{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D10","name":"Test Quality","shortDescription":{"text":"Test Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D10"},{"id":"D11","name":"Test Reliability","shortDescription":{"text":"Test Reliability"},"helpUri":"https://codehealth.canine.dev/dimensions/D11"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AX8","name":"Test isolation","shortDescription":{"text":"Test isolation"},"helpUri":"https://codehealth.canine.dev/dimensions/AX8"},{"id":"ED5","name":"Idempotency","shortDescription":{"text":"Idempotency"},"helpUri":"https://codehealth.canine.dev/dimensions/ED5"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P10","name":"Library API \u0026 versioning","shortDescription":{"text":"Library API \u0026 versioning"},"helpUri":"https://codehealth.canine.dev/dimensions/P10"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"PF3","name":"Async \u0026 latency hygiene","shortDescription":{"text":"Async \u0026 latency hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/PF3"},{"id":"SC1","name":"Supply-chain hygiene","shortDescription":{"text":"Supply-chain hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/SC1"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X28","name":"Index access outside its own emptiness guard","shortDescription":{"text":"Index access outside its own emptiness guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X28"},{"id":"X7","name":"Silent fallback defaults","shortDescription":{"text":"Silent fallback defaults"},"helpUri":"https://codehealth.canine.dev/dimensions/X7"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"ZipArchiveReader.parseCell (cyclomatic 20): ZipArchiveReader.parseCell has cyclomatic complexity 20 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet.Net/ZipArchiveReader.fs"},"region":{"startLine":215}}}],"partialFingerprints":{"codehealthFindingId/v1":"7cf8791dfcebdb2ae17234cf399e73ceaa694fa1f0fe1d02e16f75eb2df51a4c"}},{"ruleId":"D1","level":"warning","message":{"text":"Transform.Workbook.parseSheet.Static (cyclomatic 17): Transform.Workbook.parseSheet.Static has cyclomatic complexity 17 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing. This is NOT this file\u0027s highest cyclomatic complexity: Transform.splitRowsAndColumns (cyclomatic 19) is higher and carries no row of its own \u2014 it was excluded as a flat dispatcher (a long switch/match over independent cases: many branches, almost no nesting), which this dimension does not treat as a refactor obligation. It is named here so the ranking you see in this file is not mistaken for the whole of it; the excluded method is counted neither in this dimension\u0027s figures nor in its score."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/DSL/Transform.fs"},"region":{"startLine":112}}}],"partialFingerprints":{"codehealthFindingId/v1":"e6b1a9c47a65249ffafd5ec589d45767fe9d489375212ada2c379ecd155e634e"}},{"ruleId":"D2","level":"warning","message":{"text":"ZipArchiveReader.parseCell (cognitive 36): ZipArchiveReader.parseCell has cognitive complexity 36 (threshold 15). Drivers by points: if/else 9 (13 pts), error handling 3 (11 pts), match/switch 2 (7 pts), boolean chains 5 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body. This file is where this pass\u0027s cognitive complexity CONCENTRATES: src/FsSpreadsheet.Net/ZipArchiveReader.fs holds 3 of the 7 methods over the threshold \u2014 including the worst \u2014 and 32 of the 49 points over it (65%), 3.2\u00D7 the next-largest file (src/FsSpreadsheet/SheetBuilder.fs at 10). No single row can show this, because each is measured only against the threshold: reducing this one file moves this dimension further than any other file in the repository."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet.Net/ZipArchiveReader.fs"},"region":{"startLine":215}}}],"partialFingerprints":{"codehealthFindingId/v1":"c5ada30ca8cdfb4a9a5d5dfa8843ae64ff06b1a99ab4443012c23b7f3bd8d5da"}},{"ruleId":"D2","level":"warning","message":{"text":"SheetBuilder.FsWorksheet.Populate (cognitive 23): SheetBuilder.FsWorksheet.Populate has cognitive complexity 23 (threshold 15). Drivers by points: if/else 5 (11 pts), loops 4 (9 pts), match/switch 1 (3 pts) (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/SheetBuilder.fs"},"region":{"startLine":132}}}],"partialFingerprints":{"codehealthFindingId/v1":"1052d675bb1972b71af13dad9d13a643a14c8e7c736f56330989fd78f6735fc2"}},{"ruleId":"D2","level":"warning","message":{"text":"ZipArchiveReader.parseWorksheet (cognitive 22): ZipArchiveReader.parseWorksheet has cognitive complexity 22 (threshold 15). Drivers by points: if/else 5 (15 pts), loops 2 (4 pts), boolean chains 2, error handling 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body. This file is where this pass\u0027s cognitive complexity CONCENTRATES: src/FsSpreadsheet.Net/ZipArchiveReader.fs holds 3 of the 7 methods over the threshold \u2014 including the worst \u2014 and 32 of the 49 points over it (65%), 3.2\u00D7 the next-largest file (src/FsSpreadsheet/SheetBuilder.fs at 10). No single row can show this, because each is measured only against the threshold: reducing this one file moves this dimension further than any other file in the repository."