{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D39","name":"IL Efficiency","shortDescription":{"text":"IL Efficiency"},"helpUri":"https://codehealth.canine.dev/dimensions/D39"},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AC1","name":"Text alternatives","shortDescription":{"text":"Text alternatives"},"helpUri":"https://codehealth.canine.dev/dimensions/AC1"},{"id":"AC2","name":"Forms \u0026 labels","shortDescription":{"text":"Forms \u0026 labels"},"helpUri":"https://codehealth.canine.dev/dimensions/AC2"},{"id":"AC3","name":"Page structure","shortDescription":{"text":"Page structure"},"helpUri":"https://codehealth.canine.dev/dimensions/AC3"},{"id":"AC4","name":"Keyboard semantics","shortDescription":{"text":"Keyboard semantics"},"helpUri":"https://codehealth.canine.dev/dimensions/AC4"},{"id":"AC5","name":"ARIA correctness","shortDescription":{"text":"ARIA correctness"},"helpUri":"https://codehealth.canine.dev/dimensions/AC5"},{"id":"AC6","name":"Visual \u0026 motion safety","shortDescription":{"text":"Visual \u0026 motion safety"},"helpUri":"https://codehealth.canine.dev/dimensions/AC6"},{"id":"AC7","name":"A11y enforcement","shortDescription":{"text":"A11y enforcement"},"helpUri":"https://codehealth.canine.dev/dimensions/AC7"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"ED5","name":"Idempotency","shortDescription":{"text":"Idempotency"},"helpUri":"https://codehealth.canine.dev/dimensions/ED5"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"S1","name":"Web-Security Posture","shortDescription":{"text":"Web-Security Posture"},"helpUri":"https://codehealth.canine.dev/dimensions/S1"},{"id":"SC1","name":"Supply-chain hygiene","shortDescription":{"text":"Supply-chain hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/SC1"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X28","name":"Index access outside its own emptiness guard","shortDescription":{"text":"Index access outside its own emptiness guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X28"},{"id":"X6","name":"Hand-rolled structured-format parsing","shortDescription":{"text":"Hand-rolled structured-format parsing"},"helpUri":"https://codehealth.canine.dev/dimensions/X6"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D2","level":"warning","message":{"text":"Http.formatCode (cognitive 21): Http.formatCode has cognitive complexity 21 (threshold 15). Drivers by points: if/else 6 (11 pts), match/switch 3 (7 pts), error handling 1 (2 pts), boolean chains 1 (nesting depth added 10). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/FantomasOnline.Shared/Http.fs"},"region":{"startLine":44}}}],"partialFingerprints":{"codehealthFindingId/v1":"18a3682a7b5340e7ba0f330a0ef30384fe43035b654e4ed305f0070184458a12"}},{"ruleId":"D4","level":"warning","message":{"text":"Edited copy of a member (21 corresponding lines): src/client/fsharp/FantomasOnline/Decoders.fs:1-45 | src/server/FantomasOnline.Shared/Decoders.fs:1-39 \u2014 These two members are one piece of code written twice and then edited apart: 21 consecutive lines correspond almost exactly, broken only by small local edits. Most of that correspondence is NOT reported as duplicated blocks below \u2014 the edits cut it into fragments and only the largest of them clear the block floor, so the rows below understate it. The repair is at the members\u0027 grain \u2014 factor the shared implementation into one the two call with their differences as parameters or as an injected step, or, where the difference is systematic (an extra return value, one transport against another), generate one from the other. Left alone, the next edit has to be made twice and the two will drift further apart."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/FantomasOnline.Shared/Decoders.fs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"2a9117b4640157ea50f3865cf55be68c5bde05259a0d6696c36aef4027856f4c"}},{"ruleId":"D4","level":"warning","message":{"text":"Members sharing a duplicated core (6 members, 50\u002B identical tokens): src/server/FantomasOnlineMain/FormatCode.fs:1-206 | src/server/FantomasOnlinePreview/FormatCode.fs:1-200 | src/server/FantomasOnlineV6/FormatCode.fs:1-131 | src/server/FantomasOnlineV7/FormatCode.fs:1-131 | src/server/FantomasOnlineV8/FormatCode.fs:1-190 | src/server/OakViewer/GetOak.fs:1-157 \u2014 These 6 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below \u2014 it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 6 times. The repair is at the members\u0027 grain \u2014 factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 6 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/FantomasOnlineMain/FormatCode.fs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3ebcce462ae512eae318ef7bd326388ea633d9d05d6beca9b20ceec00ff7656b"}},{"ruleId":"D4","level":"warning","message":{"text":"Members sharing a duplicated core (5 members, 50\u002B identical tokens): src/server/FantomasOnlineMain/Lambda.fs:1-26 | src/server/FantomasOnlinePreview/Lambda.fs:1-26 | src/server/FantomasOnlineV6/Lambda.fs:1-26 | src/server/FantomasOnlineV7/Lambda.fs:1-26 | src/server/FantomasOnlineV8/Lambda.fs:1-26 \u2014 These 5 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below \u2014 it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 5 times. The repair is at the members\u0027 grain \u2014 factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 5 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/FantomasOnlineMain/Lambda.fs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"38e653adb8fdf6f874535834e5025e45f919d40310b46c613212276e097629f1"}},{"ruleId":"D4","level":"warning","message":{"text":"Members sharing a duplicated core (5 members, 50\u002B identical tokens): src/server/FantomasOnlineMain/Program.fs:1-49 | src/server/FantomasOnlinePreview/Program.fs:1-52 | src/server/FantomasOnlineV6/Program.fs:1-46 | src/server/FantomasOnlineV7/Program.fs:1-46 | src/server/FantomasOnlineV8/Program.fs:1-46 \u2014 These 5 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below \u2014 it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 5 times. The repair is at the members\u0027 grain \u2014 factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 5 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/FantomasOnlineMain/Program.fs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a752037b3ff5dd73b3ed071b2331bd0f993049e113d039e18c23ae63bf9e4cd"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (63 lines \u00D7 2): src/server/FantomasOnlineV6/FormatCode.fs:37-99 | src/server/FantomasOnlineV7/FormatCode.fs:37-99 \u2014 \u0060src/server/FantomasOnlineV6/FormatCode.fs\u0060 and \u0060src/server/FantomasOnlineV7/FormatCode.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 6 separate duplicated blocks between them, totalling at least 183 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/server/FantomasOnlineV6/FormatCode.fs:37\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/FantomasOnlineV6/FormatCode.fs"},"region":{"startLine":37}}}],"partialFingerprints":{"codehealthFindingId/v1":"24cd1aec275339a961f9cd89c9f326ecb13e4b0546f1cf0ece850081b38117c6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (50\u201351 lines \u00D7 3): src/server/FantomasOnlineMain/FormatCode.fs:55-105 | src/server/FantomasOnlinePreview/FormatCode.fs:49-99 | src/server/FantomasOnlineV8/FormatCode.fs:54-103 \u2014 \u0060src/server/FantomasOnlineMain/FormatCode.fs\u0060 and \u0060src/server/FantomasOnlinePreview/FormatCode.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 8 separate duplicated blocks between them, totalling at least 256 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/FantomasOnlineMain/FormatCode.fs"},"region":{"startLine":55}}}],"partialFingerprints":{"codehealthFindingId/v1":"dc7bbbae1ecc8c97b1d1e419f7df09f310e3ebbb2caa570523d687fcbe1b25de"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (40 lines \u00D7 2): src/server/FantomasOnlineMain/FormatCode.fs:150-189 | src/server/FantomasOnlinePreview/FormatCode.fs:144-183 \u2014 \u0060src/server/FantomasOnlineMain/FormatCode.fs\u0060 and \u0060src/server/FantomasOnlinePreview/FormatCode.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 8 separate duplicated blocks between them, totalling at least 256 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/server/FantomasOnlineMain/FormatCode.fs:150\u0060 it runs out through the closing brace of the declaration holding it and carries on into the declaration that follows \u2014 the window is the tail of one member plus the head of the next, so no call can be substituted for those exact lines, and the smallest declaration that contains all of them is the type they sit in. The repeated unit is the member each site sits in: where those members\u0027 bodies are the same, move one whole member to the shared location and have the others delegate to it; where the copies are a run of near-identical overloads or wrappers that differ only in their signatures, the repetition IS the run \u2014 a one-line delegation has no helper inside it to lift \u2014 so generate the run from the set it enumerates, or accept it and keep each member\u0027s own documentation with it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/FantomasOnlineMain/FormatCode.fs"},"region":{"startLine":150}}}],"partialFingerprints":{"codehealthFindingId/v1":"d64ed8eb0dd180fba3108ca149a3b274253f1b1a6ab316df28317c153e66b498"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (35\u201337 lines \u00D7 3): src/server/FantomasOnlineMain/FormatCode.fs:106-142 | src/server/FantomasOnlinePreview/FormatCode.fs:100-136 | src/server/FantomasOnlineV8/FormatCode.fs:104-138 \u2014 \u0060src/server/FantomasOnlineMain/FormatCode.fs\u0060 and \u0060src/server/FantomasOnlinePreview/FormatCode.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 8 separate duplicated blocks between them, totalling at least 256 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/server/FantomasOnlineMain/FormatCode.fs:106\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/FantomasOnlineMain/FormatCode.fs"},"region":{"startLine":106}}}],"partialFingerprints":{"codehealthFindingId/v1":"271acbbea330a5fd122b8efe96644228a2beb9b597f595522a4f84665cd2cbc0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (32\u201336 lines \u00D7 4): src/server/FantomasOnlineMain/FormatCode.fs:127-162 | src/server/FantomasOnlinePreview/FormatCode.fs:121-156 | src/server/FantomasOnlineV8/FormatCode.fs:123-158 | src/server/OakViewer/GetOak.fs:84-115 \u2014 \u0060src/server/FantomasOnlineMain/FormatCode.fs\u0060 and \u0060src/server/FantomasOnlinePreview/FormatCode.