{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AX9","name":"CQS / query purity","shortDescription":{"text":"CQS / query purity"},"helpUri":"https://codehealth.canine.dev/dimensions/AX9"},{"id":"AXB1","name":"Runtime evidence locked \u2014 no reproducible boot","shortDescription":{"text":"Runtime evidence locked \u2014 no reproducible boot"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB1"},{"id":"ES1","name":"Fold determinism","shortDescription":{"text":"Fold determinism"},"helpUri":"https://codehealth.canine.dev/dimensions/ES1"},{"id":"ES2","name":"Immutable events","shortDescription":{"text":"Immutable events"},"helpUri":"https://codehealth.canine.dev/dimensions/ES2"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X26","name":"Unsynchronised callback handoff","shortDescription":{"text":"Unsynchronised callback handoff"},"helpUri":"https://codehealth.canine.dev/dimensions/X26"},{"id":"X31","name":"Test-only surface in a production module","shortDescription":{"text":"Test-only surface in a production module"},"helpUri":"https://codehealth.canine.dev/dimensions/X31"},{"id":"X32","name":"Type resolved by simple name across every loaded assembly","shortDescription":{"text":"Type resolved by simple name across every loaded assembly"},"helpUri":"https://codehealth.canine.dev/dimensions/X32"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"esockd_udp.handle_info (cyclomatic 27): esockd_udp.handle_info has cyclomatic complexity 27 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_udp.erl"},"region":{"startLine":262}}}],"partialFingerprints":{"codehealthFindingId/v1":"aab5a3bdbac198c0034912a29cc5286fc1cd2ca88a05e47d632a8e2ba3734799"}},{"ruleId":"D1","level":"warning","message":{"text":"esockd_connection_sup.handle_call (cyclomatic 25): esockd_connection_sup.handle_call has cyclomatic complexity 25 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_connection_sup.erl"},"region":{"startLine":172}}}],"partialFingerprints":{"codehealthFindingId/v1":"89d02617c60288769b17b08bfc7d0d8ace1c9f124aaae00939ba2ccd34fe7b7d"}},{"ruleId":"D1","level":"warning","message":{"text":"esockd_udp.handle_call (cyclomatic 20): esockd_udp.handle_call has cyclomatic complexity 20 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_udp.erl"},"region":{"startLine":203}}}],"partialFingerprints":{"codehealthFindingId/v1":"202adcf3acb9689df6323f27269fb47f0a359c2e4dd21df63a6bfba2ed86fe83"}},{"ruleId":"D1","level":"warning","message":{"text":"esockd_cidr.match (cyclomatic 17): esockd_cidr.match has cyclomatic complexity 17 (threshold 15). To reduce it, name the conditions \u2014 but note WHERE they are: these tests sit in guard sequences, and a guard is a restricted expression sublanguage that allows neither binding a local nor calling a function you wrote, so neither of those moves is available in place. Move the decision out of the guard instead: keep one clause with a permissive guard, compute the compound test in the body through named predicate functions, and dispatch on their result. Where the clauses genuinely differ by pattern rather than by test, keep the patterns and lift only the comma-conjunctions. This is NOT this file\u0027s highest cyclomatic complexity: esockd_cidr.end_mask (cyclomatic 18) is higher and carries no row of its own \u2014 it was excluded as a flat dispatcher (a long switch/match over independent cases: many branches, almost no nesting), which this dimension does not treat as a refactor obligation. It is named here so the ranking you see in this file is not mistaken for the whole of it; the excluded function is counted neither in this dimension\u0027s figures nor in its score."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_cidr.erl"},"region":{"startLine":77}}}],"partialFingerprints":{"codehealthFindingId/v1":"9d622f84f90ade6fe53d76bcc7378e3b3730c1f52da1ab5a003b06542aa4bf28"}},{"ruleId":"D2","level":"warning","message":{"text":"esockd_connection_sup.handle_call (cognitive 19): esockd_connection_sup.handle_call has cognitive complexity 19 (threshold 15). Drivers by points: match/switch 7 (11 pts), error handling 2 (4 pts), if/else 1 (2 pts), loops 2 (nesting depth added 7). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_connection_sup.erl"},"region":{"startLine":172}}}],"partialFingerprints":{"codehealthFindingId/v1":"d15790150f3d20f64b9194800fc1ef3db5a38e774a60192501b08d7cc5505f23"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFunctions: esockd: TooManyFunctions \u2014 55 functions. The bar is 30 functions; this is 25 over it, 1.83\u00D7 the bar. The counted members are a module\u0027s functions \u2014 a module holds no instance state, so there is no shared data to group them by and no type to move them onto. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no single module carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd.erl"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"18727b36ae0166be223002ae94574441c919fb9ecf4ea7b05d3d744447dff3a9"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFunctions: esockd_transport: TooManyFunctions \u2014 40 functions. The bar is 30 functions; this is 10 over it, 1.33\u00D7 the bar. The counted members are a module\u0027s functions \u2014 a module holds no instance state, so there is no shared data to group them by and no type to move them onto. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no single module carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_transport.erl"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"e0e9d25321881843da78c34b908470dd3345aacb11d85174e77c9b6d53a0e917"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFunctions: esockd_connection_sup: TooManyFunctions \u2014 36 functions. The bar is 30 functions; this is 6 over it, 1.20\u00D7 the bar. The counted members are a module\u0027s functions \u2014 a module holds no instance state, so there is no shared data to group them by and no type to move them onto. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no single module carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_connection_sup.erl"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"b2211fd5754421daf8a3e0e9ebb3cfea88fc92bfb2e6781e480d154c20b97d41"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFunctions: esockd_udp: TooManyFunctions \u2014 35 functions. The bar is 30 functions; this is 5 over it, 1.17\u00D7 the bar. The counted members are a module\u0027s functions \u2014 a module holds no instance state, so there is no shared data to group them by and no type to move them onto. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no single module carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_udp.erl"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"2dabeeaff321e7ddebb9f90fc3552ed50208b79080c60ee43012f61553f406f5"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFunctions: esockd_ssl: TooManyFunctions \u2014 33 functions. The bar is 30 functions; this is 3 over it, 1.10\u00D7 the bar. The counted members are a module\u0027s functions \u2014 a module holds no instance state, so there is no shared data to group them by and no type to move them onto. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no single module carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_ssl.erl"},"region":{"startLine":22}}}],"partialFingerprints":{"codehealthFindingId/v1":"be76caa247141f3952d84052ce120a91a8142c3eb606ce207426a5b1aa67845f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): src/esockd_connection_sup.erl:209-219 | src/esockd_udp.erl:230-240 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_connection_sup.erl"},"region":{"startLine":209}}}],"partialFingerprints":{"codehealthFindingId/v1":"949897febc5718cd44e06047314a5acd387fe7045a2c8ec97e5e30afbcf16ac9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): src/esockd_listener.erl:131-141 | src/esockd_socket_listener.erl:205-215 \u2014 before extracting anything, compare \u0060src/esockd_listener.erl\u0060 and \u0060src/esockd_socket_listener.erl\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 30 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_listener.erl"},"region":{"startLine":131}}}],"partialFingerprints":{"codehealthFindingId/v1":"32009ff9b4e5eb7b509ab123e36912af3825d817b9fa4e7398ae1fc69d8df140"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7\u201310 lines \u00D7 3): src/esockd_dtls_listener.erl:145-154 | src/esockd_listener.erl:135-141 | src/esockd_socket_listener.erl:209-217 \u2014 before extracting anything, compare \u0060src/esockd_listener.erl\u0060 and \u0060src/esockd_socket_listener.erl\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 30 