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet.Net/ZipArchiveReader.fs"},"region":{"startLine":264}}}],"partialFingerprints":{"codehealthFindingId/v1":"d8ed4c8e8c5758b9ca6d0a5fdb3575794129530da3c77ebe3f519c2b4d8748dd"}},{"ruleId":"D2","level":"warning","message":{"text":"FsTable.RescanFieldNames (cognitive 20): FsTable.RescanFieldNames has cognitive complexity 20 (threshold 15). Drivers by points: if/else 5 (13 pts), loops 2 (4 pts), match/switch 1 (3 pts) (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/Tables/FsTable.fs"},"region":{"startLine":496}}}],"partialFingerprints":{"codehealthFindingId/v1":"9967b6d270a5d28f04723a40afdca9c59888f36e148eedac0e5fbda28c52a395"}},{"ruleId":"D2","level":"warning","message":{"text":"ZipArchiveReader.getStyles (cognitive 19): ZipArchiveReader.getStyles has cognitive complexity 19 (threshold 15). Drivers by points: if/else 4 (12 pts), loops 3 (7 pts) (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body. This file is where this pass\u0027s cognitive complexity CONCENTRATES: src/FsSpreadsheet.Net/ZipArchiveReader.fs holds 3 of the 7 methods over the threshold \u2014 including the worst \u2014 and 32 of the 49 points over it (65%), 3.2\u00D7 the next-largest file (src/FsSpreadsheet/SheetBuilder.fs at 10). No single row can show this, because each is measured only against the threshold: reducing this one file moves this dimension further than any other file in the repository."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet.Net/ZipArchiveReader.fs"},"region":{"startLine":140}}}],"partialFingerprints":{"codehealthFindingId/v1":"6149aad3284ddfdec1772df7e27eb4aa5ee1e733ee75af358768a0b7bfe1115c"}},{"ruleId":"D2","level":"warning","message":{"text":"SheetBuilder.FsTable.Populate (cognitive 17): SheetBuilder.FsTable.Populate has cognitive complexity 17 (threshold 15). Drivers by points: loops 4 (9 pts), if/else 5 (7 pts), boolean chains 1 (nesting depth added 7). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/SheetBuilder.fs"},"region":{"startLine":72}}}],"partialFingerprints":{"codehealthFindingId/v1":"ff460a6a76948163adf05afbcc0f974e34c0b0c5230e7ed9f1b10b3fc59e35db"}},{"ruleId":"D2","level":"warning","message":{"text":"FsExtensions.DataType.ofXlsXCell.Static (cognitive 17): FsExtensions.DataType.ofXlsXCell.Static has cognitive complexity 17 (threshold 15). Drivers by points: if/else 7 (9 pts), boolean chains 4, error handling 1 (2 pts), match/switch 1 (2 pts) (nesting depth added 4). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet.Net/FsExtensions.fs"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"ce58d5463e515329396711e0d071983cc9f524cd9116025f68a1fedd86811b95"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: FsWorksheet: TooManyMethods \u2014 61 methods. The bar is 30 methods; this is 31 over it, 2.03\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/FsWorksheet.fs"},"region":{"startLine":10}}}],"partialFingerprints":{"codehealthFindingId/v1":"19351f881ac1bc378ba3e81139f1e669709b4ace355e83bc32299162d3ff7895"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: FsTable: TooManyMethods \u2014 48 methods. The bar is 30 methods; this is 18 over it, 1.60\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/Tables/FsTable.fs"},"region":{"startLine":11}}}],"partialFingerprints":{"codehealthFindingId/v1":"79f09628fd11eda131a9708b51821725a16ec84743a80c9ec37f48c076af48d3"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFunctions: FsExtensions: TooManyFunctions \u2014 41 functions. The bar is 30 functions; this is 11 over it, 1.37\u00D7 the bar. The counted members are a module\u0027s functions \u2014 a module holds no instance state, so there is no shared data to group them by and no type to move them onto. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no single module carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet.Net/FsExtensions.fs"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"fc69be79759b7f5df24e338ea5b838c6996523a6cc0310724c27e00e0ac26cfd"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: FsCell: TooManyMethods \u2014 40 methods. The bar is 30 methods; this is 10 over it, 1.33\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/Cells/FsCell.fs"},"region":{"startLine":64}}}],"partialFingerprints":{"codehealthFindingId/v1":"0f2485241ef278e490755df55c03661edb3d9828fce39804ad6b0d79b27f93f8"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: FsCellsCollection: TooManyMethods \u2014 40 methods. The bar is 30 methods; this is 10 over it, 1.33\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/Cells/FsCellsCollection.fs"},"region":{"startLine":18}}}],"partialFingerprints":{"codehealthFindingId/v1":"8094c2e97124755a4a24f9e42801ceae6e9731905f86f01bab41e81da145f0e7"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFunctions: Row: TooManyFunctions \u2014 36 functions. The bar is 30 functions; this is 6 over it, 1.20\u00D7 the bar. The counted members are a module\u0027s functions \u2014 a module holds no instance state, so there is no shared data to group them by and no type to move them onto. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no single module carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet.Net/Row.fs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"bee986b7d4e08592c105b5a856a12269c9c9ce34f43e5fa8835bb74a5b4df33a"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFunctions: SheetData: TooManyFunctions \u2014 33 functions. The bar is 30 functions; this is 3 over it, 1.10\u00D7 the bar. The counted members are a module\u0027s functions \u2014 a module holds no instance state, so there is no shared data to group them by and no type to move them onto. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no single module carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet.Net/SheetData.fs"},"region":{"startLine":8}}}],"partialFingerprints":{"codehealthFindingId/v1":"e31ba8a6842229606ce7595fc96606c015d27db90555ee0f8812bf6d7229767c"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFunctions: Spreadsheet: TooManyFunctions \u2014 31 functions. The bar is 30 functions; this is 1 over it, 1.03\u00D7 the bar. The counted members are a module\u0027s functions \u2014 a module holds no instance state, so there is no shared data to group them by and no type to move them onto. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no single module carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet.Net/Spreadsheet.fs"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"225bcb164ed7ba4f085e6c2ba3f21c4a8ba3a5d60e395992be8d47d82c559764"}},{"ruleId":"D4","level":"warning","message":{"text":"Members sharing a duplicated core (6 members, 50\u002B identical tokens): src/FsSpreadsheet/DSL/CellBuilder.fs:1-196 | src/FsSpreadsheet/DSL/ColumnBuilder.fs:1-209 | src/FsSpreadsheet/DSL/RowBuilder.fs:1-200 | src/FsSpreadsheet/DSL/SheetBuilder.fs:1-139 | src/FsSpreadsheet/DSL/TableBuilder.fs:1-120 | src/FsSpreadsheet/DSL/WorkbookBuilder.fs:1-114 \u2014 These 6 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below \u2014 it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 6 times. The repair is at the members\u0027 grain \u2014 factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 6 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/DSL/CellBuilder.fs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"34de43a6aff0d106cab53087a0d9485ef7dac55d26d87f921d5456c79b4d1a16"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (27\u201330 lines \u00D7 2): src/FsSpreadsheet.Js/FsExtensions.fs:39-68 | src/FsSpreadsheet.Py/FsExtension.fs:37-63 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet.Js/FsExtensions.fs"},"region":{"startLine":39}}}],"partialFingerprints":{"codehealthFindingId/v1":"8eb658175b51d274dde76c29d0661560c01323d37f8a71db7961358e42549617"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (27\u201328 lines \u00D7 2): src/FsSpreadsheet.Net/FsExtensions.fs:64-90 | src/FsSpreadsheet.Net/FsExtensions.fs:98-125 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet.Net/FsExtensions.fs"},"region":{"startLine":64}}}],"partialFingerprints":{"codehealthFindingId/v1":"785a3cb0692930ec304ebd7ab9773a32bf0a61bb336575215f18632057651fb4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (25 lines \u00D7 6): src/FsSpreadsheet/DSL/CellBuilder.fs:90-114 | src/FsSpreadsheet/DSL/ColumnBuilder.fs:116-140 | src/FsSpreadsheet/DSL/RowBuilder.fs:106-130 | src/FsSpreadsheet/DSL/SheetBuilder.fs:113-137 | src/FsSpreadsheet/DSL/TableBuilder.fs:94-118 | src/FsSpreadsheet/DSL/WorkbookBuilder.fs:88-112 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from all 6 call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/DSL/CellBuilder.fs"},"region":{"startLine":90}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b70e9989f5ee8aa6ff80449e93f0e45a0da35c533dfe7583ed6b70c8ce73ce3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (19\u201321 lines \u00D7 2): src/FsSpreadsheet.Net/Row.fs:297-317 | src/FsSpreadsheet.Net/Row.fs:319-337 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet.Net/Row.fs"},"region":{"startLine":297}}}],"partialFingerprints":{"codehealthFindingId/v1":"49c543682a685b68cd7fb3d35cbefe1a804bd2ffeb15821298bc2808464dcf66"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): src/FsSpreadsheet/FsColumn.fs:45-61 | src/FsSpreadsheet/FsRow.fs:47-63 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/FsColumn.fs"},"region":{"startLine":45}}}],"partialFingerprints":{"codehealthFindingId/v1":"6c50b63cea7d54708750143e44df78fd08dc7107be5d4806c3ee3782d0f7632f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11\u201315 lines \u00D7 3): src/FsSpreadsheet.Net/Workbook.fs:116-126 | src/FsSpreadsheet.Net/Workbook.fs:139-153 | src/FsSpreadsheet.Net/Workbook.fs:164-177 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet.Net/Workbook.fs"},"region":{"startLine":116}}}],"partialFingerprints":{"codehealthFindingId/v1":"1650cee0fac336ad6c383d9ea4571ced3d39b79f4643866578a1319d8bdff257"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13\u201314 