: Backend (362-1539). The bar is 500 significant lines; this is 529 over it, 2.06\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/backend.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"db6c369904a7f5174ce0d60356485c0b9524a6a0a384c257ddcb6e996b204a3d"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Backend: TooManyMethods \u2014 61 methods. The bar is 30 methods; this is 31 over it, 2.03\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/backend.ts"},"region":{"startLine":362}}}],"partialFingerprints":{"codehealthFindingId/v1":"2e4b500c10a8d72f0554353a92bf00620537db3a996d39aaf0ed8b7dfa741899"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: slateRemark.slateToRemark: FunctionTooLong \u2014 slateToRemark runs 200 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 100 over it, 2.00\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-richtext/src/serializers/slateRemark.js"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"334838b7f1e9cbfbd51ef369d627efec1192f22cd2ca9a491068236675f95924"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: actions/entries.ts: FileTooLong \u2014 998 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 498 over it, 2.00\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/actions/entries.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"99c72c8a509361cd9e38ec3b7504ba65278bd45eef72d8a51f8a7a1875ce87f4"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: API: TooManyMethods \u2014 57 methods. The bar is 30 methods; this is 27 over it, 1.90\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-forgejo/src/API.ts"},"region":{"startLine":113}}}],"partialFingerprints":{"codehealthFindingId/v1":"cba67dcbf0ef2e668c8152b97a3428d4b7f2d58a03faf1cc2cbf380fa629acbf"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: Backend: ClassTooLong \u2014 751 significant lines (blank, comment-only and punctuation-only lines excluded), 61 methods. The bar is 400 significant lines; this is 351 over it, 1.88\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/backend.ts"},"region":{"startLine":362}}}],"partialFingerprints":{"codehealthFindingId/v1":"5894f48c4250f0f5723dbc1b302fcf400176a6dc3f072fe00ba11f31f5253d13"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: withFileControl.withFileControl: FunctionTooLong \u2014 withFileControl runs 182 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 82 over it, 1.82\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-file/src/withFileControl.js"},"region":{"startLine":240}}}],"partialFingerprints":{"codehealthFindingId/v1":"8133d61c2af4800aecd3b898801bc9c923d48abb0d9abc1a592afb04b6999e39"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: EditorControl.render: MethodTooLong \u2014 render runs 174 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 74 over it, 1.74\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/Editor/EditorControlPane/EditorControl.js"},"region":{"startLine":197}}}],"partialFingerprints":{"codehealthFindingId/v1":"24c3d93a460719d0bcf556e16b2f84a1cf22ced93d6224d7a25153e3fccd2e8c"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: configSchema.getConfigSchema: FunctionTooLong \u2014 getConfigSchema runs 173 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 73 over it, 1.73\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/constants/configSchema.js"},"region":{"startLine":158}}}],"partialFingerprints":{"codehealthFindingId/v1":"a8390616f90124857c26aef388e4ec621a876b8d9a11fa0648a5016fb2eaaecf"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: Toolbar.render: MethodTooLong \u2014 render runs 172 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 72 over it, 1.72\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/Toolbar.js"},"region":{"startLine":105}}}],"partialFingerprints":{"codehealthFindingId/v1":"9fa221b9fa13c5b395bb81937eff3fc1705210fee7a738ce62e6a0c74a2ad9c8"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: API: TooManyMethods \u2014 50 methods. The bar is 30 methods; this is 20 over it, 1.67\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-gitlab/src/API.ts"},"region":{"startLine":211}}}],"partialFingerprints":{"codehealthFindingId/v1":"23ee9157b67ee0a08777545847f1a11061f937947a363cfb647e6360b50ccd1f"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: GitLab: TooManyMethods \u2014 49 methods. The bar is 30 methods; this is 19 over it, 1.63\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-gitlab/src/implementation.ts"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"620c5424603d353c7fdc2c159ba6c3ff2a7193e2449c8099459c47ecbb98ea41"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: GitHub: TooManyMethods \u2014 46 methods. The bar is 30 methods; this is 16 over it, 1.53\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-github/src/implementation.tsx"},"region":{"startLine":65}}}],"partialFingerprints":{"codehealthFindingId/v1":"2a5d566eb76a2545e365619fe29def44d30ff2575de69be80077d98e08904d88"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: API: ClassTooLong \u2014 611 significant lines (blank, comment-only and punctuation-only lines excluded), 57 methods. The bar is 400 significant lines; this is 211 over it, 1.53\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-forgejo/src/API.ts"},"region":{"startLine":113}}}],"partialFingerprints":{"codehealthFindingId/v1":"9a1052be2fa87bdcd67506b2b2acf9a27d73d54e95873348ff6b132816dcb718"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/API.ts: FileTooLong \u2014 737 significant lines (blank, comment-only and punctuation-only lines excluded), about 78% of them inside a single declaration: API (211-1042). The bar is 500 significant lines; this is 237 over it, 1.47\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-gitlab/src/API.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"896e6990da24cd4be597e1ecff1f1f82072ff1a2a1380f64bef59997b555e32e"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: GitHub: ClassTooLong \u2014 578 significant lines (blank, comment-only and punctuation-only lines excluded), 46 methods. The bar is 400 significant lines; this is 178 over it, 1.45\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-github/src/implementation.tsx"},"region":{"startLine":65}}}],"partialFingerprints":{"codehealthFindingId/v1":"4a8f8df2b56ca5709e1c57491727fe01f0d15be942c68c9301c43702ddf8c58e"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: VisualEditor.Editor: FunctionTooLong \u2014 Editor runs 144 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 44 over it, 1.44\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/VisualEditor.js"},"region":{"startLine":85}}}],"partialFingerprints":{"codehealthFindingId/v1":"d3676783749d65c0dbc3da2d5756aba0a153cade5e8843c5fa1ae8d675b5a7d3"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: mediaLibrary.mediaLibrary: FunctionTooLong \u2014 mediaLibrary runs 143 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 43 over it, 1.43\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/reducers/mediaLibrary.ts"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"73e86a0a7ab400d3969bb45d9f6e271f59500832c6f5b4e5dfe159e514f562eb"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/API.ts: FileTooLong \u2014 702 significant lines (blank, comment-only and punctuation-only lines excluded), about 87% of them inside a single declaration: API (113-1061). The bar is 500 significant lines; this is 202 over it, 1.40\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-forgejo/src/API.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"51f98618291744d3f35fbc71bdcdf8b8d9de1d285d5e5571af0b85369d5f2107"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: API: TooManyMethods \u2014 42 methods. The bar is 30 methods; this is 12 over it, 1.40\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-bitbucket/src/API.ts"},"region":{"startLine":203}}}],"partialFingerprints":{"codehealthFindingId/v1":"8a9b55a998f72ee9d2b995c79959834c05e3739da390bf34672e2213b1ffc21d"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: index.defaultSchema: FunctionTooLong \u2014 defaultSchema runs 138 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 38 over it, 1.38\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-server/src/middlewares/joi/index.ts"},"region":{"startLine":33}}}],"partialFingerprints":{"codehealthFindingId/v1":"09a6335de18d2baed23deb7ec314b16afde16d7b02f7b866a64559dc5fa92192"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: entryDraft.entryDraftReducer: FunctionTooLong \u2014 entryDraftReducer runs 134 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 34 over it, 1.34\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/reducers/entryDraft.js"},"region":{"startLine":72}}}],"partialFingerprints":{"codehealthFindingId/v1":"180e5331a01a89308f912e06d9e7f122181a348d87f5db5ab555ea423e3477ae"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: types/redux.ts: FileTooLong \u2014 656 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 156 over it, 1.31\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/types/redux.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e63698eb7b21951bfad06b641e557b411a6eac669596c66db54c849a786ab636"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: remarkSlate.remarkToSlate: FunctionTooLong \u2014 remarkToSlate runs 129 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 29 over it, 1.29\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkSlate.js"},"region":{"startLine":82}}}],"partialFingerprints":{"codehealthFindingId/v1":"c6e4e08e0b8fdc0b760d49ff349589e0d7b985df9470978bc9001ae5ca394c3e"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/implementation.tsx: FileTooLong \u2014 633 significant lines (blank, comment-only and punctuation-only lines excluded), about 91% of them inside a single declaration: GitHub (65-955). The bar is 500 significant lines; this is 133 over it, 1.27\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-github/src/implementation.tsx"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"5002d10a65be42f414a896eb5ca236d62607b02a2458c40d91c5061c18bf1a77"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: API: TooManyMethods \u2014 37 methods. The bar is 30 methods; this is 7 over it, 1.23\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-azure/src/API.ts"},"region":{"startLine":223}}}],"partialFingerprints":{"codehealthFindingId/v1":"e1aa37c5d7d4db9b8b9241851e52561a15d18b944f53757081b0dc0680a4b05c"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: GitLab: ClassTooLong \u2014 491 significant lines (blank, comment-only and punctuation-only lines excluded), 49 methods. The bar is 400 significant lines; this is 91 over it, 1.23\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-gitlab/src/implementation.ts"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"6417a73fe3ee6d217652183ccbb45dce728cb6adcf1f213b0ce07035c647ad59"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: remarkSlate.remarkToSlate: FunctionTooLong \u2014 remarkToSlate runs 122 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 22 over it, 1.22\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-richtext/src/serializers/remarkSlate.js"},"region":{"startLine":76}}}],"partialFingerprints":{"codehealthFindingId/v1":"29558bf43e2fc1b699d3652087043fcca2629b7fdec0da6de57988e6b4bc8e12"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: BitbucketBackend: TooManyMethods \u2014 36 methods. The bar is 30 methods; this is 6 over it, 1.20\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-bitbucket/src/implementation.ts"},"region":{"startLine":66}}}],"partialFingerprints":{"codehealthFindingId/v1":"dae04d99f81bf7b5e6f33f42ae9b2ebc8accf9d89bca20c8aacc73abd9bd2da9"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/ListControl.js: FileTooLong \u2014 600 significant lines (blank, comment-only and punctuation-only lines excluded; the length bar is tripled for a single-responsibility module of 4 or fewer top-level units), about 78% of them inside a single declaration: ListControl (175-847). The bar is 500 significant lines; this is 100 over it, 1.20\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-list/src/ListControl.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"acfa7a731599bde0c85108d4dd658c3cb9015ee98634c78b208bc6299a1fbf69"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: VisualEditor.VisualEditor: FunctionTooLong \u2014 VisualEditor runs 119 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 19 over it, 1.19\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-richtext/src/RichtextControl/VisualEditor.js"},"region":{"startLine":56}}}],"partialFingerprints":{"codehealthFindingId/v1":"fb908c6cf56057c9e061de82b041925ea8377d775d9669c57ab21c73bbbcbd39"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: GraphQLAPI: TooManyMethods \u2014 35 methods. The bar is 30 methods; this is 5 over it, 1.17\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-github/src/GraphQLAPI.ts"},"region":{"startLine":98}}}],"partialFingerprints":{"codehealthFindingId/v1":"83d243cc0c777495a1bc68f89d47e07d77f1539744f2f661c73acd8630cb3e22"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: reducers/entries.ts: FileTooLong \u2014 581 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 81 over it, 1.16\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/reducers/entries.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"21f488571e2928bebc3c827d4f7ca0f4238114f4be14a081f10c77cb6a8c4d72"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/API.ts: FileTooLong \u2014 574 significant lines (blank, comment-only and punctuation-only lines excluded), about 74% of them inside a single declaration: API (203-829). The bar is 500 significant lines; this is 74 over it, 1.15\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-bitbucket/src/API.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"096b171a4fb975946973b014de168ad3ed28dd31b70352cc8b9a621481279d26"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: Editor/EditorToolbar.js: FileTooLong \u2014 572 significant lines (blank, comment-only and punctuation-only lines excluded), about 64% of them inside a single declaration: EditorToolbar (266-730). The bar is 500 significant lines; this is 72 over it, 1.14\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/Editor/EditorToolbar.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"93b454f7afe77474ed099be73c531bcdc598d3245e4baf803c6859f492006ec1"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/API.ts: FileTooLong \u2014 551 significant lines (blank, comment-only and punctuation-only lines excluded), about 71% of them inside a single declaration: API (223-807). The bar is 500 significant lines; this is 51 over it, 1.10\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-azure/src/API.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"2d587686ff942b2a34ba86dc0cd0aa4dff48f41734e80e00ed2a840a04f44d55"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: GitGateway: TooManyMethods \u2014 33 methods. The bar is 30 methods; this is 3 over it, 1.10\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-git-gateway/src/implementation.ts"},"region":{"startLine":137}}}],"partialFingerprints":{"codehealthFindingId/v1":"ba60610e2b662446772da6dfb4b5a2c3b6396e595a5d3d3edc14d1ad2d85e53c"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/implementation.ts: FileTooLong \u2014 543 significant lines (blank, comment-only and punctuation-only lines excluded), about 90% of them inside a single declaration: GitLab (57-771). The bar is 500 significant lines; this is 43 over it, 1.09\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-gitlab/src/implementation.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"511e63ecdfd1506a5849ac84e1ed2924bb92f40d8c4953be97ef00ea592c685f"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Forgejo: TooManyMethods \u2014 32 methods. The bar is 30 methods; this is 2 over it, 1.07\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-forgejo/src/implementation.tsx"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"be03aefd17f24fec2f00fa12a706217e7be263e09537b3baf0de6afc83e48cb9"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/implementation.ts: FileTooLong \u2014 519 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 19 over it, 1.04\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-lib-util/src/implementation.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c92b6af440be2920aafa8002bc5819ce36fb3503272d02b3a9f7b23906081982"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: ListControl: TooManyMethods \u2014 31 methods. The bar is 30 methods; this is 1 over it, 1.03\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-list/src/ListControl.js"},"region":{"startLine":175}}}],"partialFingerprints":{"codehealthFindingId/v1":"b1a1b1604637dc03abafa0f5f79d036b9b7b16499b8ff840a4a07dcfdc54eeec"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: Forgejo: ClassTooLong \u2014 409 significant lines (blank, comment-only and punctuation-only lines excluded), 32 methods. The bar is 400 significant lines; this is 9 over it, 1.02\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-forgejo/src/implementation.tsx"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"de7c24f2d864fc9f8c2feaf5905d089445aa53f52fbe212fc3a9b4cf23395078"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: Widget.render: MethodTooLong \u2014 render runs 102 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 2 over it, 1.02\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/Editor/EditorControlPane/Widget.js"},"region":{"startLine":285}}}],"partialFingerprints":{"codehealthFindingId/v1":"7728d9d8054988636862b9b3d6a4d6cacfad3b645109105ddaff2a89e63469cf"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: App.render: MethodTooLong \u2014 render runs 101 significant lines (blank, comment-only and punctuation-only lines excluded) in one body. The bar is 100 significant lines; this is 1 over it, 1.01\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/App/App.js"},"region":{"startLine":146}}}],"partialFingerprints":{"codehealthFindingId/v1":"ab2c7e54611d3e675ad54e9f31a1bf2dd60b05dd9fe946b20d51cdbd982fb523"}},{"ruleId":"D5","level":"warning","message":{"text":"Unstable project decap-cms-app: decap-cms-app has instability 0.97 with 1 dependents."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e13c93838cfe54f67ca20c07d2f02ab71c8a3376bdc0367509e97a289a6c5477"}},{"ruleId":"D5","level":"warning","message":{"text":"Unstable project decap-cms-backend-aws-cognito-github-proxy: decap-cms-backend-aws-cognito-github-proxy has instability 0.83 with 1 dependents."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6aa24e9ff38d03b6145f3b126c9145ab6a3109322b547cbd76edc9be3c94c000"}},{"ruleId":"D5","level":"warning","message":{"text":"Unstable project decap-cms-backend-git-gateway: decap-cms-backend-git-gateway has instability 0.88 with 1 dependents."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"eba1cae6dbd2697599d1b9feefc03ec2cd54a9efed951faa6337a7a9e2d28d53"}},{"ruleId":"D5","level":"warning","message":{"text":"Unstable project decap-cms-core: decap-cms-core has instability 0.83 with 1 dependents."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f87f1b017280dcf2841ae206ecce8e47bac64f46de93dee1575c3d2faa219f79"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: decap-cms-lib-widgets: decap-cms-lib-widgets: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and depended on by 6 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"58b276dbe23aa158f9a1b21638e44a5e663c35fc4e2886cfdc90da8e697049d5"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: decap-cms-lib-util: decap-cms-lib-util: abstractness 0.24, instability 0.00, distance 0.76 \u2014 zone of pain \u2014 concrete and depended on by 14 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"bb6959df265886a5911a248414c621a2d05021b4ab3c69dd354d7f846ab76043"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: TestBackend (LCOM4 15): TestBackend\u0027s methods fall into 15 groups that share no field and call none of each other, against a bar of more than 3 for this run (LCOM4, configurable \u2014 your repository\u0027s bar is the one quoted here). Each group is a set of methods reachable from one another through shared fields or direct calls, so 15 groups means the type has that many internally-connected clusters with nothing tying them together. Types whose shape makes a high count expected \u2014 and which would otherwise dominate this list \u2014 are excluded before this row is raised, so this is a genuine split candidate rather than a metric reading. It is still a shape, not a defect: confirm the groups match responsibilities you can name before splitting."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-test/src/implementation.ts"},"region":{"startLine":152}}}],"partialFingerprints":{"codehealthFindingId/v1":"d3ae2042b06006653a81b419bfe261eb982540de67a703f14a2ec23b2334e747"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: API (LCOM4 5): API\u0027s methods fall into 5 groups that share no field and call none of each other, against a bar of more than 3 for this run (LCOM4, configurable \u2014 your repository\u0027s bar is the one quoted here). Each group is a set of methods reachable from one another through shared fields or direct calls, so 5 groups means the type has that many internally-connected clusters with nothing tying them together. Types whose shape makes a high count expected \u2014 and which would otherwise dominate this list \u2014 are excluded before this row is raised, so this is a genuine split candidate rather than a metric reading. It is still a shape, not a defect: confirm the groups match responsibilities you can name before splitting."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-git-gateway/src/GitHubAPI.ts"},"region":{"startLine":15}}}],"partialFingerprints":{"codehealthFindingId/v1":"41854e9433ca92b3840bd27eb139753f1dae2d284bf65ad8a75e49c8bc455d0b"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: ControlPane (LCOM4 4): ControlPane\u0027s methods fall into 4 groups that share no field and call none of each other, against a bar of more than 3 for this run (LCOM4, configurable \u2014 your repository\u0027s bar is the one quoted here). Each group is a set of methods reachable from one another through shared fields or direct calls, so 4 groups means the type has that many internally-connected clusters with nothing tying them together. Types whose shape makes a high count expected \u2014 and which would otherwise dominate this list \u2014 are excluded before this row is raised, so this is a genuine split candidate rather than a metric reading. It is still a shape, not a defect: confirm the groups match responsibilities you can name before splitting."