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_dtls_listener.erl"},"region":{"startLine":145}}}],"partialFingerprints":{"codehealthFindingId/v1":"ac07609071f64bf7206e8386fb61c8cd73c3d9f668c89a118b6ac7ba7867c908"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 3): src/esockd_dtls_listener.erl:68-76 | src/esockd_listener.erl:67-75 | src/esockd_socket_listener.erl:67-75 \u2014 before extracting anything, compare \u0060src/esockd_listener.erl\u0060 and \u0060src/esockd_socket_listener.erl\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 30 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_dtls_listener.erl"},"region":{"startLine":68}}}],"partialFingerprints":{"codehealthFindingId/v1":"c860915852a359e043df797ab48438e4438530926eb1c828f5579b38ce041fd9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): src/esockd_socket.erl:106-112 | src/esockd_transport.erl:76-82 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_socket.erl"},"region":{"startLine":106}}}],"partialFingerprints":{"codehealthFindingId/v1":"a89ba70f3b8f1ac49079cfaefcf65baef7ecb26b3694e4d87ecf452f6633a59c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): src/esockd_cidr.erl:78-82 | src/esockd_cidr.erl:88-92 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_cidr.erl"},"region":{"startLine":78}}}],"partialFingerprints":{"codehealthFindingId/v1":"02b7de1404c6dc44d28bd7a7679c65b41fba214de01e7a3ee31a756ae8404172"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): src/esockd_connection_sup.erl:322-326 | src/esockd_udp.erl:401-405 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_connection_sup.erl"},"region":{"startLine":322}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b125bfe681444859549dbc46e72b2f1321ad7e5ca3377fc932507bb2b827c0f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): src/esockd_connection_sup.erl:282-287 | src/esockd_udp.erl:377-382 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_connection_sup.erl"},"region":{"startLine":282}}}],"partialFingerprints":{"codehealthFindingId/v1":"aa2b7325e70e76f68d33e03cdfb26366bcc320bf5837c7aeed9a086610e7f3cd"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): src/esockd_listener_sup.erl:143-149 | src/esockd_udp.erl:128-134 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_listener_sup.erl"},"region":{"startLine":143}}}],"partialFingerprints":{"codehealthFindingId/v1":"685a6247c32294a2e8fa506b799800efa19d9ad9adabc334d072d24bd80f6e48"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): src/esockd_dtls_listener.erl:187-192 | src/esockd_listener.erl:168-173 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_dtls_listener.erl"},"region":{"startLine":187}}}],"partialFingerprints":{"codehealthFindingId/v1":"319777d13e3246a9759c04c541488ede899e869eedb0d2dcbb728e00a25c1300"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): examples/dtls/dtls_echo_server.erl:42-50 | examples/dtls_psk/dtls_psk_echo_server.erl:34-42 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"examples/dtls/dtls_echo_server.erl"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"27b3a1e55e6be4a6cc0d9eb0c475badd8117f0d77c2cf2a3f0d1046e859208f9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): examples/simple/simple_echo_server.erl:45-50 | examples/tls/ssl_echo_server.erl:40-45 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"examples/simple/simple_echo_server.erl"},"region":{"startLine":45}}}],"partialFingerprints":{"codehealthFindingId/v1":"f9bda82e69902ac32070fb43c6b18099ffabb1e76e412ab31fabba67d93abd44"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): examples/simple/simple_echo_server.erl:54-59 | examples/tls/ssl_echo_server.erl:49-54 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"examples/simple/simple_echo_server.erl"},"region":{"startLine":54}}}],"partialFingerprints":{"codehealthFindingId/v1":"e59392f11960998aef58afb7932fb102e5b8bfd2d57cff513ed9731ddaa8675b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): examples/gen_server/gen_echo_server.erl:68-73 | examples/proxy_protocol/proxy_protocol_server.erl:68-73 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"examples/gen_server/gen_echo_server.erl"},"region":{"startLine":68}}}],"partialFingerprints":{"codehealthFindingId/v1":"cb503106aaced9435030d3491048f8081e9e802428c481afa31dae4c847c7301"}},{"ruleId":"D13","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8bb5924e438222cba44f0d9064e18ef3692f29f52c0138825547f3f53198abb0"},"taxa":[{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/esockd_acceptor_fsm.erl: src/esockd_acceptor_fsm.erl changed 2 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 15 in esockd_acceptor_fsm.handle_event at line 107. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 12:11:55 \u002B02:00\u0027 --until=\u00272026-09-24 12:11:55 \u002B02:00\u0027 --full-history --no-merges -- src/esockd_acceptor_fsm.erl\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_acceptor_fsm.erl"},"region":{"startLine":107}}}],"partialFingerprints":{"codehealthFindingId/v1":"b4dc782c56e1fd5bef7eaef517c7b16706fdf720a82b414b7d8de90121f087ec"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: src/udp_proxy/esockd_udp_proxy.erl: src/udp_proxy/esockd_udp_proxy.erl changed 4 times in last 90 days and 4 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 9 (its worst body is esockd_udp_proxy.handle_info at line 139), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix(udp_proxy): support remote connection pids\u201D; \u201Cfix: pass UDP proxy owner to connection callbacks\u201D; \u201Cfix: notify UDP proxy connection detach\u201D; \u201Cfix udp proxy reroute on connection id change\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 12:11:55 \u002B02:00\u0027 --until=\u00272026-09-24 12:11:55 \u002B02:00\u0027 --full-history --no-merges -- src/udp_proxy/esockd_udp_proxy.erl\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/udp_proxy/esockd_udp_proxy.erl"},"region":{"startLine":139}}}],"partialFingerprints":{"codehealthFindingId/v1":"a5b4727650c199469013afdca19df7da859ca2b732ba86a2361ea12730ecd2fd"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: src/udp_proxy/esockd_udp_proxy_connection.erl: src/udp_proxy/esockd_udp_proxy_connection.erl changed 3 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 3 (its worst body is esockd_udp_proxy_connection.close at line 106), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix: pass UDP proxy owner to connection callbacks\u201D; \u201Cfix: notify UDP proxy connection detach\u201D; \u201Cfix udp proxy reroute on connection id change\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 12:11:55 \u002B02:00\u0027 --until=\u00272026-09-24 12:11:55 \u002B02:00\u0027 --full-history --no-merges -- src/udp_proxy/esockd_udp_proxy_connection.erl\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/udp_proxy/esockd_udp_proxy_connection.erl"},"region":{"startLine":106}}}],"partialFingerprints":{"codehealthFindingId/v1":"d8ef66fefc3c424282ad117264f968f844acd3942f2c3b372f9d2e9a903f659c"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #1: If anonymized user #1 becomes unavailable, 3 significant file(s) lose their only recent owner: src/esockd_socket.erl, src/esockd_accept_socket.erl, src/esockd_accept_inet.erl. Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6997260d1cb602ca2035fac2bdecbf11e484eeb063f1f3947144a6721ea87fe0"}},{"ruleId":"D16","level":"note","message":{"text":"Further sole-owners (lower concentration): 3 other contributor(s) are each the sole owner of a small amount of code below the off-boarding threshold \u2014 folded into the bus-factor score and metrics (7 single-owned of 24 analysed files in total, counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 24 of the 30 production source files in this repository met that bar). They are anonymized user #2 (2 file(s)), anonymized user #3 (1 file(s)), anonymized user #4 (1 file(s)) \u2014 spread or document their files in the same way, at lower priority than the named off-boarding risks above."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6eac528f2429e724e1a97ed868f79eefbcf1888dab4af9a9e673429369bb5b2f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: get rid of this message send \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_transport.erl"},"region":{"startLine":166}}}],"partialFingerprints":{"codehealthFindingId/v1":"285ae208438a45d530e9b10c7947e0c65c6cd11131f578968791b688ee21f92c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: get rid of this message send \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_transport.erl"},"region":{"startLine":179}}}],"partialFingerprints":{"codehealthFindingId/v1":"1f72a541f1236e97341cdb32adcf26e86189efb279a5dea6cb60f0cff82119f9"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: Validate opts by esocd:open/3, and then can remove this error log. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_connection_sup.erl"},"region":{"startLine":472}}}],"partialFingerprints":{"codehealthFindingId/v1":"cf2bb6e86198264e6431c2701d96262b4735f7149ff48ca02c80500ce5223a5e"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: Ignored, need to notify user. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd_accept_socket.erl"},"region":{"startLine":161}}}],"partialFingerprints":{"codehealthFindingId/v1":"7397c44ba00b927e6660357b44a07bcae96efb2281996909889a818ec41d3b0f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: Check if Opts is valid before start_child. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/esockd.erl"},"region":{"startLine":143}}}],"partialFingerprints":{"codehealthFindingId/v1":"2f3eae4a5a7355e79cefbf6e4d45019927a977996164e09878fc3b40a077dc4b"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: %% TODO: use proc_lib:start_link to instead of this call \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/udp_proxy/esockd_udp_proxy.erl"},"region":{"startLine":334}}}],"partialFingerprints":{"codehealthFindingId/v1":"f1dce821e08e588a8a88bb53653bc0f33a01abecf9290bdcdf95d049936af005"}},{"ruleId":"D26","level":"note","message":{"text":"Projects may be oversized for their cohesion: 1 of 1 project(s) overshoot their size bounds, lowering Project Cohesion to 0.0/10. The most over is \u0060(repository root)\u0060 (6664 LoC, 257 public types across 14 directories). Review these for cohesion \u2014 draw the boundary inside the module first (group each responsibility into its own package or directory and keep the cross-boundary members non-public), since splitting a published package moves types between packages and breaks consumers."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d5a94650dc74886a0f1f08eb9fb6775f1fc395279ef7e901c970c9d26f767a72"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"36d011be78f152fdc4a100bff70dd174166f6ff3fa407f56b8679eebe8da62eb"},"properties":{"commitSha":"df4649cffaaa8eabbfbcd461a9c61d81f713577d"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bf7ec15860fdb81897c0b77bbb98963c58b6e8d7d0af609c6395877795c8e258"},"properties":{"commitSha":"71ab339c23f84027d7be9ff3efb713816279a613"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f3c0631fa952534ac60f2406893aab2e9a925af9a4a6f9fc61d1fe48ccdd9dba"}},{"ruleId":"D28","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3cdfd7beb31b791ae18dcb425e21eb157c842e7bbcd522cc330573c1a6538db1"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6f307c278b465c6679310ec235cacc86efeaa7e070f6566bdd2220983acfadc9"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"513540a6175a98bea2be454469cb8dc3cefcb8a5679696fe5bad4a5fbb359600"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D34","level":"note","message":{"text":"Orphaned files with no living knowledge: 3 of 25 analysed file(s) have no living knowledge left \u2014 their last meaningful change has decayed away, so if one breaks, no one currently understands it (counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 25 of the 30 production source files in this repository met that bar). None is large enough to earn a read-through of its own, so this row stands in for the per-file rows rather than raising one each \u2014 most significant first: src/esockd_sup.erl, src/esockd_cidr.erl, src/udp_proxy/esockd_udp_proxy_db.erl. Attach the read to the next change that touches one of them: have a second person review that change, and leave behind a short comment or test recording what the file is for, so the knowledge comes back at the cost of a change you were making anyway."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ce861fd78f6935114d3a342cb90ad25870f984e1042954fcbbe27c0e23be3658"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1b213f6eedd4b140d0bc37bdf1496f72811a643f34064f12518b32e9e83bcfc7"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e17f71490e4d120a48b2b2881ab866c93b272bef2febb673a3e8e42b2c288ab"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eb00976a698a5d68999b7ee6d27206fd374e916853e7ff1ead5eed42386f043f"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"90f83b4fa27db32740afe9540c905f3c0499caed87f61049a8a903ecc95b41c3"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9658270ba49f37ed04e99ab1263b6393cd42aed8bdfb7aafd9fa1070f5491895"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":12,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}