{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D7","name":"Architectural Integrity","shortDescription":{"text":"Architectural Integrity"},"helpUri":"https://codehealth.canine.dev/dimensions/D7"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D10","name":"Test Quality","shortDescription":{"text":"Test Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D10"},{"id":"D11","name":"Test Reliability","shortDescription":{"text":"Test Reliability"},"helpUri":"https://codehealth.canine.dev/dimensions/D11"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D22","name":"Internal API Consistency","shortDescription":{"text":"Internal API Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D22"},{"id":"D23","name":"Boundary Type-Coupling","shortDescription":{"text":"Boundary Type-Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D23"},{"id":"D24","name":"Comment Value","shortDescription":{"text":"Comment Value"},"helpUri":"https://codehealth.canine.dev/dimensions/D24"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D39","name":"IL Efficiency","shortDescription":{"text":"IL Efficiency"},"helpUri":"https://codehealth.canine.dev/dimensions/D39"},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AC2","name":"Forms \u0026 labels","shortDescription":{"text":"Forms \u0026 labels"},"helpUri":"https://codehealth.canine.dev/dimensions/AC2"},{"id":"AC3","name":"Page structure","shortDescription":{"text":"Page structure"},"helpUri":"https://codehealth.canine.dev/dimensions/AC3"},{"id":"AC4","name":"Keyboard semantics","shortDescription":{"text":"Keyboard semantics"},"helpUri":"https://codehealth.canine.dev/dimensions/AC4"},{"id":"AC6","name":"Visual \u0026 motion safety","shortDescription":{"text":"Visual \u0026 motion safety"},"helpUri":"https://codehealth.canine.dev/dimensions/AC6"},{"id":"AC7","name":"A11y enforcement","shortDescription":{"text":"A11y enforcement"},"helpUri":"https://codehealth.canine.dev/dimensions/AC7"},{"id":"AX1","name":"Captive dependencies","shortDescription":{"text":"Captive dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/AX1"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX2","name":"Stateful singletons","shortDescription":{"text":"Stateful singletons"},"helpUri":"https://codehealth.canine.dev/dimensions/AX2"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX5","name":"Architecture \u0026 structure","shortDescription":{"text":"Architecture \u0026 structure"},"helpUri":"https://codehealth.canine.dev/dimensions/AX5"},{"id":"AX6","name":"Interface segregation","shortDescription":{"text":"Interface segregation"},"helpUri":"https://codehealth.canine.dev/dimensions/AX6"},{"id":"AX7","name":"Slice cohesion","shortDescription":{"text":"Slice cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/AX7"},{"id":"AX8","name":"Test isolation","shortDescription":{"text":"Test isolation"},"helpUri":"https://codehealth.canine.dev/dimensions/AX8"},{"id":"AX9","name":"CQS / query purity","shortDescription":{"text":"CQS / query purity"},"helpUri":"https://codehealth.canine.dev/dimensions/AX9"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"ED5","name":"Idempotency","shortDescription":{"text":"Idempotency"},"helpUri":"https://codehealth.canine.dev/dimensions/ED5"},{"id":"GD1","name":"Unfinished \u0026 placeholder code","shortDescription":{"text":"Unfinished \u0026 placeholder code"},"helpUri":"https://codehealth.canine.dev/dimensions/GD1"},{"id":"IC1","name":"Incompleteness \u0026 stubs","shortDescription":{"text":"Incompleteness \u0026 stubs"},"helpUri":"https://codehealth.canine.dev/dimensions/IC1"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P10","name":"Library API \u0026 versioning","shortDescription":{"text":"Library API \u0026 versioning"},"helpUri":"https://codehealth.canine.dev/dimensions/P10"},{"id":"P11","name":"BDD / executable specs","shortDescription":{"text":"BDD / executable specs"},"helpUri":"https://codehealth.canine.dev/dimensions/P11"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"P7","name":"Outbound HTTP resilience","shortDescription":{"text":"Outbound HTTP resilience"},"helpUri":"https://codehealth.canine.dev/dimensions/P7"},{"id":"PF1","name":"Benchmark discipline","shortDescription":{"text":"Benchmark discipline"},"helpUri":"https://codehealth.canine.dev/dimensions/PF1"},{"id":"PF2","name":"Allocation hygiene","shortDescription":{"text":"Allocation hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/PF2"},{"id":"PF3","name":"Async \u0026 latency hygiene","shortDescription":{"text":"Async \u0026 latency hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/PF3"},{"id":"SC1","name":"Supply-chain hygiene","shortDescription":{"text":"Supply-chain hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/SC1"},{"id":"X1","name":"Async correctness","shortDescription":{"text":"Async correctness"},"helpUri":"https://codehealth.canine.dev/dimensions/X1"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X12","name":"Unreachable branch","shortDescription":{"text":"Unreachable branch"},"helpUri":"https://codehealth.canine.dev/dimensions/X12"},{"id":"X13","name":"Undrained process stream","shortDescription":{"text":"Undrained process stream"},"helpUri":"https://codehealth.canine.dev/dimensions/X13"},{"id":"X14","name":"Bypassable address classification","shortDescription":{"text":"Bypassable address classification"},"helpUri":"https://codehealth.canine.dev/dimensions/X14"},{"id":"X15","name":"Unvalidated length from an untrusted reader","shortDescription":{"text":"Unvalidated length from an untrusted reader"},"helpUri":"https://codehealth.canine.dev/dimensions/X15"},{"id":"X16","name":"Unfloored truncation loop","shortDescription":{"text":"Unfloored truncation loop"},"helpUri":"https://codehealth.canine.dev/dimensions/X16"},{"id":"X17","name":"Uncapped recursion over a caller-supplied document","shortDescription":{"text":"Uncapped recursion over a caller-supplied document"},"helpUri":"https://codehealth.canine.dev/dimensions/X17"},{"id":"X18","name":"Disposal-pattern correctness","shortDescription":{"text":"Disposal-pattern correctness"},"helpUri":"https://codehealth.canine.dev/dimensions/X18"},{"id":"X19","name":"Unrestored process-global state","shortDescription":{"text":"Unrestored process-global state"},"helpUri":"https://codehealth.canine.dev/dimensions/X19"},{"id":"X2","name":"Cancellation propagation","shortDescription":{"text":"Cancellation propagation"},"helpUri":"https://codehealth.canine.dev/dimensions/X2"},{"id":"X20","name":"Mistyped argument guard","shortDescription":{"text":"Mistyped argument guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X20"},{"id":"X21","name":"Side-effecting pattern guard","shortDescription":{"text":"Side-effecting pattern guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X21"},{"id":"X22","name":"Contradicted release guard","shortDescription":{"text":"Contradicted release guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X22"},{"id":"X23","name":"Unguarded diagnostic materialisation","shortDescription":{"text":"Unguarded diagnostic materialisation"},"helpUri":"https://codehealth.canine.dev/dimensions/X23"},{"id":"X24","name":"Document value interpolated into markup unescaped","shortDescription":{"text":"Document value interpolated into markup unescaped"},"helpUri":"https://codehealth.canine.dev/dimensions/X24"},{"id":"X25","name":"Inert configuration knob","shortDescription":{"text":"Inert configuration knob"},"helpUri":"https://codehealth.canine.dev/dimensions/X25"},{"id":"X26","name":"Unsynchronised callback handoff","shortDescription":{"text":"Unsynchronised callback handoff"},"helpUri":"https://codehealth.canine.dev/dimensions/X26"},{"id":"X27","name":"Collection changed while being enumerated","shortDescription":{"text":"Collection changed while being enumerated"},"helpUri":"https://codehealth.canine.dev/dimensions/X27"},{"id":"X28","name":"Index access outside its own emptiness guard","shortDescription":{"text":"Index access outside its own emptiness guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X28"},{"id":"X29","name":"Per-element action decided by a fixed element","shortDescription":{"text":"Per-element action decided by a fixed element"},"helpUri":"https://codehealth.canine.dev/dimensions/X29"},{"id":"X3","name":"Exception handling","shortDescription":{"text":"Exception handling"},"helpUri":"https://codehealth.canine.dev/dimensions/X3"},{"id":"X30","name":"Support guard that admits what it rejects","shortDescription":{"text":"Support guard that admits what it rejects"},"helpUri":"https://codehealth.canine.dev/dimensions/X30"},{"id":"X32","name":"Type resolved by simple name across every loaded assembly","shortDescription":{"text":"Type resolved by simple name across every loaded assembly"},"helpUri":"https://codehealth.canine.dev/dimensions/X32"},{"id":"X4","name":"Structured logging","shortDescription":{"text":"Structured logging"},"helpUri":"https://codehealth.canine.dev/dimensions/X4"},{"id":"X5","name":"Nullable reference types","shortDescription":{"text":"Nullable reference types"},"helpUri":"https://codehealth.canine.dev/dimensions/X5"},{"id":"X6","name":"Hand-rolled structured-format parsing","shortDescription":{"text":"Hand-rolled structured-format parsing"},"helpUri":"https://codehealth.canine.dev/dimensions/X6"},{"id":"X7","name":"Silent fallback defaults","shortDescription":{"text":"Silent fallback defaults"},"helpUri":"https://codehealth.canine.dev/dimensions/X7"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"TypeCodec.decodeWithOptions (cyclomatic 38): TypeCodec.decodeWithOptions has cyclomatic complexity 38 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/Json/Codecs/TypeCodec.fs"},"region":{"startLine":123}}}],"partialFingerprints":{"codehealthFindingId/v1":"96230f51e1a0c85f23cd455e1182fb73071678bfe4356ca9e61c8b987087a187"}},{"ruleId":"D1","level":"warning","message":{"text":"TypeValidator.inferValueType (cyclomatic 30): TypeValidator.inferValueType has cyclomatic complexity 30 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.IR.Pipeline.Plugins/TypeValidator.fs"},"region":{"startLine":82}}}],"partialFingerprints":{"codehealthFindingId/v1":"cc64cb1b11a7ee3828f6356a53ef40b4ada9bf190816dfe0d6396b2bea0dba12"}},{"ruleId":"D1","level":"warning","message":{"text":"LiteralCodec.readFromWithOptions (cyclomatic 30): LiteralCodec.readFromWithOptions has cyclomatic complexity 30 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/Json/Codecs/LiteralCodec.fs"},"region":{"startLine":106}}}],"partialFingerprints":{"codehealthFindingId/v1":"b23d3c82c78766974dc24e9d578274d7f8338d61105535719a87a0f6dc037c60"}},{"ruleId":"D1","level":"warning","message":{"text":"Value.toString (cyclomatic 24): Value.toString has cyclomatic complexity 24 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/Value.fs"},"region":{"startLine":187}}}],"partialFingerprints":{"codehealthFindingId/v1":"2255a1bde8e22766c9fcad9089c25cada4bdba1fb6213560ed8be1a730ca0def"}},{"ruleId":"D2","level":"warning","message":{"text":"LiteralCodec.readFromWithOptions (cognitive 95): LiteralCodec.readFromWithOptions has cognitive complexity 95 (threshold 15). Drivers by points: if/else 25 (61 pts), error handling 3 (18 pts), match/switch 3 (14 pts), boolean chains 2 (nesting depth added 62). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/Json/Codecs/LiteralCodec.fs"},"region":{"startLine":106}}}],"partialFingerprints":{"codehealthFindingId/v1":"bc118cf11b08d2858cd29edb160a18bd187cc3c639130fc6718779daadfdd786"}},{"ruleId":"D2","level":"warning","message":{"text":"TypeCodec.decodeWithOptions (cognitive 63): TypeCodec.decodeWithOptions has cognitive complexity 63 (threshold 15). Drivers by points: match/switch 16 (63 pts) (nesting depth added 47). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/Json/Codecs/TypeCodec.fs"},"region":{"startLine":123}}}],"partialFingerprints":{"codehealthFindingId/v1":"09ec75e0addc57ab13917bddd7d2de3d7209d261934e322e656c86e703dd2718"}},{"ruleId":"D2","level":"warning","message":{"text":"NameModule.toMorphirWords (cognitive 59): NameModule.toMorphirWords has cognitive complexity 59 (threshold 15). Drivers by points: if/else 20 (57 pts), loops 1 (2 pts) (nesting depth added 38). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Name.fs"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"2da065a0af9e02d1a4a0df441045da4e4f6acc22299bdce47506d425fc26d334"}},{"ruleId":"D2","level":"warning","message":{"text":"SemanticVersionModule.parse (cognitive 45): SemanticVersionModule.parse has cognitive complexity 45 (threshold 15). Drivers by points: if/else 18 (37 pts), match/switch 1 (5 pts), boolean chains 3 (nesting depth added 23). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Versioning.fs"},"region":{"startLine":79}}}],"partialFingerprints":{"codehealthFindingId/v1":"cbeb2f2e40c5032f2102bacc64edf2aa74a8cbd9de97eb9e260a51582bb12511"}},{"ruleId":"D2","level":"warning","message":{"text":"FQNameCodec.readFromWithOptions (cognitive 42): FQNameCodec.readFromWithOptions has cognitive complexity 42 (threshold 15). Drivers by points: if/else 10 (26 pts), match/switch 3 (15 pts), boolean chains 1 (nesting depth added 28). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/Json/Codecs/FQNameCodec.fs"},"region":{"startLine":38}}}],"partialFingerprints":{"codehealthFindingId/v1":"e8eac6976f8dd510d1efc1464687c14c96bc61aa5bc726244986a0480832f902"}},{"ruleId":"D2","level":"warning","message":{"text":"TypeValidator.inferValueType (cognitive 32): TypeValidator.inferValueType has cognitive complexity 32 (threshold 15). Drivers by points: match/switch 8 (18 pts), if/else 8 (14 pts) (nesting depth added 16). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.IR.Pipeline.Plugins/TypeValidator.fs"},"region":{"startLine":82}}}],"partialFingerprints":{"codehealthFindingId/v1":"d056c0f68a41bcede21dba1414c495e8cd5976f51811eaaf3a7404e3af5c6cd8"}},{"ruleId":"D2","level":"warning","message":{"text":"IrToolingScenario.FormatVerifyOutput (cognitive 24): IrToolingScenario.FormatVerifyOutput has cognitive complexity 24 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Scenarios/IrToolingScenario.cs"},"region":{"startLine":116}}}],"partialFingerprints":{"codehealthFindingId/v1":"652b4b2533e307c1bc0cb9bd8529e00b1433f480404b8d1ce408ac61e01dcccc"}},{"ruleId":"D2","level":"warning","message":{"text":"DistHandlers.HandleList (cognitive 23): DistHandlers.HandleList has cognitive complexity 23 (threshold 15). To reduce it, flatten the nesting: invert conditions into early returns or guard clauses so the happy path stays at one level, and lift the deepest nested block into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Features/Management/DistHandlers.cs"},"region":{"startLine":15}}}],"partialFingerprints":{"codehealthFindingId/v1":"b6aaeae18604f9f280ff8ae2fe80bb83bad1362a95f30d3d0d6e21f9a4f33c07"}},{"ruleId":"D2","level":"warning","message":{"text":"SemanticVersionModule.isValidIdentifier (cognitive 20): SemanticVersionModule.isValidIdentifier has cognitive complexity 20 (threshold 15). Drivers by points: if/else 8 (16 pts), boolean chains 2, loops 1 (2 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Versioning.fs"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"47285841546506e8ebfeaf9c2fb632e3b51dab68136aea62057f1f1c88aebae3"}},{"ruleId":"D2","level":"warning","message":{"text":"ClassicTypeJsonConverter.ReadReference (cognitive 17): ClassicTypeJsonConverter.ReadReference has cognitive complexity 17 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body. This shape REPEATS in the file: one other method here (ClassicTypeJsonConverter.ReadExtensibleRecord) has the same decision points, in the same order, at the same nesting depths \u2014 so this is one pattern written twice rather than two separate problems. Splitting this body alone leaves the other exactly as it is. Where these are variations on one operation, the change that clears both is the shared one: lift the common shape into a single routine the variants call, parameterised by whatever genuinely differs between them, and keep in each method only the part that is not shared."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Core/Classic/IR/Codecs/ClassicTypeJsonConverterFactory.cs"},"region":{"startLine":151}}}],"partialFingerprints":{"codehealthFindingId/v1":"e4ce250fc57303557f5e8f2a44ba5e490032c0e3b38f497537acdf5ca4588a8a"}},{"ruleId":"D2","level":"warning","message":{"text":"ClassicTypeJsonConverter.ReadExtensibleRecord (cognitive 17): ClassicTypeJsonConverter.ReadExtensibleRecord has cognitive complexity 17 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body. This shape REPEATS in the file: one other method here (ClassicTypeJsonConverter.ReadReference) has the same decision points, in the same order, at the same nesting depths \u2014 so this is one pattern written twice rather than two separate problems. Splitting this body alone leaves the other exactly as it is. Where these are variations on one operation, the change that clears both is the shared one: lift the common shape into a single routine the variants call, parameterised by whatever genuinely differs between them, and keep in each method only the part that is not shared."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Core/Classic/IR/Codecs/ClassicTypeJsonConverterFactory.cs"},"region":{"startLine":231}}}],"partialFingerprints":{"codehealthFindingId/v1":"738ea82f7ef1258c1ecf2acd3c7125d6f4939b422b2744a616c484e115f907ab"}},{"ruleId":"D2","level":"warning","message":{"text":"NameCodec.readFromWithOptions (cognitive 17): NameCodec.readFromWithOptions has cognitive complexity 17 (threshold 15). Drivers by points: if/else 5 (11 pts), match/switch 2 (3 pts), loops 1 (2 pts), boolean chains 1 (nesting depth added 8). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/Json/Codecs/NameCodec.fs"},"region":{"startLine":58}}}],"partialFingerprints":{"codehealthFindingId/v1":"82c5b7d28bb348af05efd5198a2d68385e005f4cd747ba9cf5da63dedb4c9119"}},{"ruleId":"D2","level":"warning","message":{"text":"ConfigResolver.ResolveConfigAsync (cognitive 16): ConfigResolver.ResolveConfigAsync has cognitive complexity 16 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Configuration/ConfigResolver.cs"},"region":{"startLine":29}}}],"partialFingerprints":{"codehealthFindingId/v1":"f8c4baf3011a4daadbd4e21bd5acdc7734aa9d1d1d3a1b8711aade820736f395"}},{"ruleId":"D2","level":"warning","message":{"text":"TomlParser.ParseCachePaths (cognitive 16): TomlParser.ParseCachePaths has cognitive complexity 16 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Configuration/TomlParser.cs"},"region":{"startLine":40}}}],"partialFingerprints":{"codehealthFindingId/v1":"bd7f5f9125004622f3758d6b95948cd9628377d353220da87587cc7cf6d36607"}},{"ruleId":"D2","level":"warning","message":{"text":"SchemaValidator.ExtractExpectedValue (cognitive 16): SchemaValidator.ExtractExpectedValue has cognitive complexity 16 (threshold 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Infrastructure/JsonSchema/SchemaValidator.cs"},"region":{"startLine":76}}}],"partialFingerprints":{"codehealthFindingId/v1":"54782ece095ea81aa05260b540acdb5214629dfcbdcb5e8716f8cf38a8672d02"}},{"ruleId":"D2","level":"warning","message":{"text":"PathCodec.readFromWithOptions (cognitive 16): PathCodec.readFromWithOptions has cognitive complexity 16 (threshold 15). Drivers by points: if/else 4 (6 pts), match/switch 2 (6 pts), boolean chains 2, loops 1 (2 pts) (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/Json/Codecs/PathCodec.fs"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"c6da2d999593aa0f0c75d1478f8bf71c096ab26a20d204b9cff429c9b367ea79"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFunctions: List: TooManyFunctions \u2014 40 functions. The bar is 30 functions; this is 10 over it, 1.33\u00D7 the bar. The counted members are a module\u0027s functions \u2014 a module holds no instance state, so there is no shared data to group them by and no type to move them onto. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no single module carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.SDK/List.fs"},"region":{"startLine":8}}}],"partialFingerprints":{"codehealthFindingId/v1":"3d8718b25977d9e0270dfb2833e7e56692829b820fb921ad9cc323d06d943742"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFunctions: String: TooManyFunctions \u2014 37 functions. The bar is 30 functions; this is 7 over it, 1.23\u00D7 the bar. The counted members are a module\u0027s functions \u2014 a module holds no instance state, so there is no shared data to group them by and no type to move them onto. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no single module carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.SDK/String.fs"},"region":{"startLine":7}}}],"partialFingerprints":{"codehealthFindingId/v1":"0417bf00e1c30cef77d77e5e0ad2a270ec745566c87b443bb483200b2699de53"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: PatternBuilder: TooManyMethods \u2014 34 methods. The bar is 30 methods; this is 4 over it, 1.13\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Patterns.fs"},"region":{"startLine":448}}}],"partialFingerprints":{"codehealthFindingId/v1":"a00f86500f8a10bb7af6b7056645693429bedb45e2a8106c6329b07e3f9e4a7a"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: ValueBuilder: TooManyMethods \u2014 34 methods. The bar is 30 methods; this is 4 over it, 1.13\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Values.fs"},"region":{"startLine":453}}}],"partialFingerprints":{"codehealthFindingId/v1":"ba012e63d38135fd05f8f2b783ed18c180d6361917ea5299eb6ca82a71ce0d42"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: PatternBuilder\u00601: TooManyMethods \u2014 33 methods. The bar is 30 methods; this is 3 over it, 1.10\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Patterns.fs"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"5d3c4c6f2b64ab40c869ddb439eebd4e3f192e4a4e3653b2916c5713bb4b1014"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: PatternBuilderWithAttrs\u00601: TooManyMethods \u2014 33 methods. The bar is 30 methods; this is 3 over it, 1.10\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Patterns.fs"},"region":{"startLine":233}}}],"partialFingerprints":{"codehealthFindingId/v1":"f5d0c81b9a48eeb113019a819ad8fc4aeac572f5eb1f98086804f5047a247611"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: TypeBuilder: TooManyMethods \u2014 31 methods. The bar is 30 methods; this is 1 over it, 1.03\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Types.fs"},"region":{"startLine":256}}}],"partialFingerprints":{"codehealthFindingId/v1":"e479ee47d4546ccb3933537b85d2a6e1e55b61e9682013f0fcfc8b07ef328be2"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: ValueBuilder\u00602: TooManyMethods \u2014 31 methods. The bar is 30 methods; this is 1 over it, 1.03\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Values.fs"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"c01a67df47f96145cbd90c3b06988837fcbeda3e3c057954a5a4995169733133"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: ValueBuilderWithAttrs\u00602: TooManyMethods \u2014 31 methods. The bar is 30 methods; this is 1 over it, 1.03\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Values.fs"},"region":{"startLine":235}}}],"partialFingerprints":{"codehealthFindingId/v1":"7af59de8305c49da3a1296f621ad95b241f6b6f8b9544580111c049784ea7692"}},{"ruleId":"D4","level":"warning","message":{"text":"Near-duplicate member pair (30 shared lines): src/Morphir.Tooling/Scenarios/ManagementScenario.cs:108-188 | src/Morphir.Tooling/Scenarios/ManagementScenario.cs:191-271 \u2014 These two members are variants of one another: 30 of their lines are already reported as duplicated blocks below, spread through both bodies rather than gathered into one. Read them as a single construct written twice. The repair is at the members\u0027 grain \u2014 factor the shared pipeline into one implementation the two call with their differences as parameters or as an injected step, or, where the difference is systematic (sync against async, one transport against another), generate one from the other. Extracting the individual blocks below is not the same fix: it leaves the two bodies in place and the next edit still has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Scenarios/ManagementScenario.cs"},"region":{"startLine":108}}}],"partialFingerprints":{"codehealthFindingId/v1":"e5c6e07785ba0fa281d10522978e85fcb097f4a36a0502fc3df5ffa632049395"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (209 lines \u00D7 2): src/Morphir.Models/IR/Classic/DSL/Values.fs:22-230 | src/Morphir.Models/IR/Classic/DSL/Values.fs:239-447 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Values.fs"},"region":{"startLine":22}}}],"partialFingerprints":{"codehealthFindingId/v1":"cddad38dd2c84aa4072ffb70e738ef5d8b9dfce0a8fa67ac8ea774044372a20f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (126 lines \u00D7 2): src/Morphir.Models/IR/Classic/DSL/Patterns.fs:102-227 | src/Morphir.Models/IR/Classic/DSL/Patterns.fs:316-441 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Patterns.fs"},"region":{"startLine":102}}}],"partialFingerprints":{"codehealthFindingId/v1":"8d8f81a45bb1a4fcec7d722af77531966703b249b3fee432325e85e30ab9869d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11\u2013113 lines \u00D7 3): src/Morphir.Models/IR/Classic/DSL/Types.fs:21-133 | src/Morphir.Models/IR/Classic/DSL/Types.fs:142-250 | src/Morphir.Models/IR/Classic/DSL/Types.fs:262-272 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Types.fs"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"d54d9a67af3431ba2bad76411b103d3de01a07f82b5a4732e28a3010081b58a5"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (44 lines \u00D7 2): src/Morphir.Models/IR/Classic/DSL/Patterns.fs:52-95 | src/Morphir.Models/IR/Classic/DSL/Patterns.fs:266-309 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Patterns.fs"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"f9ae9c0b91e17966819b63711c198bef797496bfa9e6ef8c210e43d2ba946492"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (36 lines \u00D7 3): src/Morphir.Models/IR/Classic/DSL/Patterns.fs:78-113 | src/Morphir.Models/IR/Classic/DSL/Patterns.fs:292-327 | src/Morphir.Models/IR/Classic/DSL/Patterns.fs:509-544 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Patterns.fs"},"region":{"startLine":78}}}],"partialFingerprints":{"codehealthFindingId/v1":"458895c7b0495fc62ac3088e2d484630c515cd7108ee900ee563ca9aa15e3a01"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (27 lines \u00D7 2): build/ChangelogHelper.cs:22-48 | build/ChangelogHelper.cs:65-91 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060build/ChangelogHelper.cs:22\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"build/ChangelogHelper.cs"},"region":{"startLine":22}}}],"partialFingerprints":{"codehealthFindingId/v1":"3e1dc38cb897c36ec4304888ee50cf125a65bff015fac9e5a269b8d864b3ab93"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (24 lines \u00D7 3): src/Morphir.Models/IR/Classic/DSL/Types.fs:52-75 | src/Morphir.Models/IR/Classic/DSL/Types.fs:173-196 | src/Morphir.Models/IR/Classic/DSL/Types.fs:293-316 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Types.fs"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"2699757436d10386f1b469838cde819738db4015442511a2cfe4dff055f93e40"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (21\u201323 lines \u00D7 2): src/Morphir.Tooling/MorphirCliExtensions.cs:84-104 | src/Morphir.Tooling/Scenarios/IrToolingScenario.cs:179-201 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/MorphirCliExtensions.cs"},"region":{"startLine":84}}}],"partialFingerprints":{"codehealthFindingId/v1":"35eeeb4f095fca2ec029b7597cb194d455c7914b66bfc5a9ca41995ea8f0f89e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (23 lines \u00D7 2): src/Morphir.Models/IR/Classic/DSL/Patterns.fs:23-45 | src/Morphir.Models/IR/Classic/DSL/Patterns.fs:237-259 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Patterns.fs"},"region":{"startLine":23}}}],"partialFingerprints":{"codehealthFindingId/v1":"a2acee9dc3cc3a3e84fd9d5dca11649472e8b36126ea6e298a0d582764892d14"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (21\u201322 lines \u00D7 2): src/Morphir.Core/Classic/IR/Codecs/ClassicTypeJsonConverterFactory.cs:168-188 | src/Morphir.Core/Classic/IR/Codecs/ClassicTypeJsonConverterFactory.cs:365-386 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Morphir.Core/Classic/IR/Codecs/ClassicTypeJsonConverterFactory.cs:168\u0060 it runs out through the closing brace of the declaration holding it and carries on into the declaration that follows \u2014 the window is the tail of one member plus the head of the next, so no call can be substituted for those exact lines, and the smallest declaration that contains all of them is the type they sit in. The repeated unit is the member each site sits in: where those members\u0027 bodies are the same, move one whole member to the shared location and have the others delegate to it; where the copies are a run of near-identical overloads or wrappers that differ only in their signatures, the repetition IS the run \u2014 a one-line delegation has no helper inside it to lift \u2014 so generate the run from the set it enumerates, or accept it and keep each member\u0027s own documentation with it. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Core/Classic/IR/Codecs/ClassicTypeJsonConverterFactory.cs"},"region":{"startLine":168}}}],"partialFingerprints":{"codehealthFindingId/v1":"36e21346eec7f3caceba196fd4561afde7988b01b91dd8ae9685c539b58e58cc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (22 lines \u00D7 2): src/Morphir.Core/Classic/IR/Codecs/ClassicTypeJsonConverterFactory.cs:203-224 | src/Morphir.Core/Classic/IR/Codecs/ClassicTypeJsonConverterFactory.cs:248-269 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Morphir.Core/Classic/IR/Codecs/ClassicTypeJsonConverterFactory.cs:203\u0060 it runs out through the closing brace of the declaration holding it and carries on into the declaration that follows \u2014 the window is the tail of one member plus the head of the next, so no call can be substituted for those exact lines, and the smallest declaration that contains all of them is the type they sit in. The repeated unit is the member each site sits in: where those members\u0027 bodies are the same, move one whole member to the shared location and have the others delegate to it; where the copies are a run of near-identical overloads or wrappers that differ only in their signatures, the repetition IS the run \u2014 a one-line delegation has no helper inside it to lift \u2014 so generate the run from the set it enumerates, or accept it and keep each member\u0027s own documentation with it. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Core/Classic/IR/Codecs/ClassicTypeJsonConverterFactory.cs"},"region":{"startLine":203}}}],"partialFingerprints":{"codehealthFindingId/v1":"de8dcde2f2a2dfcce48c771339dbb527ad4bd36ec7ed1242865feaf8d46b895f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (22 lines \u00D7 2): src/Morphir.Tooling/Features/Management/ExtensionHandlers.cs:69-90 | src/Morphir.Tooling/Features/Management/ToolHandlers.cs:68-89 \u2014 before extracting anything, compare \u0060src/Morphir.Tooling/Features/Management/ExtensionHandlers.cs\u0060 and \u0060src/Morphir.Tooling/Features/Management/ToolHandlers.cs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 52 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Features/Management/ExtensionHandlers.cs"},"region":{"startLine":69}}}],"partialFingerprints":{"codehealthFindingId/v1":"62376fd9b313b1c7b2909b402813c705626189366eaff91f808ab863c5f45019"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (21 lines \u00D7 3): src/Morphir.Models/IR/Classic/DSL/Patterns.fs:120-140 | src/Morphir.Models/IR/Classic/DSL/Patterns.fs:334-354 | src/Morphir.Models/IR/Classic/DSL/Patterns.fs:551-571 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Patterns.fs"},"region":{"startLine":120}}}],"partialFingerprints":{"codehealthFindingId/v1":"df1ef831b90259eebd5261fd88cfd8c39cd9dd49a378508ef9f3898f9632829c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): src/Morphir.Models/IR/Classic/Type.fs:238-254 | src/Morphir.Models/IR/Classic/Type.fs:285-301 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/Type.fs"},"region":{"startLine":238}}}],"partialFingerprints":{"codehealthFindingId/v1":"bed3129acd68072f151680a81a03049fc660bd797e4fabb3769a88f1f5778a14"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11\u201316 lines \u00D7 3): src/Morphir.Tooling/Features/Management/DistHandlers.cs:100-115 | src/Morphir.Tooling/Features/Management/ExtensionHandlers.cs:69-79 | src/Morphir.Tooling/Features/Management/ToolHandlers.cs:68-78 \u2014 before extracting anything, compare \u0060src/Morphir.Tooling/Features/Management/ExtensionHandlers.cs\u0060 and \u0060src/Morphir.Tooling/Features/Management/ToolHandlers.cs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 52 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place. \u2605 These copies have DRIFTED, and that is worth reading before extracting anything: just after the matched lines, \u0060src/Morphir.Tooling/Features/Management/DistHandlers.cs:117\u0060 calls \u0060LogInformation\u0060 and \u0060src/Morphir.Tooling/Features/Management/ExtensionHandlers.cs:81\u0060 does not \u2014 after which the two agree again for 2 more lines. One of those two behaviours is the intended one and the other is what a copy-paste left behind, so decide which BEFORE unifying them: extracting the shared part will silently settle it, and if the copy that skips the call is the wrong one, that bug is already live."