{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D22","name":"Internal API Consistency","shortDescription":{"text":"Internal API Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D22"},{"id":"D23","name":"Boundary Type-Coupling","shortDescription":{"text":"Boundary Type-Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D23"},{"id":"D24","name":"Comment Value","shortDescription":{"text":"Comment Value"},"helpUri":"https://codehealth.canine.dev/dimensions/D24"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D39","name":"IL Efficiency","shortDescription":{"text":"IL Efficiency"},"helpUri":"https://codehealth.canine.dev/dimensions/D39"},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AX1","name":"Captive dependencies","shortDescription":{"text":"Captive dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/AX1"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX2","name":"Stateful singletons","shortDescription":{"text":"Stateful singletons"},"helpUri":"https://codehealth.canine.dev/dimensions/AX2"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AX5","name":"Architecture \u0026 structure","shortDescription":{"text":"Architecture \u0026 structure"},"helpUri":"https://codehealth.canine.dev/dimensions/AX5"},{"id":"AX6","name":"Interface segregation","shortDescription":{"text":"Interface segregation"},"helpUri":"https://codehealth.canine.dev/dimensions/AX6"},{"id":"AX9","name":"CQS / query purity","shortDescription":{"text":"CQS / query purity"},"helpUri":"https://codehealth.canine.dev/dimensions/AX9"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"C1","name":"Data Protection","shortDescription":{"text":"Data Protection"},"helpUri":"https://codehealth.canine.dev/dimensions/C1"},{"id":"C2","name":"Access Controls","shortDescription":{"text":"Access Controls"},"helpUri":"https://codehealth.canine.dev/dimensions/C2"},{"id":"C4","name":"Data Retention","shortDescription":{"text":"Data Retention"},"helpUri":"https://codehealth.canine.dev/dimensions/C4"},{"id":"ED2","name":"Event/command shape","shortDescription":{"text":"Event/command shape"},"helpUri":"https://codehealth.canine.dev/dimensions/ED2"},{"id":"ED3","name":"Event naming","shortDescription":{"text":"Event naming"},"helpUri":"https://codehealth.canine.dev/dimensions/ED3"},{"id":"ED4","name":"Outbox / dual-write","shortDescription":{"text":"Outbox / dual-write"},"helpUri":"https://codehealth.canine.dev/dimensions/ED4"},{"id":"ED5","name":"Idempotency","shortDescription":{"text":"Idempotency"},"helpUri":"https://codehealth.canine.dev/dimensions/ED5"},{"id":"GD1","name":"Unfinished \u0026 placeholder code","shortDescription":{"text":"Unfinished \u0026 placeholder code"},"helpUri":"https://codehealth.canine.dev/dimensions/GD1"},{"id":"IC1","name":"Incompleteness \u0026 stubs","shortDescription":{"text":"Incompleteness \u0026 stubs"},"helpUri":"https://codehealth.canine.dev/dimensions/IC1"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P2","name":"Observability","shortDescription":{"text":"Observability"},"helpUri":"https://codehealth.canine.dev/dimensions/P2"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P5","name":"DR \u0026 Backup","shortDescription":{"text":"DR \u0026 Backup"},"helpUri":"https://codehealth.canine.dev/dimensions/P5"},{"id":"S1","name":"Web-Security Posture","shortDescription":{"text":"Web-Security Posture"},"helpUri":"https://codehealth.canine.dev/dimensions/S1"},{"id":"SC1","name":"Supply-chain hygiene","shortDescription":{"text":"Supply-chain hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/SC1"},{"id":"X1","name":"Async correctness","shortDescription":{"text":"Async correctness"},"helpUri":"https://codehealth.canine.dev/dimensions/X1"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X12","name":"Unreachable branch","shortDescription":{"text":"Unreachable branch"},"helpUri":"https://codehealth.canine.dev/dimensions/X12"},{"id":"X13","name":"Undrained process stream","shortDescription":{"text":"Undrained process stream"},"helpUri":"https://codehealth.canine.dev/dimensions/X13"},{"id":"X14","name":"Bypassable address classification","shortDescription":{"text":"Bypassable address classification"},"helpUri":"https://codehealth.canine.dev/dimensions/X14"},{"id":"X15","name":"Unvalidated length from an untrusted reader","shortDescription":{"text":"Unvalidated length from an untrusted reader"},"helpUri":"https://codehealth.canine.dev/dimensions/X15"},{"id":"X16","name":"Unfloored truncation loop","shortDescription":{"text":"Unfloored truncation loop"},"helpUri":"https://codehealth.canine.dev/dimensions/X16"},{"id":"X17","name":"Uncapped recursion over a caller-supplied document","shortDescription":{"text":"Uncapped recursion over a caller-supplied document"},"helpUri":"https://codehealth.canine.dev/dimensions/X17"},{"id":"X18","name":"Disposal-pattern correctness","shortDescription":{"text":"Disposal-pattern correctness"},"helpUri":"https://codehealth.canine.dev/dimensions/X18"},{"id":"X19","name":"Unrestored process-global state","shortDescription":{"text":"Unrestored process-global state"},"helpUri":"https://codehealth.canine.dev/dimensions/X19"},{"id":"X2","name":"Cancellation propagation","shortDescription":{"text":"Cancellation propagation"},"helpUri":"https://codehealth.canine.dev/dimensions/X2"},{"id":"X20","name":"Mistyped argument guard","shortDescription":{"text":"Mistyped argument guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X20"},{"id":"X21","name":"Side-effecting pattern guard","shortDescription":{"text":"Side-effecting pattern guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X21"},{"id":"X22","name":"Contradicted release guard","shortDescription":{"text":"Contradicted release guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X22"},{"id":"X23","name":"Unguarded diagnostic materialisation","shortDescription":{"text":"Unguarded diagnostic materialisation"},"helpUri":"https://codehealth.canine.dev/dimensions/X23"},{"id":"X24","name":"Document value interpolated into markup unescaped","shortDescription":{"text":"Document value interpolated into markup unescaped"},"helpUri":"https://codehealth.canine.dev/dimensions/X24"},{"id":"X25","name":"Inert configuration knob","shortDescription":{"text":"Inert configuration knob"},"helpUri":"https://codehealth.canine.dev/dimensions/X25"},{"id":"X26","name":"Unsynchronised callback handoff","shortDescription":{"text":"Unsynchronised callback handoff"},"helpUri":"https://codehealth.canine.dev/dimensions/X26"},{"id":"X27","name":"Collection