{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D11","name":"Test Reliability","shortDescription":{"text":"Test Reliability"},"helpUri":"https://codehealth.canine.dev/dimensions/D11"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D39","name":"IL Efficiency","shortDescription":{"text":"IL Efficiency"},"helpUri":"https://codehealth.canine.dev/dimensions/D39"},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AX8","name":"Test isolation","shortDescription":{"text":"Test isolation"},"helpUri":"https://codehealth.canine.dev/dimensions/AX8"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"ED5","name":"Idempotency","shortDescription":{"text":"Idempotency"},"helpUri":"https://codehealth.canine.dev/dimensions/ED5"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"SC1","name":"Supply-chain hygiene","shortDescription":{"text":"Supply-chain hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/SC1"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X28","name":"Index access outside its own emptiness guard","shortDescription":{"text":"Index access outside its own emptiness guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X28"},{"id":"X6","name":"Hand-rolled structured-format parsing","shortDescription":{"text":"Hand-rolled structured-format parsing"},"helpUri":"https://codehealth.canine.dev/dimensions/X6"},{"id":"X7","name":"Silent fallback defaults","shortDescription":{"text":"Silent fallback defaults"},"helpUri":"https://codehealth.canine.dev/dimensions/X7"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"FantomasFactory.mapToFantomas (cyclomatic 44): FantomasFactory.mapToFantomas has cyclomatic complexity 44 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ElectronApi.Json.Parser/SourceMapper.fs"},"region":{"startLine":235}}}],"partialFingerprints":{"codehealthFindingId/v1":"cdf843dd6b0cb0e44cad2c2f076b5e61f3a2cc8d930955e5b9add1cd68a5bff0"}},{"ruleId":"D1","level":"warning","message":{"text":"Path.tracePathOfEntry (cyclomatic 42): Path.tracePathOfEntry has cyclomatic complexity 42 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ElectronApi.Json.Parser/Types.fs"},"region":{"startLine":754}}}],"partialFingerprints":{"codehealthFindingId/v1":"dac604d66caf1595110c37ad6fe8a9b1db25ea5b18a48622c5ede4e58ae608a8"}},{"ruleId":"D1","level":"warning","message":{"text":"TypeModule.readInfoString (cyclomatic 32): TypeModule.readInfoString has cyclomatic complexity 32 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ElectronApi.Json.Parser/Prelude.fs"},"region":{"startLine":530}}}],"partialFingerprints":{"codehealthFindingId/v1":"1525ec3616fc259b5bfa36408864e0ac2066da76ebc352ef9d772d9f5d532c95"}},{"ruleId":"D1","level":"warning","message":{"text":"EventInterfaces.makeInterfaces (cyclomatic 20): EventInterfaces.makeInterfaces has cyclomatic complexity 20 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ElectronApi.Json.Parser/SourceMapper.fs"},"region":{"startLine":408}}}],"partialFingerprints":{"codehealthFindingId/v1":"05ed7143ed44142c7ea647a9ef7ee6cd5a60123db3d4fa5b55aa3c930da73581"}},{"ruleId":"D1","level":"warning","message":{"text":"Build.main (cyclomatic 17): Build.main has cyclomatic complexity 17 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ci/Build.fs"},"region":{"startLine":492}}}],"partialFingerprints":{"codehealthFindingId/v1":"6c3acae840ab28a72227e4a73938dd17f80bbc22f211f689e1f09cbac429750e"}},{"ruleId":"D2","level":"warning","message":{"text":"EventInterfaces.makeInterfaces (cognitive 21): EventInterfaces.makeInterfaces has cognitive complexity 21 (threshold 15). Drivers by points: match/switch 10 (15 pts), if/else 4 (6 pts) (nesting depth added 7). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident. This file is where this pass\u0027s cognitive complexity CONCENTRATES: src/ElectronApi.Json.Parser/SourceMapper.fs holds 2 of the 4 methods over the threshold \u2014 including the worst \u2014 and 11 of the 15 points over it (73%), 3.7\u00D7 the next-largest file (ci/Build.fs at 3). No single row can show this, because each is measured only against the threshold: reducing this one file moves this dimension further than any other file in the repository."