lines \u00D7 2): src/FsSpreadsheet.CsvIO/FsExtension.fs:81-94 | src/FsSpreadsheet.CsvIO/FsExtension.fs:99-111 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet.CsvIO/FsExtension.fs"},"region":{"startLine":81}}}],"partialFingerprints":{"codehealthFindingId/v1":"acc0900dcb5faa5ab6727128f8c81845f675953adb13acd159d5b4e67f0d0731"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12\u201314 lines \u00D7 2): src/FsSpreadsheet/Json/Worksheet.fs:38-51 | src/FsSpreadsheet/Json/Worksheet.fs:105-116 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/FsSpreadsheet/Json/Worksheet.fs:38\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/Json/Worksheet.fs"},"region":{"startLine":38}}}],"partialFingerprints":{"codehealthFindingId/v1":"92649b1aacd6a4a8e325929fa996d9ab4865661166efde442c718c6b1b5007e4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): src/FsSpreadsheet/Json/Worksheet.fs:71-83 | src/FsSpreadsheet/Json/Worksheet.fs:136-148 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/FsSpreadsheet/Json/Worksheet.fs:71\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/Json/Worksheet.fs"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"6c4790e0677413105e7b5c27a8368bc75f8099c7e8f06b1620c7f96d5199bb98"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): src/FsSpreadsheet/DSL/SheetBuilder.fs:31-41 | src/FsSpreadsheet/DSL/TableBuilder.fs:33-43 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/DSL/SheetBuilder.fs"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"9926e385425e80ac595edf4917d4de3507ce504af6504908e61fc12e20c8f8fb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): src/FsSpreadsheet/Tables/FsTable.fs:120-130 | src/FsSpreadsheet/Tables/FsTable.fs:134-144 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/FsSpreadsheet/Tables/FsTable.fs:120\u0060 it runs out through the closing brace of the declaration holding it and carries on into the declaration that follows \u2014 the window is the tail of one member plus the head of the next, so no call can be substituted for those exact lines, and the smallest declaration that contains all of them is the type they sit in. The repeated unit is the member each site sits in: where those members\u0027 bodies are the same, move one whole member to the shared location and have the others delegate to it; where the copies are a run of near-identical overloads or wrappers that differ only in their signatures, the repetition IS the run \u2014 a one-line delegation has no helper inside it to lift \u2014 so generate the run from the set it enumerates, or accept it and keep each member\u0027s own documentation with it. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/Tables/FsTable.fs"},"region":{"startLine":120}}}],"partialFingerprints":{"codehealthFindingId/v1":"2fd880224537c29d4cea9006ad83edcecca9f731df9c6d9f274ccc58dbd19792"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): src/FsSpreadsheet/Json/Column.fs:16-25 | src/FsSpreadsheet/Json/Row.fs:16-25 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/FsSpreadsheet/Json/Column.fs:16\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/Json/Column.fs"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"97864c949b1f183294bbeed6eae301f76ea80fe82cc7fdf044accdba5119c1a2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8\u20139 lines \u00D7 2): src/FsSpreadsheet.Js/Json.fs:41-48 | src/FsSpreadsheet.Py/Json.fs:35-43 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet.Js/Json.fs"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"735cf8d2aef2fac17a9206479685ed85df16f11641d4d30e99551ab9d3ab8d5c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): src/FsSpreadsheet/Cells/FsCellsCollection.fs:328-336 | src/FsSpreadsheet/Cells/FsCellsCollection.fs:366-374 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/FsSpreadsheet/Cells/FsCellsCollection.fs:328\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/Cells/FsCellsCollection.fs"},"region":{"startLine":328}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c5c8e70fb7baa988ae049d9784e377d1acb80c3f97eb94418b9c76fa1f67a37"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): src/FsSpreadsheet.Net/Stylesheet.fs:87-94 | src/FsSpreadsheet.Net/ZipArchiveReader.fs:56-63 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet.Net/Stylesheet.fs"},"region":{"startLine":87}}}],"partialFingerprints":{"codehealthFindingId/v1":"c137d4797602d20cf04d5e41c07258e3761d3e04e65bb4666eeace8e1d50d1f6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): src/FsSpreadsheet.Net/Table.fs:308-314 | src/FsSpreadsheet.Net/Table.fs:320-326 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/FsSpreadsheet.Net/Table.fs:308\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet.Net/Table.fs"},"region":{"startLine":308}}}],"partialFingerprints":{"codehealthFindingId/v1":"5d5ecd07419ca8ca7fcfd709934edb70f134d3e7b7c1dfea61fc3965c755c4c3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6\u20137 lines \u00D7 