changed while being enumerated","shortDescription":{"text":"Collection changed while being enumerated"},"helpUri":"https://codehealth.canine.dev/dimensions/X27"},{"id":"X28","name":"Index access outside its own emptiness guard","shortDescription":{"text":"Index access outside its own emptiness guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X28"},{"id":"X29","name":"Per-element action decided by a fixed element","shortDescription":{"text":"Per-element action decided by a fixed element"},"helpUri":"https://codehealth.canine.dev/dimensions/X29"},{"id":"X3","name":"Exception handling","shortDescription":{"text":"Exception handling"},"helpUri":"https://codehealth.canine.dev/dimensions/X3"},{"id":"X30","name":"Support guard that admits what it rejects","shortDescription":{"text":"Support guard that admits what it rejects"},"helpUri":"https://codehealth.canine.dev/dimensions/X30"},{"id":"X32","name":"Type resolved by simple name across every loaded assembly","shortDescription":{"text":"Type resolved by simple name across every loaded assembly"},"helpUri":"https://codehealth.canine.dev/dimensions/X32"},{"id":"X4","name":"Structured logging","shortDescription":{"text":"Structured logging"},"helpUri":"https://codehealth.canine.dev/dimensions/X4"},{"id":"X5","name":"Nullable reference types","shortDescription":{"text":"Nullable reference types"},"helpUri":"https://codehealth.canine.dev/dimensions/X5"},{"id":"X6","name":"Hand-rolled structured-format parsing","shortDescription":{"text":"Hand-rolled structured-format parsing"},"helpUri":"https://codehealth.canine.dev/dimensions/X6"},{"id":"X7","name":"Silent fallback defaults","shortDescription":{"text":"Silent fallback defaults"},"helpUri":"https://codehealth.canine.dev/dimensions/X7"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 3): BankApplication.Domain/Aggregates/AccountAggregate.cs:8-24 | BankApplication.Domain/Aggregates/TransferAggregate.cs:8-24 | BankApplication.Domain/Entities/Transaction.cs:10-26 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 3 call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made 3 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Domain/Aggregates/AccountAggregate.cs"},"region":{"startLine":8}}}],"partialFingerprints":{"codehealthFindingId/v1":"c020ef4a4529147d287303bb1af0458eb394cfaf3d13dd76a9d2eaedb70cc698"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: BankApplication.Domain: BankApplication.Domain: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and depended on by 3 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"44bfd6f7a1284c60b25d743e0eed8dc615673f10ca4b7ae08754714408cb189d"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: BankApplication.Contracts: BankApplication.Contracts: abstractness 0.00, instability 0.00, distance 1.00 \u2014 the shape a shared-kernel / building-block library has BY DESIGN \u2014 concrete and widely depended-on is what makes it useful, and this dimension does not penalise it (the distance is reported for completeness, not as a defect). Worth a look only if it has grown past one coherent kernel into an everything-bucket."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9dd7b0ce7827a9fcd25afdee89a46d66b8b45c03c6c523d8e2ee08db634e3b10"}},{"ruleId":"D8","level":"error","message":{"text":"No automated tests: No automated tests \u2014 no test code was found in this repository. Untested code is the largest single risk to changing it safely. Start with the code you change most often: add a suite in a framework a runner can collect (xUnit, NUnit or MSTest), and run it in CI so the gap cannot reopen."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3132564c6310e5d01a231f252a02d5d2f5a542c0a8fa29a14c89693f1e3df871"}},{"ruleId":"D9","level":"note","message":{"text":"No tests found: No test suite could be collected \u2014 no discoverable tests to count. If this repository does test, wiring the suite to a framework a runner can collect (xUnit, NUnit or MSTest) is what makes it countable here; a pipeline step that invokes a runner is not evidence on its own, because a runner over an empty suite passes. Tests written as plain executables or shell/PowerShell harnesses are not collectible this way and are not scored here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c9bf64cbb5a4ae13d6bcd01fa3bc8d2879d860c73bc67f176ee3c2cecb8adce3"}},{"ruleId":"D12","level":"error","message":{"text":"Vulnerable: System.Data.SqlClient: System.Data.SqlClient 4.8.5 \u2014 High severity. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"60c18bdfb9bcb0c9e6645ce9a6a2dbec1c036f361f6e3e38e9fa51fbdebad14f"}},{"ruleId":"D12","level":"error","message":{"text":"Vulnerable: System.IdentityModel.Tokens.Jwt: System.IdentityModel.Tokens.Jwt 6.25.1 \u2014 Moderate severity. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b1aa57ff1b6d7e72651ec0fc7a5d3c72a563804fe76ce2b0617eefc6a133ac5e"}},{"ruleId":"D12","level":"error","message":{"text":"Vulnerable: Azure.Identity: Azure.Identity 1.9.0 \u2014 Moderate severity. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4b82a82ead2038444235c5c303e0864f14bd669ef3d03d66c536e0cc097bb0ce"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.Extensions.Configuration.UserSecrets: Microsoft.Extensions.Configuration.UserSecrets 5.0.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"57d28f605d8088f401dafb3693c00f01f94d64c60c4000af41a949738fdf3238"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: System.IdentityModel.Tokens.Jwt: System.IdentityModel.Tokens.Jwt 6.25.1 \u2014 Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5e25a2addd53321a5f56d70917c9cacbd45ad10a65768c7f7d77713591bd3d37"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Azure.Identity: Azure.Identity 1.9.0 \u2014 Other"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"2c48b8b518e33f322169a01b4e304c093ae4e143a4f32e23f92274ffeccb9051"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no installation or build instructions: The \u0027How to run the project\u0027 section gives Docker and native build instructions but no setup steps (e.g. SQL Server credentials, .env configuration) needed to run the web API. Add a minimal setup note for environment variables (.env) required by the JWT authentication flow."