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Features/Management/DistHandlers.cs"},"region":{"startLine":100}}}],"partialFingerprints":{"codehealthFindingId/v1":"3d8231b331e0e19c75ea193e41b3e0f5ca1677c280a0d3b6dc283b010dcc4cd1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15\u201316 lines \u00D7 2): src/Morphir.Tooling/Infrastructure/JsonSchema/SchemaValidator.cs:85-100 | src/Morphir.Tooling/Infrastructure/JsonSchema/SchemaValidator.cs:131-145 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Morphir.Tooling/Infrastructure/JsonSchema/SchemaValidator.cs:85\u0060 it runs out through the closing brace of the declaration holding it and carries on into the declaration that follows \u2014 the window is the tail of one member plus the head of the next, so no call can be substituted for those exact lines, and the smallest declaration that contains all of them is the type they sit in. The repeated unit is the member each site sits in: where those members\u0027 bodies are the same, move one whole member to the shared location and have the others delegate to it; where the copies are a run of near-identical overloads or wrappers that differ only in their signatures, the repetition IS the run \u2014 a one-line delegation has no helper inside it to lift \u2014 so generate the run from the set it enumerates, or accept it and keep each member\u0027s own documentation with it. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Infrastructure/JsonSchema/SchemaValidator.cs"},"region":{"startLine":85}}}],"partialFingerprints":{"codehealthFindingId/v1":"6acd82f1c68fc096e8aa8057073e895bf2b0a5f85dcb2044ecd2974a90932be6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): src/Morphir.Models/Json/Encode.fs:66-80 | src/Morphir.Models/Json/Encode.fs:81-95 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/Json/Encode.fs"},"region":{"startLine":66}}}],"partialFingerprints":{"codehealthFindingId/v1":"4a238ab7d914a61182d1045cb753133a5aab7f036e4b6c59e1ae04a3f7e8d1ab"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 3): src/Morphir.Tooling/Features/Management/DistCommands.cs:96-109 | src/Morphir.Tooling/Features/Management/ExtensionCommands.cs:107-120 | src/Morphir.Tooling/Features/Management/ToolCommands.cs:107-120 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from all 3 call sites, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Morphir.Tooling/Features/Management/ExtensionCommands.cs:107\u0060 it runs out through the closing brace of the declaration holding it \u2014 the window is that declaration\u0027s tail, not a fragment that begins part-way through something, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Features/Management/DistCommands.cs"},"region":{"startLine":96}}}],"partialFingerprints":{"codehealthFindingId/v1":"9a955f929379fbd35ca3bc2accaf958744e25580fb6bd8297aad239c8918c638"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): src/Morphir.Tooling/Features/Management/ExtensionHandlers.cs:24-37 | src/Morphir.Tooling/Features/Management/ToolHandlers.cs:23-36 \u2014 before extracting anything, compare \u0060src/Morphir.Tooling/Features/Management/ExtensionHandlers.cs\u0060 and \u0060src/Morphir.Tooling/Features/Management/ToolHandlers.cs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 52 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Morphir.Tooling/Features/Management/ExtensionHandlers.cs:24\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Features/Management/ExtensionHandlers.cs"},"region":{"startLine":24}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b69a16fc3f51d21f4d20c26e0f7c40fbea532dc54848f4866f543ee40b6d9b7"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 3): src/Morphir.Models/IR/FQName.fs:56-68 | src/Morphir.Models/IR/FQName.fs:80-92 | src/Morphir.Models/IR/FQName.fs:104-116 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/FQName.fs"},"region":{"startLine":56}}}],"partialFingerprints":{"codehealthFindingId/v1":"a50ab95d914752740853c81e00140863cbd3ed4a45ffba785e9c15807b8a6987"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): src/Morphir.Tooling/Configuration/TomlParser.cs:48-60 | src/Morphir.Tooling/Configuration/TomlParser.cs:61-73 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Morphir.Tooling/Configuration/TomlParser.cs:48\u0060 it runs out through the closing brace of the declaration holding it and carries on into the declaration that follows \u2014 the window is the tail of one member plus the head of the next, so no call can be substituted for those exact lines, and the smallest declaration that contains all of them is the type they sit in. The repeated unit is the member each site sits in: where those members\u0027 bodies are the same, move one whole member to the shared location and have the others delegate to it; where the copies are a run of near-identical overloads or wrappers that differ only in their signatures, the repetition IS the run \u2014 a one-line delegation has no helper inside it to lift \u2014 so generate the run from the set it enumerates, or accept it and keep each member\u0027s own documentation with it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Configuration/TomlParser.cs"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee0021505c9fbaf3b61925cc0c1594acfd242c7bed236f09c3e2c29dfe8806bd"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): src/Morphir.Tooling/Features/Management/ExtensionCommands.cs:126-138 | src/Morphir.Tooling/Features/Management/ExtensionCommands.cs:144-156 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Features/Management/ExtensionCommands.cs"},"region":{"startLine":126}}}],"partialFingerprints":{"codehealthFindingId/v1":"746a81df313836cf6b88dde6cdcd9c9627b7c962ddcc250146fa6518d865d716"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): src/Morphir.Tooling/Features/Management/ToolCommands.cs:126-138 | src/Morphir.Tooling/Features/Management/ToolCommands.cs:144-156 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Features/Management/ToolCommands.cs"},"region":{"startLine":126}}}],"partialFingerprints":{"codehealthFindingId/v1":"dbca89981e376b2142f09ed25ff592b04934058e1affcd30d5f592103e66c029"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): src/Morphir.Tooling/Scenarios/ManagementScenario.cs:123-134 | src/Morphir.Tooling/Scenarios/ManagementScenario.cs:206-217 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Morphir.Tooling/Scenarios/ManagementScenario.cs:123\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Scenarios/ManagementScenario.cs"},"region":{"startLine":123}}}],"partialFingerprints":{"codehealthFindingId/v1":"3b09a817c4cc32abf6af716c0341b22403410838704355e17f1fc21285f56842"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): src/Morphir.Core/Classic/IR/Codecs/ClassicTypeJsonConverterFactory.cs:452-462 | src/Morphir.Core/Classic/IR/Codecs/ClassicTypeJsonConverterFactory.cs:471-481 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Morphir.Core/Classic/IR/Codecs/ClassicTypeJsonConverterFactory.cs:452\u0060 it runs out through the closing brace of the declaration holding it \u2014 the window is that declaration\u0027s tail, not a fragment that begins part-way through something, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. \u2605 These copies have DRIFTED, and that is worth reading before extracting anything: just before the matched lines, \u0060src/Morphir.Core/Classic/IR/Codecs/ClassicTypeJsonConverterFactory.cs:469\u0060 calls \u0060Write\u0060 and \u0060src/Morphir.Core/Classic/IR/Codecs/ClassicTypeJsonConverterFactory.cs:450\u0060 does not \u2014 after which the two agree again for 3 more lines. One of those two behaviours is the intended one and the other is what a copy-paste left behind, so decide which BEFORE unifying them: extracting the shared part will silently settle it, and if the copy that skips the call is the wrong one, that bug is already live."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Core/Classic/IR/Codecs/ClassicTypeJsonConverterFactory.cs"},"region":{"startLine":452}}}],"partialFingerprints":{"codehealthFindingId/v1":"f6c89a0e45a67d8e48144874e7230354d783f44f715e47b400253f461beca09a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): src/Morphir.Models/IR/Classic/DSL/Modules.fs:295-304 | src/Morphir.Models/IR/Classic/DSL/Modules.fs:325-334 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Modules.fs"},"region":{"startLine":295}}}],"partialFingerprints":{"codehealthFindingId/v1":"107c14201c07453e9fff045e01d680ab859fefc5a832f07caec4c7b58dab6b34"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): src/Morphir.Models/IR/Classic/DSL/Modules.fs:306-315 | src/Morphir.Models/IR/Classic/DSL/Modules.fs:347-356 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Modules.fs"},"region":{"startLine":306}}}],"partialFingerprints":{"codehealthFindingId/v1":"c988eb138f818d4aa29e5e8b8958b1d8e13ae6684ad189d9baf766e1bab36180"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 5): src/Morphir.Tooling/Scenarios/ManagementScenario.cs:53-61 | src/Morphir.Tooling/Scenarios/ManagementScenario.cs:144-152 | src/Morphir.Tooling/Scenarios/ManagementScenario.cs:161-169 | src/Morphir.Tooling/Scenarios/ManagementScenario.cs:227-235 | src/Morphir.Tooling/Scenarios/ManagementScenario.cs:244-252 \u2014 all 5 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Morphir.Tooling/Scenarios/ManagementScenario.cs:53\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Scenarios/ManagementScenario.cs"},"region":{"startLine":53}}}],"partialFingerprints":{"codehealthFindingId/v1":"434f7f090991cf28147e66cb4250db26f02885d05ff276abf3b321aea314b48d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): src/Morphir.Tooling/Features/Management/ExtensionHandlers.cs:123-131 | src/Morphir.Tooling/Features/Management/ExtensionHandlers.cs:172-181 