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ElectronApi.Json.Parser/SourceMapper.fs"},"region":{"startLine":408}}}],"partialFingerprints":{"codehealthFindingId/v1":"3faaf5fd63e897dd86abb718f649ca0a8fe533e5518e2c3a19fc0f8d4de6dd6d"}},{"ruleId":"D2","level":"warning","message":{"text":"GeneratorContainerModule.makePropertyMemberDefn (cognitive 20): GeneratorContainerModule.makePropertyMemberDefn has cognitive complexity 20 (threshold 15). Drivers by points: if/else 11 (17 pts), match/switch 2, boolean chains 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body. This file is where this pass\u0027s cognitive complexity CONCENTRATES: src/ElectronApi.Json.Parser/SourceMapper.fs holds 2 of the 4 methods over the threshold \u2014 including the worst \u2014 and 11 of the 15 points over it (73%), 3.7\u00D7 the next-largest file (ci/Build.fs at 3). No single row can show this, because each is measured only against the threshold: reducing this one file moves this dimension further than any other file in the repository."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ElectronApi.Json.Parser/SourceMapper.fs"},"region":{"startLine":880}}}],"partialFingerprints":{"codehealthFindingId/v1":"b79dd913926749818d37f767907e80658b75df2525dbcfb5451fee2a0506de39"}},{"ruleId":"D2","level":"warning","message":{"text":"Build.main (cognitive 18): Build.main has cognitive complexity 18 (threshold 15). Drivers by points: if/else 8 (13 pts), match/switch 2 (5 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ci/Build.fs"},"region":{"startLine":492}}}],"partialFingerprints":{"codehealthFindingId/v1":"8fc834019269ca2651c40e21d07c731c1c037903d3524b8fed2a3889f1cdf6fe"}},{"ruleId":"D2","level":"warning","message":{"text":"Path.tracePathOfEntry (cognitive 16): Path.tracePathOfEntry has cognitive complexity 16 (threshold 15). Drivers by points: match/switch 9 (16 pts) (nesting depth added 7). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ElectronApi.Json.Parser/Types.fs"},"region":{"startLine":754}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b4e0661ae517866d2f9000f558fc7d70c1608f63f25399fb0dc491d05d80b54"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: Fable.Electron/Program.fs: FileTooLong \u2014 20283 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 19783 over it, 40.57\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Fable.Electron/Program.fs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"fd12ce0453a7a098cbaab0cc0f1d88caef2ca2b7ed3e362823be60ca6f1e0569"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: WebContents: TooManyMethods \u2014 288 methods. The bar is 30 methods; this is 258 over it, 9.60\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Fable.Electron/Program.fs"},"region":{"startLine":28592}}}],"partialFingerprints":{"codehealthFindingId/v1":"6e979f38f44f27a51c896aaf15c6e525985b2f304f3f3b3e47e4c498bd7f53fd"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: BrowserWindow: TooManyMethods \u2014 251 methods. The bar is 30 methods; this is 221 over it, 8.37\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Fable.Electron/Program.fs"},"region":{"startLine":41851}}}],"partialFingerprints":{"codehealthFindingId/v1":"0d484450b837f47479007e71a30a6c47178e0582e6550fd52eed8cb892589b3b"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: BaseWindow: TooManyMethods \u2014 218 methods. The bar is 30 methods; this is 188 over it, 7.27\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Fable.Electron/Program.fs"},"region":{"startLine":44827}}}],"partialFingerprints":{"codehealthFindingId/v1":"68cba0b3056def741cfbf1cca64f0eb07406e3dbf786ceecb9ceddce472a3684"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: WebviewTag: TooManyMethods \u2014 171 methods. The bar is 30 methods; this is 141 over it, 5.70\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Fable.Electron/Program.fs"},"region":{"startLine":9760}}}],"partialFingerprints":{"codehealthFindingId/v1":"be389a7987d8a5fe2da6f645bf0c50a308bf10863c0a0b09e924b1ae0388d1d0"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: app: TooManyMethods \u2014 164 methods. The bar is 30 methods; this is 134 over it, 5.47\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Fable.Electron/Program.fs"},"region":{"startLine":47649}}}],"partialFingerprints":{"codehealthFindingId/v1":"cbdd1a85efdbfb762f1d2da198fbf260997771f27ea9d48103abbd3a016f87a7"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Session: TooManyMethods \u2014 123 methods. The bar is 30 methods; this is 93 over it, 4.10\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Fable.Electron/Program.fs"},"region":{"startLine":34566}}}],"partialFingerprints":{"codehealthFindingId/v1":"e32f55ca59e510f5512d00cf3cde50e9af2daa001b72b5b91ebbb0c79b849bbf"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: ElectronApi.Json.Parser/SourceMapper.fs: FileTooLong \u2014 1609 significant lines (blank, comment-only and punctuation-only lines excluded), declaring 89 functions. The bar is 500 significant lines; this is 1109 over it, 3.22\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ElectronApi.Json.Parser/SourceMapper.fs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e3a08714972d373ae1ca9f8118c7e3841f04d23108e967c2e2b6c91bb2c00f79"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: ElectronApi.Json.Parser/Prelude.fs: FileTooLong \u2014 1245 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 745 over it, 2.49\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ElectronApi.Json.Parser/Prelude.fs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"af70816a71b41704ea003a1fb7f3904b6818bf48a4b182db2d554218ca9956ac"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Tray: TooManyMethods \u2014 72 methods. The bar is 30 methods; this is 42 over it, 2.40\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Fable.Electron/Program.fs"},"region":{"startLine":32389}}}],"partialFingerprints":{"codehealthFindingId/v1":"f105b46ed88e3330b0859ba65a674c0b9cbd24b5752ea27cfba207bb06297854"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: ElectronApi.Json.Parser/Types.fs: FileTooLong \u2014 658 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 158 over it, 1.32\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ElectronApi.Json.Parser/Types.fs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"66f98a77c925e80b40f53a4c58d936cdeb6a65022f88c09ea5a9cf0ec447a25a"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: powerMonitor: TooManyMethods \u2014 38 methods. The bar is 30 methods; this is 8 over it, 1.27\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Fable.Electron/Program.fs"},"region":{"startLine":37543}}}],"partialFingerprints":{"codehealthFindingId/v1":"5ef64da7feae03caaa355a48c3d622bf8e11ae706d73456a583f62fd55ffa1a2"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: ElectronApi.Json.Parser/Fantomas.Utils.fs: FileTooLong \u2014 618 significant lines (blank, comment-only and punctuation-only lines excluded), declaring 59 functions. The bar is 500 significant lines; this is 118 over it, 1.24\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/ElectronApi.Json.Parser/Fantomas.Utils.fs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"288e112d41199874629729885e20ba20bd58df4e089aeb0e39ea4257e5bff7b4"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: Fable.Electron/Types.fs: FileTooLong \u2014 609 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 109 over it, 1.22\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Fable.Electron/Types.fs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d17c088b876b4ba7d9f3a95085a2857664d9b6c535fa348a993587341159e715"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: systemPreferences: TooManyMethods \u2014 31 methods. The bar is 30 methods; this is 1 over it, 1.03\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Fable.Electron/Program.fs"},"region":{"startLine":13945}}}],"partialFingerprints":{"codehealthFindingId/v1":"0d4b3782e2421979c9401787f15c843fc40f497f88617b4ecb26692daa58b3de"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: systemPreferences: TooManyMethods \u2014 31 methods. The bar is 30 methods; this is 1 over it, 1.03\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Fable.Electron/Program.fs"},"region":{"startLine":33921}}}],"partialFingerprints":{"codehealthFindingId/v1":"6eb932bde0cb34a78004a28e0d1a468b4617cc361bf5e6e605977e1b1fa93215"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: DownloadItem: TooManyMethods \u2014 31 methods. The bar is 30 methods; this is 1 over it, 1.03\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Fable.Electron/Program.fs"},"region":{"startLine":40222}}}],"partialFingerprints":{"codehealthFindingId/v1":"ddf7a3bc2c7acee614b293f75763e2e6cfa02c960aef04e580e688329cba2913"}},{"ruleId":"D8","level":"warning","message":{"text":"Coverage not measured \u2014 .NET and JavaScript/TypeScript suite: Coverage NOT MEASURED: the .NET half could not be measured \u2014 the repository wires up no coverage collector for \u0060--collect:\u0022XPlat Code Coverage\u0022\u0060 to use; the JavaScript/TypeScript half could not be measured \u2014 tests/Fable.Electron.Remoting.Tests/ runs vitest but declares no coverage provider, so the suite can run and still produce no lcov \u2014 add \u0060@vitest/coverage-v8\u0060 (or \u0060@vitest/coverage-istanbul\u0060) as a devDependency. This repository\u0027s production source spans both ecosystems, and no partial figure is published as if it were the whole: coverage is excluded from the score rather than counted as a near-zero. The named suite step is one the repository\u0027s maintainers can perform; once it passes, the real number is measured on the next scan. Alternatively, commit the lcov/Cobertura report your CI produces and it is read without a re-run."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"62e63e619c28f057e129f2997c965d32a457366a9ce18ca019ffb6bdfba85c99"}},{"ruleId":"D11","level":"error","message":{"text":"Test suite cannot be installed from its own lockfile: tests/Fable.Electron.Remoting.Tests/: The vitest suite in tests/Fable.Electron.Remoting.Tests/ was never exercised because its dependency install refused the committed lockfile \u2014 the dependency install for tests/Fable.Electron.Remoting.Tests/ refused the committed lockfile (npm error code EUSAGE), so the suite never ran. The suite is declared and committed but cannot be installed from what the repository ships, so neither this scan nor a new contributor can run it. The ask is the one the owner performs: run the install locally and commit the lockfile it writes."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6def27d587454cd43724c317400ea63ef53be0259bf3d0a2302284776850cdeb"}},{"ruleId":"D11","level":"warning","message":{"text":"Test reliability not measured \u2014 JavaScript/TypeScript suite install refused the lockfile: Test reliability NOT MEASURED: this repository\u0027s test suite spans .NET and JavaScript/TypeScript, and the JavaScript/TypeScript half could not be re-run \u2014 unit: measured (0 flaky); other: measured (0 flaky); JavaScript/TypeScript (vitest via \u0060npm ci --ignore-scripts\u0060 in tests/Fable.Electron.Remoting.Tests/): not included \u2014 the dependency install for tests/Fable.Electron.Remoting.Tests/ refused the committed lockfile (npm error code EUSAGE), so the suite never ran. No partial figure is published as if it were the whole: reliability is excluded from the score rather than counted as a near-zero."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"166e5a7f1e7f7840934bd0f1c14ddd658b4d7aa7c7571340b9874ca6caf351a2"}},{"ruleId":"D12","level":"warning","message":{"text":"Prerelease dependency: Fable.Core: Fable.Core resolves to 5.0.0-beta.1, a prerelease build. Prerelease packages carry no support policy, may change breaking between previews and can be unlisted \u2014 pin a stable release before shipping, or record the reason this preview is required."