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1fa6bfcd5c6ae231d1b8ee99bced50b832d1f61cde9da6cbb533467b879a57db"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no usage examples: The README describes how to build/run the project but provides no runnable usage examples (e.g. POST /Accounts/Create, GET /Transfers/Get). Add a short \u0027How to call the API\u0027 example showing one or two endpoints with curl/json requests."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1355eb4e127a4bc9236772ce1c46f09510aa9286e7a06d1e47f308229df19049"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found. No recognised ADR directory (\u0060docs/adr/\u0060, \u0060docs/decisions/\u0060, \u0060adr/\u0060, \u0060docs/rfcs/\u0060, an \u0060ADR0001/\u0060 folder, or their siblings) exists anywhere in this tree. What was searched, so you can tell an empty log from a search that missed one: every directory under the tree (build output, dependencies and VCS metadata excepted), for a document that is either any non-index page inside a recognised ADR directory, whatever its name and however deeply nested (\u0060docs/adr/use-postgres.md\u0060, \u0060docs/adr/2024/0001-x.md\u0060); or a file anywhere whose name is ADR-shaped (\u00600001-use-postgres.md\u0060, \u0060adr-012-caching.md\u0060); or, when neither turned anything up, a document carrying the decision-record signature (an \u0022Architecture Decision Record\u0022 heading, or Status / Context / Decision / Consequences as section headings). A decision log that clears none of these \u2014 unnumbered files outside any recognised directory, without those headings \u2014 is not seen by this check and this row is then wrong. If that is your case, say so rather than renaming anything; otherwise, consider recording architectural decisions in \u0060docs/adr/\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D21","level":"note","message":{"text":"The word \u0027Administrator\u0027 is consistently misspelled as \u0027Adminstrator\u0027 across namespaces, types, controllers, and repositories. While this is a consistent typo, it represents a deviation from standard English spelling conventions for the concept of an administrator.: Rename \u0027Adminstrator\u0027 to \u0027Administrator\u0027 across all affected symbols to correct the spelling error. (symbols: Namespace: BankApplication.Application.Adminstrator, Type: public BankApplication.Contracts.Adminstrator.CustomerAccount, Type: public BankApplication.Contracts.Adminstrator.AddAccountCreditRequest, Type: public BankApplication.Api.Mapping.AddAccountCreditMappingConfig, Method: public BankApplication.Api.Controllers.AdminstratorController.AddAccountCredit(...), Type: public BankApplication.Infrastructure.Presistence.AdminstratorRepository, Parameter: BankApplication.Application.Adminstrator.AddAccountCreditResponse dest, Type: public BankApplication.Application.Adminstrator.Response.Commands)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"2412bcaeff4c63b35efe4b8deb6b504213365823e02c485117d3c28c3815ae86"}},{"ruleId":"D21","level":"note","message":{"text":"The namespace and class name \u0027Presistence\u0027 is a misspelling of \u0027Persistence\u0027. This typo appears in the namespace, multiple repository types, and the dependency injection method name.: Rename \u0027Presistence\u0027 to \u0027Persistence\u0027 in the namespace and all associated types/methods. (symbols: Method: public BankApplication.Infrastructure.Presistence.UserRepository.Add(...), Method: public BankApplication.Application.Common.Interfaces.Persistence.IUserRepository.Add(...), Type: public BankApplication.Infrastructure.Presistence.UserRepository, Type: public BankApplication.Infrastructure.Presistence.IDispositionRepository, Type: public BankApplication.Infrastructure.Presistence.TransactionsRepository, Type: public BankApplication.Infrastructure.Presistence.DispositionRepository, Type: public BankApplication.Infrastructure.Presistence.AccountsRepository, Type: public BankApplication.Infrastructure.Presistence.DapperSettings, Method: public BankApplication.Infrastructure.DependencyInjection.AddPersistence(...), Type: public BankApplication.Infrastructure.Presistence.AdminstratorRepository)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"49e2437d637ce11456604f888cd6d4d750c6ed3a72c81e035ff99a5e66f9ada8"}},{"ruleId":"D21","level":"note","message":{"text":"The property/parameter name \u0027Telephonenumber\u0027 (and \u0027Telephonecountrycode\u0027) uses a concatenated camelCase style that is inconsistent with standard PascalCase naming for properties and often clearer as \u0027PhoneNumber\u0027 or \u0027TelephoneNumber\u0027. More critically, \u0027Telephonenumber\u0027 is a non-standard spelling of \u0027PhoneNumber\u0027 or \u0027Telephone Number\u0027.: Rename \u0027Telephonenumber\u0027 to \u0027PhoneNumber\u0027 and \u0027Telephonecountrycode\u0027 to \u0027TelephoneCountryCode\u0027 for consistency with standard naming conventions. (symbols: Parameter: string? Telephonenumber, Property: public Domain.Models.Customer.Telephonenumber, Property: public Domain.Models.Customer.Telephonecountrycode)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"787bc09fbc53d10a5c4477ab586c5e107632293581711263c2714845347f8800"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent casing in Domain Models: \u0027Givenname\u0027 is camelCase, while \u0027Surname\u0027, \u0027City\u0027, \u0027Birthday\u0027, \u0027Country\u0027, \u0027CountryCode\u0027 are PascalCase. This inconsistency within the same model namespace suggests a lack of standardization.: Rename \u0027Givenname\u0027 to \u0027GivenName\u0027 to match the PascalCase convention used by other properties in the same model. (symbols: Property: public Domain.Models.Customer.Givenname, Property: public Domain.Models.Customer.Surname, Property: public Domain.Models.Customer.City, Property: public Domain.Models.Customer.Birthday, Property: public Domain.Models.Customer.Country, Property: public Domain.Models.Customer.CountryCode, Property: public Domain.Models.Customer.Telephonenumber, Property: public Domain.Models.Customer.Telephonecountrycode, Property: public Domain.Models.Customer.Emailaddress)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"efa365e5de868841c90588ae189807ba420f4211a8f008d2300ab9ac5af22abc"}},{"ruleId":"D22","level":"warning","message":{"text":"Duplicate intent with inconsistent naming and signature. Both types represent the data required to create an account. The \u0027Data\u0027 suffix implies a DTO or internal representation, but the naming convention is inconsistent with other pairs (e.g., TransferRequest vs TransferRequestData). Furthermore, the