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Morphir.Tooling/Features/Management/ExtensionHandlers.cs:123\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Features/Management/ExtensionHandlers.cs"},"region":{"startLine":123}}}],"partialFingerprints":{"codehealthFindingId/v1":"57dd8eea6672607bafb8c6e90136bcd65cf2c51430a6b522c28e735aaa779045"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): src/Morphir.Tooling/Features/Management/ToolHandlers.cs:122-130 | src/Morphir.Tooling/Features/Management/ToolHandlers.cs:171-180 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Morphir.Tooling/Features/Management/ToolHandlers.cs:122\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Features/Management/ToolHandlers.cs"},"region":{"startLine":122}}}],"partialFingerprints":{"codehealthFindingId/v1":"ccc5001e5345ed9a06dbcbdac17efd019cbdc55086754c2eca3dde9f61f776ef"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): src/Morphir.Models/IR/Classic/DSL/Modules.fs:94-102 | src/Morphir.Models/IR/Classic/DSL/Modules.fs:208-216 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Morphir.Models/IR/Classic/DSL/Modules.fs:94\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Modules.fs"},"region":{"startLine":94}}}],"partialFingerprints":{"codehealthFindingId/v1":"b0c9cfeca2af2a13b19d4e75ddc3856665ebd3ee57841c5eb06df51f39323cb3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 3): src/Morphir.Tooling/Scenarios/ManagementScenario.cs:52-59 | src/Morphir.Tooling/Scenarios/ManagementScenario.cs:124-131 | src/Morphir.Tooling/Scenarios/ManagementScenario.cs:207-214 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Scenarios/ManagementScenario.cs"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"17f459780009a2349025fc07bb8e1e0f59e14e944e1c247705a15cc653e52e02"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): src/Morphir.Tooling/Scenarios/ManagementScenario.cs:69-76 | src/Morphir.Tooling/Scenarios/ManagementScenario.cs:83-90 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Morphir.Tooling/Scenarios/ManagementScenario.cs:69\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Scenarios/ManagementScenario.cs"},"region":{"startLine":69}}}],"partialFingerprints":{"codehealthFindingId/v1":"977923cbe7f8ef240f850b2f1dc7a48246cff9a4f39371c7463885608872bd4d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7\u20138 lines \u00D7 2): src/Morphir.Models/IR/Classic/Value.fs:249-255 | src/Morphir.Models/IR/Classic/Value.fs:263-270 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/Value.fs"},"region":{"startLine":249}}}],"partialFingerprints":{"codehealthFindingId/v1":"46cb3252ba08206fc7cdaacb439c7b546156878f5ca3ee8a0cc58e188555fa94"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6\u20137 lines \u00D7 3): src/Morphir.Models/IR/Classic/Value.fs:250-256 | src/Morphir.Models/IR/Classic/Value.fs:265-270 | src/Morphir.Models/IR/Classic/Value.fs:305-311 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/Value.fs"},"region":{"startLine":250}}}],"partialFingerprints":{"codehealthFindingId/v1":"b8330734ceb47757585d83a7e6bd7eb6e036b7ddd1a2e01997220ee40356bdaf"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): src/Morphir.Models/Json/Codecs/TypeCodec.fs:154-160 | src/Morphir.Models/Json/Codecs/TypeCodec.fs:167-173 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/Json/Codecs/TypeCodec.fs"},"region":{"startLine":154}}}],"partialFingerprints":{"codehealthFindingId/v1":"6fe03fff876c7702fd64d22b7c0f7b0e02237708e1865f5c5595fcc5ed852d2b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): src/Morphir.IR.Pipeline.Plugins/Optimizer.fs:155-160 | src/Morphir.IR.Pipeline.Plugins/Optimizer.fs:164-169 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.IR.Pipeline.Plugins/Optimizer.fs"},"region":{"startLine":155}}}],"partialFingerprints":{"codehealthFindingId/v1":"2473b926c4025329742889d24a0f0f8886150663970ab5f4938f163c0e89b8d2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): src/Morphir.Models/IR/Classic/DSL/Patterns.fs:46-51 | src/Morphir.Models/IR/Classic/DSL/Patterns.fs:260-265 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Patterns.fs"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"d0d39d7001151688d19b4daf717a6dc71deb2532b4bf5f0b592102c7018deb67"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 3): src/Morphir.Models/Json/Codecs/FQNameCodec.fs:98-110 | src/Morphir.Models/Json/Codecs/LiteralCodec.fs:207-220 | src/Morphir.Models/Json/Codecs/PathCodec.fs:81-93 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from all 3 call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/Json/Codecs/FQNameCodec.fs"},"region":{"startLine":98}}}],"partialFingerprints":{"codehealthFindingId/v1":"2555fbdc7b82438ee0e331140f22523a2a4b384bbb27c6cb83aa878bef2437ea"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): src/Morphir.IR.Pipeline.Plugins/PrettyPrinter.fs:225-229 | src/Morphir.IR.Pipeline.Plugins/PrettyPrinter.fs:249-253 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.IR.Pipeline.Plugins/PrettyPrinter.fs"},"region":{"startLine":225}}}],"partialFingerprints":{"codehealthFindingId/v1":"a50e4cafb137a1b7251c6199fd2fcb47d93e238add11a5edb7e727558036a97d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): src/Morphir.IR.Pipeline.Plugins/PrettyPrinter.fs:221-225 | src/Morphir.IR.Pipeline.Plugins/PrettyPrinter.fs:239-243 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.IR.Pipeline.Plugins/PrettyPrinter.fs"},"region":{"startLine":221}}}],"partialFingerprints":{"codehealthFindingId/v1":"6a10eebbb1441eec41c140f92fc6d9289ddaaca43f0f89f804f90f4d376c8637"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): src/Morphir.IR.Pipeline/PipelineBuilder.fs:158-165 | src/Morphir.IR.Pipeline/PipelineBuilder.fs:177-184 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.IR.Pipeline/PipelineBuilder.fs"},"region":{"startLine":158}}}],"partialFingerprints":{"codehealthFindingId/v1":"9cd3c679c4b7f376d16ae7e4a979d0c2901c2a54d2cb8bc10a4f4591c6bb420a"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: Morphir.Core: Morphir.Core: abstractness 0.12, instability 0.00, distance 0.88 \u2014 zone of pain \u2014 concrete and depended on by 2 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"cec01533d53d7d7ccd866e580a3b5799f10f7760b46bce74cd42c2a8cca610a7"}},{"ruleId":"D8","level":"warning","message":{"text":"No test project references Morphir.Tool: No test project in this repository references Morphir.Tool (1 production source file(s)), so \u0060dotnet test\u0060 never loads it and no coverage tool can measure it \u2014 its code is absent from the 100.0% above rather than counted at zero. This is the whole assembly, not a gap within one: add a test project that references it (or a ProjectReference from an existing suite) and its coverage starts being measured."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tool/Morphir.Tool.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"812f336941bfff8779a700e517141e366b1d27e13f21f855c941f637b56c5cb7"}},{"ruleId":"D9","level":"note","message":{"text":"Inverted test pyramid: Only 14 % of tests are unit tests (57 unit vs 0 integration, 326 BDD); a broader unit base gives faster, more localised feedback."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3fc0c6fc621cd18b83a2d2c03ea6976b61fb4769f62dc21043f0af4cad912d10"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/Morphir.Models/IR/Classic/Value.fs: src/Morphir.Models/IR/Classic/Value.fs changed 3 times in last 90 days, max cyclomatic complexity 24 in Value.toString at line 187. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2025-12-05..2026-03-05, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272025-12-05 03:56:44 \u002B00:00\u0027 --until=\u00272026-03-05 03:56:44 \u002B00:00\u0027 --full-history --no-merges -- src/Morphir.Models/IR/Classic/Value.fs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/Value.fs"},"region":{"startLine":187}}}],"partialFingerprints":{"codehealthFindingId/v1":"f9e1e2e3505d03b1dc43cc4e9366aa9ec3d68e9a0caefdef9d1e79cdc3537820"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: src/Morphir.Tooling/Program.cs: src/Morphir.Tooling/Program.cs changed 5 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 1 (its worst body is Program.CreateToolingHost at line 19), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix: redirect all console output to stderr to preserve stdout for command output (#207)\u201D; \u201Cfix: redirect all logging to stderr to preserve stdout for command output (#205)\u201D; \u201Cfix: correct MSBuild XML encoding in VersionInfo generation (#198)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2025-12-05..2026-03-05, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272025-12-05 03:56:44 \u002B00:00\u0027 --until=\u00272026-03-05 03:56:44 \u002B00:00\u0027 --full-history --no-merges -- src/Morphir.Tooling/Program.cs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Program.cs"},"region":{"startLine":19}}}],"partialFingerprints":{"codehealthFindingId/v1":"fb1d4087b88c5c2df8817131c1e0d762973cfe7ca7abc96695b9365496293cb0"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #1: If anonymized user #1 becomes unavailable, 2 significant file(s) lose their only recent owner: src/Morphir.Core/IR/Name.cs, src/Morphir.Core/IR/Path.cs. Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ff3c6b657d8d53b5725cf70ff6d7ca598c1bef6392dcd13a9a3e3ed75f3228d4"}},{"ruleId":"D17","level":"error","message":{"text":"WriteOnlyPrivateField: private MorphirJsonOptions _morphirJsonOptions \u2014 assigned 1 time(s), read never \u2014 this field is written and never read anywhere its type can be reached from, so the state it keeps answers no question: every assignment to it computes a value that nothing observes, on every instance, for the lifetime of each one. It reads as a flag the code branches on, and nothing branches on it. Delete the field and its assignments \u2014 or, if the value was MEANT to be consulted, the missing read is the defect this row is pointing at, and the branch that should have depended on it is not there."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Core/Classic/IR/Codecs/ClassicTypeJsonConverterFactory.cs"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"0ba397c45a292fa5a86087eb38d403d993a53c0840a4c584b13ab3058e894f7f"}},{"ruleId":"D17","level":"error","message":{"text":"WriteOnlyPrivateField: private MorphirJsonOptions _morphirJsonOptions \u2014 assigned 1 time(s), read never \u2014 this field is written and never read anywhere its type can be reached from, so the state it keeps answers no question: every assignment to it computes a value that nothing observes, on every instance, for the lifetime of each one. It reads as a flag the code branches on, and nothing branches on it. Delete the field and its assignments \u2014 or, if the value was MEANT to be consulted, the missing read is the defect this row is pointing at, and the branch that should have depended on it is not there."