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/Editor/EditorControlPane/EditorControlPane.js"},"region":{"startLine":98}}}],"partialFingerprints":{"codehealthFindingId/v1":"0ac7e034566f4382ff6edf38011db9fdd8184b9b0d7a872f1b58d94cf2e888f3"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: successfully loads: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/simple_workflow_spec_test_backend.js"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"0ab57ccd555b889cc16bdd466032113faee89231dff68fde65b24750b593269f"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can publish a new entry: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/simple_workflow_spec_test_backend.js"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"ec5cb55814aae4b240e3c452b0d78ff2e30344ed567571c7e1f5d199589dac95"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can publish a new entry and create new: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/simple_workflow_spec_test_backend.js"},"region":{"startLine":63}}}],"partialFingerprints":{"codehealthFindingId/v1":"c7e07237f999e9b68b2bf801e298293bb548190b64a6c27bc2a02acd50ee8c20"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can publish a new entry and duplicate: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/simple_workflow_spec_test_backend.js"},"region":{"startLine":69}}}],"partialFingerprints":{"codehealthFindingId/v1":"dc8cef411a405dec527bc3a45d55a6207bf717bf17396b97df88d0984904c16a"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can edit an existing entry and publish: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/simple_workflow_spec_test_backend.js"},"region":{"startLine":75}}}],"partialFingerprints":{"codehealthFindingId/v1":"6ab40febcf183d5491ac09bd64521af2b03a28151f13ecfc0308d4c0e8375a1f"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can edit an existing entry, publish and create new: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/simple_workflow_spec_test_backend.js"},"region":{"startLine":83}}}],"partialFingerprints":{"codehealthFindingId/v1":"c95956b465673345100b893ef65e98cd0d44291d7a711fae229759d77c375e15"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can edit an existing entry, publish and duplicate: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/simple_workflow_spec_test_backend.js"},"region":{"startLine":91}}}],"partialFingerprints":{"codehealthFindingId/v1":"d0adce46ce08741d824828218e358d74e94c08ef6d42941f4f29cd8cc6581514"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can duplicate an existing entry: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/simple_workflow_spec_test_backend.js"},"region":{"startLine":99}}}],"partialFingerprints":{"codehealthFindingId/v1":"1cace8dcc501df9808ef737c83422a3e421bf076e441e6f1e43e5e127be43a74"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can combine code mark with other marks: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_marks_spec.js"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"4f13fb40bcedd1665441335a909dd8497440aa36cc67ddf266881b9fd850b8d4"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can add a new valid link: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_link_spec.js"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"e82a4e801cdf8e36d154a1e56ff3846535645834ccb721fda67cf3fa5c76e774"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can add a new invalid link: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_link_spec.js"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"8a789f638a10d096bf4c6395e150918ba00964f8a23366aabb06287c31d1e24f"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can select existing text as link: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_link_spec.js"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"c1c6c3c4745a1ddc02f88de34b10c699618aea0135edb75341834ad6c8340275"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: pressing mod\u002Bb bolds the text: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_hotkeys_spec.js"},"region":{"startLine":30}}}],"partialFingerprints":{"codehealthFindingId/v1":"3569311d6209755ce04e4c586553ebcb9aa95bcd16c00a55c0f850e0ad92be46"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: pressing mod\u002Bi italicizes the text: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_hotkeys_spec.js"},"region":{"startLine":43}}}],"partialFingerprints":{"codehealthFindingId/v1":"946b99ce413505396e13e62ddddbaa1473b333d7c3330a0fbe7fa3234a9e4c60"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: pressing mod\u002Bshift\u002Bs displays a strike through the text: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_hotkeys_spec.js"},"region":{"startLine":56}}}],"partialFingerprints":{"codehealthFindingId/v1":"83b5b10d64eb3fee9cb74c27ebb83ebec32afafbfd94d4812b24ddc9c6bf895b"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: pressing mod\u002Bshift\u002Bc displays a code block around the text: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_hotkeys_spec.js"},"region":{"startLine":68}}}],"partialFingerprints":{"codehealthFindingId/v1":"512b62a61f3227dbf624368fcbf3fc6ee0d48b9b33f7a80dee8f92fde5c9c1d9"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: pressing mod\u002Bk transforms the text to a link: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_hotkeys_spec.js"},"region":{"startLine":83}}}],"partialFingerprints":{"codehealthFindingId/v1":"7e41a04d173a04ac5d809f3e56d2edc0f5b63b5f610f1e07bb18de5298344c82"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: pressing mod\u002B${i} transforms the text to a heading: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_hotkeys_spec.js"},"region":{"startLine":98}}}],"partialFingerprints":{"codehealthFindingId/v1":"75f2eea65b157f0d87cef7ff03a976a49b940dcbf8903ba67e910b1866256de1"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: creates new default block from empty block: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_enter_spec.js"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"0ea674cde9d822256bd0d82579ccc109b6775839369b134d52835c68aafb22fc"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: creates new default block when selection collapsed at end of block: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_enter_spec.js"},"region":{"startLine":28}}}],"partialFingerprints":{"codehealthFindingId/v1":"a40c21d6210986e926bf24f287a8821e22e73d30ae5b91947d06ee9450d4dcd0"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: creates new default block when selection collapsed at end of non-default block: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_enter_spec.js"},"region":{"startLine":37}}}],"partialFingerprints":{"codehealthFindingId/v1":"abf716a6ebf199194f7f47c40abc4d3c7437063a7a0c93dc04a45203f99714a2"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: creates new default block when selection collapsed in empty non-default block: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_enter_spec.js"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"7eb93eb848af44db718514ce2ff7828824dc7a303e731ee2961d0e911eb0bc0b"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: splits block into two same-type blocks when collapsed selection at block start: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_enter_spec.js"},"region":{"startLine":56}}}],"partialFingerprints":{"codehealthFindingId/v1":"58297e506f6c853fcd4f46eed45a64b945eb62ba041e4196ec119911455f3f1a"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: splits block into two same-type blocks when collapsed in middle of selection at block start: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_enter_spec.js"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"e112190b325bd55f734528811d74bbed5e3437adc9fa5d25c77418b2bd7e81e8"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: deletes selected content and splits to same-type block when selection is expanded: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_enter_spec.js"},"region":{"startLine":77}}}],"partialFingerprints":{"codehealthFindingId/v1":"f46e780800e5d852726508d2c8d9975a8b7a8f82848dc830fe913c7abe0fa262"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: creates line break: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_enter_spec.js"},"region":{"startLine":91}}}],"partialFingerprints":{"codehealthFindingId/v1":"3f6e9c07655276ec32f380ff59ce64daae184a7e60c7d4f6f19efdec82b842c1"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: creates consecutive line break: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_enter_spec.js"},"region":{"startLine":100}}}],"partialFingerprints":{"codehealthFindingId/v1":"7b7f6cab5a51308c92f4966e15622b1a4002f16093c190abd6a1c67605abada7"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: outputs code: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_code_block_spec.js"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"3ecf539eb8281c9a15e82e1bc1ce3e52fd3a929c0792133f3e38e84295e31844"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: sets non-default block to default when empty: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_backspace_spec.js"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"9866ed0de341c234b1ccc41e847af031f03525626afd7d29594b3cb3967a8a09"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: moves to previous block when no character left to delete: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_backspace_spec.js"},"region":{"startLine":29}}}],"partialFingerprints":{"codehealthFindingId/v1":"fa7ce98db96e0911e1887636e606f934ff89e21c5b9fa248d56b927ceb730ca2"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: does nothing at start of first block in document when non-empty and non-default: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_backspace_spec.js"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"23e8f431d4a20d15a9d2b7635919357ae48c994385ccb7b278975b17c274956d"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: deletes individual characters in middle of non-empty non-default block in document: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_backspace_spec.js"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"2fb723af8c531f4747870a5eb7362b593f08c81934c7b807fd79dff362b91c26"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: at beginning of non-first block, moves default block content to previous block: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_backspace_spec.js"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"0860be1ee338d75e74e418b896e2a6d15939e469aecd80dbdee958a5af4fd50f"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: at beginning of non-first block, moves non-default block content to previous block: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/richtext_widget_backspace_spec.js"},"region":{"startLine":74}}}],"partialFingerprints":{"codehealthFindingId/v1":"544aa35e05fb07a1a3999403027792577c7b1492b720335888775c9039d14ce4"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: toggles empty quote block on and off in empty editor: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_quote_spec.js"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"71d4cc041ccf4f26d6d039291181435981569dd6d3cf0b27093f8d76c574f1ae"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: toggles empty quote block on and off for current block: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_quote_spec.js"},"region":{"startLine":32}}}],"partialFingerprints":{"codehealthFindingId/v1":"6b222ba70bcafd926fd0f7c5c0b6af0171dbb3351f1b9d74ce43d59fc9268799"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: toggles entire quote block without expanded selection: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_quote_spec.js"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"3cce9944b8a0c1ec515d35489b12014f2512522c1de178d827b5d51f4b74646c"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: toggles entire quote block with complex content: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_quote_spec.js"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"664e49dc98b9bdfb5259372b383c5092fed64890d3295ee9ac13e68fcc1579ba"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: toggles empty quote block on and off for selected blocks: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_quote_spec.js"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"38e26bba118fe37a21608bcc3a718bbe54fdf0e716171d14599844ed29149ecb"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: toggles empty quote block on and off for partially selected blocks: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_quote_spec.js"},"region":{"startLine":101}}}],"partialFingerprints":{"codehealthFindingId/v1":"7c45f4d34289a0fc812024a756bbedcab718d6f4cb801fc083abc15ed346c3a6"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: toggles quote block on and off for multiple selected list items: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_quote_spec.js"},"region":{"startLine":129}}}],"partialFingerprints":{"codehealthFindingId/v1":"89ac4f8e4d93b35e4bb7f00436197f873a4508d3f410eb480089cb54127784ec"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: creates new quote block if parent is not a quote, can deeply nest: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_quote_spec.js"},"region":{"startLine":187}}}],"partialFingerprints":{"codehealthFindingId/v1":"8ffd8602c2800b6b0d3e26c211547e61e2596c2a0d3cc86dfc7029ad05b2896c"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: joins two paragraphs: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_quote_spec.js"},"region":{"startLine":268}}}],"partialFingerprints":{"codehealthFindingId/v1":"27ba9baed6be99d2cd3ce5d65793be1d87c8ae79f11354ccf3b0b21ee41f7fab"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: joins quote with previous quote: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_quote_spec.js"},"region":{"startLine":281}}}],"partialFingerprints":{"codehealthFindingId/v1":"96fa93e02819793ceeae1d2b9eb703931fd4c00cb8047c958bf77d6dad9e3d85"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: removes first block from quote when focused at first block at start: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_quote_spec.js"},"region":{"startLine":304}}}],"partialFingerprints":{"codehealthFindingId/v1":"ae00698ef8d1c6b4dd19565abaa2ad90de5fe9d92855a60b26a7a6f20ca97a02"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: creates new block inside quote: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_quote_spec.js"},"region":{"startLine":323}}}],"partialFingerprints":{"codehealthFindingId/v1":"e1d9987f7cf0668b7fb02eca23617af4aa0ec5513e67814688aceed286029f4c"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: creates new block after quote from empty last block: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_quote_spec.js"},"region":{"startLine":346}}}],"partialFingerprints":{"codehealthFindingId/v1":"a9e0ed3f0298dad46c5e69b2605451d34cd8a5aeb3d97ce27018fabf5b5eb8c9"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can combine code mark with other marks: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_marks_spec.js"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"8ed1550ff3dcdcddf92a7dcc2f78a43cfdbe7e60bf8bd4d3b8e4ffc152792423"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: creates and focuses empty list: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_list_spec.js"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"510443c4eec1f1eb896f36acd6b280b97ac4fbab9b72d7f3acfc78431a383761"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: removes list: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_list_spec.js"},"region":{"startLine":30}}}],"partialFingerprints":{"codehealthFindingId/v1":"a5cb5bde4adf7c84e061d3dcda2cd16494cfb6dfd3a9d4a193d97cdc7d04bfa3"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: converts a list item to a paragraph block which is a sibling of the parent list: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_list_spec.js"},"region":{"startLine":36}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b0b560c37741ed3b0a0821fda50a451e843166ec3b36cb23f5f363e6ce6be6f"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: converts empty nested list item to empty paragraph block in parent list item: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_list_spec.js"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"21e4ff49ada8483ee6c0e255c99c6e014b81b9b3aa23fa8f56edafb67df077bc"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: moves nested list item content to parent list item when in first block: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_list_spec.js"},"region":{"startLine":103}}}],"partialFingerprints":{"codehealthFindingId/v1":"8d373d7f0722a6befece0a3afc3352f8bf123c832a096d04ce39538f4fb7e660"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: affects only the current block with collapsed selection: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_list_spec.js"},"region":{"startLine":150}}}],"partialFingerprints":{"codehealthFindingId/v1":"b93f37bde727293e38155229e8c9ea57f92b945feb28fcb2c114f1034b871bcd"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: wrap each bottom-most block in a selection with a list item block: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_list_spec.js"},"region":{"startLine":170}}}],"partialFingerprints":{"codehealthFindingId/v1":"e39333f1f8ebbc537f5ebcf81d076113e4978e933b6f2bb4f81e44769fb95b8a"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: unwraps list item block from each selected list item and unwraps all of them from the outer list block: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_list_spec.js"},"region":{"startLine":196}}}],"partialFingerprints":{"codehealthFindingId/v1":"2aa9bdb8f1a2fc14ff8b9ec2a594ac1d368b9964248e7fc68ff166d097a8f157"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: combines adjacent same-typed lists, not differently typed lists: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_list_spec.js"},"region":{"startLine":214}}}],"partialFingerprints":{"codehealthFindingId/v1":"7349a156d72497508d76caf51868b55438789258f4ec6837e7fcd98d0c5e7c41"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: removes the list item and list if empty: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_list_spec.js"},"region":{"startLine":496}}}],"partialFingerprints":{"codehealthFindingId/v1":"624b49e6269b10effd1cf50adaa132cb65a831ee12cdbdabb884ff5fdb8cc677"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: creates a new list item in a non-empty list: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_list_spec.js"},"region":{"startLine":502}}}],"partialFingerprints":{"codehealthFindingId/v1":"71d07b17231c85e70b95891f4d2519a1bdb95f6fb4367975745156a1a44ffcbc"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: creates a new default block below a list when hitting Enter twice on an empty list item of the list: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_list_spec.js"},"region":{"startLine":535}}}],"partialFingerprints":{"codehealthFindingId/v1":"31e64053036acd13cd8c682bf693837667b6fe20d16a69d91dd9d7c1bd2eac71"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: removes the list item and list if empty: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_list_spec.js"},"region":{"startLine":548}}}],"partialFingerprints":{"codehealthFindingId/v1":"bd93039606739fdc95f721f9ac475d26c7305ad1f9cdc23bd070972e13d97e03"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: removes the list item if list not empty: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_list_spec.js"},"region":{"startLine":554}}}],"partialFingerprints":{"codehealthFindingId/v1":"a26b26b89a40bf20764190b409856350f1bf97d59561bef3053b6fdde5a4ec24"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: does not remove list item if empty with non-default block: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_list_spec.js"},"region":{"startLine":565}}}],"partialFingerprints":{"codehealthFindingId/v1":"ce7ce450eacf2233db7cb297aca41e7b72fd2cf36d2f52d85b82a4efd749c71e"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: does nothing in top level list: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_list_spec.js"},"region":{"startLine":578}}}],"partialFingerprints":{"codehealthFindingId/v1":"3c267e2d6930e1c839679906c7575c1a08eaa8724d5eeb3c29e3df5d0e8e656a"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: indents nested list items: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_list_spec.js"},"region":{"startLine":601}}}],"partialFingerprints":{"codehealthFindingId/v1":"1d0ddb29ae40753d86d46ecc6d15fc74b81b90a594f9ef868e67602a3260ab50"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: only nests up to one level down from the parent list: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_list_spec.js"},"region":{"startLine":642}}}],"partialFingerprints":{"codehealthFindingId/v1":"e9ff7b6f2efe8c5b7f189117f58404f9525840a4978bac1dadb64dbd48e433fd"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: unindents nested list items with shift: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_list_spec.js"},"region":{"startLine":657}}}],"partialFingerprints":{"codehealthFindingId/v1":"10808f1b79e412b210d390e2c05f9b88318cbf9a81b622f3757641ab88a301df"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: indents and unindents from one level below parent back to document root: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_list_spec.js"},"region":{"startLine":671}}}],"partialFingerprints":{"codehealthFindingId/v1":"ac5e7e99d1dd3c2469ed455019f036991cfd1307d58ae9c790a959e6a05fb69a"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can add a new valid link: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_link_spec.js"},"region":{"startLine":19}}}],"partialFingerprints":{"codehealthFindingId/v1":"4522cad8a12e20343e0c5b062b3c286424d61f5946d95fb1a15869ca99986429"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can add a new invalid link: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_link_spec.js"},"region":{"startLine":34}}}],"partialFingerprints":{"codehealthFindingId/v1":"f737e64da2ac44689b4a0739bd8dcb83699d52b5912c7e6aae9b0c2d8dc1784f"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can select existing text as link: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_link_spec.js"},"region":{"startLine":49}}}],"partialFingerprints":{"codehealthFindingId/v1":"961929ef8ff2f00ce4e9f4f16e9349327e9d24b4c45469f37c397824e4f02442"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: pressing mod\u002Bb bolds the text: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_hotkeys_spec.js"},"region":{"startLine":29}}}],"partialFingerprints":{"codehealthFindingId/v1":"1d5198d9d81a7e834b8e1d2c0916ce1a9ceace7c04868be7e65a7def270e46bd"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: pressing mod\u002Bi italicizes the text: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_hotkeys_spec.js"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"33c3c94145bd979ef04fedb270f7ccdcfd6abcb52c957580008a76c3b80d3e8a"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: pressing mod\u002Bshift\u002Bs displays a strike through the text: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_hotkeys_spec.js"},"region":{"startLine":55}}}],"partialFingerprints":{"codehealthFindingId/v1":"30e0831e94e9fa9b41a202f2afc4f43e04198f82d8fadcf33264dec4d11e0570"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: pressing mod\u002Bshift\u002Bc displays a code block around the text: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_hotkeys_spec.js"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"50b11de7143b0eac9988bb0f93d83b0d580ba3d07fdeddb33bd7eb0bcc967c8e"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: pressing mod\u002Bk transforms the text to a link: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_hotkeys_spec.js"},"region":{"startLine":82}}}],"partialFingerprints":{"codehealthFindingId/v1":"a4b940062b9cee0007bc5bbc04b9b76dd09e72d7ff81c2f90f6108ad8bc2ce8c"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: pressing mod\u002B${i} transforms the text to a heading: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_hotkeys_spec.js"},"region":{"startLine":97}}}],"partialFingerprints":{"codehealthFindingId/v1":"2e161319ea74e2ff8fe31b03e57acbbcde8b188b2a47068e1b8ff5c1742d464d"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: creates new default block from empty block: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_enter_spec.js"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"0c57325df0c139e48fefa01529aea57e545f7872d3f880667b6ed370061bbe3a"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: creates new default block when selection collapsed at end of block: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_enter_spec.js"},"region":{"startLine":28}}}],"partialFingerprints":{"codehealthFindingId/v1":"9b54391c3e8019155f6eaae53a4b02aa7ff6cae581e45cc73a78dc981eb93716"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: creates new default block when selection collapsed at end of non-default block: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_enter_spec.js"},"region":{"startLine":37}}}],"partialFingerprints":{"codehealthFindingId/v1":"f2a1e5ff76934e156b82c044e0fc7bcc5ff581c0b570e79c32a600418302cb47"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: creates new default block when selection collapsed in empty non-default block: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_enter_spec.js"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"3e76a1ee92e75d0194a7d37ce06a19ead901c6ae154fe075a7d22fc9ced3ad2c"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: splits block into two same-type blocks when collapsed selection at block start: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_enter_spec.js"},"region":{"startLine":54}}}],"partialFingerprints":{"codehealthFindingId/v1":"df59a69212ddb9bd859a96e31b9431c2abef0225ce7814713a490b272892ff2a"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: splits block into two same-type blocks when collapsed in middle of selection at block start: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_enter_spec.js"},"region":{"startLine":64}}}],"partialFingerprints":{"codehealthFindingId/v1":"3cc6dd64842a790d377a41df84ab645d0fc044310b1f88f909a3624e9a7e9d2b"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: deletes selected content and splits to same-type block when selection is expanded: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_enter_spec.js"},"region":{"startLine":74}}}],"partialFingerprints":{"codehealthFindingId/v1":"58ae413fd82a181b67c729eca1bab9af92a862ac1b3b1460a84be4f4414f436d"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: creates line