inclusion of UserId in the \u0027Data\u0027 variant suggests a separation of concerns that isn\u0027t reflected in the \u0027Request\u0027 variant, leading to confusion about which type should be used by the client.: Unify into a single \u0060CreateAccountRequest\u0060 type. If UserId is required, include it in the request. If the separation is intentional (e.g., one for API contract, one for internal service), rename to \u0060CreateAccountCommand\u0060 and \u0060CreateAccountDto\u0060 to clarify the distinction, or remove the \u0027Data\u0027 suffix if it adds no semantic value. (signatures: CreateAccountRequest(int AccountTypesId, string Frequency) | CreateAccountRequestData(Guid UserId, string Frequency, int AccountTypesId))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"90e53849fbcf82e510fbd1716a00522dc50eab3e5502e4b7505d2fe243c56b1f"}},{"ruleId":"D22","level":"warning","message":{"text":"Duplicate intent with inconsistent naming and signature. Similar to the CreateAccount pair, these types represent the same query intent. The \u0027Data\u0027 variant includes UserId, while the \u0027Request\u0027 variant does not. This inconsistency in parameter inclusion and naming (\u0027Request\u0027 vs \u0027RequestData\u0027) creates ambiguity about the expected input for the operation.: Unify into a single \u0060GetAccountTransactionsRequest\u0060 type. Include UserId if it is required for authorization or filtering, or exclude it if the AccountId is sufficient. Remove the redundant \u0027Data\u0027 suffix. (signatures: GetTransactionsByAccIdResultRequest(int AccountId) | GetTransactionsByAccIdResultRequestData(Guid UserId, int AccountId))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"629272904fafd9f5760a4bae98611a65e2a7fa4fb65b9480a77259f811b422ef"}},{"ruleId":"D22","level":"warning","message":{"text":"Duplicate intent with inconsistent naming and signature. Both types represent a money transfer. The \u0027Data\u0027 variant includes UserId, while the \u0027Request\u0027 variant does not. The naming convention is inconsistent with other request types in the API (some use \u0027Request\u0027, some \u0027RequestData\u0027), and the parameter difference suggests an unclear boundary between client-facing requests and internal data transfer objects.: Unify into a single \u0060TransferRequest\u0060 type. Standardize the inclusion of UserId (either always include it for context or rely on authentication context). Remove the redundant \u0027Data\u0027 suffix to maintain consistent naming conventions across the API. (signatures: TransferRequest(int AccountId, int Operation, decimal Amount, string Account) | TransferRequestData(Guid UserId, int AccountId, int Operation, decimal Amount, string Account))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ba2e41d4b65bd2ea11e5ac6c846af4ad68e1867c5930473b178f15706e01afe5"}},{"ruleId":"D22","level":"warning","message":{"text":"Type duplication. \u0060NewCustomerAccountRequest.CustomerAccount\u0060 is a nested type within the request, while \u0060CustomerAccount\u0060 is a top-level type in the \u0060Adminstrator\u0060 namespace. They have identical signatures and likely represent the same entity. This creates confusion about whether the client should use the nested type or the top-level type.: Remove the nested \u0060CustomerAccount\u0060 type from \u0060NewCustomerAccountRequest\u0060 and reference the top-level \u0060CustomerAccount\u0060 type instead. This reduces redundancy and clarifies the public API surface. (signatures: NewCustomerAccountRequest.CustomerAccount(int AccountTypesId, string? Frequency) | CustomerAccount.CustomerAccount(int AccountTypesId, string? Frequency))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3af0ce1ab0ef6573eae8505ad4599d2965269eb2c08ca748467197a4558c582e"}},{"ruleId":"D24","level":"note","message":{"text":"misleading comment: \u0022validate so that user doesn\u0027t exists\u0022 \u2014 correct - the if is for existence, not absence; fix the comment or delete it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Application/Authentication/Commands/Register/RegisterCommandHandler.cs"},"region":{"startLine":24}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c3efe6bd40b374f64dafe4f7aa83fdf7ad2030b7c93bef60aa2f7f1e4ef285b"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b9413ce332628012133fd6e57c1acce3644aedc7dd6eb1a70109028a1753f875"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"482bf2b6d1511893cd08f84416e01f98e341bf57298169215ae8cd1523425cca"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a489534d9b24b1cf36acd5738d19eeb8699efcf0e8930d45c6b46f1e035c8dd7"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4e755975ee1df4fee20a383393d40dab8c4c592be1a36239a391b3b4e9df84e6"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e462fef9aabfaf16192972b3a92d63269bb117e199b266a6bab6beff8f5de4ab"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"03b31df8570933308505a1624e4fd5ee0390537c65b94f5898a4ad85f2c0b177"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7cf85abffe732f2645ef95a624d6badc26f0263616284d6a4cc46ca8e983031d"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"03f9fac878dcbf07aca7022f18e373fffff3a6521448932b27c09f1f7c846066"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b96b7173c4377d5bea4d6fd7b52323631c631c44172b743bec6f266c10a4e538"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9cb7174f671a31deccb7bf333ea533fe87178670fefd58841930464e623c1bef"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dc5a2f6465256a13d0e7c858ef5de1d74768b69ca9af3e6965257a57fe9502dc"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"047f5e326fad066b88e65fc10595315c450fdeb8286beedbe2ed4c335381cd68"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fe2d688610b51e0a5a02c7c5dd1724a4986e40f2689fb84510e2ec0164c27d6a"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e83b518b7f52f2dcaa5ae6040062bb11c1eb9b8af4b47d50866778e1f843e3bd"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ec1b042386f30e6ec10894c5e7ac948b1eec9ec65136f98beabc15d88a0e9410"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"41e7af7b96de625288980b527daf7e582c4c3eacdb660e3022f0c15f6c25479a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1f51a163f26d94ce6b6f473117dde579d091c8cbf9e59810475c94d9fc921120"}},{"ruleId":"D44","level":"warning","message":{"text":"End-of-life runtime: .NET net7.0: BankApplication.Infrastructure/BankApplication.Infrastructure.csproj declares .NET net7.0 as this project\u0027s target framework, and .NET 7, support ended 2024-05-14. An unsupported runtime receives no security patches, so every vulnerability disclosed in it since 2024-05-14 is present and unfixable without moving off it. This is a migration rather than an upgrade: there is no newer release of a runtime that has ended."