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Core/IR/Codecs/TypeJsonConverter.cs"},"region":{"startLine":8}}}],"partialFingerprints":{"codehealthFindingId/v1":"afbf20081410ee9ad2688bb433d496e41d2ca11c206604f693564720e6effd63"}},{"ruleId":"D17","level":"error","message":{"text":"NoWarnInCsproj: CS0649 \u2014 this warning is switched off for the WHOLE project, in every file it builds, including code written years from now: nothing at the call site records that the rule was ever silenced, so the next reader has no reason to look here. Fix what the rule is reporting and drop the code from the list, or \u2014 if some occurrences really are legitimate \u2014 narrow the suppression to those sites and give each one its reason, so the rule keeps protecting the rest of the project."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"build/_build.csproj"},"region":{"startLine":8}}}],"partialFingerprints":{"codehealthFindingId/v1":"f09f81c3f190b17be70536dc9c3fc48524368a6a533a6b84f2d4a3b496f71028"}},{"ruleId":"D17","level":"error","message":{"text":"NoWarnInCsproj: CS0169 \u2014 this warning is switched off for the WHOLE project, in every file it builds, including code written years from now: nothing at the call site records that the rule was ever silenced, so the next reader has no reason to look here. Fix what the rule is reporting and drop the code from the list, or \u2014 if some occurrences really are legitimate \u2014 narrow the suppression to those sites and give each one its reason, so the rule keeps protecting the rest of the project."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"build/_build.csproj"},"region":{"startLine":8}}}],"partialFingerprints":{"codehealthFindingId/v1":"992cc15224ca8df5f5393ecb5e51a0f849ad491bcd33c45f1783f1588f2bd564"}},{"ruleId":"D17","level":"error","message":{"text":"NoWarnInCsproj: NU1608 \u2014 this warning is switched off for the WHOLE project, including builds years from now. It is raised by the build itself \u2014 the packaging, restore or SDK step \u2014 about the project as a whole, not by the compiler or an analyzer at a line of code, so there is no call site to narrow it to and no per-site directive that could carry a reason: this element is the only place the decision can be recorded. Say WHY here, in a comment on the entry, or fix what the rule is reporting and drop the code from the list."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Morphir.Tooling.csproj"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"70814eda0ca80138603bff577f8919cfd4efd5b2b82b26cbf9adb7893c5ccbe6"}},{"ruleId":"D21","level":"note","message":{"text":"The method \u0060GetArchComponent\u0060 appears to be a helper or internal accessor for the architecture component of a Runtime Identifier, while \u0060GetCurrentRid\u0060 returns the full Runtime Identifier string. While they serve different roles (one returns a component, the other the full ID), the naming convention for the \u0027current\u0027 context is inconsistent. \u0060GetCurrentRid\u0060 implies a getter for the current state, whereas \u0060GetArchComponent\u0060 is a generic getter. If \u0060GetArchComponent\u0060 is intended to get the architecture part of the *current* RID, it should likely follow the \u0060GetCurrent...\u0060 pattern or be named \u0060GetArch\u0060 to match the brevity of \u0060GetCurrentRid\u0060. However, given \u0060GetCurrentRid\u0060 is the primary accessor, \u0060GetArchComponent\u0060 is likely a distinct helper. A more significant inconsistency is found in the test helpers vs production code naming for \u0027RID\u0027.: Ensure consistency in how \u0027Runtime Identifier\u0027 components are named. If \u0060GetCurrentRid\u0060 is the standard accessor for the current environment\u0027s RID, consider if \u0060GetArchComponent\u0060 should be \u0060GetArch\u0060 or if it needs a qualifier like \u0060GetCurrentArchComponent\u0060 if it depends on the current state. Alternatively, if \u0060GetArchComponent\u0060 is a static utility, ensure the distinction between \u0027current state\u0027 and \u0027static utility\u0027 is clear in naming. (symbols: Morphir.Tooling.Infrastructure.RuntimeIdentifier.GetArchComponent, Morphir.Tooling.Infrastructure.RuntimeIdentifier.GetCurrentRid)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0038c32113b97796122f7322ea4d82457a05094d7ca65e041f2af12b0d61ba82"}},{"ruleId":"D21","level":"note","message":{"text":"The method \u0060GetCurrentRid\u0060 is implemented in both the production infrastructure class \u0060Morphir.Tooling.Infrastructure.RuntimeIdentifier\u0060 and the test step class \u0060Morphir.E2E.Tests.Features.AOT.NativeAOTCompilationSteps\u0060. While the test method is likely a helper to get the current RID for assertions, having the same name in a test class as a production method can be confusing if the test helper is not clearly marked as such (e.g., \u0060GetExpectedRid\u0060 or \u0060GetActualRid\u0060). However, since one is a test helper and the other is production code, this is a minor style issue rather than a semantic inconsistency. A stronger inconsistency is the duplication of logic/naming where the test helper duplicates the production method\u0027s name exactly, potentially implying they are the same thing, whereas the test helper might be wrapping or asserting against it.: Rename the test helper \u0060Morphir.E2E.Tests.Features.AOT.NativeAOTCompilationSteps.GetCurrentRid\u0060 to something more descriptive of its role in the test, such as \u0060GetActualRid\u0060 or \u0060GetRuntimeIdentifier\u0060, to distinguish it from the production \u0060GetCurrentRid\u0060 and clarify that it is part of the test setup/verification flow. (symbols: Morphir.E2E.Tests.Features.AOT.NativeAOTCompilationSteps.GetCurrentRid, Morphir.Tooling.Infrastructure.RuntimeIdentifier.GetCurrentRid)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9ee8157d20da7bde2e1a3cf8e27356097a188ece1ed5ad14e0c71ea04bd8f771"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d5b8f11381d61a58459ffc7c595fd52d09c03c711894a63a9578043d2338412b"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"86bb8fd820dd21756fa85ee7b9be1c8ef106bdf220177e528e2fccf71b7b4b69"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0c9d4d9d38a33ba3c28f1650876b55a539ce0ec49bbe15da48bbf69701018f3c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1c5cd6e845fee4df4956da8cd065590076a05029e3062395cf7435d48073ae13"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"297a8821f009a647ae856e57b8c9f893516d76e672e88770b0486e780441c831"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"27da7da39e6ff2a948f1724c4e866eb482fda1d6a6aa938d8117570f320814a8"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9bc5e751ad89694f32c367fc3bc98bdc87d73c780da417b200534d329a4cad52"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"65c5ce643814585b87a1392434c36aecd8d505b205d47c82d9e4aa8b942ddb33"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"24b4071d9079894d61b37e76742e5846ea031751800cbcf6dd0ada97cbd6e33c"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"297cc27931ed65b1da1f6a28e742602666b165713a84f7a15c962ec0575e1fa1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d967baadb37e1e8ea5c7d3fb0e12327a68affe6b98f6db795391908d9306e127"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c4288c81417f8d7999fd8c9c026f0361ab8afd275e3bc490877086e87f59a9c2"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1957a800f1a2cdc426d6c37547f2b4075de7a6a89e729aeb596eb302676c7c53"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"43a10c6907b46efb121c21d06b0a359237a975c39e6b144a50eb02d47b8c7f43"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"14921277dd497972dee9d25ae9878df50b844010ed23069a7d0fd7de346eba62"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"329d54251a77b7fcc1f11df47de13db6557375664b6a3d5ca2b16cc5ea497417"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c3dbbef4bb1ee1475cf73bc3ba7fadf60116bb93fe25c80595611c31ce26028a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d634cae71b3962d1d156e1729721aaaaf69c7d7b5607e9e897371c9f4c73294c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9084ed6b5cd9b49dc74154d7b0857d53049991139f5cec233992bbb8bfb2399c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"693128c6d2e1f459d3102145b2d12f9fb5d25cc1dc41581ab8bc9651fc323996"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"605664ab45fc33ce445d5b48734aafee68910dc5a440ae0d03b50651d4e17deb"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dbd602e1a969640541c60c800c4d3965263ea9dae26c30fd8ea6740b3e1510c4"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1fdec66755b6c9bd9043493e96cba7e8d32bd4c67c9977b29bfcf77e089425cb"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"282876d330d4906955d7f9280440f74ba5ac3bca07aad240d3a9bc7f8d21c1f9"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"03aa768abb3f92d7494af30e80ca363e5f83da2bf80313a6b2b8bbb08b73227c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d3abb989f1e3d2d765750fd16797cf337c787e12c39a3fd0f6400116796a65e8"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1c951985319529a87938cc6836ba7b43eae43bbb6085e90ef0b0b8a704715ded"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c1ead987719a4d7f2e0c0f10b63b71e7c465cfc0f49b12a297b583f65f1fd13a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a7b9485dbf33c7e309da9c5b855642122b29df514fcb1765d88f675a7a7d7204"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0da9845e9525b3a86849379b93f3fda845a5f721d89afe94cd1930891f579aed"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"35659f52da36f678acb7c0bac047ba8cc114b595ac5136be18dc0e88bc50ea8a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"aa92f3a5daf7dbbfe0b3600f570f12041c8864a0a673a1cbd2ad0783815c2468"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8e18ee88f9ff1879f1c6320c2ec40b6096c625cedb9741adac2dc0e244a6808f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"92245a52b767e0a0f123043bb7f15891f68f35c8054a6385dcf924c7f89dfc04"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e3a6205ba21265a3805fa52fc2dc2d64df0d36e0621ef5f4745098ced7b87f37"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3e9e9d938b2c8da22bea3ca1a54d8a9c4f22108683329559c9cdd3187495ca2c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"50adbcd711dca68f872cf2be71adcafe71227cad845e99d760eb77a975a1047e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d5d9ff4cb42fa8d33c910edbb9d94b96654754eff13360c21647d60bc6276c8a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"03aa03ae844f3b8016f0704b18d999f0eefe405453ec8051e008b62264fc8fc3"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"76bc2a6983fbe92f554749bebe21b004158408b6327a1758334a051e641a2e14"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eefa0471354574a7d56b2e024c1c8a5daee075201c39c4f36debea2f9c184174"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9df5b3aac7466f63963509aff9