2): src/FsSpreadsheet.Net/Worksheet.fs:121-126 | src/FsSpreadsheet.Net/Worksheet.fs:139-145 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/FsSpreadsheet.Net/Worksheet.fs:121\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet.Net/Worksheet.fs"},"region":{"startLine":121}}}],"partialFingerprints":{"codehealthFindingId/v1":"cae70e118a77a8b1d5f8e0fbc18d633b7fc90d0f3e28da87fad288115d10eaf7"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): src/FsSpreadsheet/SheetBuilder.fs:73-79 | src/FsSpreadsheet/SheetBuilder.fs:206-212 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/SheetBuilder.fs"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"cded2351b22261d689e19cfad441018ec0d187ca7deb10cb33280e69ea3a49a2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): src/FsSpreadsheet/SheetBuilder.fs:133-139 | src/FsSpreadsheet/SheetBuilder.fs:206-212 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/SheetBuilder.fs"},"region":{"startLine":133}}}],"partialFingerprints":{"codehealthFindingId/v1":"30af8cbe32e5ca923a35a92693b3fb1f90f166a99938668773e3b35330b6bcbd"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): src/FsSpreadsheet/Json/Cell.fs:23-28 | src/FsSpreadsheet/Json/Cell.fs:37-42 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/FsSpreadsheet/Json/Cell.fs:23\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/Json/Cell.fs"},"region":{"startLine":23}}}],"partialFingerprints":{"codehealthFindingId/v1":"d63ba189c8836cae8704ed059ce3730e813ef0712a19e2c58b327dcd1e54a5dc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): src/FsSpreadsheet/DSL/CellBuilder.fs:35-42 | src/FsSpreadsheet/DSL/RowBuilder.fs:23-30 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/FsSpreadsheet/DSL/CellBuilder.fs"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"049f8382e70c63d0b420f6109b05be0f2c982e2d4ab0b69fddfe8804e679c8cf"}},{"ruleId":"D8","level":"warning","message":{"text":"Coverage not measured \u2014 no coverage collector is wired up: Coverage NOT MEASURED: \u0060--collect:\u0022XPlat Code Coverage\u0022\u0060 names a data collector that ships in the \u0060coverlet.collector\u0060 package, and this repository wires up none \u2014 no test project references it and no runsettings declares one. The absence of coverage here is therefore not evidence about the suite or about our analyzer environment: without a collector, \u0060--collect\u0060 produces nothing even from a suite that builds and passes. Add a \u0060coverlet.collector\u0060 PackageReference to the test project(s) (or commit the Cobertura/OpenCover/lcov report your CI produces) and real coverage will be measured. It is excluded from the score rather than counted as a near-zero defect."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"62e63e619c28f057e129f2997c965d32a457366a9ce18ca019ffb6bdfba85c99"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: values: No conventional assertion call was detected, and 10 of 10 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/JS/Exceljs.js"},"region":{"startLine":10}}}],"partialFingerprints":{"codehealthFindingId/v1":"8abe3e81d6c04fc5442327dd2f826180dbb1695134f2f7b0219350c17872becf"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: table: No conventional assertion call was detected, and 10 of 10 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/JS/Exceljs.js"},"region":{"startLine":30}}}],"partialFingerprints":{"codehealthFindingId/v1":"9551b3075f733fe64fdd0e8db307962c93f403ed2251e42f748a3946657e2227"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: isa.investigation.xlsx: No conventional assertion call was detected, and 10 of 10 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/JS/Exceljs.js"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"f3c2beeaf05e7f3aaee42162160e976dc2b5b815af47c84cf676cdcd4b73da73"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: isa_assay_keineTables: No conventional assertion call was detected, and 10 of 10 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/JS/Exceljs.js"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"3229202481663f1fe79abedb26088d2847b496986fe71edc62b3c58f6e592773"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: fsspreadsheet.minimalTable: No conventional assertion call was detected, and 10 of 10 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/JS/Exceljs.js"},"region":{"startLine":64}}}],"partialFingerprints":{"codehealthFindingId/v1":"c8823201381f8f7a083c96df41dec7ef6939a87e477323fa306b0bcf0003ea12"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: isa.study.xlsx: No conventional assertion call was detected, and 10 of 10 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/JS/Exceljs.js"},"region":{"startLine":70}}}],"partialFingerprints":{"codehealthFindingId/v1":"7576850f5a59d41f72770aae9a35277e791c6c5fb56791ce716def5f1903f302"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: readOldClosedXml: No conventional assertion call was detected, and 10 of 10 