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e8e3681b5cb164ca7e1efbb847d8deb5351a973ce49cbdaec3c4686bc11b832c"}},{"ruleId":"C1","level":"warning","message":{"text":"No data-protection/encryption: No data-protection or encryption usage (ASP.NET Data Protection, AES, column encryption, PBKDF2) was found \u2014 sensitive data at rest may be unprotected. If TDE/KMS/vault is delegated to infrastructure, ignore."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3674448ef29fbd006d82bb49ec9615cf1ee508105aa1d952555aabaf3e10a9f9"}},{"ruleId":"C2","level":"note","message":{"text":"No named authorization policies: Authorization IS enforced here (via [Authorize]/guards) \u2014 this is NOT a claim that endpoints are unprotected. What\u0027s missing is NAMED policies (AddAuthorization/AddPolicy, RequireRole/RequireClaim, RequireAuthorization): the access rules are implicit rather than named and testable. Recommendation, not a defect \u2014 name the rules so they\u0027re reviewable."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b048fdf3fa524ac68c7874fdfcdb4c49d5f010013f2cb22a0bd84cb12ceb951f"}},{"ruleId":"C4","level":"note","message":{"text":"Partial data-retention evidence: A retention mechanism is present, but the data-lifecycle is not yet complete \u2014 missing: a scheduled purge / cleanup job (PurgeOlderThan / CleanupJob), a documented retention period / data-expiry."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e6c843eccaff7ffcfe5241125b74768c2364055ab6678b12b10d47f44086afa4"}},{"ruleId":"ED3","level":"note","message":{"text":"Event not named in past tense: CreateAccountRequest: \u0060CreateAccountRequest\u0060 reads as an instruction, not a fact that happened. Events describe something that already occurred \u2014 name them in the past tense (e.g. \u0060OrderPlaced\u0060, \u0060PaymentCaptured\u0060) so the ubiquitous language stays clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Presentation/BankApplication.Contracts/Accounts/CreateAccount/CreateAccountRequest.cs"},"region":{"startLine":6}}}],"partialFingerprints":{"codehealthFindingId/v1":"453e2351e1606ed03537bae236591ae75d6a051ec2de4d9c04a47ec886994164"}},{"ruleId":"ED3","level":"note","message":{"text":"Event not named in past tense: CreateAccountRequestData: \u0060CreateAccountRequestData\u0060 reads as an instruction, not a fact that happened. Events describe something that already occurred \u2014 name them in the past tense (e.g. \u0060OrderPlaced\u0060, \u0060PaymentCaptured\u0060) so the ubiquitous language stays clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Presentation/BankApplication.Contracts/Accounts/CreateAccount/CreateAccountRequestData.cs"},"region":{"startLine":4}}}],"partialFingerprints":{"codehealthFindingId/v1":"8b60e8e380b8d1f5b736e589c5ada44dcbfc0956552ed60d0683dcdad4eb82c5"}},{"ruleId":"ED3","level":"note","message":{"text":"Event not named in past tense: GetTransactionsByAccIdResultRequest: \u0060GetTransactionsByAccIdResultRequest\u0060 reads as an instruction, not a fact that happened. Events describe something that already occurred \u2014 name them in the past tense (e.g. \u0060OrderPlaced\u0060, \u0060PaymentCaptured\u0060) so the ubiquitous language stays clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Presentation/BankApplication.Contracts/Accounts/GetAccount/GetTransactionsByAccIdResultRequest.cs"},"region":{"startLine":6}}}],"partialFingerprints":{"codehealthFindingId/v1":"ce58017dba22ee3325a2f205d81fe14c112e827ceb824c166729c31d9b8c98b9"}},{"ruleId":"ED3","level":"note","message":{"text":"Event not named in past tense: GetTransactionsByAccIdResultRequestData: \u0060GetTransactionsByAccIdResultRequestData\u0060 reads as an instruction, not a fact that happened. Events describe something that already occurred \u2014 name them in the past tense (e.g. \u0060OrderPlaced\u0060, \u0060PaymentCaptured\u0060) so the ubiquitous language stays clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Presentation/BankApplication.Contracts/Accounts/GetAccount/GetTransactionsByAccIdResultRequestData.cs"},"region":{"startLine":4}}}],"partialFingerprints":{"codehealthFindingId/v1":"0f4b41743152b8cf7c77cde4ea77205445290f69e70c11b64e31b469cfe198e3"}},{"ruleId":"ED3","level":"note","message":{"text":"Event not named in past tense: GetTransactionsByAccIdResultResponse: \u0060GetTransactionsByAccIdResultResponse\u0060 reads as an instruction, not a fact that happened. Events describe something that already occurred \u2014 name them in the past tense (e.g. \u0060OrderPlaced\u0060, \u0060PaymentCaptured\u0060) so the ubiquitous language stays clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Presentation/BankApplication.Contracts/Accounts/GetAccount/GetTransactionsByAccIdResultResponse.cs"},"region":{"startLine":4}}}],"partialFingerprints":{"codehealthFindingId/v1":"9c54a4dcbf76bf0717f8991f22f09f2b6cbef0e217e4f123f5d899c84f9a6a63"}},{"ruleId":"ED3","level":"note","message":{"text":"Event not named in past tense: AccountTransactionsResponse: \u0060AccountTransactionsResponse\u0060 reads as an instruction, not a fact that happened. Events describe something that already occurred \u2014 name them in the past tense (e.g. \u0060OrderPlaced\u0060, \u0060PaymentCaptured\u0060) so the ubiquitous language stays clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Presentation/BankApplication.Contracts/Accounts/GetAccount/GetTransactionsByAccIdResultResponse.cs"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"99b8136c365a2cfa5b8f1db4f8bc66827a819bf61e4a89f384be9ab486dbec0c"}},{"ruleId":"ED3","level":"note","message":{"text":"Event not named in past tense: GetAccountsRequest: \u0060GetAccountsRequest\u0060 reads as an instruction, not a fact that happened. Events describe something that already occurred \u2014 name them in the past tense (e.g. \u0060OrderPlaced\u0060, \u0060PaymentCaptured\u0060) so the ubiquitous language stays clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Presentation/BankApplication.Contracts/Accounts/GetAccounts/GetAccountsRequest.cs"},"region":{"startLine":3}}}],"partialFingerprints":{"codehealthFindingId/v1":"99b6a6a3f4fa896954f102e07e192a55cdd21da9383700a68dd0d4dbba216787"}},{"ruleId":"ED3","level":"note","message":{"text":"Event