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"19edfa144f0784289fdd7aabce70c1d9748f95e5c5a50ddfafb1922636381c24"}},{"ruleId":"D14","level":"error","message":{"text":"Banned license: Partas.GitNet: \u0060Partas.GitNet\u0060 3.0.0 resolves to SPDX id GPL-3.0-or-later, and this run\u0027s banned set is AGPL-3.0, GPL-2.0, GPL-3.0, LGPL-3.0. The match is a SUBSTRING of the id, not an exact comparison \u2014 which is how variants like \u0060-only\u0060 and \u0060-or-later\u0060 are caught, and it is the rule to apply if you re-check this by hand. The set is policy, not law: it is configurable, so a licence banned here may be acceptable in your context, and the row is then something to record an exception for rather than to fix. \u2605 This arm reads the resolved package list and knows nothing about dependency SCOPE \u2014 it cannot tell a runtime dependency from a build- or test-only one, so unlike the Bundler arm it is NOT claiming this ships to your users. Check where it sits before acting. \u2605 DEPTH: this repository\u0027s MSBuild projects declare 27 direct \u0060PackageReference\u0060(s), and 179 further package(s) were reached beyond them by closing the graph over nuget.org\u0027s own nuspec dependency graph \u2014 so a banned licence pulled in only by a dependency\u0027s OWN dependencies is inside this verdict. A package whose licence nuget.org could not be asked for is not graded, and version ranges are taken at their lower bound, so this is the closure as that graph states it rather than a restored consumer\u0027s exact resolution."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ddccadceac7e1828402748408b22d477b5ed22d5947b17a92511ef0bfd8809e3"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: ci/Build.fs: ci/Build.fs changed 3 times in last 90 days, max cyclomatic complexity 17 in Build.main at line 492. 2 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-01-26..2026-04-26, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-01-26 12:01:32 \u002B00:00\u0027 --until=\u00272026-04-26 12:01:32 \u002B00:00\u0027 --full-history --no-merges -- ci/Build.fs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ci/Build.fs"},"region":{"startLine":492}}}],"partialFingerprints":{"codehealthFindingId/v1":"606035ae309e179cc7a1fbac90ef832730f637e650ce1a9aabe28797d6812759"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/Fable.Electron.Remoting/Preload.fs: src/Fable.Electron.Remoting/Preload.fs changed 2 times in last 90 days, max cyclomatic complexity 15 in Remoting.buildRendererToMainProxy at line 99. 1 of those changes was a fix/bug commit, and the other 1 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-01-26..2026-04-26, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-01-26 12:01:32 \u002B00:00\u0027 --until=\u00272026-04-26 12:01:32 \u002B00:00\u0027 --full-history --no-merges -- src/Fable.Electron.Remoting/Preload.fs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Fable.Electron.Remoting/Preload.fs"},"region":{"startLine":99}}}],"partialFingerprints":{"codehealthFindingId/v1":"6e97f781e3745c538bdf1d2956d8b2bd079e927e7311a7f90f92c97f095eff77"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #1: If anonymized user #1 becomes unavailable, 7 significant file(s) lose their only recent owner: src/ElectronApi.Json.Parser/SourceMapper.fs, ci/Build.fs, src/ElectronApi.Json.Parser/Generator.fs, ci/lib/Workers.fs, src/Fable.Electron.Remoting/Main.fs, src/Fable.Electron.Remoting/Preload.fs, src/Fable.Electron.Remoting/Renderer.fs. Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"eba07f05268a3f5e3688b125f81da429205df94215d97a13d62a6eb8eedf7c13"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b41a2d21dd11a9b86c0442cb6cdd92e726e281845a58b042e1bf5dc9906836f0"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"df6ade0f85533bef4229794690a265bbcf5ec1f075f98f02c38749b3cf30155c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ade059454c8b17b5431691b9fba046db103d10e0dfd7c752640bc4595a13b5ca"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6ab88d9e173e6c9a9880c3281671adae28cb598cd4c8927786d16bcfb6b3ded0"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"72d931825a09658831155a87cfffcb38a6b70a772e9777a8e83ae8404834df19"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"905d6abef7164a6