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/JS/Exceljs.js"},"region":{"startLine":76}}}],"partialFingerprints":{"codehealthFindingId/v1":"d4a2f2c942b5dd8195f0ba1a8757247864ebb4753f3ab095db8d749a4c07513b"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: passes: No conventional assertion call was detected, and 10 of 10 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/JS/Exceljs.js"},"region":{"startLine":84}}}],"partialFingerprints":{"codehealthFindingId/v1":"b766c2679ea67fb096d907cfc7c7350f91cad6a13e32838bff977f956e515b04"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: from excel: No conventional assertion call was detected, and 10 of 10 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/JS/Exceljs.js"},"region":{"startLine":114}}}],"partialFingerprints":{"codehealthFindingId/v1":"11cf063f46976504e9580632e5f871c51e6a36d160fa5c6382701d902859fa18"}},{"ruleId":"D10","level":"note","message":{"text":"No direct assertions: should return -1 when the value is not present: No conventional assertion call was detected, and 10 of 10 tests in \u0060the repository root\u0060 read the same way \u2014 so this is treated as that project\u0027s convention rather than a broken test, and it does not drag the score. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a project of runnable samples compiled as tests, where a run that does not throw is the only check. If it is the latter, these methods genuinely verify nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/JS/Core.js"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b2052b97ea2e4eed1ce9fce1fde0b0c7cd1447e386abe741835e641d8729e91"}},{"ruleId":"D10","level":"note","message":{"text":"Test project verifies nothing: the repository root: No conventional assertion call was detected in 10 of 10 tests in \u0060the repository root\u0060 \u2014 the project as a whole, not one method. Two things look like this: verification that happens indirectly (an approval/verifier harness or BDD step methods), or a suite that genuinely checks nothing. If it is the latter, this project passes unconditionally and cannot fail."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/JS/Exceljs.js"},"region":{"startLine":10}}}],"partialFingerprints":{"codehealthFindingId/v1":"cf94801c4041b50c2e3c9396509690ea81213e9ef0ce35215fc86bb32ffe52b2"}},{"ruleId":"D12","level":"warning","message":{"text":"Prerelease dependency: Microsoft.DotNet.Interactive: Microsoft.DotNet.Interactive resolves to 1.0.0-beta.24229.4, a prerelease build. Prerelease packages carry no support policy, may change breaking between previews and can be unlisted \u2014 pin a stable release before shipping, or record the reason this preview is required."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b96144747cb39aa6e82edba3460933fb5e7faac667a3182bdf5a24d843642069"}},{"ruleId":"D12","level":"warning","message":{"text":"Prerelease dependency: Microsoft.DotNet.Interactive.Formatting: Microsoft.DotNet.Interactive.Formatting resolves to 1.0.0-beta.24229.4, a prerelease build. Prerelease packages carry no support policy, may change breaking between previews and can be unlisted \u2014 pin a stable release before shipping, or record the reason this preview is required."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"242681f9aed19f449ead9c5151fb3419f520ec020999ef9a003337e4f1ae9656"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #1: If anonymized user #1 becomes unavailable, 3 significant file(s) lose their only recent owner: src/FsSpreadsheet.Net/Cell.fs, src/FsSpreadsheet.Js/Cell.fs, src/FsSpreadsheet.Py/Cell.fs. Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5d880023dafba752d011fac7f159d1e5516b7d087c890f015d42f1736d8db62d"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no architecture or design documentation: The document is a usage guide; no architecture or design documentation exists in the set."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/index.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c334a70505afa4daa2af8f154917ed2cd6ce2b63062cc24f27ed83dc966043b4"}},{"ruleId":"D26","level":"note","message":{"text":"Projects may be oversized for their cohesion: 1 of 1 project(s) overshoot their size bounds, lowering Project Cohesion to 0.0/10. The most over is \u0060(repository root)\u0060 (9145 LoC, 138 module-visible types across 12 directories). Review these for cohesion \u2014 draw the boundary inside the module first (group each responsibility into its own package or directory and keep the cross-boundary members non-public), since splitting a published package moves types between packages and breaks consumers."