not named in past tense: AddAccountCreditRequest: \u0060AddAccountCreditRequest\u0060 reads as an instruction, not a fact that happened. Events describe something that already occurred \u2014 name them in the past tense (e.g. \u0060OrderPlaced\u0060, \u0060PaymentCaptured\u0060) so the ubiquitous language stays clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Presentation/BankApplication.Contracts/Adminstrator/AddAccountCredit/AddAccountCreditRequest.cs"},"region":{"startLine":6}}}],"partialFingerprints":{"codehealthFindingId/v1":"c1b3884a1943b840ca4c2d3f464fa176738038cff1fe8b0270f764c7a4b8e789"}},{"ruleId":"ED3","level":"note","message":{"text":"Event not named in past tense: NewCustomerAccountRequest: \u0060NewCustomerAccountRequest\u0060 reads as an instruction, not a fact that happened. Events describe something that already occurred \u2014 name them in the past tense (e.g. \u0060OrderPlaced\u0060, \u0060PaymentCaptured\u0060) so the ubiquitous language stays clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Presentation/BankApplication.Contracts/Adminstrator/NewCustomerAccount/NewCustomerAccountRequest.cs"},"region":{"startLine":6}}}],"partialFingerprints":{"codehealthFindingId/v1":"cc84cb28f195621423bd705e8a7e7a6fae631b21c867a7b14e8c69068bd48995"}},{"ruleId":"ED3","level":"note","message":{"text":"Event not named in past tense: CustomerAccount: \u0060CustomerAccount\u0060 reads as an instruction, not a fact that happened. Events describe something that already occurred \u2014 name them in the past tense (e.g. \u0060OrderPlaced\u0060, \u0060PaymentCaptured\u0060) so the ubiquitous language stays clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Presentation/BankApplication.Contracts/Adminstrator/NewCustomerAccount/NewCustomerAccountRequest.cs"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"17c0161e8df8fefa2c8561f317e49cdfd3483bb76859c00d9732a94f4b575197"}},{"ruleId":"ED3","level":"note","message":{"text":"Event not named in past tense: NewCustomerAccountResponse: \u0060NewCustomerAccountResponse\u0060 reads as an instruction, not a fact that happened. Events describe something that already occurred \u2014 name them in the past tense (e.g. \u0060OrderPlaced\u0060, \u0060PaymentCaptured\u0060) so the ubiquitous language stays clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Presentation/BankApplication.Contracts/Adminstrator/NewCustomerAccount/NewCustomerAccountResponse.cs"},"region":{"startLine":6}}}],"partialFingerprints":{"codehealthFindingId/v1":"23ac2b435fae30fd1f8a3f3ffd0e4e3225200ab6cf8bed6e9fd639a132cc33d7"}},{"ruleId":"ED3","level":"note","message":{"text":"Event not named in past tense: Customer: \u0060Customer\u0060 reads as an instruction, not a fact that happened. Events describe something that already occurred \u2014 name them in the past tense (e.g. \u0060OrderPlaced\u0060, \u0060PaymentCaptured\u0060) so the ubiquitous language stays clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Presentation/BankApplication.Contracts/Adminstrator/NewCustomerAccount/NewCustomerAccountResponse.cs"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"fb43d187bc5e411454a7ccc65afa1e15aeb059ae5a630e59682c2a1318e735b5"}},{"ruleId":"ED3","level":"note","message":{"text":"Event not named in past tense: Account: \u0060Account\u0060 reads as an instruction, not a fact that happened. Events describe something that already occurred \u2014 name them in the past tense (e.g. \u0060OrderPlaced\u0060, \u0060PaymentCaptured\u0060) so the ubiquitous language stays clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Presentation/BankApplication.Contracts/Adminstrator/NewCustomerAccount/NewCustomerAccountResponse.cs"},"region":{"startLine":25}}}],"partialFingerprints":{"codehealthFindingId/v1":"0fedf120f1111b1b87327f4ac39aae7bb7940dbb5b5b6bdacfc31f44f23ea3b7"}},{"ruleId":"ED3","level":"note","message":{"text":"Event not named in past tense: User: \u0060User\u0060 reads as an instruction, not a fact that happened. Events describe something that already occurred \u2014 name them in the past tense (e.g. \u0060OrderPlaced\u0060, \u0060PaymentCaptured\u0060) so the ubiquitous language stays clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Presentation/BankApplication.Contracts/Adminstrator/NewCustomerAccount/NewCustomerAccountResponse.cs"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"33ea95299b095f97775e5a0d4a7be7bdd3e48453537f4844de6fd13fde354b6a"}},{"ruleId":"ED3","level":"note","message":{"text":"Event not named in past tense: AuthenticationResponse: \u0060AuthenticationResponse\u0060 reads as an instruction, not a fact that happened. Events describe something that already occurred \u2014 name them in the past tense (e.g. \u0060OrderPlaced\u0060, \u0060PaymentCaptured\u0060) so the ubiquitous language stays clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Presentation/BankApplication.Contracts/Authentication/AuthenticationResponse.cs"},"region":{"startLine":4}}}],"partialFingerprints":{"codehealthFindingId/v1":"6c37ee96520043d65317f77dd5f79eb204ad49408ce3c6a7ba0d1664d054af0e"}},{"ruleId":"ED3","level":"note","message":{"text":"Event not named in past tense: LoginRequest: \u0060LoginRequest\u0060 reads as an instruction, not a fact that happened. Events describe something that already occurred \u2014 name them in the past tense (e.g. \u0060OrderPlaced\u0060, \u0060PaymentCaptured\u0060) so the ubiquitous language stays clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Presentation/BankApplication.Contracts/Authentication/LoginRequest.cs"},"region":{"startLine":4}}}],"partialFingerprints":{"codehealthFindingId/v1":"261bcfc05d5c179aad346d0a87a484c5e881c12dd3ed99ea3956face8cada272"}},{"ruleId":"ED3","level":"note","message":{"text":"Event not named in past tense: RegisterRequest: \u0060RegisterRequest\u0060 reads as an instruction, not a fact that happened. Events describe something that already occurred \u2014 name them in the past tense (e.g. \u0060OrderPlaced\u0060, \u0060PaymentCaptured\u0060) so the ubiquitous language stays clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Presentation/BankApplication.Contracts/Authentication/RegisterRequest.cs"},"region":{"startLine":6}}}],"partialFingerprints":{"codehealthFindingId/v1":"853682987aa47f1b445375c77bd256651336212ce407fd2d629f5e1c1abf164c"}},{"ruleId":"ED3","level":"note","message":{"text":"Event