break: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_enter_spec.js"},"region":{"startLine":87}}}],"partialFingerprints":{"codehealthFindingId/v1":"74e8e719727e30d81e5bd7b426c557060880839d35477a0fcd15415af0b5dc8a"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: creates consecutive line break: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_enter_spec.js"},"region":{"startLine":96}}}],"partialFingerprints":{"codehealthFindingId/v1":"3e24c09ed8d4a1747a635affa4b763e409f408282da6faaf7ce934f92bda4c50"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: outputs code: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_code_block_spec.js"},"region":{"startLine":19}}}],"partialFingerprints":{"codehealthFindingId/v1":"e0d3b7b4833cda9bdd3b77523469c330a5a2b07b38e517166cdd773796bfac62"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: sets non-default block to default when empty: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_backspace_spec.js"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"5328e603068a669958bd61467cc4f155ba14b95855c6d26393c8e51caa5d69cb"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: moves to previous block when no character left to delete: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_backspace_spec.js"},"region":{"startLine":29}}}],"partialFingerprints":{"codehealthFindingId/v1":"bc64f78a919a4d517a11ff0bddc62064fb2b06d112234582357c22bdfcff5f2a"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: does nothing at start of first block in document when non-empty and non-default: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_backspace_spec.js"},"region":{"startLine":40}}}],"partialFingerprints":{"codehealthFindingId/v1":"8f09d80a7606a16ce76139c87aa5eed944bd2ca5db89d1f0c574147f043f7dd7"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: deletes individual characters in middle of non-empty non-default block in document: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_backspace_spec.js"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"4928fa76e050c7011efec5d338921ff8191351a978fe430d213132b3ff98714a"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: at beginning of non-first block, moves default block content to previous block: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_backspace_spec.js"},"region":{"startLine":60}}}],"partialFingerprints":{"codehealthFindingId/v1":"a32d25ec59258df3aa02a3e504a6a7878ebd9de0733c64d7481e3761e5086559"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: at beginning of non-first block, moves non-default block content to previous block: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/markdown_widget_backspace_spec.js"},"region":{"startLine":72}}}],"partialFingerprints":{"codehealthFindingId/v1":"ffb92c191c2569a76e6f2c9d70647fd123d775abbcb7af2580b2d32d2b77f742"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can validate object fields: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/field_validations_spec.js"},"region":{"startLine":88}}}],"partialFingerprints":{"codehealthFindingId/v1":"9abd53df3c04043e9e260ce2efe1535e7cea11be9a9791dd454616d0fe3eae4e"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can validate fields nested in an object field: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/field_validations_spec.js"},"region":{"startLine":93}}}],"partialFingerprints":{"codehealthFindingId/v1":"9f2755259b93de8d04dfeeb72e8c862c6e5bf324712c116e398824608edf6e9c"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can validate list fields: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/field_validations_spec.js"},"region":{"startLine":98}}}],"partialFingerprints":{"codehealthFindingId/v1":"b0f5f0430d836142e95090a7e88b950b724c6975173236fb973059dc7135f246"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can validate deeply nested list fields: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/field_validations_spec.js"},"region":{"startLine":103}}}],"partialFingerprints":{"codehealthFindingId/v1":"092de59263704772c700aea38f662e1058377a66d0daef216e95f29e12ba46b7"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: successfully loads: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/editorial_workflow_spec_test_backend.js"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"370345337402dc3c51c82971165d411ed4d9159622f21622ab58d87c60fc4822"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can publish an editorial workflow entry: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/editorial_workflow_spec_test_backend.js"},"region":{"startLine":76}}}],"partialFingerprints":{"codehealthFindingId/v1":"a9522cb9aeab1f3f713b1d92ad3c353ed379b2e9148341ecfaf472e0dd4e1be4"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can change workflow status: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/editorial_workflow_spec_test_backend.js"},"region":{"startLine":105}}}],"partialFingerprints":{"codehealthFindingId/v1":"2dd3827d1efbd358b31bacf96570c47ea9e8340872f6df5730eed45688e2968b"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can change status on and publish multiple entries: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/editorial_workflow_spec_test_backend.js"},"region":{"startLine":116}}}],"partialFingerprints":{"codehealthFindingId/v1":"d5c5136729c4ac2a62c5fd6b6f9aa02ad9aaca12121ea07f11ebf0a127359495"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can delete an entry: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/editorial_workflow_spec_test_backend.js"},"region":{"startLine":132}}}],"partialFingerprints":{"codehealthFindingId/v1":"d04c4a1b1b9ed6c35e6866e1389d11af678ff6ae388560b0e4a4715f054ddebe"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can update workflow status from within the editor: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/editorial_workflow_spec_test_backend.js"},"region":{"startLine":140}}}],"partialFingerprints":{"codehealthFindingId/v1":"74c9794373e41c71b73d429499f2d4ba5fb09bbb2188bc8c69e38ee3f371e671"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can unpublish an existing entry: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/editorial_workflow_spec_test_backend.js"},"region":{"startLine":153}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a01eb25e40c672c84c3d53d3352765eaa2df8929259aecdd844c2f154efed0d"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can duplicate an existing entry: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/editorial_workflow_spec_test_backend.js"},"region":{"startLine":164}}}],"partialFingerprints":{"codehealthFindingId/v1":"260bb448659ead3f882c08788bf01aae21dfe062f5f63f6930d184343a806a84"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can create a new entry, publish and create new: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/editorial_workflow_spec_test_backend.js"},"region":{"startLine":183}}}],"partialFingerprints":{"codehealthFindingId/v1":"c976b2e85b77d346677c6202e1583c644c6614d0aed687ccc16822879496616d"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can create a new entry, publish and duplicate: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/editorial_workflow_spec_test_backend.js"},"region":{"startLine":191}}}],"partialFingerprints":{"codehealthFindingId/v1":"047dff8fe94a14f4ff8c03e64ccb0a9fad1e0fd0e2bc679d428973ce08740053"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can navigate to nested entry: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/editorial_workflow_spec_test_backend.js"},"region":{"startLine":231}}}],"partialFingerprints":{"codehealthFindingId/v1":"96c0c6c8bb50f216acd9291b1860d3fbe5e288090f16e10daf14b3f1cb3b56a1"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: successfully loads: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/simple_workflow.js"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"c8861e33df3d50896122edc66520237dcd900c88260c08cc53922e577fd1480d"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can create an entry: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/simple_workflow.js"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b7e476223eb49418b298a85dc4657ce8981c9dc5106b7e701529031a9c14c34"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: successfully loads: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/open_authoring.js"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"6eba166b4a527d1f110a2cb5c6cd394476e3bced415533d19c1086b7aa8399c8"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can create an entry: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/open_authoring.js"},"region":{"startLine":18}}}],"partialFingerprints":{"codehealthFindingId/v1":"0431d1bedf48c68dcc45304a6f85c8f1146abab3b8cbcfe0ce1654fda73d12ce"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can update an entry: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/open_authoring.js"},"region":{"startLine":23}}}],"partialFingerprints":{"codehealthFindingId/v1":"2c2de35d3e7c38aeb9b15ea5755ae45854bf2e5d895e0232a559873c55b3f255"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can publish an editorial workflow entry: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/open_authoring.js"},"region":{"startLine":29}}}],"partialFingerprints":{"codehealthFindingId/v1":"bd4cb5696ee9d0c028b2977c8d969c753bb71dd505f5eb5203f65a2a45be700d"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: successfully forks repository and loads: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/open_authoring.js"},"region":{"startLine":37}}}],"partialFingerprints":{"codehealthFindingId/v1":"e90b0d908f1ea5146a1ce3d9d1e6c574730415cb4c8b97ceefda455c63fe9903"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can create an entry on fork: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/open_authoring.js"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"fa40bbab6dc5ef264caf33688ec7200e62264f6ebe84ff16a35c0550b550c8d4"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can update a draft entry on fork: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/open_authoring.js"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"60eb7ee30ab1785d068594e6d106358d1e2adeb9a53e0a0cb175bd584dd6fd64"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can change entry status from fork: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/open_authoring.js"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"4ef620f3c5fc112a8a7912f86c848dc973f623ebef5840ab6a351b10f0df113d"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can delete review entry from fork: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/open_authoring.js"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"09be85f16096732bf1f13065faf7930951216960bf4a04f609c2e788eb22c04b"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can return entry to draft and delete it: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/open_authoring.js"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"8bb12729ea4d0369530497bc6bbaf4e61e90bd458b6a4a8d32620d402ea5e50e"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can upload image from entry media library: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/media_library.js"},"region":{"startLine":174}}}],"partialFingerprints":{"codehealthFindingId/v1":"bc5d77cfc9ff803c2ec9f616cb1cff676e47a5765ec3c740d616449033ff3e1c"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can save entry with image: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/media_library.js"},"region":{"startLine":181}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7e0557e4fb0e88a4dd940eca785fca3a0cfe2eaa8ad5b14b669766b9459afd9"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can create and publish entry with translation in ${structure} mode: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/i18n_editorial_workflow_spec.js"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"33168f1cfca715df4a2476e61b5aec066099c77fbdb558f188954e8f88f4f336"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can update translated entry in ${structure} mode: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/i18n_editorial_workflow_spec.js"},"region":{"startLine":37}}}],"partialFingerprints":{"codehealthFindingId/v1":"bb5f551d7f39bab58591e11c7ff01ea7a273d66a4569a28296d302a5c56a0311"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: successfully loads: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/editorial_workflow.js"},"region":{"startLine":23}}}],"partialFingerprints":{"codehealthFindingId/v1":"a6e4e172cb69687c885df5820dad57f35a8ad64cf6bf0576fe3803f7a577499e"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can create an entry: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/editorial_workflow.js"},"region":{"startLine":27}}}],"partialFingerprints":{"codehealthFindingId/v1":"8a0009355e3bc44d25521d92e086c2501be6b6f7f07ddc78eaf9563e09632871"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can update an entry: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/editorial_workflow.js"},"region":{"startLine":32}}}],"partialFingerprints":{"codehealthFindingId/v1":"5637e7742974bb525e2dc0f194a0686ab9696af381e61467bcfaa1b7dea6ea8f"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can publish an editorial workflow entry: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/editorial_workflow.js"},"region":{"startLine":38}}}],"partialFingerprints":{"codehealthFindingId/v1":"27644d1810f025de90964d848796fef8e48e53716114da3204b070aae5ac8c11"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can change workflow status: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/editorial_workflow.js"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"26e169ad306908cc104029d40ea89ae8e53aaf20569d5b677919e8b43cd3bdfb"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can change status on and publish multiple entries: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/editorial_workflow.js"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"b66c8c7ff3ad4fb4478397ed82826e9919af788be0713a9b6cab8290745cfff4"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can delete an entry: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/editorial_workflow.js"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"9857e69c79910fc04935aba4cbc9bea20f543039801cf2b057a24d51f72f2a8c"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: can update workflow status from within the editor: No conventional assertion call was detected, and 132 of 161 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/e2e/common/editorial_workflow.js"},"region":{"startLine":81}}}],"partialFingerprints":{"codehealthFindingId/v1":"ca8d073635874488845aa2c88fb9fdfe0b3d1d668d0bd75d9591c6e7cdf7005a"}},{"ruleId":"D10","level":"warning","message":{"text":"No assertions: should convert inline-shortcode between Slate and MDAST: This method\u0027s body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* \u2014 so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as \u0027no assertion this check knows how to see\u0027, and if that is right, add one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/__tests__/slate.spec.js"},"region":{"startLine":343}}}],"partialFingerprints":{"codehealthFindingId/v1":"f64fca2d40b7247a780078331a1de5f346647bc071c4ea1c655be66900bdc913"}},{"ruleId":"D10","level":"warning","message":{"text":"No assertions: should parse inline shortcode inside paragraph without breaking paragraph into blocks: This method\u0027s body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* \u2014 so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as \u0027no assertion this check knows how to see\u0027, and if that is right, add one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/__tests__/remarkShortcodes.spec.js"},"region":{"startLine":116}}}],"partialFingerprints":{"codehealthFindingId/v1":"c0c7aba8f9b1b418d5e0db44cba1e6a3395571ecf608cbcfa4a8b94140e485e2"}},{"ruleId":"D10","level":"warning","message":{"text":"No assertions: should stringify inline shortcodes correctly in round-trip: This method\u0027s body runs code, and no assertion call was recognised in it. Recognised by name: Assert*, *Should*/ShouldBe*, Verify, Expect, Throws, Record, Received/DidNotReceive, MustHaveHappened/MustNotHaveHappened, EnsureSuccessStatusCode and *AndEnsure* \u2014 so verification routed through a helper of your own naming, through a base-class or callback object whose members hold the assertions, or through a harness that fails by throwing under some other name, is not visible to this check and is not counted here. Read it as \u0027no assertion this check knows how to see\u0027, and if that is right, add one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/__tests__/remarkShortcodes.spec.js"},"region":{"startLine":253}}}],"partialFingerprints":{"codehealthFindingId/v1":"662c2aee3f5672be7423818e563e46100c93e1dd78b3fec99a56195a5469477a"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: packages/decap-cms-core/src/reducers/mediaLibrary.ts: packages/decap-cms-core/src/reducers/mediaLibrary.ts changed 3 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 37 in mediaLibrary.mediaLibrary at line 62. 1 of those changes was a fix/bug commit, and the other 2 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-24..2026-09-22, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-24 14:36:34 \u002B02:00\u0027 --until=\u00272026-09-22 14:36:34 \u002B02:00\u0027 --full-history --no-merges -- packages/decap-cms-core/src/reducers/mediaLibrary.ts\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/reducers/mediaLibrary.ts"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"13d4505d84814b90ddbcb6250e548e7ad2d40738e3bbd2d82d70bd5feec97335"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: packages/decap-cms-core/src/components/Editor/EditorToolbar.js: packages/decap-cms-core/src/components/Editor/EditorToolbar.js changed 2 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 22 in EditorToolbar.renderWorkflowControls at line 599. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-24..2026-09-22, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-24 14:36:34 \u002B02:00\u0027 --until=\u00272026-09-22 14:36:34 \u002B02:00\u0027 --full-history --no-merges -- packages/decap-cms-core/src/components/Editor/EditorToolbar.js\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/Editor/EditorToolbar.js"},"region":{"startLine":599}}}],"partialFingerprints":{"codehealthFindingId/v1":"f43f8a53448fb31fded8c287cabc5f1c274a6ee82e3be60d63c1dd3d3a52ae52"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: packages/decap-cms-core/src/reducers/editorialWorkflow.ts: packages/decap-cms-core/src/reducers/editorialWorkflow.ts changed 2 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 20 in editorialWorkflow.unpublishedEntries at line 27. 1 of those changes was a fix/bug commit, and the other 1 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-24..2026-09-22, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-24 14:36:34 \u002B02:00\u0027 --until=\u00272026-09-22 14:36:34 \u002B02:00\u0027 --full-history --no-merges -- packages/decap-cms-core/src/reducers/editorialWorkflow.ts\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/reducers/editorialWorkflow.ts"},"region":{"startLine":27}}}],"partialFingerprints":{"codehealthFindingId/v1":"a8b47e950540414c4fa4fadd3dab4ee01ca40d38bb29d991863928133859bafc"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: packages/decap-cms-widget-markdown/src/serializers/remarkRehypeShortcodes.js: packages/decap-cms-widget-markdown/src/serializers/remarkRehypeShortcodes.js changed 2 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 16 in remarkRehypeShortcodes.remarkToRehypeShortcodes at line 12. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-24..2026-09-22, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-24 14:36:34 \u002B02:00\u0027 --until=\u00272026-09-22 14:36:34 \u002B02:00\u0027 --full-history --no-merges -- packages/decap-cms-widget-markdown/src/serializers/remarkRehypeShortcodes.js\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkRehypeShortcodes.js"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"c9b7d3d3bf37b4131aee1b3aa6e3c05115f14e1ca14529b01aa5209106a4431c"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: packages/decap-cms-widget-relation/src/RelationControl.js: packages/decap-cms-widget-relation/src/RelationControl.js changed 5 times in last 90 days and 4 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 7 (its worst body is RelationControl.loadInitialOptions at line 276), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201CRevert \u0022fix(relation): retry menu options after a failed query\u0022 and its follow-up\u201D; \u201Cfix(relation): guard shouldComponentUpdate when nextState is missing\u201D; \u201Cfix(relation): retry menu options after a failed query and cache only success\u201D; \u201CFix: improve relation widget (#7968)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-06-24..2026-09-22, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-24 14:36:34 \u002B02:00\u0027 --until=\u00272026-09-22 14:36:34 \u002B02:00\u0027 --full-history --no-merges -- packages/decap-cms-widget-relation/src/RelationControl.js\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-relation/src/RelationControl.js"},"region":{"startLine":276}}}],"partialFingerprints":{"codehealthFindingId/v1":"be48c5da26c10e47210edd39ae0dea190d1ec8c7ad0ef124480ced2a020c9aaa"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #1: If anonymized user #1 becomes unavailable, 3 significant file(s) lose their only recent owner: packages/decap-cms-backend-git-gateway/src/netlify-lfs-client.ts, packages/decap-cms-lib-auth/src/netlify-auth.js, packages/decap-cms-backend-bitbucket/src/git-lfs-client.ts. Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6a713a95d04842fbdb522c031c16e1c597cbe4ef1ff424b1893b5dbae399fa39"}},{"ruleId":"D16","level":"note","message":{"text":"Further sole-owners (lower concentration): 8 other contributor(s) are each the sole owner of a small amount of code below the off-boarding threshold \u2014 folded into the bus-factor score and metrics (13 single-owned of 200 analysed files in total, counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 200 of the 528 production source files in this repository met that bar). They are anonymized user #2 (2 file(s)), anonymized user #3 (2 file(s)), anonymized user #4 (1 file(s)), anonymized user #5 (1 file(s)), anonymized user #6 (1 file(s)), anonymized user #7 (1 file(s)) (\u002B2 more) \u2014 spread or document their files in the same way, at lower priority than the named off-boarding risks above."