bc2648ffa89f1916f18725abea099a28391064a2061b3ff38"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3027d0d971eef7079cccbfe2a36f2ba7842e9110c42889deb0dbab4c3961f58d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"95c6e1bb41a248a01679b4da96b9cc7559d1ddb602f2a00635aae4d2605f0e4a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d4c7b9071e03e30df3120652403b5d2a463bd1627ada1fa13dacf399c8d2cb46"},"taxa":[{"id":"CWE-214","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-532","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fbe1d25949ce73d4e339de92742da115218ad9b45c09eb14125a2ae815fc2c4a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"85e79f34cd65074cd657eda98e139565bb3bcfbbfff50687d9115e0f6da26ea7"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"056f708015c0ae6a4e5c18abac02b1be8c1b6c885f71376d1927c50f47796d55"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b6fea606afe810aa07ea9498223f02f9ab4e7db4f5d23119a85d0a44c23b4408"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c9d86bd231d9c7b1e9e55bc3ff10aebb2779736ec17b7ecf90c7a70ef8818bd6"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fa5156d382a0720d6ccac5ac3c70e789ed32168f26a65a9ca893bbfa643f6dc0"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d9041f3208c5a6a3514ce1ceea834becc49d7fbb296c566d224b5ee858df39c8"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"44d910379dbae624e470f50dd1f2d9c4f2b5de876825cf078966d7eb4ad0d4e1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1a62258c368324ca0d6c7c926ae07fa4049ba3f92e0077564f6c1d1581f3129e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2d2b60a9a58dd9063a045f6aedb3743699a80df3a036e5cc605cbfc6e262db78"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a9f13d9a6b1c4fdcd4a7496477a77ff82ad366cb6d10e1084f0ebffb3022843d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fe6267f5bb209529a955272b4302834fa3f56765c4a8275df255ff941a14198a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9fe162d614817686d368d5101241681e09f06c8a2468c09153dd6ddd725c8e8b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3920faea2a9b8f18d6e2df77f4830901eade34b35d8a82b12fd68506fb99fab4"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0be67f358c7f0a0b46183a8da652eafc1ce2cde59a1a248ee6d5ab497b5576ab"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"03b74446420b6451bdba3df17d9339fd86307b9cd2ebdf60bdf300f11eed0c29"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eaae2043b383eb43b15bd93142153e1bd389f8414b941c02b3fd7a24f3f004fb"},"taxa":[{"id":"CWE-214","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-532","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3fb58aaed37198f02458f341577b14a67fe618602a24bcb9f451beea61020fbc"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1329","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1f79a595d62add568feda19f54d04fdad0273f072ae213a4e4ad714127a8a2fe"},"properties":{"dependency":{"package":"System.Drawing.Common","version":"4.7.0","advisory":"[GHSA redacted]","reachability":{"kind":"production","file":"Build.fsproj"}}}},{"ruleId":"D30","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"179799009a3ded3dbd12f81b973f639221dbccd561818be8e9e8a00cfb1cddc0"},"properties":{"dependency":{"package":"NuGet.Packaging","version":"6.12.4","advisory":"[GHSA redacted]","reachability":{"kind":"production","file":"Build.fsproj"}}}},{"ruleId":"D30","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8311b17f90be2139d4d23c99da91aeac24530a01d9415c9b53c9cf43e505d883"},"properties":{"dependency":{"package":"NuGet.Protocol","version":"6.12.4","advisory":"[GHSA