not named in past tense: TransferRequest: \u0060TransferRequest\u0060 reads as an instruction, not a fact that happened. Events describe something that already occurred \u2014 name them in the past tense (e.g. \u0060OrderPlaced\u0060, \u0060PaymentCaptured\u0060) so the ubiquitous language stays clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Presentation/BankApplication.Contracts/Transactions/Transfer/TransferRequest.cs"},"region":{"startLine":6}}}],"partialFingerprints":{"codehealthFindingId/v1":"3a7261f1a2bc99941113b0054865e8f028f16d24ef701f3f57f3ddf430494d3c"}},{"ruleId":"ED3","level":"note","message":{"text":"Event not named in past tense: TransferRequestData: \u0060TransferRequestData\u0060 reads as an instruction, not a fact that happened. Events describe something that already occurred \u2014 name them in the past tense (e.g. \u0060OrderPlaced\u0060, \u0060PaymentCaptured\u0060) so the ubiquitous language stays clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Presentation/BankApplication.Contracts/Transactions/Transfer/TransferRequestData.cs"},"region":{"startLine":4}}}],"partialFingerprints":{"codehealthFindingId/v1":"d0a80de35ba0afeeacfd96084f1ca9f6b7d9852ba7b637c061157d74a8c69e0b"}},{"ruleId":"ED3","level":"note","message":{"text":"Event not named in past tense: TransferResponse: \u0060TransferResponse\u0060 reads as an instruction, not a fact that happened. Events describe something that already occurred \u2014 name them in the past tense (e.g. \u0060OrderPlaced\u0060, \u0060PaymentCaptured\u0060) so the ubiquitous language stays clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Presentation/BankApplication.Contracts/Transactions/Transfer/TransferResponse.cs"},"region":{"startLine":4}}}],"partialFingerprints":{"codehealthFindingId/v1":"051601031597d24491764209022396a55ae0a9c52a841346954666678b8a92f5"}},{"ruleId":"M1","level":"warning","message":{"text":"Repository declared end-of-life: This repository declares its own end of life: \u0060README.md\u0060 line 16 reads \u201CThis project has been retired and is no longer maintained.\u201D. That is a first-party statement of intent, not an inference \u2014 the Maturity and Knowledge lenses otherwise approximate the same fact from decayed commit history (D16 reports a dormant codebase, D34 orphaned files), and this row says the maintainer already told you. It does NOT change any score: an honest end-of-life notice is the README doing its job, and every dimension below still measures the code as it stands. Read the whole report as an assessment of software the author has stopped working on."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"3e004c35cfb0f545005a1751b408088865c81b7248bb65240c7771e85dff66d9"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"M3","level":"note","message":{"text":"No src/ separation: Production code isn\u0027t grouped under a src/ folder \u2014 it\u0027s spread across several top-level directories, so there\u0027s no one place that says \u0027this is the product\u0027."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"fdf7f5b24e313364d10170a5c2542959902fe0d26ed70edef3eaa10ec5bcdb1d"}},{"ruleId":"M3","level":"note","message":{"text":"No tests/ separation: No test surface was found \u2014 this check walked the tree for authored source in the languages it models (\u0060.cs\u0060, \u0060.vb\u0060, \u0060.fs\u0060, \u0060.java\u0060, \u0060.kt\u0060, \u0060.scala\u0060, \u0060.py\u0060, \u0060.php\u0060, \u0060.rb\u0060, \u0060.ex\u0060, \u0060.exs\u0060, \u0060.go\u0060, \u0060.erl\u0060, \u0060.hrl\u0060, \u0060.swift\u0060, \u0060.dart\u0060, \u0060.rs\u0060, \u0060.ts\u0060, \u0060.tsx\u0060, \u0060.mts\u0060, \u0060.cts\u0060) and found none of it test-shaped. \u2605 \u0060.js\u0060, \u0060.jsx\u0060, \u0060.mjs\u0060 and \u0060.cjs\u0060 are NOT in that walk, so a Jest or Mocha suite written in plain JavaScript is invisible to it and this row is then wrong. If that is your case, say so rather than moving anything. Otherwise there are no tests here to separate from production code, so the folder question hasn\u0027t been reached yet."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"999e0c784909c76b6346a705ee63961fe363ed1cd6a94e3f80e2ebe7820ccd5d"}},{"ruleId":"M4","level":"note","message":{"text":"README/code drift: README claims the project is retired and no longer maintained \u2014 reported by the model that read the README against this repository; no term search was run for this one, so nothing here has been checked against the tree. Treat it as a reading to confirm, not as a measured contradiction: verify it against the code before acting on it, and if the footprint it describes does exist, this row is wrong."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"343bbbd51ceb8de7a9ff88d79f7c797abf9b5921f8727b67b4d0f4f8a22c5e49"}},{"ruleId":"P1","level":"warning","message":{"text":"No CI pipeline: No CI workflow found (.github/workflows, azure-pipelines.yml, .gitlab-ci.yml, \u2026) \u2014 changes aren\u0027t gated by an automated build/test."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"44f01af96e50474fba2df84d95ddf4f7e1d34c29c307830b9efc9057daa6b670"}},{"ruleId":"P2","level":"warning","message":{"text":"No structured logging: No logging call was found in the 116 \u0060.cs\u0060 file(s) this check read. Each was searched for the framework names \u0060ILogger\u0060, \u0060Serilog\u0060, \u0060NLog\u0060 and \u0060log4net\u0060; for a call on a receiver whose name ends in \u0060Logger\u0060; for a \u0060System.Diagnostics\u0060 write; for a level-gated log facade; and for the builder spellings that CONFIGURE logging for everyone else (\u0060AddLogging(\u0060, \u0060ConfigureLogging(\u0060, \u0060UseSerilog(\u0060, \u0060UseNLog(\u0060, \u0060.Logging.Add\u2026(\u0060). That walk sees only \u0060.cs\u0060 documents from projects the workspace loaded, so it cannot see logging in source that did not load, in another language, or through a repo-local wrapper whose name does not end in \u0060Logger\u0060 \u2014 this is \u0027no logging found by this walk\u0027, not a verdict that nothing here logs. If it is right, production issues will be hard to diagnose."