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6eac528f2429e724e1a97ed868f79eefbcf1888dab4af9a9e673429369bb5b2f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: get real id \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-bitbucket/src/API.ts"},"region":{"startLine":735}}}],"partialFingerprints":{"codehealthFindingId/v1":"77a8ba1f350247a362677376dd3879eea3ff67ea450752f5f649af2868d71360"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: what kind of error to throw here? APIError doesn\u0027t seem \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-git-gateway/src/netlify-lfs-client.ts"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"6a375cdece03f2d64a678676aa23882619d26869cf5dbcbe1b03df95d46929a6"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: remove after https://github.com/netlify/gotrue-js/pull/83 is merged"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-git-gateway/src/implementation.ts"},"region":{"startLine":415}}}],"partialFingerprints":{"codehealthFindingId/v1":"73c99d60944c31dcf815ea805429f6efece078acb204668a5a18559eeb6a7981"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: get Netlify API Token and use it to access private logs \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-git-gateway/src/implementation.ts"},"region":{"startLine":617}}}],"partialFingerprints":{"codehealthFindingId/v1":"2440a7468a9692d7f148fd1fa681504b7ae24036726c0faa232a2aafcb751a5c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: stop assuming cursors are for collections \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-test/src/implementation.ts"},"region":{"startLine":212}}}],"partialFingerprints":{"codehealthFindingId/v1":"ff38811f17ef9585a64a0a48a2caa3529803e21c172c6a47f052728eec7a695e"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: pass search fields in as an argument \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/backend.ts"},"region":{"startLine":770}}}],"partialFingerprints":{"codehealthFindingId/v1":"2af1ca0876eda320735019a43c638d5c488aad32a717e63d5881cf826c60fba2"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: stop assuming all cursors are for collections \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/backend.ts"},"region":{"startLine":855}}}],"partialFingerprints":{"codehealthFindingId/v1":"8e5a52b6dc974742a9c87d0ada184c9ea77b89c715d8253501cfefd46a7c5e2f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO remove fromJS when Immutable is removed from the collections state slice \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/actions/config.ts"},"region":{"startLine":372}}}],"partialFingerprints":{"codehealthFindingId/v1":"e440967714bd069e870a4597d6e85bfdfad5af3e97b4657d9de88857721842f6"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO change to proper payload when immutable is removed \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/actions/__tests__/media.spec.ts"},"region":{"startLine":45}}}],"partialFingerprints":{"codehealthFindingId/v1":"c52d49700b261550b768197b0753b49406b7fdcc43bda0da945a4efbba1d8280"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO change to proper payload when immutable is removed \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/actions/__tests__/media.spec.ts"},"region":{"startLine":72}}}],"partialFingerprints":{"codehealthFindingId/v1":"9a40780178ffa21b6782cd2f67f5d30d1d00d05c520f29f62b3296af342b5553"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO change to proper payload when immutable is removed \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/actions/__tests__/media.spec.ts"},"region":{"startLine":102}}}],"partialFingerprints":{"codehealthFindingId/v1":"81bdd15827e8d29485edc39af47a7af1bbc51d25337ac220a6b911c8da54f0e7"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO change to proper payload when immutable is removed \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/actions/__tests__/media.spec.ts"},"region":{"startLine":125}}}],"partialFingerprints":{"codehealthFindingId/v1":"969b48b5af397d3fa517dfe245557de19204d404d9cc4ff33c40bbeb489142ef"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO change to proper payload when immutable is removed \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/actions/__tests__/media.spec.ts"},"region":{"startLine":155}}}],"partialFingerprints":{"codehealthFindingId/v1":"5b6612be674f703d55011420f46b58b452dded5351f891d9e9d5e5523c2cce5b"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO change to proper store data when immutable is removed \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/actions/__tests__/media.spec.ts"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"ad6d80978a73c0e5e69346e23963155f6641ecb001cd16ef3c51b8a3d85d5baa"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: type properly \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/types/redux.ts"},"region":{"startLine":505}}}],"partialFingerprints":{"codehealthFindingId/v1":"2784bac237161287f54ee9c07865d0343aba9cee7cfd4da5b782b9dfb10fe777"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no installation or build instructions: There are no installation or build instructions for decap-cms-widget-code. Add a short install line (npm install) and any prerequisites, then a quick run command."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-code/README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f78345df7ef949953c0cf372e6234c0a3072039ab0801e8f7780c4a87bf55151"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found. No recognised ADR directory (\u0060docs/adr/\u0060, \u0060docs/decisions/\u0060, \u0060adr/\u0060, \u0060docs/rfcs/\u0060, an \u0060ADR0001/\u0060 folder, or their siblings) exists anywhere in this tree. What was searched, so you can tell an empty log from a search that missed one: every directory under the tree (build output, dependencies and VCS metadata excepted), for a document that is either any non-index page inside a recognised ADR directory, whatever its name and however deeply nested (\u0060docs/adr/use-postgres.md\u0060, \u0060docs/adr/2024/0001-x.md\u0060); or a file anywhere whose name is ADR-shaped (\u00600001-use-postgres.md\u0060, \u0060adr-012-caching.md\u0060); or, when neither turned anything up, a document carrying the decision-record signature (an \u0022Architecture Decision Record\u0022 heading, or Status / Context / Decision / Consequences as section headings). A decision log that clears none of these \u2014 unnumbered files outside any recognised directory, without those headings \u2014 is not seen by this check and this row is then wrong. If that is your case, say so rather than renaming anything; otherwise, consider recording architectural decisions in \u0060docs/adr/\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D26","level":"note","message":{"text":"Split packages/decap-cms-core: A 20k-LoC CMS core with 24 unrelated namespaces is a sprawling grab-bag. Suggested: "},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3aae6a46b354d69afc821875a7ac59106a3d7415221711bce18c5c07d6ef8404"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"226817c687e461edd8dd3e7a3e62a52faa9616a62342fcad9193054428476bbd"},"properties":{"commitSha":"3d474b1944239cfe0600e8410a7f8ff303d07b55"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"53c8cc8b842a6d2613224f6f64f69d913fa5c243229cf59f6c228f88232c5beb"},"properties":{"commitSha":"04c44518b205fae902c189a21d10fd768357f3bd"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"51d1c2cac122f0ce303046e0fa3d246280f883d0de78a89040fae2d4648d1635"},"properties":{"commitSha":"155f40e5e4d09610c11e40a66969af5f2cdf5248"}},{"ruleId":"D28","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3cdfd7beb31b791ae18dcb425e21eb157c842e7bbcd522cc330573c1a6538db1"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0ec4d1455cf61acfa62b7aa8e596cfbec3a905cd225bf5db33a3bae350022a8c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e68f6ee13d8b4445d070c9bc2259c553c0969c623ab8310e62bf207cc35e9de1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9d8137e2843a4d9ace312984d4d1b8b07998cf19f7a31e2c7e904de2ca9c84a6"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5347ecec7591170629c15c4fa6ca3de2ee2c5ba0078db47a37988365a2931868"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"310f8ffc5418403b7e0b9a597391dded20c062ac8c10200e4020b8020d32cbf7"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5aee62ee6dc9df52041e8b135f4a97570211029bb52de85a2da56ea8b1693f65"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"832cdfb152c393d0e559645bd8079a778bee771ff838fce1c8b7bc987dc9ac85"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d788572f45b9168624027b8915ff0115c7d1610c07e39df375a3bd16788eeda5"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3511acbec5078504c176a4d654f66174afbdaf5bcaea19d60c77f386db06de20"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8cccc2527c7888a19b78ddea0cd307bf70d5806efc8238afc148b51e38c1e594"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f7f980a9cf42abc7b05fa027a355d0b70694f525fb25561bb62db503e1d678c8"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"caaef870639f1d402ff92a847892f1e68b2c910575918e131f0335b4b1d4926e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a2fbd63b77f952622ad09538860ac1abe6ecef36f8ee9d103d3e5331aeeb29f8"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"edaef0c30876b6e5087983cddfb0934ad51ffbe1bcaf1a7d72269978dc7af6b4"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"826a0b72e2a83db4e3f9dc31a5bb4460c351f850d6b7ae6a1a036de330bfe1e8"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f4e65b5e346b5bcb40594d11b6d427d90e02dcb264dae72256b5c53282e3035b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5d6b70d54245615977d74d44ce561eec408b63f675f9e8a08efb99832961b897"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f55cdede0a7ae889c9a3c0c2032310429875c8ceba201ae1c6891f7ad64d7324"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7aea1ec2f93cac7dbca992f8d53e0bca3943de587b7bbb7635a10457caef1193"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3f018d9b02c4527372c4d562ed0780acdada5f6cdf4aa6e5f56d550463429eb9"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"03d11c6190b37acd4374b4198acdda884b974c7ad62386587633481ecb69eda2"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"69f2db33b9fbe25ea79ee911844c43e170b1ecb54696f58397516e18edf74e21"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ddb6faffe20ecc2090072dd71727513620301e0303cbf74925e1ee47db820283"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8dc838f700a56de0cf4b4a3639621f4b64cc2676507af1f80275fdabb4b38f52"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0c072246e95eba514471fc803c50f5f0013b0fe9d1af7e65d67297ace8188d48"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"55be33be57338051591d9d30e0eee44112d77ddebfa90a4aced3fdd2b88b2122"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4fbc6df3d72864219648f8a5e2a3fe4857d204776cc76785ab693bf45ade35c2"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"08303728022f83e73efc210add81bd315c8a086c289b3d95ae5582b317b91d8b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d75904c8723a31ba01c02a467ad73fa22eed54ca13ff19ae4442cb79f4d82afd"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3c178b5df30ae3835b2a69751a1f407c53fd3cd10005389f7d8fc977f5478ee7"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cfd63c4ff2fdf682b767fca6359499a0b632d44ddded7a159dd9b05373f680ef"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6ba02b84abe6a9485bcf3f185d77ed63826c7ed0f947188818d008b4f7f59643"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ea169d59f2dd0f25009885a035cf54238f18264e0ab32215983b4207a514c368"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4133fe2e013a87e541bd0855b5448f4831718eb94035111f7d5e657ab2d80695"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8af93b54d7b6d09176d9c9016e65470b9e3497c2e30cd6af0b8b0a89230292a4"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7cf8a78c4a993aecafcb4fe2b18ecb6ff3aced137586a07de2812771fcf18756"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1498825690ee691422757d83c6c8726aaf69040fa62a3b6b71a03075f0880320"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"85f99189d964cdde824a816d83f2290af0a3f7efe42feb1d6495743a90e33e22"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cdf55fc70b901991f8931b9f7a7734d17c7916cb7a7697332e6173d36bc2c061"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"46781f1aa0068928ca28fcba7a7cfb1dd78d1eb9898e091a08a4bcb36d50fe83"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1329","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d30fa16bab97564316796271c5f9a90fe15d2123c6464d1da53ae0ef8a559231"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"efb3ef0ea42d30f0158541595a74f03e5f1783fcb4e3a00783f8fef2a9e34df5"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1329","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"badffefc10be94eaa34f89e7293d09dbb9481c02d7b243653e79263ea90278bb"},"taxa":[{"id":"CWE-125","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"38b50d527a16ff9dcd6ab49f44eb4a2bbd02611615f55f816db2b2c109f5814d"},"taxa":[{"id":"CWE-457","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dd39ab68b9681c5df6a012e2469f935e963f5b77fb3ba27c3f5575b6c69fbdee"},"taxa":[{"id":"CWE-457","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3bc867bbaaf570f0895afddd4adb65ffcb97a432be1e6c1089da08892bdb6a67"},"taxa":[{"id":"CWE-457","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1da6ea807ed2687670ea1970b6ef75720dbe9bcb7a372f1bf7202e1d29b327a7"},"taxa":[{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8c8371d8a9b063df0d6f4e61d46d8bb1379a749fd484e0c3145c486cdea1abaf"},"taxa":[{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"64817b26bce4caf686ef1ed996068f9a778c7d72e0be66ddef1ec3ef5f8dc9a4"},"properties":{"dependency":{"package":"tar","version":"7.5.11","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6317349905c8cb6ded85959c367d0855688400172bd906e6d9ccc4276f51ba9f"},"properties":{"dependency":{"package":"handlebars","version":"4.7.8","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6a9c5dc02a305a3849efcbc83cb36ace3ea22ee5324e0e6d34e674e83f3f018e"},"properties":{"dependency":{"package":"babel-traverse","version":"6.26.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eed3513a7ea7c143dafadba572ab28dc428f5f9d9d64a11270275dd896eeb91d"},"properties":{"dependency":{"package":"cipher-base","version":"1.0.4","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9e32a448cc007ced35f574ac851d62d56116470e427182b0cdc6268bd3dd0048"},"properties":{"dependency":{"package":"form-data","version":"2.3.3","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e3216153f19210535a93a95ef5e1fa74be81a68647897919f46ab92c9eb2cddd"},"properties":{"dependency":{"package":"form-data","version":"3.0.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"52816bc9690d30935d4cab1279f9a4864ef8ff42147bfe81e2a84797f34bbb41"},"properties":{"dependency":{"package":"simple-git","version":"3.20.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"production","file":"packages/decap-server/src/middlewares/localGit/index.ts","line":14}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"29827ff1862f4841c892ec8b8867f048f1bfa9d96110dfe90e22961d0aa8306d"},"properties":{"dependency":{"package":"shell-quote","version":"1.8.3","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"875d3d67c2a0356b999350052ad38eb97853110cf75fc4de20725ee90d0f713b"},"properties":{"dependency":{"package":"minimatch","version":"3.1.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"production","file":"packages/decap-cms-backend-bitbucket/src/git-lfs-client.ts","line":1}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ac7893c432641d49d7dba4e2926bb50b71a6e40b382cf80c51e186d0dd375f12"},"properties":{"dependency":{"package":"minimatch","version":"5.1.6","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"production","file":"packages/decap-cms-backend-bitbucket/src/git-lfs-client.ts","line":1}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f01487d28b5947f42c1c01c74e0be45880cd5f0f9b1bc88debcfb318cf696c49"},"properties":{"dependency":{"package":"minimatch","version":"7.4.6","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"production","file":"packages/decap-cms-backend-bitbucket/src/git-lfs-client.ts","line":1}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bc0d4bfbc2dbf13b7b4678c7f750f00c9c46698f61534d37a6a18fd133b243d5"},"properties":{"dependency":{"package":"flatted","version":"3.2.9","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e8696820da588f2f886b1969e3625ad950b8bb4fa07132938e25b8abf526fb08"},"properties":{"dependency":{"package":"js-yaml","version":"3.14.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"test-or-tooling","file":"package.json"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"56a6baedff85f2c9359f23d086afa0615f014dfc35a2236e74e787763e2e8289"},"properties":{"dependency":{"package":"js-yaml","version":"4.1.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"test-or-tooling","file":"package.json"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6b5b8bd683e8d06246b76bdfa89ad3374176943ffd7ad2e6c5fb65b79764443c"},"properties":{"dependency":{"package":"js-yaml","version":"4.1.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"test-or-tooling","file":"package.json"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2ea65af982fbfa7ee58dbe3fa40bd975ecb648d209c563eae9269b519d2be2a6"},"properties":{"dependency":{"package":"nanoid","version":"3.3.11","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"036ceb1c827887c9feb7b132d0f921bc5f3fcceb704bc04b99a26df371b5f1b3"},"properties":{"dependency":{"package":"svgo","version":"2.8.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"45c488355148beef8e20121a79c71a37282ddf9decac207cb0129be85f28503f"},"properties":{"dependency":{"package":"axios","version":"1.12.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"test-or-tooling","file":"package.json"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f92fc2ddb946ed0765e4c67aa7e243a07870f2368edac2bd98c50b6c0d66c7eb"},"properties":{"dependency":{"package":"path-to-regexp","version":"0.1.12","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c2b24aaa67f38274086d7b9b346106d216dd78d4885c67628dcf133ba0a29934"},"properties":{"dependency":{"package":"axios","version":"0.27.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"test-or-tooling","file":"package.json"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"df21b8127d24aeed9579f3ce44f2f84d2d4f9ae41d6b03d4309b75c4781747cc"},"properties":{"dependency":{"package":"brace-expansion","version":"1.1.11","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6fde06abe7dac0b6bc6951df4e58a3dd77b634a2402a8ce8ec6bcc39669c05de"},"properties":{"dependency":{"package":"brace-expansion","version":"2.0.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d413b799df6a5824528071c98e7f12373a3498303fa33c50104b3c9319c46b58"},"properties":{"dependency":{"package":"axios","version":"1.18.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"test-or-tooling","file":"package.json"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4ec11b29f3c789ce8470b2eb8eb555d532a149ef406d732512c142060cef3d29"},"properties":{"dependency":{"package":"cross-spawn","version":"6.0.5","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b3b87a1a4dd6c709137ea165a09c11e4a735ae492c8b42d1893ab5ea92ddd0a7"},"properties":{"dependency":{"package":"cross-spawn","version":"7.0.3","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"06593c39ce911a216ed914a471d9cdd931bac450d9675076e44dd756bcb35a60"},"properties":{"dependency":{"package":"fast-uri","version":"3.1.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"39c6279a8811e4625e1a3f81408b30bdb35987e457510c1bc2b7498e61fb7122"},"properties":{"dependency":{"package":"postcss","version":"7.0.39","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"test-or-tooling","file":"package.json"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dd1e69a91b75204779677afd337a46a77485eeab37049d9a968c8ca3ce741fb8"},"properties":{"dependency":{"package":"postcss","version":"8.5.6","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"test-or-tooling","file":"package.json"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7efd016abae99d72844bbb774ba5625064247ddf2419145f6f0addff7d5a7b2b"},"properties":{"dependency":{"package":"joi","version":"17.11.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d17c1896d62e8f674c99d479578fc7c634390f59470213ab43667ad171d8d5ee"},"properties":{"dependency":{"package":"brace-expansion","version":"2.1.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"479fe6f46e89b73b3c5d22c1d1e662aa9925f0eb723ba5fb480bbaa5384dd778"},"properties":{"dependency":{"package":"brace-expansion","version":"5.0.8","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8a5a82821c71f8aadce4c10b9c3690e4a810e3db0f8b2e78f054dfb04d823c9a"},"properties":{"dependency":{"package":"brace-expansion","version":"5.0.9","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ce9bbfea95fe015374ae86e03b9373fd15c82feee84c4ee070b765207d8d9476"},"properties":{"dependency":{"package":"browserslist","version":"4.26.3","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2293c5b7438af6e9b72fcd6de42f60336e9647543d0ec963a873c5fd77b6da43"},"properties":{"dependency":{"package":"extract-zip","version":"2.0.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b9e6ed2f1c3b9d06c1ae728ca0754a134c8b09e532a74b14e5e76708e01e4c58"},"properties":{"dependency":{"package":"smol-toml","version":"1.6.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"de68e4e429cde4647cc3e2d6206bac18fc18427ad4dd8ce8e8961c45c553c30d"},"properties":{"dependency":{"package":"storybook","version":"9.1.15","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"659b17df3a297d0c761f05e64fbd7a7fec481b8fec3425db0f2590512d5583b5"},"properties":{"dependency":{"package":"ws","version":"7.5.10","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"98f5b7f1cc7ab72c7ef988be1ab835626c9ba93796c264fb44a05726fc7d8dd6"},"properties":{"dependency":{"package":"picomatch","version":"2.3.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d1b40cfcc9d78218aa0f480502edb47dff77a7506ea9522cc092162c50587e66"},"properties":{"dependency":{"package":"semver","version":"7.0.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"98204145f96342d1f975bb5d8264cb4e9a8d76c1095e50fce1327da005521263"},"properties":{"dependency":{"package":"semver","version":"7.3.7","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"85a0cc54a04a258f890dfcf56d8b54e982ad85db677a716180fa388a7789ed89"},"properties":{"dependency":{"package":"@babel/plugin-transform-modules-systemjs","version":"7.27.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"50158e674a425a76864e10f3dc10943702dcd4e3db70274c526a9a9e55691783"},"properties":{"dependency":{"package":"webpack-dev-middleware","version":"8.1.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fab4940bf2a8fc270c68898bb2d086ce8ede7e6a694d8591e3fb0414eeecfcdf"},"properties":{"dependency":{"package":"braces","version":"2.3.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ef89e1adf763e8d2b24925fe8b814a4b416c038f9ba0294ef7d7384363a53259"},"properties":{"dependency":{"package":"braces","version":"3.0.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"01fc85053279d115ea033564d5712283763a31a120ba4ad4775e78b10049b1a1"},"properties":{"dependency":{"package":"form-data","version":"4.0.4","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"38ebac7fc1d141303bf1fe260614c25cdc6587739d42356be3777debe9b00be1"},"properties":{"dependency":{"package":"lodash.set","version":"4.3.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"090bd9ff8a4b793c4328aae66595d61318c232e1c2234af72321a86c072ada29"},"properties":{"dependency":{"package":"tmp","version":"0.0.33","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8128eabcfe3707af062c4a3a8e59930cea00c3060018c4147bdb3846da53d168"},"properties":{"dependency":{"package":"tmp","version":"0.2.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"81f6b717902adb5e36bbd223067380a6728f35e08905f8910d1bf59c9df3b40a"},"properties":{"dependency":{"package":"lodash","version":"4.17.21","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"production","file":"packages/decap-cms-backend-azure/src/API.ts","line":2}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2a16831730511895240ff77dbbc1152ed9c4b40d44d9d54bc87945035b69e17a"},"properties":{"dependency":{"package":"lodash-es","version":"4.17.21","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9fd7f84b2b8c5f1916c523db2952bbaca02004965fa0b9413b362516e0e7248e"},"properties":{"dependency":{"package":"undici","version":"6.28.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"691b7e2bf95c8af84df5ce832211dd11cd5da521b87c95df1fe446031c2b4fca"},"properties":{"dependency":{"package":"immutable","version":"5.1.3","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"production","file":"packages/decap-cms-backend-azure/src/API.ts","line":28}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5e2337973b03a2fe612ccb0f2b2c9f1440c549a43135f096fd89166b5d8dfd40"},"properties":{"dependency":{"package":"nx","version":"21.6.6","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"test-or-tooling","file":"package.json"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1898d9f46541a6397b5a5b9ef1e18edef78eb0b68672e5c955952ea77ea09b7a"},"properties":{"dependency":{"package":"pacote","version":"21.0.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1008129bad142f90a000f81ae6964099b8355d375f85fc00c7495851dc9a84eb"},"properties":{"dependency":{"package":"trim","version":"0.0.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"addbeeceadb4c5bc8ee5caeb04de03ac44d22d147c99d7f88af5a778dea0b9c6"},"properties":{"dependency":{"package":"serialize-javascript","version":"6.0.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b7bda289298f8c7b577c3df21f51a6fc17f92b7e23b2a76b5f7c4731a8327d8c"},"properties":{"dependency":{"package":"ajv","version":"6.12.6","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"production","file":"packages/decap-cms-core/src/constants/configSchema.js","line":1}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"92da29f94e263abea0ade968703748a9c42d1739d2b2b4fd0b3d8bd698b99428"},"properties":{"dependency":{"package":"ajv","version":"8.17.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"production","file":"packages/decap-cms-core/src/constants/configSchema.js","line":1}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d10c79b7ba192f2bf3e9d396706548fd35619089ac0c9053c2f32644873e24c7"},"properties":{"dependency":{"package":"ip-address","version":"10.5.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3e28dd2da9a40e794e9cb9bb48d649ff80832ed5b9964b8392540d4033c64d16"},"properties":{"dependency":{"package":"colord","version":"2.9.3","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4ec37e44d35d330622658f261dbe762d5a43a65df6039cefb3f9868a8460ce99"},"properties":{"dependency":{"package":"bn.js","version":"4.12.