b7ac3a699f7a7c27b0f9b22c35607a96ed5613"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"20bfab8a37cc870e3591ca7908f471d62614873c955d5bd1bf7e9aaceeb1f13f"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8301aaebdb5d915a9134291926a3587f544c4c202dab519a666a6bca73ddec4a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"265e1521e303a1431bb1fa1573336fa6dbd56e4b75c6ff756c112c83c57c53cc"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3a4250207c76b123907d66fadb0ef1acb3c040f17f07291c733ee7da6a87d366"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d136f8d65335d000e5fd7cd8b79dbcdeb957d5f85e8c2f36302eeee7f9c1dd59"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"94af549e04a5c5b5e366b27f68c2ca7e828e1aded986aeabedc73d040414cfa2"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bcfb060184df5de3a4425ee47c457278b01463a5348f7f01809cb743895810a1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7874d2359efa9956dcc225d11c313959bfa1ee9bb6e57f3f256a7d0ec35dd6eb"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"311b92b76ae055e56010e62d54257e36bb38f0f2af46a7a0365c71b8a9bb4667"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"00ff1c0265419b21ef2ebc05b07f363b9333f5314f6e5a4ecd0d16c6b8fb5a1b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f0c091e0963fed213c3c2d181165758a326af8bfa59b169fd8e0d963ddd8e508"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cc5b434ad95bfac0c2dad151370267cd30b0a6d3b2a599faa6ef014c9bac757a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a50d66b429894cfc5e1a939b6fc16d208f9b8bbe3fb5464b1f47ad8b336092a4"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5bfb59674abfb872a23a046999d53c27d74456c2bce438e77b3f6e52aeddde36"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9202d068eb43bde3318987d5a5a1b4769bdf9ae4f03ba234bedf456edb75f57d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"79f65a244ea029db031b71374211e1980b040bc989a2839c4ce55667a21cd88f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"58cdf47133001c14a8b1794ecc2a0f242635f80d676c1c6e88c1522435debf6e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fe3c6595d71d19521e4b432d398fe1bac5809469334c779466c05e0c3ad5956a"},"taxa":[{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"320d27e18c213f2109f8df9d071a877d00d36167031ec9a285738176a2f38ad8"},"taxa":[{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ebe11557fcbf4fde8dbe03e70bc2c36296cb50d4a447a3c87cddd9d0dfb35bfd"},"taxa":[{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"25ac1d8fd273a86e278ba8b13d0fa9bb506aca583dc876a555ff688e6cdc6ab3"},"taxa":[{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c4029383ac4f09c15231dc999e513045a6459b9f4df8f30f4d180f1165e558fc"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1352","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"88ea3c4ed6172e7425ec8f75401d5c7b581380acc47ed6208e55addb3d314672"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1352","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"50a035a50aa41f5c2726e91947e9bd8f0814382aee72c2308bd9e401037a531a"},"properties":{"dependency":{"package":"System.Security.Cryptography.Xml","version":"9.0.0","advisory":"[GHSA redacted]","aliases":["[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"production","file":"build/_build.csproj"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"47818b50db2b79c30c4edb90952cc28a08dccf54111110d9dc084ae6be9b414b"},"properties":{"dependency":{"package":"AngleSharp","version":"1.2.0","advisory":"[GHSA redacted]","reachability":{"kind":"production","file":"tests/Morphir.Live.Tests/Morphir.Live.Tests.fsproj"}}}},{"ruleId":"D30","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e6474ae56907f21d65433a6575309f85070103ee909588acaa1f38b23e9af2ee"},"properties":{"dependency":{"package":"NuGet.Packaging","version":"6.12.1","advisory":"[GHSA redacted]","reachability":{"kind":"production","file":"build/_build.csproj"}}}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3b1568673c97a5ce9b1ec5a08dba083d705b7ca92047378b6f33333438b27491"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c790f76cf70ef3b7e11b2b2e046aa998549442297137ee1873617b41f8d8e165"}},{"ruleId":"D34","level":"note","message":{"text":"Dormant codebase: 68 of 73 significant files have no living knowledge \u2014 the codebase as a whole is dormant, not 68 separate risks. Counted over 73 of the 137 production source files in this repository: the rest are under the ~2,400-byte size floor this dimension measures over. Re-engage owners or document before change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4c69f1e54b7dd6fe9029dd02df6ba8f8145b789f2f18dbdaa086c40ded49dba6"}},{"ruleId":"D34","level":"note","message":{"text":"Most significant orphaned file: One of the orphaned files carrying the most lost knowledge \u2014 ranked by size weighted by the file\u0027s role in the codebase, the same weighting behind the score above, so core code outranks equally large plumbing. A reasonable place to start a read-through before the aggregate risk above bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Patterns.fs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"19edcf4e0366e7ee913afe935eb046f3a5b389e87a0ecd49ca8d8283cbe57d79"}},{"ruleId":"D34","level":"note","message":{"text":"Most significant orphaned file: One of the orphaned files carrying the most lost knowledge \u2014 ranked by size weighted by the file\u0027s role in the codebase, the same weighting behind the score above, so core code outranks equally large plumbing. A reasonable place to start a read-through before the aggregate risk above bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Models/IR/Classic/DSL/Values.fs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"44f56ad7e822b3c440a5e362e26cf908a10fb48245f79e40531a1ef0948a5138"}},{"ruleId":"D34","level":"note","message":{"text":"Most significant orphaned file: One of the orphaned files carrying the most lost knowledge \u2014 ranked by size weighted by the file\u0027s role in the codebase, the same weighting behind the score above, so core code outranks equally large plumbing. A reasonable place to start a read-through before the aggregate risk above bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Core/Classic/IR/Codecs/ClassicTypeJsonConverterFactory.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"010e9d3625f38dd05c0a8c3460b8019252ee71f74920f6c5e23675bb6cf85af6"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1b213f6eedd4b140d0bc37bdf1496f72811a643f34064f12518b32e9e83bcfc7"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e17f71490e4d120a48b2b2881ab866c93b272bef2febb673a3e8e42b2c288ab"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"759dca709f1a032fb6f624ce672e6afb5558fce53ecf01fb73618c4d33923164"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"90f83b4fa27db32740afe9540c905f3c0499caed87f61049a8a903ecc95b41c3"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0752d0df7434000fcabf1048e2de30a7a1a8b982b3db9a19898c4dec199856b4"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4bdd4cc8bc9daa17b484ebc3110c93822e162bc790a47d1c0ea9b9018f462d28"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fe274ba5adebde25ca0b3db842e44cbb1aaeb7cfecfbb7215cd452596ba1f4c2"}},{"ruleId":"AC4","level":"warning","message":{"text":"Anchor without href: An \u003Ca\u003E with no href, role or tabindex isn\u0027t focusable or keyboard-activatable. Give it a real href, or use a \u003Cbutton\u003E for an action."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Live/wwwroot/index.html"},"region":{"startLine":34}}}],"partialFingerprints":{"codehealthFindingId/v1":"3cd35e08e039088953b240fbad6d2576e2bdab3a4c8bc9f469ed27039ba67bc8"}},{"ruleId":"AC7","level":"warning","message":{"text":"Accessibility enforcement below the top rung: No accessibility enforcement found \u2014 no automated accessibility check runs over the HTML your app renders. Assert the accessibility invariants over that HTML in the test suite you already have (parse the output and assert, or drive a browser), and gate that test in CI so a regression blocks the merge. What was searched, so you can tell an absence from a miss: the 4 markup file(s) this pass actually assessed, the linter configuration checked in beside them, and this repository\u0027s test and CI files \u2014 matched by name against the accessibility checkers this dimension carries. An audit run outside the repository, a hosted scanner, or a check whose name is not one of those, is not seen here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d46019b86eff5ddad9db289e6802ac158899e980df54c34f67722442787ead62"}},{"ruleId":"GD1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: A shipped member still throws NotImplementedException \u2014 generated scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Core/IR/Codecs/TypeJsonConverter.cs"},"region":{"startLine":10}}}],"partialFingerprints":{"codehealthFindingId/v1":"105ff76e49db39ca58a349dcdaebbb5f605dad03c065e635729d24902ab43147"}},{"ruleId":"GD1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: A shipped member still throws NotImplementedException \u2014 generated scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Core/IR/Codecs/TypeJsonConverter.cs"},"region":{"startLine":15}}}],"partialFingerprints":{"codehealthFindingId/v1":"235189997f005a4a93426099abfdd998b689af9c6b37ce441e05dea2273ea3eb"}},{"ruleId":"IC1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: \u0060Read\u0060 is a shipped member whose whole body throws NotImplementedException \u2014 scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Core/IR/Codecs/TypeJsonConverter.cs"},"region":{"startLine":10}}}],"partialFingerprints":{"codehealthFindingId/v1":"8cc697202b2ab149f6ff2b548eb0330c375f9ad6d54388c26a8cc28d133e4422"}},{"ruleId":"IC1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: \u0060Write\u0060 is a shipped member whose whole body throws NotImplementedException \u2014 scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Core/IR/Codecs/TypeJsonConverter.cs"},"region":{"startLine":15}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c42b6b8c083c6e19e586fff597159e45f0d5c2062dcb0120abe6abf5d5b1935"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Scenarios/IrToolingScenario.cs"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"9f073f9114a0c6d6ac788c22a90cb64f43304992d81a17fc58990a2237e9df7c"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Scenarios/IrToolingScenario.cs"},"region":{"startLine":36}}}],"partialFingerprints":{"codehealthFindingId/v1":"43fa62674d56a02ddc6d216943630135c09c0199407c3723a1fe57a5543bc342"}},{"ruleId":"P10","level":"note","message":{"text":"Large public API surface: 160/197 types (81%) are public. For a library, every public type is a stability contract \u2014 make internal-by-default and expose only the intended API."