redacted]","reachability":{"kind":"production","file":"Build.fsproj"}}}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1b213f6eedd4b140d0bc37bdf1496f72811a643f34064f12518b32e9e83bcfc7"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e17f71490e4d120a48b2b2881ab866c93b272bef2febb673a3e8e42b2c288ab"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eb00976a698a5d68999b7ee6d27206fd374e916853e7ff1ead5eed42386f043f"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"90f83b4fa27db32740afe9540c905f3c0499caed87f61049a8a903ecc95b41c3"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0752d0df7434000fcabf1048e2de30a7a1a8b982b3db9a19898c4dec199856b4"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fe274ba5adebde25ca0b3db842e44cbb1aaeb7cfecfbb7215cd452596ba1f4c2"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d657599f6f99da1927d3377533dfc0888b34c4d84aa7d5579841fd72d0e39bce"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ace515990e7ee0f17b5c17e44dd168a5bdecf90804a3a3dd845cf05540978013"}},{"ruleId":"D44","level":"warning","message":{"text":"End-of-life runtime: .NET net9.0: Build.fsproj declares .NET net9.0 as this project\u0027s target framework, and .NET 9 STS, support ended 2026-05-12. An unsupported runtime receives no security patches, so every vulnerability disclosed in it since 2026-05-12 is present and unfixable without moving off it. This is a migration rather than an upgrade: there is no newer release of a runtime that has ended."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"cf833dd2e60d7abeaab60bf3ef76eff2806e8ec26408f1f9382eb19e6e5923da"}},{"ruleId":"M1","level":"note","message":{"text":"Thin README: The root README is 115 words, against a bar of 120. Of the three newcomer-critical sections this check looks for by heading, it found no a build/run or getting-started section, no a testing section, no an architecture or project-map section. Sections are matched on HEADING text only, so material written under a heading this check does not recognise \u2014 or with no heading at all \u2014 is not seen and this row may understate what the document covers."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5fc8f78bec0b6b3daab9d9139ba49b687f61b54f8310b64c159df9616f47e38e"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"P3","level":"note","message":{"text":"No SAST: No static application security testing detected. For this repository\u0027s stack, add \u0060semgrep --config=auto\u0060 plus gitleaks for committed secrets (F# is not a CodeQL language and has no language-specific SAST engine) as a CI step. What was searched, so you can tell an absence from a miss: the 10580 CI workflow file(s) in this repository, and the scanner and linter configuration checked in beside them. A scan that runs outside CI, one configured in your forge\u0027s web UI rather than in a committed file, or a tool whose name is none of those this check carries, is not seen \u2014 if that is your case the row is wrong, and saying so is more useful than adding a second scanner."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6e54424179c892f03ef2fd003130ac4bd43f39bbf3b1ca0a0143e25acb80ec87"}},{"ruleId":"SC1","level":"warning","message":{"text":"NuGet dependencies are not locked: No packages.lock.json and no central package management \u2014 restores aren\u0027t reproducible or pinned (SSDF PW.4.4). Enable \u003CRestorePackagesWithLockFile\u003Etrue\u003C/RestorePackagesWithLockFile\u003E (commit the lockfile) or adopt Directory.Packages.props. Advisory \u2014 never scored."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0a97b4f69ccac509400ece7eedefb06d3ede0522cd4d8bcb5c068bea719545a6"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1104","guid":"4c918cb5-b2a6-6c55-9963-a44ee464305e","name":"CWE-1104","shortDescription":{"text":"CWE-1104"},"helpUri":"https://cwe.mitre.org/data/definitions/1104.html"},{"id":"CWE-1329","guid":"f70f1c3f-4ccf-cb5e-bdd3-03ba4868d36d","name":"CWE-1329","shortDescription":{"text":"CWE-1329"},"helpUri":"https://cwe.mitre.org/data/definitions/1329.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-214","guid":"b10ad120-fb22-1351-9348-aa23b453e815","name":"CWE-214","shortDescription":{"text":"CWE-214"},"helpUri":"https://cwe.mitre.org/data/definitions/214.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-532","guid":"1cd8877a-76e8-ce54-b40b-779af23364a0","name":"CWE-532","shortDescription":{"text":"CWE-532"},"helpUri":"https://cwe.mitre.org/data/definitions/532.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":38,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}