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d5a94650dc74886a0f1f08eb9fb6775f1fc395279ef7e901c970c9d26f767a72"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"86e52e48f5534c39e1d16ce0052d62966b7bcfe3644f8dad0834c227e5b67fb9"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1e37790c1acaafcd8f8ea1c610818b26bd8bbf6bbb6280ccf4efb89f600de68e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"058defd02c84da32979a86528ce67f2a36071d021c81e24de59647371aca0b01"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4f0bf5cba78164d02e4c6eadf4bb0d9ec91f4796fbfbfd1e6d28c38329510d6f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a91a8c7ab3db9c9bc12cacd4ec0e6fe5d1cfd04431668736deddcb62fe8c1535"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dcfadace57f76b4307a70cf37d46a3c6b2e5c05467253919ae4d3f9d63c529db"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4abfb1ce33f8a99db9ce842794218e1d3761cc36a41bc00ac9fd5f18c86c890b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"50c7d86ee34bf1daca23d0d2bd5ade0f79cc97aa61aed9d7cad326355daf4600"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d155236a8e3d40194479662cf80a032f74b8d77b5c516024ec439f85ad0713f5"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e8b5c1277a98354b75d02c4f857121f49a6a9e06e30888c300d37b027e86f991"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1329","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1f79a595d62add568feda19f54d04fdad0273f072ae213a4e4ad714127a8a2fe"},"properties":{"dependency":{"package":"System.Drawing.Common","version":"4.7.0","advisory":"[GHSA redacted]","reachability":{"kind":"production","file":"build/Build.fsproj"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"80be2362a0aacfe00a8164aedf008cc9b3c5563cc99639b97baf91859f2b9485"},"properties":{"dependency":{"package":"System.Formats.Asn1","version":"6.0.0","advisory":"[GHSA redacted]","reachability":{"kind":"production","file":"build/Build.fsproj"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3add75db01ee22304cfddf5f7e64296f5227bafb7644dc7a0c0ce035fe9fb2b6"},"properties":{"dependency":{"package":"System.IO.Packaging","version":"6.0.0","advisory":"[GHSA redacted]","aliases":["[GHSA redacted]"],"reachability":{"kind":"production","file":"tests/Speedtest/Speedtest.fsproj"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c475b5d776175d1181892c3e7e72c31acdbe224ac300e32808399947498db6c9"},"properties":{"dependency":{"package":"System.Text.Json","version":"8.0.0","advisory":"[GHSA redacted]","aliases":["[GHSA redacted]"],"reachability":{"kind":"production","file":"src/FsSpreadsheet.Interactive/FsSpreadsheet.Interactive.fsproj"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a39a021ec66f5261d0cb19f88ef354f73bd671d730442cfbdc62290469f6eece"},"properties":{"dependency":{"package":"minimatch","version":"3.1.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5a31a0b5364830f542d37385755d27dd90f97746286a80cb6c17836bc6e14179"},"properties":{"dependency":{"package":"js-yaml","version":"4.3.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fc3a276440d0ba0f42a76f0f05d4bcadc154f53b4f76137d309f4163a01cee35"},"properties":{"dependency":{"package":"brace-expansion","version":"1.1.11","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"22afa891f042056c64f70e50419ac0131db93b099ffdfec999789df9bbb7b0c5"},"properties":{"dependency":{"package":"brace-expansion","version":"2.0.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"02f809db19946ff68dac97234c12abfc27eedc356a81cfd3ee9e444a4053df19"},"properties":{"dependency":{"package":"tmp","version":"0.2.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6c89993a1ea03beb84f6b69a0440aa089477476a8d8a2e55c2799b42491c3a09"},"properties":{"dependency":{"package":"braces","version":"3.0.3","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"87839f7289af0999d94a99db6eefa4a0c9cb8f6ea36e8599abd5bd35ced532c8"},"properties":{"dependency":{"package":"serialize-javascript","version":"6.0.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c93c9e9a7508d1bb1d419bfe67a538fbd81572ddc053c684d546cff31ca78570"},"properties":{"dependency":{"package":"uuid","version":"8.3.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D34","level":"note","message":{"text":"Orphaned files with no living knowledge: 6 of 43 analysed file(s) have no living knowledge left \u2014 their last meaningful change has decayed away, so if one breaks, no one currently understands it (counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 43 of the 68 production source files in this repository met that bar). None is large enough to earn a read-through of its own, so this row stands in for the per-file rows rather than raising one each \u2014 most significant first: src/FsSpreadsheet.Js/Workbook.fs, src/FsSpreadsheet/FsRow.fs, src/FsSpreadsheet/DSL/RowBuilder.fs, src/FsSpreadsheet/Tables/FsTableField.fs, src/FsSpreadsheet.Interactive/FsSparseMatrix.fs, src/FsSpreadsheet.Interactive/Formatters.fs. Attach the read to the next change that touches one of them: have a second person review that change, and leave behind a short comment or test recording what the file is for, so the knowledge comes back at the cost of a change you were making anyway."