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ed2ba843444ae377c17142f58f714e281e4bd3f183ab100ee1fbef389875d3e6"}},{"ruleId":"P10","level":"note","message":{"text":"No explicit versioning: No explicit version was found by any of the six routes this check reads: a \u0060\u003CVersion\u003E\u0060 or \u0060\u003CVersionPrefix\u003E\u0060 property; a \u0060GitVersion\u0060 or \u0060MinVer\u0060 reference; the split Arcade spelling (\u0060\u003CMajorVersion\u003E\u0060 AND \u0060\u003CMinorVersion\u003E\u0060 together); a hand-written \u0060[assembly: AssemblyVersion]\u0060 in source, with \u0060bin/\u0060 and \u0060obj/\u0060 excluded so the SDK\u0027s generated AssemblyInfo cannot satisfy it; or a version handed to MSBuild by the pipeline, as \u0060-p:Version=\u0060 / \u0060-p:PackageVersion=\u0060 on a \u0060dotnet build\u0060 or \u0060dotnet pack\u0060 line. Only project files, first-party source and CI files are read, so a version computed somewhere none of those can see is invisible here. A published library needs explicit semantic versioning so consumers can reason about breaking changes."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f25ed74033b9d9b8444441f8dacb71f30e7bc88fc4c32bea7aeaebd4fda20968"}},{"ruleId":"P3","level":"note","message":{"text":"No SAST: No static application security testing detected. For this repository\u0027s stack, add \u0060semgrep --config=auto\u0060 plus gitleaks for committed secrets (F# is not a CodeQL language and has no language-specific SAST engine) as a CI step. What was searched, so you can tell an absence from a miss: the 37172 CI workflow file(s) in this repository, and the scanner and linter configuration checked in beside them. A scan that runs outside CI, one configured in your forge\u0027s web UI rather than in a committed file, or a tool whose name is none of those this check carries, is not seen \u2014 if that is your case the row is wrong, and saying so is more useful than adding a second scanner."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6e54424179c892f03ef2fd003130ac4bd43f39bbf3b1ca0a0143e25acb80ec87"}},{"ruleId":"P7","level":"warning","message":{"text":"Outbound HTTP without resilience: Outbound HTTP calls were found with no timeout or retry policy around them. This codebase ships libraries/tools rather than a service it operates, so the failure lands differently: an unbounded call hangs the caller\u0027s process \u2014 a build step, a CLI run, a UI thread \u2014 with no way out."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ade5e84aadd8f28a7d64d01fa0cdf67f4f716f0df3ba2641e60599b08325bd5f"}},{"ruleId":"PF1","level":"note","message":{"text":"No performance benchmarks: No benchmark suite was found by the two searches this check runs. FIRST, a BenchmarkDotNet package reference in any project file \u2014 every project the workspace loaded, plus a walk of project files on disk that never loaded, because a benchmark suite is exactly the project a partial load drops. SECOND, a script harness: a file whose name contains \u0060benchmark\u0060 and ends \u0060.py\u0060, \u0060.sh\u0060, \u0060.ps1\u0060, \u0060.bash\u0060, \u0060.rb\u0060, \u0060.js\u0060 or \u0060.mjs\u0060, credited ONLY when this repository\u0027s CI text also mentions benchmarks \u2014 a harness no pipeline runs is read as a fixture, deliberately. Neither search can see a benchmark suite in another ecosystem\u0027s idiom (a Go \u0060testing.B\u0060 file, a JMH or criterion project, a pytest-benchmark run), so this is \u0027no benchmark found by those two searches\u0027, not a verdict that the repository has none. Where code is performance-sensitive, a benchmark guards against silent regressions \u2014 but it\u0027s a bonus here, not a deduction."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"fd90d18ee3bb127e8033d41e8efe4e131487a6d794a5730a72c56105ef7485ea"}},{"ruleId":"PF3","level":"warning","message":{"text":"Sync-over-async blocking: 1 blocking call(s) on async work (.Wait()/.GetAwaiter().GetResult()) \u2014 these waste a thread and can deadlock wherever a synchronization context is in play (a UI thread, or a caller that has one)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"2dedb76432d7d4f359386b5c37564c0f3de368182a77e31aa8af9ba73f9a4def"}},{"ruleId":"PF3","level":"warning","message":{"text":"Awaits without ConfigureAwait(false): Only 0/24 awaits use ConfigureAwait(false). A library that captures the caller\u0027s context can stall or deadlock its host \u2014 the classic way a dependency drags an app down."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9409e0163ea155fbf96ac6090b9aebd32c62808d0aee4aa2a31f3d049418befc"}},{"ruleId":"X1","level":"warning","message":{"text":"Sync-over-async (deadlock risk): Blocking on a Task with \u0060.Wait()\u0060/\u0060.GetAwaiter().GetResult()\u0060 can deadlock (and wastes a thread). Prefer awaiting it: make the caller \u0060async\u0060 and \u0060await\u0060 instead. Where a synchronous entry point must stay \u2014 a public sync API you cannot break, or a process entry point that must not return until the work finishes \u2014 the block belongs in ONE documented bridge and never inside code that is already async; and where it already is that bridge, give the wait a TIMEOUT so a hung task fails the call instead of hanging the process."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/MorphirCli.cs"},"region":{"startLine":266}}}],"partialFingerprints":{"codehealthFindingId/v1":"9b10b604cc379e42b866f9d914af61d0c2c01691045b0c3af5a9d1e14c70802e"}},{"ruleId":"X18","level":"warning","message":{"text":"Disposes a dependency it does not own: \u0060_host\u0060 is never created by \u0060MorphirCliApp\u0060 \u2014 every assignment to it takes a constructor parameter \u2014 yet this type disposes it here (line 273). Its declared type \u0060IHost\u0060 is an interface, so the instance came from whoever resolved it, and that owner decides when it ends. Disposing it from here reaches outside this object\u0027s lifetime: a dependency shared with the rest of the process is torn down when THIS instance goes away, and the real owner\u0027s later \u0060Dispose()\u0060 runs a second time on an object already disposed. Drop the call \u2014 a type disposes what it constructed, and only that. If this dependency genuinely is exclusive to this instance, construct it here (or take an owned factory) so the ownership is stated in the code rather than assumed."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/MorphirCli.cs"},"region":{"startLine":273}}}],"partialFingerprints":{"codehealthFindingId/v1":"86b17fc26baae7d0a14ac0aeb1528f943ddf30bbede369762d47542039fd791f"}},{"ruleId":"X18","level":"warning","message":{"text":"Disposes a dependency it does not own: \u0060_host\u0060 is never created by \u0060MorphirCliApp\u0060 \u2014 every assignment to it takes a constructor parameter \u2014 yet this type disposes it here (line 286). Its declared type \u0060IHost\u0060 is an interface, so the instance came from whoever resolved it, and that owner decides when it ends. Disposing it from here reaches outside this object\u0027s lifetime: a dependency shared with the rest of the process is torn down when THIS instance goes away, and the real owner\u0027s later \u0060Dispose()\u0060 runs a second time on an object already disposed. Drop the call \u2014 a type disposes what it constructed, and only that. If this dependency genuinely is exclusive to this instance, construct it here (or take an owned factory) so the ownership is stated in the code rather than assumed."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/MorphirCli.cs"},"region":{"startLine":286}}}],"partialFingerprints":{"codehealthFindingId/v1":"0d2f0698f7c2424d20213a0d54e575021738e2aba677b811030038812ffcc931"}},{"ruleId":"X3","level":"warning","message":{"text":"Swallowed exception (caught, then discarded): \u0060catch\u0060 takes every exception and records none of it \u2014 the body neither logs it, rethrows it, nor even names it, so the failure is discarded as completely as by an empty catch and only the substituted value survives. Log it through whatever this codebase already uses to report problems, narrow the catch to the exception this call can actually raise, or say in a comment on the catch why the failure genuinely cannot matter."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Infrastructure/JsonSchema/SchemaValidator.cs"},"region":{"startLine":116}}}],"partialFingerprints":{"codehealthFindingId/v1":"5e4bbe9b9406c3e7604355ecfc8943d31b7b8f588085d28cefc9e52a8cc241e2"}},{"ruleId":"X3","level":"warning","message":{"text":"Swallowed exception (caught, then discarded): \u0060catch\u0060 takes every exception and records none of it \u2014 the body neither logs it, rethrows it, nor even names it, so the failure is discarded as completely as by an empty catch and only the substituted value survives. Log it through whatever this codebase already uses to report problems, narrow the catch to the exception this call can actually raise, or say in a comment on the catch why the failure genuinely cannot matter."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Morphir.Tooling/Infrastructure/JsonSchema/SchemaValidator.cs"},"region":{"startLine":156}}}],"partialFingerprints":{"codehealthFindingId/v1":"c9667ba338f72a69d401193e6b9bc54aff694d1da0bcf415befeda5b432cbd49"}},{"ruleId":"X5","level":"note","message":{"text":"Null-forgiving operator (\u0060!\u0060) suppressions reduce the NRT score: ~1.6 \u0060!\u0060 suppressions per 1k syntax nodes \u2014 37 suppression(s) across the 23548 syntax node(s) in code where nullable warnings are ENABLED, which is the only code a \u0060!\u0060 can suppress anything in (a \u0060!\u0060 under \u0060#nullable disable\u0060 is inert and is not counted, and its file\u0027s nodes are not in the denominator). Each one tells the compiler to trust you about null, suppressing the very safety NRTs provide."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"93cfe05d4ad8c8c171267603b23dfe289b74842e38edd1b7bfed59cc32bda337"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-1104","guid":"4c918cb5-b2a6-6c55-9963-a44ee464305e","name":"CWE-1104","shortDescription":{"text":"CWE-1104"},"helpUri":"https://cwe.mitre.org/data/definitions/1104.html"},{"id":"CWE-1352","guid":"5257f322-5cfc-6b52-bedd-0b9a526b4c7d","name":"CWE-1352","shortDescription":{"text":"CWE-1352"},"helpUri":"https://cwe.mitre.org/data/definitions/1352.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-522","guid":"71fb233e-ce6a-ae57-9419-ef8373540b09","name":"CWE-522","shortDescription":{"text":"CWE-522"},"helpUri":"https://cwe.mitre.org/data/definitions/522.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-829","guid":"13c33925-97fb-5a5e-b40c-56d328b8a4d7","name":"CWE-829","shortDescription":{"text":"CWE-829"},"helpUri":"https://cwe.mitre.org/data/definitions/829.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":77,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}