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"91ef51b5caa33ab32f5b35448f0a52f82a2bc75e4cc857aa664ca69ae31ba414"},"properties":{"dependency":{"package":"bn.js","version":"5.2.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cab2098e551f88d096756eea896ab201fc72ec0275bddc366f276c5eb947889d"},"properties":{"dependency":{"package":"yaml","version":"1.10.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"production","file":"packages/decap-cms-core/src/actions/config.ts","line":1}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8e366a86dbc7cf9c2aa6ab83ef9700659bb56257d01b33b97ccbb5c13d5e384d"},"properties":{"dependency":{"package":"yaml","version":"2.8.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"production","file":"packages/decap-cms-core/src/actions/config.ts","line":1}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0f1d6574f44267a1be7340b910e0297b8e643072cd8e24037118c0e625764f8d"},"properties":{"dependency":{"package":"qs","version":"6.10.5","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7976330f55bdde6d246144cb38f82ea3b883d65a0b6bbda4c4f2e0ad7dac7f4a"},"properties":{"dependency":{"package":"qs","version":"6.13.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"18785048b9f22fc318ac59623702d64b6cd20f7b40685e22b7a4e66277ebb682"},"properties":{"dependency":{"package":"qs","version":"6.14.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"637f03998798e3179fb275559b9cbed8c4bd6683c17eca0af7e3b76484812cd2"},"properties":{"dependency":{"package":"qs","version":"6.15.3","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5ff0245ddbdb43295c7a1178f85e1df8e0e3e430504c3a2da1d4a3f8c28de71e"},"properties":{"dependency":{"package":"morgan","version":"1.10.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"production","file":"packages/decap-server/src/middlewares/common/index.ts","line":2}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"10e7ebf2bc6f092b587e1c5c6554560a1e358ae0c03c4a8acfc1fe5df51e8d09"},"properties":{"dependency":{"package":"@vitest/mocker","version":"3.2.4","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"52750697fd8e900586c56c0582fa46b9e47d6ecff03c0178c428b68ae328b6d5"},"properties":{"dependency":{"package":"micromatch","version":"3.1.10","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7b8ded84571516c1d5a1c985d305fc7a42eda37070076005a30725a3a03aea77"},"properties":{"dependency":{"package":"micromatch","version":"4.0.5","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"adb1db0a33a4e2ed4d3e8978da58716dce74069c784425f9459d47a78d1185a0"},"properties":{"dependency":{"package":"@octokit/plugin-paginate-rest","version":"1.1.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2a10bf30330aa4cd034a62b84eec735a20fec1e53a688411a12bc03e86bfe06e"},"properties":{"dependency":{"package":"protocol-buffers-schema","version":"3.6.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2a1187aa88b5f103d60aad5310ba3f08326d5bc366c9bdf6b5ed532e5987856d"},"properties":{"dependency":{"package":"@cypress/request","version":"2.88.12","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"731fc6919e686e405010261bcbd6985287fb25ce82e964fafabe78ab584c5826"},"properties":{"dependency":{"package":"serialize-javascript","version":"7.0.4","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"591417462a483eb87339a94ce25848791dd95a861c7ae8ed3f906008de1cd19c"},"properties":{"dependency":{"package":"@platejs/core","version":"49.2.21","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8d58c68394c16b8c0a4366511da73d604492f8dbc6e97d556c290a4d2eac4df4"},"properties":{"dependency":{"package":"@octokit/request","version":"5.6.3","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bea5062a3b6660225d627f9c4bdb4f25fec7bc046da1156713c45b0c01333efd"},"properties":{"dependency":{"package":"decode-uri-component","version":"0.2.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ddc6dc7f4f905b76df84b4f502d4454c95af060bcf85dfcdae96a6b156a3ec32"},"properties":{"dependency":{"package":"uuid","version":"8.3.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"497a86b9a8fe7596dee5e13e910abc344bee6528537e831e48e6a42549745eef"},"properties":{"dependency":{"package":"uuid","version":"9.0.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"79ca8dc1cfc3a191151c814b55bf11606fbe6b718c02717ff2c35660618baee6"},"properties":{"dependency":{"package":"@octokit/request-error","version":"1.2.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8dde4420dc1e054e52808a8097109e75cabd9ccc77a729fc55727351f5e9dc3d"},"properties":{"dependency":{"package":"@octokit/request-error","version":"2.1.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8ad99cb4954b0f40a074c9b419d41dde3c5238c306ff64bb372d7d4805267e0f"},"properties":{"dependency":{"package":"follow-redirects","version":"1.15.11","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f725ad925cf527603c81b184e74678a84b7e7fa9f0fbc2a67fdf2a7487746145"},"properties":{"dependency":{"package":"webpack","version":"5.102.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"production","file":"scripts/webpack.js","line":2}}}},{"ruleId":"D30","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"079eedc19ff1f01e3b25ea8106932dbd1ac1e7ac727e3e9afcb0bf8467d900b5"},"properties":{"dependency":{"package":"es5-ext","version":"0.10.62","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f392b1419f96aa208ac2115d3c34c2f00540ad0c5381e81423f8727e54319f35"},"properties":{"dependency":{"package":"@babel/core","version":"7.28.4","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"test-or-tooling","file":"package.json"}}}},{"ruleId":"D30","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"00aab61e1689d7ecd379e73ab3c2b832b93b3fe40ac33a8dff3e40f9708b4aa2"},"properties":{"dependency":{"package":"@hapi/joi","version":"17.1.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"production","file":"packages/decap-server/src/middlewares/joi/customValidators.ts","line":1}}}},{"ruleId":"D30","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d8884977fb5db81074778c0c1d8e66cf2219fb89e44e4956024b365306db135d"},"properties":{"dependency":{"package":"diff","version":"4.0.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"27d974ee3fd5dcbd0dc61a8a77f97951971d209729c9538c070e3cb1baa1af25"},"properties":{"dependency":{"package":"elliptic","version":"6.6.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7ddbaf099bc937d503bb4f377c7294decf05b8f82a7f86e2267c1dc8fe41bdd2"},"properties":{"dependency":{"package":"body-parser","version":"1.20.3","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"986be8a9e3e6a6d872fe1ae6395a44a270132f5a5f578c7a3b3dbb6c999205d6"},"properties":{"dependency":{"package":"@tootallnate/once","version":"1.1.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eba7fb25d0b8d38048d1fab612533e16c381b81645728bbe7213282cfb7a64f5"},"properties":{"dependency":{"package":"postcss-selector-parser","version":"7.1.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f94af38354d00f774672ecff0be62a065155a62ec6854c4ecddad3252798b0ec"},"properties":{"dependency":{"package":"dompurify","version":"3.4.13","advisory":"[GHSA redacted]","reachability":{"kind":"production","file":"packages/decap-cms-widget-markdown/src/MarkdownControl/plugins/html/withHtml.js","line":2}}}},{"ruleId":"D34","level":"error","message":{"text":"Orphaned knowledge: No living knowledge remains for this large file \u2014 its last meaningful change has decayed away; if it breaks, no one currently understands it. Schedule a read-through / add characterisation tests before it bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-bitbucket/src/API.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"4c3bd216f7e2c8e103336f4aaa8be842ffc99e8e6cd51a8a8393956c547606b0"}},{"ruleId":"D34","level":"error","message":{"text":"Orphaned knowledge: No living knowledge remains for this large file \u2014 its last meaningful change has decayed away; if it breaks, no one currently understands it. Schedule a read-through / add characterisation tests before it bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-github/src/GraphQLAPI.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b3621ad98f870672bff52c013a60f08c9c1ed4fafc2b6e23f2d6669fb282aedc"}},{"ruleId":"D34","level":"error","message":{"text":"Orphaned knowledge: No living knowledge remains for this large file \u2014 its last meaningful change has decayed away; if it breaks, no one currently understands it. Schedule a read-through / add characterisation tests before it bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-locales/src/th/index.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"83dd7dc08f3b3e43e1af81e62fb6dbe999adaf3975f1418b3ac151a876de5524"}},{"ruleId":"D34","level":"error","message":{"text":"Orphaned knowledge: No living knowledge remains for this large file \u2014 its last meaningful change has decayed away; if it breaks, no one currently understands it. Schedule a read-through / add characterisation tests before it bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-bitbucket/src/implementation.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"2612b02d9376800e97b1a5a0cd206e6408081531e8b59675f82f89cbce5a5f5b"}},{"ruleId":"D34","level":"note","message":{"text":"Further orphaned files (smaller): 83 smaller file(s) also have no living knowledge \u2014 folded into the freshness score and metrics rather than raised one row each \u2014 most significant first: packages/decap-cms-locales/src/ru/index.js, packages/decap-cms-locales/src/mk/index.js, packages/decap-cms-locales/src/fa/index.js, packages/decap-cms-locales/src/ua/index.js, packages/decap-cms-locales/src/bg/index.js, packages/decap-cms-locales/src/uk/index.js, packages/decap-cms-widget-richtext/src/serializers/slateRemark.js, packages/decap-cms-locales/src/he/index.js (and 75 more) (87 orphaned of 200 analysed files in total, counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 200 of the 528 production source files in this repository met that bar). Attach the read to the next change that touches one of them: have a second person review that change, and leave behind a short comment or test recording what the file is for, so the knowledge comes back at the cost of a change you were making anyway."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ce861fd78f6935114d3a342cb90ad25870f984e1042954fcbbe27c0e23be3658"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: AuthenticationPage.js \u2194 AuthenticationPage.js: \u0060packages/decap-cms-backend-bitbucket/src/AuthenticationPage.js\u0060 (context decap-cms-backend-bitbucket) and \u0060packages/decap-cms-backend-github/src/AuthenticationPage.js\u0060 (context decap-cms-backend-github) sit in DIFFERENT parts of the tree yet change together 55% of the time (6 of the 11 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see. You can check this without leaving the row: of the 6 shared commits counted here, the most recent 3 are \u0060b540acec\u0060 feat: add logo to header (#7487); \u0060ff85991b\u0060 chore: replace demo links (#6894); \u00607c45a3cd\u0060 fix(locale): Remove hard coded string literals (#3333) (at that commit the files were still \u0060packages/netlify-cms-backend-bitbucket/src/AuthenticationPage.js\u0060 and \u0060packages/netlify-cms-backend-github/src/AuthenticationPage.js\u0060) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-bitbucket/src/AuthenticationPage.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f5345f2e1032e9f17aadbf2967952bda649947743d1e41b3f19597046ff74cbb"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: implementation.ts \u2194 backend.ts: \u0060packages/decap-cms-backend-test/src/implementation.ts\u0060 (context decap-cms-backend-test) and \u0060packages/decap-cms-core/src/backend.ts\u0060 (context decap-cms-core) sit in DIFFERENT parts of the tree yet change together 50% of the time (7 of the 14 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see. You can check this without leaving the row: of the 7 shared commits counted here, the most recent 3 are \u006003d6446d\u0060 Feature: Collaborative Notes Pane for the Editor screen (#7563); \u0060a50edc70\u0060 feat: add backend status down indicator (#3889) (at that commit the files were still \u0060packages/netlify-cms-backend-test/src/implementation.ts\u0060 and \u0060packages/netlify-cms-core/src/backend.ts\u0060); \u0060285c9405\u0060 fix: handle token expiry (#3847) (at that commit the files were still \u0060packages/netlify-cms-backend-test/src/implementation.ts\u0060 and \u0060packages/netlify-cms-core/src/backend.ts\u0060) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-test/src/implementation.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"80cd0c4816bf4ef0fe8355d18574d4db920c0ed0f26f5d4fcf9544664b7cdb70"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e17f71490e4d120a48b2b2881ab866c93b272bef2febb673a3e8e42b2c288ab"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"759dca709f1a032fb6f624ce672e6afb5558fce53ecf01fb73618c4d33923164"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eb00976a698a5d68999b7ee6d27206fd374e916853e7ff1ead5eed42386f043f"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"90f83b4fa27db32740afe9540c905f3c0499caed87f61049a8a903ecc95b41c3"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0752d0df7434000fcabf1048e2de30a7a1a8b982b3db9a19898c4dec199856b4"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d068c977b62d9a977df1bb6f53e8b00b586c3abee955f91d715f92b8e019d624"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4bdd4cc8bc9daa17b484ebc3110c93822e162bc790a47d1c0ea9b9018f462d28"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5e4607103018ccbf4772504c4475df05c43062f243e17471503584c98dc62fdc"}},{"ruleId":"AX4","level":"error","message":{"text":"Dependency-rule violation: decap-cms-app (Application) \u2192 decap-cms-ui-auth (Web): \u0060decap-cms-app\u0060 is a Application project but references \u0060decap-cms-ui-auth\u0060, a Web project. The clean-architecture rule is that dependencies point INWARD \u2014 the domain/application core must not depend on outer layers (infrastructure/web). Invert it: define the abstraction in the inner layer and implement it in the outer one."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d756e3127d415972d39e3e8f0250487785526f18475181e5c54fd2078dd646ec"}},{"ruleId":"AX4","level":"error","message":{"text":"Dependency-rule violation: decap-cms-app (Application) \u2192 decap-cms-ui-default (Web): \u0060decap-cms-app\u0060 is a Application project but references \u0060decap-cms-ui-default\u0060, a Web project. The clean-architecture rule is that dependencies point INWARD \u2014 the domain/application core must not depend on outer layers (infrastructure/web). Invert it: define the abstraction in the inner layer and implement it in the outer one."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"80d1897f677e5d18118b1ed1a2f42a3c4e6ca1d390e2d86c0e8160acac617da0"}},{"ruleId":"AX4","level":"error","message":{"text":"Dependency-rule violation: decap-cms-core (Domain) \u2192 decap-cms-ui-default (Web): \u0060decap-cms-core\u0060 is a Domain project but references \u0060decap-cms-ui-default\u0060, a Web project. The clean-architecture rule is that dependencies point INWARD \u2014 the domain/application core must not depend on outer layers (infrastructure/web). Invert it: define the abstraction in the inner layer and implement it in the outer one."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"8e905f236cccb5d656dc012bcdeb859f1606fd3f48968f2f1797ad69d0bea405"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"P3","level":"note","message":{"text":"No SAST: No static application security testing detected. For this repository\u0027s stack, add CodeQL\u0027s javascript-typescript pack, \u0060semgrep --config=p/typescript\u0060, or eslint-plugin-security as a CI step. What was searched, so you can tell an absence from a miss: the 10919 CI workflow file(s) in this repository, and the scanner and linter configuration checked in beside them. A scan that runs outside CI, one configured in your forge\u0027s web UI rather than in a committed file, or a tool whose name is none of those this check carries, is not seen \u2014 if that is your case the row is wrong, and saying so is more useful than adding a second scanner."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6e54424179c892f03ef2fd003130ac4bd43f39bbf3b1ca0a0143e25acb80ec87"}},{"ruleId":"R1","level":"warning","message":{"text":"Type Safety: 136 typed \u00B7 549 plain JS \u2014 the untyped files are __mocks__/cleanStackMock.js, __mocks__/fileMock.js, __mocks__/styleMock.js, cypress/e2e/common/editorial_workflow.js, cypress/e2e/common/entries.js, cypress/e2e/common/i18n.js (\u002B543 more). 0 production file(s) opt out entirely with @ts-nocheck \u00B7 11 @ts-ignore suppression(s)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d00ee7953f55325a823d27e5db9657c80ca9b9861c0c0abf8fe487cd3fa586d3"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplication concentrated across 30 sibling directories (90 clone groups): 90 duplicated blocks under packages/ have copies in at least two of the sibling directories decap-cms, decap-cms-app, decap-cms-backend-aws-cognito-github-proxy, decap-cms-backend-azure, decap-cms-backend-bitbucket, decap-cms-backend-forgejo (\u002B24 more sibling(s) not listed) \u2014 73 of them are reported below, and 17 are counted here but not reported individually: those copies match on shape but no longer clear R10\u0027s bar for an individually reported row \u2014 either they kept neither their own names nor their values, or what was copied is too small to stand on its own (it reports near-exact duplication only, and only of substantial extent). What this row states is the concentration, which the detector measured over all 90 and which does not depend on how exactly each block\u0027s copies still match. That concentration is one structural fact, not 90 local ones: the siblings replicate behaviour none of them owns, which is the shape of a missing shared module \u2014 a common library every sibling imports \u2014 rather than 90 separate extractions. Check first whether the siblings are deliberately standalone deliverables (scaffold templates, demo apps that must stay copy-pasteable); where they are, the duplication is the design and the per-block rows are the ones to act on."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-forgejo/src/API.ts"},"region":{"startLine":56}}}],"partialFingerprints":{"codehealthFindingId/v1":"3bd8a83c27774b5ac752c296fd6e3537fa39679d5a4bb7713069b5399aaaef56"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplication concentrated across 5 sibling directories (7 clone groups): 7 duplicated blocks under packages/decap-cms-core/src/components/ have copies in at least two of the sibling directories Collection, Editor, MediaLibrary, UI, Workflow \u2014 1 of them are reported below, and 6 are counted here but not reported individually: those copies match on shape but no longer clear R10\u0027s bar for an individually reported row \u2014 either they kept neither their own names nor their values, or what was copied is too small to stand on its own (it reports near-exact duplication only, and only of substantial extent). What this row states is the concentration, which the detector measured over all 7 and which does not depend on how exactly each block\u0027s copies still match. That concentration is one structural fact, not 7 local ones: the siblings replicate behaviour none of them owns, which is the shape of a missing shared module \u2014 a common library every sibling imports \u2014 rather than 7 separate extractions. Check first whether the siblings are deliberately standalone deliverables (scaffold templates, demo apps that must stay copy-pasteable); where they are, the duplication is the design and the per-block rows are the ones to act on."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/Collection/Entries/EntryCard.js"},"region":{"startLine":232}}}],"partialFingerprints":{"codehealthFindingId/v1":"eda3bee11c9d8af11a96bc4dc8ee66efd9a108f1390c82b7103231a8034bd4bc"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplication concentrated across 4 sibling directories (6 clone groups): 6 duplicated blocks under packages/decap-cms-widget-markdown/src/MarkdownControl/plugins/ have copies in at least two of the sibling directories blocks, inlines, lists, shortcodes \u2014 3 of them are reported below, and 3 are counted here but not reported individually: those copies match on shape but no longer clear R10\u0027s bar for an individually reported row \u2014 either they kept neither their own names nor their values, or what was copied is too small to stand on its own (it reports near-exact duplication only, and only of substantial extent). What this row states is the concentration, which the detector measured over all 6 and which does not depend on how exactly each block\u0027s copies still match. That concentration is one structural fact, not 6 local ones: the siblings replicate behaviour none of them owns, which is the shape of a missing shared module \u2014 a common library every sibling imports \u2014 rather than 6 separate extractions. Check first whether the siblings are deliberately standalone deliverables (scaffold templates, demo apps that must stay copy-pasteable); where they are, the duplication is the design and the per-block rows are the ones to act on."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/plugins/blocks/events/keyDown.js"},"region":{"startLine":10}}}],"partialFingerprints":{"codehealthFindingId/v1":"ba74c0e5bcd7c321abac32be7c5fd1a7003f23da6c4073f356024d65b7bd303b"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block with local edits (350 matched lines \u00D7 2 locations): packages/decap-cms-backend-forgejo/src/API.ts:56 \u00B7 packages/decap-cms-backend-gitea/src/API.ts:40 \u2014 the two spans are one implementation copied and then locally edited \u2014 2148 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row\u0027s finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters \u2014 or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-forgejo/src/API.ts"},"region":{"startLine":56}}}],"partialFingerprints":{"codehealthFindingId/v1":"0f53b3863c2992960a4bdadaedce95662e7a2a23da805ef066dd0806a4a93e64"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block with local edits (333 matched lines \u00D7 2 locations): packages/decap-cms-backend-bitbucket/src/implementation.ts:93 \u00B7 packages/decap-cms-backend-gitlab/src/implementation.ts:91 \u2014 the two spans are one implementation copied and then locally edited \u2014 2043 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row\u0027s finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters \u2014 or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-bitbucket/src/implementation.ts"},"region":{"startLine":93}}}],"partialFingerprints":{"codehealthFindingId/v1":"4a99e00ea5fbac3850c21d478b7ceb793e3c091f3af7b61f347314d250ab4096"}},{"ruleId":"R10","level":"warning","message":{"text":"Wholesale file copy (192 identical lines \u00D7 2 files): packages/decap-cms-widget-markdown/src/serializers/slateRemark.js:7 \u00B7 packages/decap-cms-widget-richtext/src/serializers/slateRemark.js:2 \u2014 these 2 files are line-for-line copies of one another \u2014 192 lines are identical, in the same order, in every one of them \u2014 so this is one fact about the file set, not a block to extract. An edit made to one file and not the others changes behaviour silently, which is the failure a wholesale copy guarantees. Pick one file as the single source and derive the others from it (re-export it, spread it into the local overrides each variant genuinely needs, or generate the copies at build time) \u2014 the few lines that differ between the files are exactly the part each variant should still own. Check first whether the copies are deliberately standalone deliverables (a translation file seeded from its sibling and waiting to be translated); where they are, the duplication is the design, and the honest move is to mark the seeded file as untranslated rather than to let it pass as done."