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ce861fd78f6935114d3a342cb90ad25870f984e1042954fcbbe27c0e23be3658"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0752d0df7434000fcabf1048e2de30a7a1a8b982b3db9a19898c4dec199856b4"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d068c977b62d9a977df1bb6f53e8b00b586c3abee955f91d715f92b8e019d624"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ace515990e7ee0f17b5c17e44dd168a5bdecf90804a3a3dd845cf05540978013"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"M2","level":"note","message":{"text":"No architecture diagram/doc: No C4/Structurizr/PlantUML/Mermaid/Graphviz/D2 diagram, no drawn diagram named for the architecture, no file named \u0060architecture\u0060 or \u0060design\u0060 in any markup this check reads, and nothing in the README, docs or contributor guides that announces the shape \u2014 no \u0060## Architecture\u0060 heading, no \u0022architecture overview\u0022/\u0022high-level design\u0022 phrasing, no \u0022the architecture is \u2026\u0022 introduction, no guided code tour. A shape laid out in prose that never names itself as the architecture is not visible to this check, and neither is one kept outside the repository, so this row reports the absence of a re-findable shape document \u2014 not evidence that nobody wrote the shape down."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0c190e7c159d1850ee706c3ac4486e151e8a4fe169de4bf61436b9f399654f06"}},{"ruleId":"P3","level":"note","message":{"text":"No SAST: No static application security testing detected. For this repository\u0027s stack, add \u0060semgrep --config=auto\u0060 plus gitleaks for committed secrets (F# is not a CodeQL language and has no language-specific SAST engine) as a CI step. What was searched, so you can tell an absence from a miss: the 3412 CI workflow file(s) in this repository, and the scanner and linter configuration checked in beside them. A scan that runs outside CI, one configured in your forge\u0027s web UI rather than in a committed file, or a tool whose name is none of those this check carries, is not seen \u2014 if that is your case the row is wrong, and saying so is more useful than adding a second scanner."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6e54424179c892f03ef2fd003130ac4bd43f39bbf3b1ca0a0143e25acb80ec87"}},{"ruleId":"P4","level":"note","message":{"text":"No release approval gate: The release is automated and no gate that pauses it for a human is DECLARED IN THIS REPOSITORY\u0027S PIPELINE FILES. What was read: every file under \u0060.github/workflows/\u0060, \u0060.forgejo/workflows/\u0060, \u0060.gitea/workflows/\u0060, \u0060.azuredevops/\u0060 and \u0060.azure-pipelines/\u0060, plus \u0060.gitlab-ci*\u0060 and \u0060azure-pipelines*\u0060 \u2014 with comment text stripped, so documenting a gate is not declaring one. What would have counted: GitLab\u0027s \u0060when: manual\u0060, CircleCI\u0027s \u0060type: approval\u0060, an Azure \u0060ManualValidation@\u0060 task or an \u0060approvals:\u0060 block, a Jenkins \u0060input\u0060 step, a \u0060uses:\u0060 step naming an approval action, an \u0060environment:\u0060 paired with \u0060reviewers\u0060 / \u0060required_reviewers\u0060 / \u0060protection\u0060 / \u0060wait-timer\u0060 / \u0060deployment_branch_policy\u0060, a draft-release step, a \u0060workflow_dispatch\u0060 promotion, or a release-event gate. \u2605 What this cannot see, because none of it is a file: a GitHub environment whose required reviewers are configured in repo SETTINGS, a branch protection rule, or an organisation deployment policy \u2014 all of them real, enforced gates that live outside the repository. If yours is one of those, this row is wrong and nothing in the tree could have told us. Otherwise: whatever the release trigger points at is published to users unreviewed, so a mistagged or unverified commit ships and the only remedy is a follow-up release."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6c11e2dbd483b4b423b95ac61bfcc7af1d55351b28a20d2b1105b31cfe38cc60"}},{"ruleId":"SC1","level":"warning","message":{"text":"NuGet dependencies are not locked: No packages.lock.json and no central package management \u2014 restores aren\u0027t reproducible or pinned (SSDF PW.4.4). Enable \u003CRestorePackagesWithLockFile\u003Etrue\u003C/RestorePackagesWithLockFile\u003E (commit the lockfile) or adopt Directory.Packages.props. Advisory \u2014 never scored."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0a97b4f69ccac509400ece7eedefb06d3ede0522cd4d8bcb5c068bea719545a6"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1104","guid":"4c918cb5-b2a6-6c55-9963-a44ee464305e","name":"CWE-1104","shortDescription":{"text":"CWE-1104"},"helpUri":"https://cwe.mitre.org/data/definitions/1104.html"},{"id":"CWE-1329","guid":"f70f1c3f-4ccf-cb5e-bdd3-03ba4868d36d","name":"CWE-1329","shortDescription":{"text":"CWE-1329"},"helpUri":"https://cwe.mitre.org/data/definitions/1329.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-522","guid":"71fb233e-ce6a-ae57-9419-ef8373540b09","name":"CWE-522","shortDescription":{"text":"CWE-522"},"helpUri":"https://cwe.mitre.org/data/definitions/522.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-829","guid":"13c33925-97fb-5a5e-b40c-56d328b8a4d7","name":"CWE-829","shortDescription":{"text":"CWE-829"},"helpUri":"https://cwe.mitre.org/data/definitions/829.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":25,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}