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9f10d71351c6778ebe84e761f82a90d4f9ed6c64f5e01975ede8fda7e4e2ebc5"}},{"ruleId":"P3","level":"note","message":{"text":"No SAST: No static application security testing detected. For this repository\u0027s stack, add CodeQL\u0027s csharp pack, or a .NET security analyzer package (or \u0060semgrep --config=auto\u0060, which runs on any language) \u2014 this repository has no CI pipeline yet, so run it locally to clear the existing findings, then make it a step of the first workflow you add so a regression fails the build. What was searched, so you can tell an absence from a miss: the 0 CI workflow file(s) in this repository, and the scanner and linter configuration checked in beside them. A scan that runs outside CI, one configured in your forge\u0027s web UI rather than in a committed file, or a tool whose name is none of those this check carries, is not seen \u2014 if that is your case the row is wrong, and saying so is more useful than adding a second scanner."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6e54424179c892f03ef2fd003130ac4bd43f39bbf3b1ca0a0143e25acb80ec87"}},{"ruleId":"P4","level":"note","message":{"text":"No rollback/health safety: Deployment is orchestrated by compose, but no service declares a \u0060healthcheck:\u0060 and nothing pins a previous image to fall back to \u2014 the runtime can tell that the container is up, not that it is serving, so a bad release is harder to detect and reverse."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"db6bab8a28a2145f47e5a4e6683cda39d2ba0296c723238e8057da979ae1c706"}},{"ruleId":"P5","level":"warning","message":{"text":"No DR/backup evidence: A persistence guard (data volume / purge-protection) was found, but no backup, geo-recovery or RTO/RPO controls were evidenced \u2014 a volume that survives a container recreate is not a tested restore from catastrophic loss."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5daabb38c90b07af65b8738cf94ce884e90a7d8fef810d341de5c186188c8fe0"}},{"ruleId":"S1","level":"note","message":{"text":"No security response headers detected: No Content-Security-Policy / X-Frame-Options / X-Content-Type-Options configuration found \u2014 defense in depth, even when a reverse proxy could set them. (\u22122.0 on this card.)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"bd19c680309417e132c0be93c2002123f0664b42afe6172b1319da65a6a57ba7"}},{"ruleId":"SC1","level":"warning","message":{"text":"NuGet dependencies are not locked: No packages.lock.json and no central package management \u2014 restores aren\u0027t reproducible or pinned (SSDF PW.4.4). Enable \u003CRestorePackagesWithLockFile\u003Etrue\u003C/RestorePackagesWithLockFile\u003E (commit the lockfile) or adopt Directory.Packages.props. Advisory \u2014 never scored."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0a97b4f69ccac509400ece7eedefb06d3ede0522cd4d8bcb5c068bea719545a6"}},{"ruleId":"X2","level":"note","message":{"text":"Not all async methods take a CancellationToken: Only 8/16 async methods accept a CancellationToken, so in-flight work can\u0027t be stopped early when the caller gives up \u2014 whatever ends it in your host (shutdown signal, timeout, abandoned request, user cancel). Thread a token through the call chain and honour it at each await and loop; where a method genuinely cannot be interrupted, omitting it is a deliberate choice \u2014 judge against your hosting model."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"bf623a92fb752b336427856888a9b386c434e686662a2cdc1bba21832c0a048c"}},{"ruleId":"X3","level":"warning","message":{"text":"Swallowed exception (caught, then discarded): \u0060catch (Exception)\u0060 takes every exception and records none of it \u2014 the body neither logs it, rethrows it, nor even names it, so the failure is discarded as completely as by an empty catch and only the substituted value survives. Log it through whatever this codebase already uses to report problems, narrow the catch to the exception this call can actually raise, or say in a comment on the catch why the failure genuinely cannot matter."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Infrastructure/Presistence/AccountsRepository.cs"},"region":{"startLine":34}}}],"partialFingerprints":{"codehealthFindingId/v1":"5f0bc5d34336452c3d3cc3eb15ffb68c37b19db2b47f217035e732ca7cef92bb"}},{"ruleId":"X3","level":"warning","message":{"text":"Swallowed exception (caught, then discarded): \u0060catch (Exception)\u0060 takes every exception and records none of it \u2014 the body neither logs it, rethrows it, nor even names it, so the failure is discarded as completely as by an empty catch and only the substituted value survives. Log it through whatever this codebase already uses to report problems, narrow the catch to the exception this call can actually raise, or say in a comment on the catch why the failure genuinely cannot matter."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Infrastructure/Presistence/DispositionRepository.cs"},"region":{"startLine":28}}}],"partialFingerprints":{"codehealthFindingId/v1":"ba50e6191355358b7f39ec1bb7ff1de6b530bf4247c1a363cf9e880ea0034725"}},{"ruleId":"X3","level":"warning","message":{"text":"Swallowed exception (caught, then discarded): \u0060catch (Exception)\u0060 takes every exception and records none of it \u2014 the body neither logs it, rethrows it, nor even names it, so the failure is discarded as completely as by an empty catch and only the substituted value survives. Log it through whatever this codebase already uses to report problems, narrow the catch to the exception this call can actually raise, or say in a comment on the catch why the failure genuinely cannot matter."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"BankApplication.Infrastructure/Presistence/UserRepository.cs"},"region":{"startLine":39}}}],"partialFingerprints":{"codehealthFindingId/v1":"b7c70fac4e1adb820b22ebde004a77139d74f3f80aa361a65002745298e0d88e"}},{"ruleId":"X5","level":"note","message":{"text":"Null-forgiving operator (\u0060!\u0060) suppressions reduce the NRT score: ~4.3 \u0060!\u0060 suppressions per 1k syntax nodes \u2014 37 suppression(s) across the 8528 syntax node(s) in code where nullable warnings are ENABLED, which is the only code a \u0060!\u0060 can suppress anything in (a \u0060!\u0060 under \u0060#nullable disable\u0060 is inert and is not counted, and its file\u0027s nodes are not in the denominator). Each one tells the compiler to trust you about null, suppressing the very safety NRTs provide."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"93cfe05d4ad8c8c171267603b23dfe289b74842e38edd1b7bfed59cc32bda337"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":17,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}