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/slateRemark.js"},"region":{"startLine":7}}}],"partialFingerprints":{"codehealthFindingId/v1":"0dc5c85e8baa6df39ef62b3883d24a7ee85e9ada90cab1ed732a7071502965a9"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block with local edits (164 matched lines \u00D7 2 locations): packages/decap-cms-backend-azure/src/implementation.ts:108 \u00B7 packages/decap-cms-backend-gitlab/src/implementation.ts:138 \u2014 the two spans are one implementation copied and then locally edited \u2014 998 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row\u0027s finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters \u2014 or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-azure/src/implementation.ts"},"region":{"startLine":108}}}],"partialFingerprints":{"codehealthFindingId/v1":"a26a2ca2ad98f3d68de5d8582683e03f053845166d81d795221fb1f4d6109fe9"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block with local edits (162 matched lines \u00D7 2 locations): packages/decap-cms-backend-github/src/implementation.tsx:647 \u00B7 packages/decap-cms-backend-gitlab/src/implementation.ts:503 \u2014 the two spans are one implementation copied and then locally edited \u2014 1089 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row\u0027s finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters \u2014 or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-github/src/implementation.tsx"},"region":{"startLine":647}}}],"partialFingerprints":{"codehealthFindingId/v1":"b2feacc3bc732241589fa5bd51973c5702108b3c12998fbb5c23e2dd514ee546"}},{"ruleId":"R10","level":"warning","message":{"text":"Wholesale file copy (157 identical lines \u00D7 2 files): packages/decap-cms-widget-markdown/src/serializers/remarkSlate.js:11 \u00B7 packages/decap-cms-widget-richtext/src/serializers/remarkSlate.js:6 \u2014 these 2 files are line-for-line copies of one another \u2014 157 lines are identical, in the same order, in every one of them \u2014 so this is one fact about the file set, not a block to extract. An edit made to one file and not the others changes behaviour silently, which is the failure a wholesale copy guarantees. Pick one file as the single source and derive the others from it (re-export it, spread it into the local overrides each variant genuinely needs, or generate the copies at build time) \u2014 the few lines that differ between the files are exactly the part each variant should still own. Check first whether the copies are deliberately standalone deliverables (a translation file seeded from its sibling and waiting to be translated); where they are, the duplication is the design, and the honest move is to mark the seeded file as untranslated rather than to let it pass as done."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkSlate.js"},"region":{"startLine":11}}}],"partialFingerprints":{"codehealthFindingId/v1":"2673a39041bf828e3afc37db7fd9c0d668165145d18d0b7be7091a50eca6e20e"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block with local edits (153 matched lines \u00D7 2 locations): packages/decap-cms-backend-forgejo/src/implementation.tsx:41 \u00B7 packages/decap-cms-backend-gitea/src/implementation.tsx:38 \u2014 the two spans are one implementation copied and then locally edited \u2014 1011 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row\u0027s finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters \u2014 or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-forgejo/src/implementation.tsx"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"7a76bed11633e7676f272c548ce32fd7d3f6609e6c42a119d4e474274e8db1cd"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block with local edits (106 matched lines \u00D7 2 locations): packages/decap-cms-backend-azure/src/API.ts:511 \u00B7 packages/decap-cms-backend-gitlab/src/API.ts:640 \u2014 the two spans are one implementation copied and then locally edited \u2014 639 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row\u0027s finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters \u2014 or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-azure/src/API.ts"},"region":{"startLine":511}}}],"partialFingerprints":{"codehealthFindingId/v1":"f061b15b9530c311b1d5bc117e5f74b016a494a5f9074a229dd20e7ac5621b23"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (106 lines \u00D7 2 locations): packages/decap-cms-widget-markdown/src/regexHelper.js:32 \u00B7 packages/decap-cms-widget-richtext/src/serializers/regexHelper.js:32 \u2014 the 2 copies are spread across 2 directories, so the shared home is a decision rather than an obvious spot: check first whether one of them already owns this behaviour, and otherwise put the extracted module somewhere all of the sites already reach rather than making one of them depend on another."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/regexHelper.js"},"region":{"startLine":32}}}],"partialFingerprints":{"codehealthFindingId/v1":"6cc173d5366f0cea05d7a36fb0eb84248e69f19dfd33d91ae14cb984a943fc91"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block with local edits (102 matched lines \u00D7 2 locations): packages/decap-cms-backend-forgejo/src/implementation.tsx:95 \u00B7 packages/decap-cms-backend-github/src/implementation.tsx:115 \u2014 the two spans are one implementation copied and then locally edited \u2014 633 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row\u0027s finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters \u2014 or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-forgejo/src/implementation.tsx"},"region":{"startLine":95}}}],"partialFingerprints":{"codehealthFindingId/v1":"e0298737ca790bff7d6497e1370b0c5cf450202c93c40d67a65158412b6e23a3"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (97 lines \u00D7 2 locations): packages/decap-cms-backend-gitea/src/implementation.tsx:306 \u00B7 packages/decap-cms-backend-github/src/implementation.tsx:520 \u2014 the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-gitea/src/implementation.tsx"},"region":{"startLine":306}}}],"partialFingerprints":{"codehealthFindingId/v1":"cdaf08ed05b1422e5e256d0001e1df06d41e155293ed1d3cbd45f016049fdc64"}},{"ruleId":"R10","level":"warning","message":{"text":"Wholesale file copy (90 identical lines \u00D7 2 files): packages/decap-cms-widget-markdown/src/serializers/index.js:2 \u00B7 packages/decap-cms-widget-richtext/src/serializers/index.js:2 \u2014 these 2 files are line-for-line copies of one another \u2014 90 lines are identical, in the same order, in every one of them \u2014 so this is one fact about the file set, not a block to extract. An edit made to one file and not the others changes behaviour silently, which is the failure a wholesale copy guarantees. Pick one file as the single source and derive the others from it (re-export it, spread it into the local overrides each variant genuinely needs, or generate the copies at build time) \u2014 the few lines that differ between the files are exactly the part each variant should still own. Check first whether the copies are deliberately standalone deliverables (a translation file seeded from its sibling and waiting to be translated); where they are, the duplication is the design, and the honest move is to mark the seeded file as untranslated rather than to let it pass as done."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/index.js"},"region":{"startLine":2}}}],"partialFingerprints":{"codehealthFindingId/v1":"7448313dcecf7706343550f0374a9c828db15cbc915a49cdbe96fc9b97171e4e"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (71 lines \u00D7 2 locations): packages/decap-cms-backend-forgejo/src/types.ts:182 \u00B7 packages/decap-cms-backend-gitea/src/types.ts:182 \u2014 the 2 copies are spread across 2 files, and the CITED SPAN is a run of DECLARATIONS inside a construct \u2014 the members of a type, or the entries of an object or array literal \u2014 with no statement anywhere in it. Do not read this as an extract-a-helper row: nothing here executes, so there is no call site, and a call expression cannot stand where a member declaration or a literal\u0027s entry was. What repeats is a SHAPE, and which shape decides the move. Where the copies declare the same members, the repetition is a missing common ancestor: give it a base type, an interface both extend, a generic instantiated twice, or \u2014 where the copies are a literal\u0027s entries rather than a type\u0027s members \u2014 one shared constant each site spreads or refers to, so the set is written once. Where they declare DIFFERENT members and only the form is shared \u2014 a decorator and its options, an annotation, a registration table\u0027s keys \u2014 the form is prescribed by a framework or a schema rather than copied, and the only collapse available is to generate the declarations from that schema; where you do not own the generator, this is the cost of the framework and there is nothing to extract. Check which of the two it is before acting: these copies still drift apart the first time only one of them is edited, which is why the repetition is reported, but the sentence to act on is not the same in both cases."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-forgejo/src/types.ts"},"region":{"startLine":182}}}],"partialFingerprints":{"codehealthFindingId/v1":"0e9804819c33bc49a82d90b37d481299c0465585c3a97b34ddc64700fb54f5b5"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block with local edits (69 matched lines \u00D7 2 locations): packages/decap-cms-widget-markdown/src/MarkdownControl/index.js:25 \u00B7 packages/decap-cms-widget-richtext/src/RichtextControl.js:12 \u2014 the two spans are one implementation copied and then locally edited \u2014 423 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row\u0027s finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters \u2014 or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/index.js"},"region":{"startLine":25}}}],"partialFingerprints":{"codehealthFindingId/v1":"565e3947c40c40953e813801309e05e2d6ae1741a820eae513d79a1a2d2c44c9"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (67 lines \u00D7 2 locations): packages/decap-cms-widget-markdown/src/serializers/remarkEscapeMarkdownEntities.js:11 \u00B7 packages/decap-cms-widget-richtext/src/serializers/remarkEscapeMarkdownEntities.js:8 \u2014 the 2 copies are spread across 2 directories, so the shared home is a decision rather than an obvious spot: check first whether one of them already owns this behaviour, and otherwise put the extracted module somewhere all of the sites already reach rather than making one of them depend on another."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkEscapeMarkdownEntities.js"},"region":{"startLine":11}}}],"partialFingerprints":{"codehealthFindingId/v1":"dffd968e292a52d843c0a41a3597047535a8835884f31e564b5f89fd3579466b"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block with local edits (65 matched lines \u00D7 2 locations): packages/decap-cms-core/src/actions/editorialWorkflow.ts:335 \u00B7 packages/decap-cms-core/src/actions/entries.ts:961 \u2014 the two spans are one implementation copied and then locally edited \u2014 310 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row\u0027s finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters \u2014 or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/actions/editorialWorkflow.ts"},"region":{"startLine":335}}}],"partialFingerprints":{"codehealthFindingId/v1":"5f278b0d926b466528bdc540c6929b91fc7b9ecd21ebd79021e5bd1f1d681e48"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block with local edits (59 matched lines \u00D7 2 locations): packages/decap-cms-backend-forgejo/src/AuthenticationPage.js:7 \u00B7 packages/decap-cms-backend-github/src/AuthenticationPage.js:7 \u2014 the two spans are one implementation copied and then locally edited \u2014 309 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row\u0027s finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters \u2014 or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-forgejo/src/AuthenticationPage.js"},"region":{"startLine":7}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b22cc7240bc2d8d530b558d499a24c75306bc2edf759b080e76ecd5f5b592cf"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (48 lines \u00D7 2 locations): packages/decap-cms-widget-markdown/src/serializers/remarkPaddedLinks.js:20 \u00B7 packages/decap-cms-widget-richtext/src/serializers/remarkPaddedLinks.js:14 \u2014 the 2 copies are spread across 2 directories, so the shared home is a decision rather than an obvious spot: check first whether one of them already owns this behaviour, and otherwise put the extracted module somewhere all of the sites already reach rather than making one of them depend on another."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkPaddedLinks.js"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"bce55a7fe97fe9af449e58e845b83a50c6561196a22b904a7558051c02dae0ac"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (45 lines \u00D7 3 locations): packages/decap-cms-backend-forgejo/src/implementation.tsx:525 \u00B7 packages/decap-cms-backend-gitea/src/implementation.tsx:370 \u00B7 packages/decap-cms-backend-github/src/implementation.tsx:584 \u2014 the 3 copies are spread across 3 directories, so the shared home is a decision rather than an obvious spot: check first whether one of them already owns this behaviour, and otherwise put the extracted module somewhere all of the sites already reach rather than making one of them depend on another. There is one copy in each of 3 separate files rather than several in one place, so check first whether these are sibling modules that each declare their own version of one shape \u2014 one per entity, per provider, per language. Where they are, no single extracted module collapses them: each module still has to be written, and what recurs is the TEMPLATE. The moves that do collapse a template are to generate these modules from the set they enumerate, or to replace the repeated construction with one factory each site calls with its own values \u2014 and where the set is the point, each module pinning one distinct thing, the repetition IS the enumeration and there is nothing to delete."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-forgejo/src/implementation.tsx"},"region":{"startLine":525}}}],"partialFingerprints":{"codehealthFindingId/v1":"c6adaffc5595b47853652b29410ec09a6feb31a2e21490a594e84a724f65fb6e"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (43 lines \u00D7 2 locations): packages/decap-cms-backend-forgejo/src/types.ts:36 \u00B7 packages/decap-cms-backend-gitea/src/types.ts:36 \u2014 the 2 copies are spread across 2 files, and the CITED SPAN is a run of DECLARATIONS inside a construct \u2014 the members of a type, or the entries of an object or array literal \u2014 with no statement anywhere in it. Do not read this as an extract-a-helper row: nothing here executes, so there is no call site, and a call expression cannot stand where a member declaration or a literal\u0027s entry was. What repeats is a SHAPE, and which shape decides the move. Where the copies declare the same members, the repetition is a missing common ancestor: give it a base type, an interface both extend, a generic instantiated twice, or \u2014 where the copies are a literal\u0027s entries rather than a type\u0027s members \u2014 one shared constant each site spreads or refers to, so the set is written once. Where they declare DIFFERENT members and only the form is shared \u2014 a decorator and its options, an annotation, a registration table\u0027s keys \u2014 the form is prescribed by a framework or a schema rather than copied, and the only collapse available is to generate the declarations from that schema; where you do not own the generator, this is the cost of the framework and there is nothing to extract. Check which of the two it is before acting: these copies still drift apart the first time only one of them is edited, which is why the repetition is reported, but the sentence to act on is not the same in both cases."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-forgejo/src/types.ts"},"region":{"startLine":36}}}],"partialFingerprints":{"codehealthFindingId/v1":"22aed3e154d63c2f0476fb9395de60d8947acdf3ffa12b1eadbb5be92d2c2e27"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (42 lines \u00D7 2 locations): packages/decap-cms-widget-markdown/src/serializers/remarkAllowHtmlEntities.js:1 \u00B7 packages/decap-cms-widget-richtext/src/serializers/remarkAllowHtmlEntities.js:1 \u2014 the 2 copies are spread across 2 directories, so the shared home is a decision rather than an obvious spot: check first whether one of them already owns this behaviour, and otherwise put the extracted module somewhere all of the sites already reach rather than making one of them depend on another."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkAllowHtmlEntities.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"699c38298e56c2adbea51ed10586a234a149c87ade81861e9714e892f89c45e5"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block with local edits (42 matched lines \u00D7 2 locations): packages/decap-cms-widget-markdown/src/serializers/remarkShortcodes.js:28 \u00B7 packages/decap-cms-widget-richtext/src/serializers/remarkShortcodes.js:13 \u2014 the two spans are one implementation copied and then locally edited \u2014 214 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row\u0027s finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters \u2014 or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkShortcodes.js"},"region":{"startLine":28}}}],"partialFingerprints":{"codehealthFindingId/v1":"87a164c086967bf8b24c38c35652ffe7e84de9ac1647e84469b925b4826811b2"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (36 lines \u00D7 2 locations): packages/decap-cms-widget-markdown/src/schema.js:1 \u00B7 packages/decap-cms-widget-richtext/src/schema.js:1 \u2014 the 2 copies are spread across 2 files, and the CITED SPAN is a run of DECLARATIONS inside a construct \u2014 the members of a type, or the entries of an object or array literal \u2014 with no statement anywhere in it. Do not read this as an extract-a-helper row: nothing here executes, so there is no call site, and a call expression cannot stand where a member declaration or a literal\u0027s entry was. What repeats is a SHAPE, and which shape decides the move. Where the copies declare the same members, the repetition is a missing common ancestor: give it a base type, an interface both extend, a generic instantiated twice, or \u2014 where the copies are a literal\u0027s entries rather than a type\u0027s members \u2014 one shared constant each site spreads or refers to, so the set is written once. Where they declare DIFFERENT members and only the form is shared \u2014 a decorator and its options, an annotation, a registration table\u0027s keys \u2014 the form is prescribed by a framework or a schema rather than copied, and the only collapse available is to generate the declarations from that schema; where you do not own the generator, this is the cost of the framework and there is nothing to extract. Check which of the two it is before acting: these copies still drift apart the first time only one of them is edited, which is why the repetition is reported, but the sentence to act on is not the same in both cases."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/schema.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1e36bacb54aeaea15918cb26c2df9b6d18b787681086a489be462019ec93ae9a"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (35 lines \u00D7 2 locations): packages/decap-cms-core/src/actions/entries.ts:244 \u00B7 packages/decap-cms-core/src/actions/entries.ts:283 \u2014 all 2 copies are in the same file, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/actions/entries.ts"},"region":{"startLine":244}}}],"partialFingerprints":{"codehealthFindingId/v1":"9815707e6522a11b31533591e344b90da93c4ea576b42eceefd67beab4f3d38f"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block with local edits (35 matched lines \u00D7 2 locations): scripts/publish-packages.mjs:45 \u00B7 scripts/verify-published-packages.mjs:36 \u2014 the two spans are one implementation copied and then locally edited \u2014 249 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row\u0027s finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters \u2014 or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/publish-packages.mjs"},"region":{"startLine":45}}}],"partialFingerprints":{"codehealthFindingId/v1":"a53ddecc89214ed82d5725967221425104e01597b7c59ffac6dbec4658f78887"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (32 lines \u00D7 2 locations): packages/decap-cms-backend-bitbucket/src/implementation.ts:136 \u00B7 packages/decap-cms-backend-github/src/implementation.tsx:145 \u2014 the 2 copies are spread across 2 directories, so the shared home is a decision rather than an obvious spot: check first whether one of them already owns this behaviour, and otherwise put the extracted module somewhere all of the sites already reach rather than making one of them depend on another."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-bitbucket/src/implementation.ts"},"region":{"startLine":136}}}],"partialFingerprints":{"codehealthFindingId/v1":"12877b26673fa745bfcf86db31a9a059902484ecb4bf4be9dc113e8f6db69339"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (32 lines \u00D7 2 locations): packages/decap-cms-core/src/components/Editor/EditorToolbar.js:453 \u00B7 packages/decap-cms-core/src/components/Editor/EditorToolbar.js:555 \u2014 all 2 copies are in the same file, and the SHAPE of this repetition could not be determined. It is not a run of declarations, a listing, a declaration header, a type body or a slice through a construct \u2014 and it was not measured as a run of executable statements either, so this row cannot tell you whether a function can stand where these lines are. Read the two spans before acting, because the move is opposite in the two cases. Where they are statements, the ordinary answer holds: give the shared part one home and call it from each site. Where they turn out to be declarations, a literal\u0027s entries, or the cases of an enumeration, there is no call site to call anything from, and collapsing them would delete what each copy pins \u2014 a shared base type, a generated set, or one exported constant each site refers to is the move instead, and sometimes the honest answer is that there is nothing to extract at all. Reported because the copies drift apart the first time only one of them is edited, which is true whichever of those they are."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/Editor/EditorToolbar.js"},"region":{"startLine":453}}}],"partialFingerprints":{"codehealthFindingId/v1":"811c4c2dba3c7d84c396a4fc1327c837aa3c031e7605e191fe212fd37ebe0af6"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (28 lines \u00D7 3 locations): packages/decap-cms-backend-aws-cognito-github-proxy/src/AuthenticationPage.js:55 \u00B7 packages/decap-cms-backend-bitbucket/src/AuthenticationPage.js:73 \u00B7 packages/decap-cms-ui-auth/src/PKCEAuthenticationPage.js:125 \u2014 the 3 copies are spread across 3 directories, so the shared home is a decision rather than an obvious spot: check first whether one of them already owns this behaviour, and otherwise put the extracted module somewhere all of the sites already reach rather than making one of them depend on another. There is one copy in each of 3 separate files rather than several in one place, so check first whether these are sibling modules that each declare their own version of one shape \u2014 one per entity, per provider, per language. Where they are, no single extracted module collapses them: each module still has to be written, and what recurs is the TEMPLATE. The moves that do collapse a template are to generate these modules from the set they enumerate, or to replace the repeated construction with one factory each site calls with its own values \u2014 and where the set is the point, each module pinning one distinct thing, the repetition IS the enumeration and there is nothing to delete."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-aws-cognito-github-proxy/src/AuthenticationPage.js"},"region":{"startLine":55}}}],"partialFingerprints":{"codehealthFindingId/v1":"32a0d835407f80ee62de08a2c1eadb08fc8e63d764f8876771516e82d50cb7f3"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (27 lines \u00D7 2 locations): packages/decap-cms-backend-forgejo/src/AuthenticationPage.js:163 \u00B7 packages/decap-cms-backend-github/src/AuthenticationPage.js:117 \u2014 the 2 copies are spread across 2 files, and the SHAPE of this repetition could not be determined. It is not a run of declarations, a listing, a declaration header, a type body or a slice through a construct \u2014 and it was not measured as a run of executable statements either, so this row cannot tell you whether a function can stand where these lines are. Read the two spans before acting, because the move is opposite in the two cases. Where they are statements, the ordinary answer holds: give the shared part one home and call it from each site. Where they turn out to be declarations, a literal\u0027s entries, or the cases of an enumeration, there is no call site to call anything from, and collapsing them would delete what each copy pins \u2014 a shared base type, a generated set, or one exported constant each site refers to is the move instead, and sometimes the honest answer is that there is nothing to extract at all. Reported because the copies drift apart the first time only one of them is edited, which is true whichever of those they are."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-forgejo/src/AuthenticationPage.js"},"region":{"startLine":163}}}],"partialFingerprints":{"codehealthFindingId/v1":"c7f1f8df254ec2f66556cec5a6301fedb6af04b993a14a6b99c6b7ff5eed21eb"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (27 lines \u00D7 2 locations): packages/decap-cms-widget-markdown/src/serializers/remarkSquashReferences.js:28 \u00B7 packages/decap-cms-widget-richtext/src/serializers/remarkSquashReferences.js:30 \u2014 the 2 copies are spread across 2 directories, so the shared home is a decision rather than an obvious spot: check first whether one of them already owns this behaviour, and otherwise put the extracted module somewhere all of the sites already reach rather than making one of them depend on another."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkSquashReferences.js"},"region":{"startLine":28}}}],"partialFingerprints":{"codehealthFindingId/v1":"321adfaccd19e1fb0c2a3132b03bbd1b7e9cdadf784d7348ad7c235f13571bf1"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (26 lines \u00D7 2 locations): packages/decap-cms-widget-markdown/src/MarkdownControl/VisualEditor.js:53 \u00B7 packages/decap-cms-widget-richtext/src/RichtextControl/mergeMediaConfig.js:1 \u2014 the 2 copies are spread across 2 directories, so the shared home is a decision rather than an obvious spot: check first whether one of them already owns this behaviour, and otherwise put the extracted module somewhere all of the sites already reach rather than making one of them depend on another."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/VisualEditor.js"},"region":{"startLine":53}}}],"partialFingerprints":{"codehealthFindingId/v1":"09f53dcc85aa33bebe3c51f4fc8eb6da302157089f27677baaa73e516132df29"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (25 lines \u00D7 2 locations): packages/decap-cms-widget-markdown/src/MarkdownControl/Toolbar.js:194 \u00B7 packages/decap-cms-widget-richtext/src/RichtextControl/components/Toolbar/HeadingToolbarButton.js:66 \u2014 the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/Toolbar.js"},"region":{"startLine":194}}}],"partialFingerprints":{"codehealthFindingId/v1":"14f552b3bec9f6c69e72142a8e973824e7ac274c9bbdb38d5e3520ee055fc3ae"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (24 lines \u00D7 2 locations): packages/decap-cms-widget-markdown/src/MarkdownControl/ToolbarButton.js:12 \u00B7 packages/decap-cms-widget-richtext/src/RichtextControl/components/Toolbar/ToolbarButton.js:13 \u2014 the 2 copies are spread across 2 files, and the SHAPE of this repetition could not be determined. It is not a run of declarations, a listing, a declaration header, a type body or a slice through a construct \u2014 and it was not measured as a run of executable statements either, so this row cannot tell you whether a function can stand where these lines are. Read the two spans before acting, because the move is opposite in the two cases. Where they are statements, the ordinary answer holds: give the shared part one home and call it from each site. Where they turn out to be declarations, a literal\u0027s entries, or the cases of an enumeration, there is no call site to call anything from, and collapsing them would delete what each copy pins \u2014 a shared base type, a generated set, or one exported constant each site refers to is the move instead, and sometimes the honest answer is that there is nothing to extract at all. Reported because the copies drift apart the first time only one of them is edited, which is true whichever of those they are."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/ToolbarButton.js"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"73152a3844ba2fd9e03d64c453c5b6c2c76425d853716716f4216145329f7dec"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (24 lines \u00D7 2 locations): packages/decap-cms-widget-markdown/src/serializers/remarkRehypeShortcodes.js:61 \u00B7 packages/decap-cms-widget-richtext/src/serializers/remarkRehypeShortcodes.js:57 \u2014 the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkRehypeShortcodes.js"},"region":{"startLine":61}}}],"partialFingerprints":{"codehealthFindingId/v1":"5f8c94876f578d4aad73ee87ffeb6a7d2b2efb7d765b2d3154f71b91249bc444"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (23 lines \u00D7 2 locations): packages/decap-cms-core/src/integrations/providers/algolia/implementation.js:44 \u00B7 packages/decap-cms-core/src/integrations/providers/assetStore/implementation.js:18 \u2014 the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/integrations/providers/algolia/implementation.js"},"region":{"startLine":44}}}],"partialFingerprints":{"codehealthFindingId/v1":"3907be1995872a9440cd436e9578796a03fd4671a6a0c338e0de239e167b8703"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (23 lines \u00D7 2 locations): packages/decap-cms-core/src/reducers/entries.ts:703 \u00B7 packages/decap-cms-core/src/reducers/entries.ts:731 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/reducers/entries.ts"},"region":{"startLine":703}}}],"partialFingerprints":{"codehealthFindingId/v1":"b11e2fe8689a7ef9a9c1204c2412373101043417c60b67a573026b2d1c359d97"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (22 lines \u00D7 3 locations): packages/decap-cms-core/src/actions/entries.ts:211 \u00B7 packages/decap-cms-core/src/actions/entries.ts:253 \u00B7 packages/decap-cms-core/src/actions/entries.ts:292 \u2014 all 3 copies are in the same file, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/actions/entries.ts"},"region":{"startLine":211}}}],"partialFingerprints":{"codehealthFindingId/v1":"d5f43c018b42f2002c596d8859eaed6153628d221cdf1e4422dd16077fd9445f"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:third-party-deep-import]: packages/decap-cms-core/src/components/UI/Notifications.tsx:3 imports react-toastify/dist/inject-style, reaching past a declared dependency\u0027s public entry into its build output \u2014 that path is the package\u0027s toolchain layout, not its API, and a minor version bump can relocate it with no semver signal. Import from the package\u0027s documented entry point instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/UI/Notifications.tsx"},"region":{"startLine":3}}}],"partialFingerprints":{"codehealthFindingId/v1":"3e4bc2ad060d3859c00605f0ef65049a71066d686f461c751c3258356f9d12b0"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:third-party-deep-import]: packages/decap-cms-core/src/constants/configSchema.js:2 imports ajv-keywords/dist/keywords, reaching past a declared dependency\u0027s public entry into its build output \u2014 that path is the package\u0027s toolchain layout, not its API, and a minor version bump can relocate it with no semver signal. Import from the package\u0027s documented entry point instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/constants/configSchema.js"},"region":{"startLine":2}}}],"partialFingerprints":{"codehealthFindingId/v1":"e2d45767a52ce3284dd6b90171d78364c80e23f6f0147a25c19ef6eb1da37e99"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:test-cross-package-internals]: packages/decap-cms-widget-richtext/src/RichtextControl/__tests__/VisualEditor.spec.js:4 reaches past another workspace package\u0027s public entry into its internals with a relative path (../../../../decap-cms-editor-component-image/src) \u2014 the test is coupled to a file layout that package makes no promise about, so a refactor behind its entry point breaks the suite. Import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-richtext/src/RichtextControl/__tests__/VisualEditor.spec.js"},"region":{"startLine":4}}}],"partialFingerprints":{"codehealthFindingId/v1":"3aff8227be0f6e644b6ceea2c39a83997205910ccbaff7aca425ce3a9053daa7"}},{"ruleId":"R11","level":"warning","message":{"text":"Boundary violation [package:test-cross-package-internals]: packages/decap-cms-widget-richtext/src/__tests__/renderer.spec.js:5 reaches past another workspace package\u0027s public entry into its internals with a relative path (../../../decap-cms-editor-component-image/src) \u2014 the test is coupled to a file layout that package makes no promise about, so a refactor behind its entry point breaks the suite. Import the package by name instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-richtext/src/__tests__/renderer.spec.js"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"91bafb0fcfb41fdca3b5edee1b8e7ec74371fda9845246d02d5e19456e3bd6ab"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function (anonymous) (cyclomatic 40, cognitive 69): (anonymous) has cyclomatic complexity 40 and cognitive complexity 69; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/actions/config.ts"},"region":{"startLine":232}}}],"partialFingerprints":{"codehealthFindingId/v1":"b9948303209c9e3e8382d73c4738abc03d041e937cdc7b68b2d0aadb7080468d"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function (anonymous) (cyclomatic 31, cognitive 23): (anonymous) has cyclomatic complexity 31 and cognitive complexity 23; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-server/src/middlewares/localGit/index.ts"},"region":{"startLine":179}}}],"partialFingerprints":{"codehealthFindingId/v1":"0096f329c921402b0e37f2edc09a3785b0ea77341dfea28a27ff5086587b4cad"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function entryDraftReducer (cyclomatic 31, cognitive 4): entryDraftReducer has cyclomatic complexity 31 and cognitive complexity 4; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/reducers/entryDraft.js"},"region":{"startLine":72}}}],"partialFingerprints":{"codehealthFindingId/v1":"651c00e715e3a0d5d162f13bcf82de818ad46321ef1de806a366c8ac8939dbc4"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function mediaLibrary (cyclomatic 30, cognitive 24): mediaLibrary has cyclomatic complexity 30 and cognitive complexity 24; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/reducers/mediaLibrary.ts"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"bd38c625aad12cbcb86e2df5856efe7dbc0f1be6db60c7db69c33df0f3543857"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function convertNode (cyclomatic 28, cognitive 11): convertNode has cyclomatic complexity 28 and cognitive complexity 11; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkSlate.js"},"region":{"startLine":235}}}],"partialFingerprints":{"codehealthFindingId/v1":"b58d33b2f4e13ff637dddcc6a2cd18737e1c09523a979882ab6e757c01ddb41e"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function convertNode (cyclomatic 26, cognitive 9): convertNode has cyclomatic complexity 26 and cognitive complexity 9; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-richtext/src/serializers/remarkSlate.js"},"region":{"startLine":229}}}],"partialFingerprints":{"codehealthFindingId/v1":"b5871fa96b03e3aab800e7e90f9872818525ce6e47416e669505242c19858423"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function convertBlockNode (cyclomatic 26, cognitive 9): convertBlockNode has cyclomatic complexity 26 and cognitive complexity 9; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-richtext/src/serializers/slateRemark.js"},"region":{"startLine":322}}}],"partialFingerprints":{"codehealthFindingId/v1":"92a6236c6078cf240ce383586acbc15f7899b423a4112d2eb8aa750e1ebb2b3a"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function convertBlockNode (cyclomatic 25, cognitive 9): convertBlockNode has cyclomatic complexity 25 and cognitive complexity 9; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/slateRemark.js"},"region":{"startLine":328}}}],"partialFingerprints":{"codehealthFindingId/v1":"b2a9b98853be44d5f80073e367f700c9b882e08c42a2c2632ad78a2b553d7ea6"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function renderWorkflowControls (cyclomatic 22, cognitive 18): renderWorkflowControls has cyclomatic complexity 22 and cognitive complexity 18; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/Editor/EditorToolbar.js"},"region":{"startLine":599}}}],"partialFingerprints":{"codehealthFindingId/v1":"61ac1b221d5cd3c98230d80a1177e442002f3b43d7bf2224bb21bac82e1dcfb8"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function Element (cyclomatic 22, cognitive 4): Element has cyclomatic complexity 22 and cognitive complexity 4; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/renderers.js"},"region":{"startLine":298}}}],"partialFingerprints":{"codehealthFindingId/v1":"0d90a51073729d65f29ed48abd9f3b5d3a689490321fb8fddddd603114bfe48d"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function persistEntry (cyclomatic 21, cognitive 25): persistEntry has cyclomatic complexity 21 and cognitive complexity 25; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/backend.ts"},"region":{"startLine":1246}}}],"partialFingerprints":{"codehealthFindingId/v1":"077128d0dc187bcfe9a6fb7fb59aaae1d0ff4300d896e6ccfae674099555f897"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function MediaLibraryModal (cyclomatic 20, cognitive 18): MediaLibraryModal has cyclomatic complexity 20 and cognitive complexity 18; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/MediaLibrary/MediaLibraryModal.js"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"4b86987e013be0848e229d558b31008d7f7381bf009ec9f34d8c6bdc4ebcc82b"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function unpublishedEntries (cyclomatic 20, cognitive 4): unpublishedEntries has cyclomatic complexity 20 and cognitive complexity 4; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/reducers/editorialWorkflow.ts"},"region":{"startLine":27}}}],"partialFingerprints":{"codehealthFindingId/v1":"e21f4c71bcb3766a1b3a93f09cb3b09aa5b43568fdd9bd76673a67c9c34a573e"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function constructor (cyclomatic 18, cognitive 19): constructor has cyclomatic complexity 18 and cognitive complexity 19; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-github/src/implementation.tsx"},"region":{"startLine":99}}}],"partialFingerprints":{"codehealthFindingId/v1":"047cb9324ccc9991b8a97af92a31ddb26954a1e6fcc04219790a3af64a3a2ac8"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function constructor (cyclomatic 18, cognitive 17): constructor has cyclomatic complexity 18 and cognitive complexity 17; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-gitlab/src/implementation.ts"},"region":{"startLine":93}}}],"partialFingerprints":{"codehealthFindingId/v1":"8067ea0502321d09bfb1a725cd506a0360706054017f0d4dbaa32a2de4606d60"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function render (cyclomatic 17, cognitive 16): render has cyclomatic complexity 17 and cognitive complexity 16; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/Toolbar.js"},"region":{"startLine":105}}}],"partialFingerprints":{"codehealthFindingId/v1":"277094fda01809c29b3036f671fb3cdb46e7ef2ecb4286d326b02344f2f99852"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function deserialize (cyclomatic 16, cognitive 19): deserialize has cyclomatic complexity 16 and cognitive complexity 19; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/plugins/html/withHtml.js"},"region":{"startLine":75}}}],"partialFingerprints":{"codehealthFindingId/v1":"94bb688b573d4cc16cd567d6df8de535128775600cf4e342ed83b06c1e810a66"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function (anonymous) (cyclomatic 16, cognitive 16): (anonymous) has cyclomatic complexity 16 and cognitive complexity 16; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-ui-auth/src/PKCEAuthenticationPage.js"},"region":{"startLine":19}}}],"partialFingerprints":{"codehealthFindingId/v1":"246c20b229018cf7ad215a504ca24e41623a2f85942acaef929a20a3c726d13b"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function constructor (cyclomatic 16, cognitive 15): constructor has cyclomatic complexity 16 and cognitive complexity 15; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-bitbucket/src/implementation.ts"},"region":{"startLine":95}}}],"partialFingerprints":{"codehealthFindingId/v1":"2695571b0a246d673a5ef2d10ac662f87cddbb0bcb50aebde522930b7aa70f3d"}},{"ruleId":"R4","level":"warning","message":{"text":"This test file cannot be loaded: cypress/run.mjs:7 imports \u0027./e2e/\u0027, which names no file in this repository \u2014 and no rule in its .gitignore chain could cover one, so no build writes it either. The import throws as the runner collects this file, so none of its test cases run and nothing it was written to verify is verified. Restore the missing module or delete the test. It is excluded from the reachability measured above, because a file that cannot load reaches nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/run.mjs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"850893802169d07d0f5c3216e1717f5c75ec241b31fc6f89850a8bcf0f7cd82a"}},{"ruleId":"R4","level":"warning","message":{"text":"This test file cannot be loaded: packages/decap-cms-backend-gitlab/src/__tests__/gitlab.spec.js:8 imports \u0027../AuthenticationPage\u0027, which names no file in this repository \u2014 and no rule in its .gitignore chain could cover one, so no build writes it either. The import throws as the runner collects this file, so none of its test cases run and nothing it was written to verify is verified. Restore the missing module or delete the test. It is excluded from the reachability measured above, because a file that cannot load reaches nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-gitlab/src/__tests__/gitlab.spec.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e032977b74eb4834c596f29c99a77ef21cabf6510b820fa5d08f002347b45d8a"}},{"ruleId":"R4","level":"warning","message":{"text":"This test file cannot be loaded: packages/decap-cms-backend-proxy/src/__tests__/implementation.spec.ts:1 imports \u0027../implementation\u0027, which names no file in this repository \u2014 and no rule in its .gitignore chain could cover one, so no build writes it either. The import throws as the runner collects this file, so none of its test cases run and nothing it was written to verify is verified. Restore the missing module or delete the test. It is excluded from the reachability measured above, because a file that cannot load reaches nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-proxy/src/__tests__/implementation.spec.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3d7ec03529fcf85165f841cfd55db100dc9c262116f95c66d3e1f49521a5e569"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-azure/src/API.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0c80705d1ed087acecce5f67c9466b8e1b887c1565aa9ff4643591a8ba76216b"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-file/src/withFileControl.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"deb4438c07cb3aab544199a383c63c12c121acc388abf78f5c44ce46c12af3e6"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/MediaLibrary/MediaLibrary.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d99115a77507a8b21b8443525374e48350ab6350f941a7e3117e07f24abc6726"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-azure/src/implementation.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"8cb01c57dbc9aacfbc3ce46b0141db993b6191289428674721c5b0ed18da5ea6"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-code/src/CodeControl.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b32c6a6aed291a46e2b201bb34dc77c036b50a08c09705886bf471e11c733cbf"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/test-package-integrity.mjs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c413ce087963d2ea84a5fbab4646b0a3bc2e40da0293c828f04cc915fc37ffa6"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/publish-packages.mjs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"694ec4e38ba660a795d17d1eb0b344fb184de11ad7aa283f3823565513db037e"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/App/Header.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"216b4498a465b73c111ae52f7b9c463f3b5c922afaea18005642c8bf7acf94c4"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/App/App.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"13849da27617b2d907335da1e16435494c09fcd727df0d87d09d48a82dbf30fc"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/Workflow/WorkflowList.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"48b50db6a42cb59432f51760e4a5029240b7819dec7bfd4174f48ce4fb7d73fe"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/Workflow/WorkflowCard.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"80eb6493c3108ad464925e719c282b95b3771d9b89e6750fe25a0bb9fd7c8ab0"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-richtext/src/RichtextControl/VisualEditor.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"999da3b50f4a4da4ccab3fea0015c19b50fc43a82c33af552321e2e50fcc9eef"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/MediaLibrary/MediaLibraryModal.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"fdbbfb7d4c569a9d4521497ed82d5d49be2ac630331f37ffdc3b3917799964a7"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/MediaLibrary/MediaLibraryCardGrid.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b647eb8efb7dc634dd870e2331fbfb6f23c32b4f81cecc8608bfa3a2c0531df"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-richtext/src/RichtextControl/components/Toolbar/Toolbar.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0fd8841bf3a863e380b09462d8141233d7de04c106dbd4b0e468099f59ee03a0"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/Workflow/Workflow.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"6ca457e0399890e5e06691ebb0215fe24632434d85def31ebb3fbef8e524f5e1"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-colorstring/src/ColorControl.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0967947476744073affaad8ec4ae656f40f2c523e4fb1e5f7402de68ad8bbc55"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/MediaLibrary/MediaLibraryTop.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c85cebe9d423ed4756fcf633cb7cb24d55536f14203302f938fc850e2bf26025"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-ui-auth/src/PKCEAuthenticationPage.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e65b2412d60eb4e390a4feff3e4330ccfa6abcfec7ff6114ff7440a187951474"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-richtext/src/RichtextControl.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c8fc3b39d290b80472d9e6f9384da4b8ae704744561f17dac564af5449d82229"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-code/src/SettingsPane.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"470dc77182c13d72ae77df90d6c1aa85956dfbbd49fe42d04a828c30c4531fc2"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-map/src/withMapControl.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e55e50b9934b966e7c044f18ececd94dfd2c199d25a46f8ca4ea93e423b783a2"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-richtext/src/RichtextControl/components/Toolbar/HeadingToolbarButton.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"765133fda0200ffbb4a43d92c0528975ccafea6c30886cb5e7c65d5d27e285cc"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-richtext/src/RichtextControl/RawEditor.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"dbbcdeaf03157a261f865e03c99e34dd6454ce7538b66ebadbe8de337f88ddae"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-richtext/src/RichtextControl/components/Toolbar/EditorComponentsToolbarButton.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"6281eb8b76c3b45bc859ef9080d4f97b6074a787c514d526e522b16b7ac35bd8"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-azure/src/AuthenticationPage.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a5391a9badab2fc00ac11269bc1c0eb7aa8a3e4e1b68f35620b3f4a57c06a8c7"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"functions/publish.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"5c594a97296c39989e712430acd8be05f5dbcfe5792cf581ec6b4fa15fa1a4de"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-aws-cognito-github-proxy/src/AuthenticationPage.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c3627b25a1a23f44bf60178f47a35b2791d050e38619b36a2824b2e0653b5e99"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-app/src/extensions.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b3599e801b5e9bda4fb7d5c02fe686c35c704fa2021560a1c35867c6b62a553"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-lib-auth/src/implicit-oauth.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1498f97b02af96ab9f3b13168fa73db5def6763854e588f44f3b82087d4a3d51"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-proxy/src/AuthenticationPage.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0d637187b2f2dd6014959706f20bec9e4f0b5df0b901b9422ac4c545ac70be5c"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-string/src/StringControl.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a3df9941bd8d4c2a7f6a3b2f26211fcb442d6a711078b0695ae8ea482f6e9fed"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/MediaLibrary/MediaLibraryHeader.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"963f004aa3c686315691d8313d3cded2905f75df82494adc241404acd2c6dc90"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/MediaLibrary/MediaLibrarySearch.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"04742d3fba6a2731a8523bff035dd2816568c90d5f3ecbb567720ce57a5dd0d0"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-image/src/ImagePreview.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"2b850c927b94fd02ea8e2c65e9b5f15f4c366b9f518c5f85e10b8d2344684108"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-aws-cognito-github-proxy/src/implementation.tsx"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"5085bc8661cd1a4c7c5ac82ba9c201d543d4b01a270bd7a197c0e8a96ed041e8"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-text/src/TextControl.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"bcbbb2216c88a7bc8c2d06f20b487bebbdcebffc835621de620a899ed9a9c3bf"}},{"ruleId":"R6","level":"warning","message":{"text":"The declared test suite includes a file that cannot be loaded: This repository declares test tooling, and the \u2713 above records that declaration \u2014 but cypress/run.mjs and 2 other test file(s) in this workspace cannot be loaded at all: it imports a module that names no file in this repository, so the runner throws while collecting it and none of its cases execute. The wiring is present and the suite it points at does not run as written, which is why the tooling tick must not be read as a statement that the tests pass. Fix the unloadable file(s) \u2014 each one is reported with its failing import under Test Coverage \u2014 then the declared script exercises what it claims to."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"cypress/run.mjs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"9d5b13cdf773d4bbdd0b1e120477245e3bd6136ae0ae7362b92b6d4d67104243"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~84 LoC): no import path from any entry point (123 application, 65 tooling, 206 test roots considered), and no other file in the scanned tree imports it \u2014 nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"functions/publish.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b9939be2522b79372535d5eeee705ad7606af3bb483e66731516a23bbb377fd4"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~83 LoC): no import path from any entry point (123 application, 65 tooling, 206 test roots considered), and no other file in the scanned tree imports it \u2014 nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-aws-cognito-github-proxy/src/AuthenticationPage.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3c1067dfad74caf9a9ba8ebc91e850be232574beea7d0b320b9d10d1135fd27f"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~18 LoC): no import path from any entry point (123 application, 65 tooling, 206 test roots considered), and no other file in the scanned tree imports it \u2014 nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"setupTestFramework.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"700cf7d9f8b160d303d3b9af4f22c8fcf39f35481589c73dd6aaf7ddaf69f745"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~15 LoC): no import path from any entry point (123 application, 65 tooling, 206 test roots considered), and no other file in the scanned tree imports it \u2014 nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/cache.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1ba4fec19e9306d7aeea0cdca6ea76c6ca963bfdb8625e45ed1f394178bfe668"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~7 LoC): no import path from any entry point (123 application, 65 tooling, 206 test roots considered), and no other file in the scanned tree imports it \u2014 nothing in-repo names this module at all, which is the strongest form of this claim the import graph can make"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"jest.resolver.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"557be4da9f89bfc84c091e0dc90d1324561ebf6ef98be7d79e60e572a58d4ad7"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027treeEntry\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-github/src/fragments.ts"},"region":{"startLine":72}}}],"partialFingerprints":{"codehealthFindingId/v1":"97e7f478299fafa6256d79ba0609437814cf75dd6772a9d3df070993c0e77add"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027showCollection\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/actions/collections.ts"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"183885cbc4368de52cdeac10599791ad9492024cd35f778e848abb02118e383a"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027refreshNotesNow\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/actions/entries.ts"},"region":{"startLine":1298}}}],"partialFingerprints":{"codehealthFindingId/v1":"a683b43c57065d681c75f90fb57b03d7ae2c53bf11fb5441b3e0dcec183aabd4"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027toggleNoteResolutionPersist\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/actions/entries.ts"},"region":{"startLine":1449}}}],"partialFingerprints":{"codehealthFindingId/v1":"4ebb8e6e3770662b49accd0bf772ee2afe6bf4b53a3f19b7c2da23d76ed14588"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027statusDescriptions\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/constants/publishModes.ts"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"cb45d8ba7ee53845dcb5612f72dbed1f9a41808dcd4da1bba66419215fbadd0d"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027getFormatter\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/lib/registry.js"},"region":{"startLine":313}}}],"partialFingerprints":{"codehealthFindingId/v1":"06e86356127030cf2beb551b7033fa48f8aed8249b9cb16d6f0b67020b2dcaa9"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027selectEntries\u0027: Nothing imports THIS copy of \u0027selectEntries\u0027 \u2014 but packages/decap-cms-core/src/reducers/entries.ts:432 in the same directory exports that same name, and it is the copy every import site resolves to. Grepping the name therefore finds live callers that do not reach this binding: it is the dead half of a duplicated pair, left behind when the API moved. Delete it here and keep packages/decap-cms-core/src/reducers/entries.ts\u0027s, or, if this one is meant to be the survivor, repoint the importers before removing the other."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/reducers/index.ts"},"region":{"startLine":51}}}],"partialFingerprints":{"codehealthFindingId/v1":"4b9bf5bda44b570f5e91d50f639a4aa11ab9289a5c1e292805c602c7076634f4"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027endpointConstants\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-lib-util/src/API.ts"},"region":{"startLine":155}}}],"partialFingerprints":{"codehealthFindingId/v1":"0487876e589fa18a5c09961b0d7d6b9b3ef8cfd44746280706ddd015b3950cee"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027NOTES_POLLING_START\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-lib-util/src/notesPolling.ts"},"region":{"startLine":58}}}],"partialFingerprints":{"codehealthFindingId/v1":"abc6ace35bdfaaeef4f3740974c3964021efcb2912a15f587fa9ad67e92ee127"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027NOTES_POLLING_STOP\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-lib-util/src/notesPolling.ts"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"de56c3fc7bd26cccf74745b96f4808970a40758d4cbc83a6e6e00344e76ad7fe"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027NOTES_POLLING_UPDATE\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-lib-util/src/notesPolling.ts"},"region":{"startLine":60}}}],"partialFingerprints":{"codehealthFindingId/v1":"96b063d0663eae249a06d6eaa7196e92feca7dace1a3321d5570ab4d3e736783"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027NOTES_CHANGE_DETECTED\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-lib-util/src/notesPolling.ts"},"region":{"startLine":61}}}],"partialFingerprints":{"codehealthFindingId/v1":"02b83cebc6fb8ffd3ab42180c902537c6edd9efe9da838d12ef864099ec3fb28"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027default\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-lib-util/src/notesPolling.ts"},"region":{"startLine":523}}}],"partialFingerprints":{"codehealthFindingId/v1":"d634e4eda9b15e527edcdc6174fbef7a59d9fa38c3d8162eea93029d15cafdc5"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027resolveFunctionForTypedField\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-list/src/typedListHelpers.js"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"593f6e977b65b00fc183a25a929890cdaac69075c22226c16db49bf3953ad3c8"}},{"ruleId":"R7","level":"note","message":{"text":"Unused export \u0027renderInline__DEPRECATED\u0027: Nothing imports this binding \u2014 it is safe to review for removal."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/renderers.js"},"region":{"startLine":285}}}],"partialFingerprints":{"codehealthFindingId/v1":"dbbf563e502bbcf289643bb4a66ddaa28335207055e5d0766b1b245d46d2c4f7"}},{"ruleId":"R8","level":"warning","message":{"text":"Unlisted import \u0027unified\u0027: Imported only as a TYPE and declared in no reachable package.json. The import is erased at compile time, so nothing is installed and no runtime resolution depends on it \u2014 but type-checking a clean clone will fail. Declare the typings it resolves through (or the package itself) in the owning package.json."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/index.d.ts"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"72b4222e047f46322abfb0b3f7f850a7b246566284b86d798bb3a1cced0e158f"}},{"ruleId":"R8","level":"warning","message":{"text":"Unused dependency \u0027all-contributors-cli\u0027: Declared in the root package.json but never imported anywhere in that package or its workspace members \u2014 no static import reaches it. Usually that is dead weight and attack surface, but two shapes are indistinguishable from source and are NOT dead: an optional or native peer that another dependency loads dynamically at runtime, and a package a build, docs or test step installs and invokes separately. Confirm which of the three this is before removing it."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c00c914176ffe3e3339d87bdc8d222c1dd4ff5ed8d91ed5e57687615b3c3a85a"}},{"ruleId":"R8","level":"warning","message":{"text":"Unused dependency \u0027axios\u0027: Declared in the root package.json but never imported anywhere in that package or its workspace members \u2014 no static import reaches it. Usually that is dead weight and attack surface, but two shapes are indistinguishable from source and are NOT dead: an optional or native peer that another dependency loads dynamically at runtime, and a package a build, docs or test step installs and invokes separately. Confirm which of the three this is before removing it."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"47bd42e4e250c4e6e33385b1e68b1c2c324de0c2b8a8bfcbc1526d442b3375b9"}},{"ruleId":"R8","level":"warning","message":{"text":"Unused dependency \u0027browserify\u0027: Declared in the root package.json but never imported anywhere in that package or its workspace members \u2014 no static import reaches it. Usually that is dead weight and attack surface, but two shapes are indistinguishable from source and are NOT dead: an optional or native peer that another dependency loads dynamically at runtime, and a package a build, docs or test step installs and invokes separately. Confirm which of the three this is before removing it."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e5eaf7559490dc503e78dc04bc1f6a9a31d63c290893d934e161ea7aa65d7ad5"}},{"ruleId":"R9","level":"error","message":{"text":"Import cycle (4 files): packages/decap-cms-core/src/backend.ts \u2192 packages/decap-cms-core/src/lib/formatters.ts \u2192 packages/decap-cms-core/src/reducers/collections.ts \u2192 packages/decap-cms-core/src/actions/config.ts \u2192 packages/decap-cms-core/src/backend.ts (one verified cycle inside a mutually-dependent group of 30 files)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/backend.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d18a7816cbb4c9c3f88d886477f4d23cce7e430087d08c3f116fc58223bd1319"}},{"ruleId":"R9","level":"error","message":{"text":"Import cycle (3 files): packages/decap-cms-core/src/components/Collection/Entries/Entries.js \u2192 packages/decap-cms-core/src/components/Collection/Entries/EntryListing.js \u2192 packages/decap-cms-core/src/components/Collection/Entries/EntriesCollection.js \u2192 packages/decap-cms-core/src/components/Collection/Entries/Entries.js"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/Collection/Entries/Entries.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"eb78d60e742c5ae7ce0819d7475e1aa842722f9f668e9272f96a2276d71645a7"}},{"ruleId":"R9","level":"error","message":{"text":"Import cycle (4 files): packages/decap-cms-widget-markdown/src/MarkdownControl/VisualEditor.js \u2192 packages/decap-cms-widget-markdown/src/MarkdownControl/renderers.js \u2192 packages/decap-cms-widget-markdown/src/MarkdownControl/components/InlineShortcode.js \u2192 packages/decap-cms-widget-markdown/src/MarkdownControl/index.js \u2192 packages/decap-cms-widget-markdown/src/MarkdownControl/VisualEditor.js (one verified cycle inside a mutually-dependent group of 6 files)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/VisualEditor.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0c47575a75036f11564f3ee91dc5132a3e380deb423cd619fc92afc8a691aefd"}},{"ruleId":"S1","level":"note","message":{"text":"No security response headers detected: No Content-Security-Policy / X-Frame-Options / X-Content-Type-Options configuration found \u2014 defense in depth, even when a reverse proxy could set them. This is reported because \u0060netlify.toml\u0060 configures this repository\u0027s static hosting, including its response headers, so the configuration that would carry these headers is in this repository and was read in full. (\u22122.0 on this card.)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"netlify.toml"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"8b1fc99a2627121a3303b80ac48a36f267e6e7f5c3a740175ff6cfdd1826ad7f"}},{"ruleId":"X10","level":"note","message":{"text":"Duplicated predicate: \u0060!field.get(\u0027required\u0027, true) || isMultiple\u0060 appears character-identically in 2 files \u2014 packages/decap-cms-widget-relation/src/RelationControl.js, packages/decap-cms-widget-select/src/SelectControl.js. It is one line, so the duplication detector\u0027s token window never sees it; the copies drift when only one is corrected. Give the condition a name and one home."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-relation/src/RelationControl.js"},"region":{"startLine":491}}}],"partialFingerprints":{"codehealthFindingId/v1":"131b18967604709078fd47a11dfc84ff633c2c6d6897b6c08b6afbfb161a24fb"}},{"ruleId":"X10","level":"note","message":{"text":"Duplicated predicate: \u0060[\u0027text\u0027, \u0027html\u0027].includes(node.type) \u0026\u0026 node.value\u0060 appears character-identically in 2 files \u2014 packages/decap-cms-widget-markdown/src/serializers/remarkEscapeMarkdownEntities.js, packages/decap-cms-widget-richtext/src/serializers/remarkEscapeMarkdownEntities.js. It is one line, so the duplication detector\u0027s token window never sees it; the copies drift when only one is corrected. Give the condition a name and one home."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkEscapeMarkdownEntities.js"},"region":{"startLine":256}}}],"partialFingerprints":{"codehealthFindingId/v1":"533c05de2d0aa9df7e06daf4513d508990c42c956e9d2e03e34ac6363f1eac3e"}},{"ruleId":"X10","level":"note","message":{"text":"Duplicated predicate: \u0060codeBlockComponent || editorComponents.has(\u0027code-block\u0027)\u0060 appears character-identically in 2 files \u2014 packages/decap-cms-widget-markdown/src/MarkdownControl/VisualEditor.js, packages/decap-cms-widget-richtext/src/RichtextControl/VisualEditor.js. It is one line, so the duplication detector\u0027s token window never sees it; the copies drift when only one is corrected. Give the condition a name and one home."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/VisualEditor.js"},"region":{"startLine":112}}}],"partialFingerprints":{"codehealthFindingId/v1":"cc10f83669182f05275dd92293bc08bc1cd3b3214e2b3571f754465abbe0c5e8"}},{"ruleId":"X10","level":"note","message":{"text":"Duplicated predicate: \u0060collection.get(\u0027label_singular\u0027) || collection.get(\u0027label\u0027)\u0060 appears character-identically in 2 files \u2014 packages/decap-cms-core/src/components/App/Header.js, packages/decap-cms-core/src/lib/formatters.ts. It is one line, so the duplication detector\u0027s token window never sees it; the copies drift when only one is corrected. Give the condition a name and one home."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-core/src/components/App/Header.js"},"region":{"startLine":266}}}],"partialFingerprints":{"codehealthFindingId/v1":"d29211c3dd2596fe816946a0b724bae6e3c09ac8f0eaf293f72cb6760e3ccbe0"}},{"ruleId":"X10","level":"note","message":{"text":"Duplicated predicate: \u0060config.backend.branch?.trim() || \u0027master\u0027\u0060 appears character-identically in 3 files \u2014 packages/decap-cms-backend-git-gateway/src/implementation.ts, packages/decap-cms-backend-gitea/src/implementation.tsx, packages/decap-cms-backend-github/src/implementation.tsx. It is one line, so the duplication detector\u0027s token window never sees it; the copies drift when only one is corrected. Give the condition a name and one home."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-backend-git-gateway/src/implementation.ts"},"region":{"startLine":170}}}],"partialFingerprints":{"codehealthFindingId/v1":"7fbdd5c966b94f99e1763703fd499e0b09fc45ea36d4b44310e1a3e462da8dec"}},{"ruleId":"X10","level":"note","message":{"text":"Duplicated predicate: \u0060endsWith(text, \u0027 \u0027) \u0026\u0026 getEdgeTextChild(node, true)\u0060 appears character-identically in 2 files \u2014 packages/decap-cms-widget-markdown/src/serializers/remarkPaddedLinks.js, packages/decap-cms-widget-richtext/src/serializers/remarkPaddedLinks.js. It is one line, so the duplication detector\u0027s token window never sees it; the copies drift when only one is corrected. Give the condition a name and one home."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkPaddedLinks.js"},"region":{"startLine":60}}}],"partialFingerprints":{"codehealthFindingId/v1":"549d6b0e065f49e64c18de5d1d94d1d67139a9d04d75d7ba2e82664cda541a65"}},{"ruleId":"X10","level":"note","message":{"text":"Duplicated predicate: \u0060field.has(\u0027media_folder\u0027) \u0026\u0026 !f.has(\u0027media_folder\u0027)\u0060 appears character-identically in 2 files \u2014 packages/decap-cms-widget-markdown/src/MarkdownControl/VisualEditor.js, packages/decap-cms-widget-richtext/src/RichtextControl/mergeMediaConfig.js. It is one line, so the duplication detector\u0027s token window never sees it; the copies drift when only one is corrected. Give the condition a name and one home."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/VisualEditor.js"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"a2174a606952af1d4684eb8f9b09d207b539e31d1dffee142a0f081a7dc35d0f"}},{"ruleId":"X10","level":"note","message":{"text":"Duplicated predicate: \u0060field.has(\u0027public_folder\u0027) \u0026\u0026 !f.has(\u0027public_folder\u0027)\u0060 appears character-identically in 2 files \u2014 packages/decap-cms-widget-markdown/src/MarkdownControl/VisualEditor.js, packages/decap-cms-widget-richtext/src/RichtextControl/mergeMediaConfig.js. It is one line, so the duplication detector\u0027s token window never sees it; the copies drift when only one is corrected. Give the condition a name and one home."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownControl/VisualEditor.js"},"region":{"startLine":75}}}],"partialFingerprints":{"codehealthFindingId/v1":"55eb4b9b51d82759cce17941f8e989e22345eda5a188d51ddd8b15e6f5b2d891"}},{"ruleId":"X10","level":"note","message":{"text":"Duplicated predicate: \u0060node.nodeName === \u0027IMG\u0027 \u0026\u0026 data.attrName === \u0027src\u0027 \u0026\u0026 isSameOriginBlobUrl(data.attrValue)\u0060 appears character-identically in 2 files \u2014 packages/decap-cms-widget-markdown/src/MarkdownPreview.js, packages/decap-cms-widget-richtext/src/RichtextPreview.js. It is one line, so the duplication detector\u0027s token window never sees it; the copies drift when only one is corrected. Give the condition a name and one home."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/MarkdownPreview.js"},"region":{"startLine":32}}}],"partialFingerprints":{"codehealthFindingId/v1":"dbc54afa0ede5a586a84f11648e02025542b8d0a2c56a4b45c139fd4cd0e2f12"}},{"ruleId":"X10","level":"note","message":{"text":"Duplicated predicate: \u0060startsWith(text, \u0027 \u0027) \u0026\u0026 getEdgeTextChild(node)\u0060 appears character-identically in 2 files \u2014 packages/decap-cms-widget-markdown/src/serializers/remarkPaddedLinks.js, packages/decap-cms-widget-richtext/src/serializers/remarkPaddedLinks.js. It is one line, so the duplication detector\u0027s token window never sees it; the copies drift when only one is corrected. Give the condition a name and one home."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkPaddedLinks.js"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"acb7e17a7c7e31c8add291df2204abe9127844d5ceb708ad04060e890b2c78c8"}},{"ruleId":"X10","level":"note","message":{"text":"Duplicated predicate: \u0060trailingWhitespaceNode \u0026\u0026 u(\u0027text\u0027, \u0027 \u0027)\u0060 appears character-identically in 2 files \u2014 packages/decap-cms-widget-markdown/src/serializers/remarkPaddedLinks.js, packages/decap-cms-widget-richtext/src/serializers/remarkPaddedLinks.js. It is one line, so the duplication detector\u0027s token window never sees it; the copies drift when only one is corrected. Give the condition a name and one home."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-cms-widget-markdown/src/serializers/remarkPaddedLinks.js"},"region":{"startLine":84}}}],"partialFingerprints":{"codehealthFindingId/v1":"b588d88b4762fbbd4c97e58277bc23220c707120e0151932a7a04f1e53a7d1ea"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default in catch: \u0060listFiles\u0060 swallows every exception into \u0060return []\u0060 \u2014 a data error becomes a silent behavior change with no trail. Log the failure or let it raise. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the handler or in the docstring, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"packages/decap-server/src/middlewares/utils/fs.ts"},"region":{"startLine":22}}}],"partialFingerprints":{"codehealthFindingId/v1":"1cc182d9b6d706238868ef55ab3370ba9cc0ce6f85edf78092162131d58538d9"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1059","guid":"a2381a08-60f6-9554-a8b8-f3018cfaaca5","name":"Insufficient Technical Documentation","shortDescription":{"text":"Insufficient Technical Documentation"},"helpUri":"https://cwe.mitre.org/data/definitions/1059.html"},{"id":"CWE-1104","guid":"4c918cb5-b2a6-6c55-9963-a44ee464305e","name":"CWE-1104","shortDescription":{"text":"CWE-1104"},"helpUri":"https://cwe.mitre.org/data/definitions/1104.html"},{"id":"CWE-125","guid":"98717707-96bf-ca5b-9568-8d1d257574c1","name":"CWE-125","shortDescription":{"text":"CWE-125"},"helpUri":"https://cwe.mitre.org/data/definitions/125.html"},{"id":"CWE-1329","guid":"f70f1c3f-4ccf-cb5e-bdd3-03ba4868d36d","name":"CWE-1329","shortDescription":{"text":"CWE-1329"},"helpUri":"https://cwe.mitre.org/data/definitions/1329.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-457","guid":"b62874fe-6222-8b5b-8ade-9527ad1cbb4a","name":"CWE-457","shortDescription":{"text":"CWE-457"},"helpUri":"https://cwe.mitre.org/data/definitions/457.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-522","guid":"71fb233e-ce6a-ae57-9419-ef8373540b09","name":"CWE-522","shortDescription":{"text":"CWE-522"},"helpUri":"https://cwe.mitre.org/data/definitions/522.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-829","guid":"13c33925-97fb-5a5e-b40c-56d328b8a4d7","name":"CWE-829","shortDescription":{"text":"CWE-829"},"helpUri":"https://cwe.mitre.org/data/definitions/829.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":154,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}