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 8 separate duplicated blocks between them, totalling at least 256 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/server/FantomasOnlineMain/FormatCode.fs:127\u0060 it runs out through the closing brace of the declaration holding it and carries on into the declaration that follows \u2014 the window is the tail of one member plus the head of the next, so no call can be substituted for those exact lines, and the smallest declaration that contains all of them is the type they sit in. The repeated unit is the member each site sits in: where those members\u0027 bodies are the same, move one whole member to the shared location and have the others delegate to it; where the copies are a run of near-identical overloads or wrappers that differ only in their signatures, the repetition IS the run \u2014 a one-line delegation has no helper inside it to lift \u2014 so generate the run from the set it enumerates, or accept it and keep each member\u0027s own documentation with it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/FantomasOnlineMain/FormatCode.fs"},"region":{"startLine":127}}}],"partialFingerprints":{"codehealthFindingId/v1":"04948c815ee266bcc0a48300787ba42356d0bd854dc09fc2e6624444351b272d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (34 lines \u00D7 5): src/server/FantomasOnlineMain/FormatCode.fs:12-45 | src/server/FantomasOnlinePreview/FormatCode.fs:12-45 | src/server/FantomasOnlineV6/FormatCode.fs:11-44 | src/server/FantomasOnlineV7/FormatCode.fs:11-44 | src/server/FantomasOnlineV8/FormatCode.fs:11-44 \u2014 \u0060src/server/FantomasOnlineMain/FormatCode.fs\u0060 and \u0060src/server/FantomasOnlinePreview/FormatCode.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 8 separate duplicated blocks between them, totalling at least 256 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/FantomasOnlineMain/FormatCode.fs"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"69a669bee29da53c6ef5637d8541a89532ac50ca769d8e36258a1708700d91ce"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (28 lines \u00D7 3): src/server/FantomasOnlineV6/FormatCode.fs:87-114 | src/server/FantomasOnlineV7/FormatCode.fs:87-114 | src/server/FantomasOnlineV8/FormatCode.fs:146-173 \u2014 \u0060src/server/FantomasOnlineV6/FormatCode.fs\u0060 and \u0060src/server/FantomasOnlineV7/FormatCode.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 6 separate duplicated blocks between them, totalling at least 183 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/server/FantomasOnlineV6/FormatCode.fs:87\u0060 it runs out through the closing brace of the declaration holding it and carries on into the declaration that follows \u2014 the window is the tail of one member plus the head of the next, so no call can be substituted for those exact lines, and the smallest declaration that contains all of them is the type they sit in. The repeated unit is the member each site sits in: where those members\u0027 bodies are the same, move one whole member to the shared location and have the others delegate to it; where the copies are a run of near-identical overloads or wrappers that differ only in their signatures, the repetition IS the run \u2014 a one-line delegation has no helper inside it to lift \u2014 so generate the run from the set it enumerates, or accept it and keep each member\u0027s own documentation with it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/FantomasOnlineV6/FormatCode.fs"},"region":{"startLine":87}}}],"partialFingerprints":{"codehealthFindingId/v1":"3d69eacb9dad1f90f6cc5d5d83efac65c50f2d5349248eac9d5be210ac0bdd7e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (26 lines \u00D7 5): src/server/FantomasOnlineMain/Program.fs:1-26 | src/server/FantomasOnlinePreview/Program.fs:1-26 | src/server/FantomasOnlineV6/Program.fs:1-26 | src/server/FantomasOnlineV7/Program.fs:1-26 | src/server/FantomasOnlineV8/Program.fs:1-26 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 5 call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made 5 times. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/server/FantomasOnlineMain/Program.fs:1\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/FantomasOnlineMain/Program.fs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"44e367f63d1dc43ba81f5617000d71a73b97e7075effb39662f34377a953c86c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (23 lines \u00D7 5): src/server/FantomasOnlineMain/FormatCode.fs:184-206 | src/server/FantomasOnlinePreview/FormatCode.fs:178-200 | src/server/FantomasOnlineV6/FormatCode.fs:109-131 | src/server/FantomasOnlineV7/FormatCode.fs:109-131 | src/server/FantomasOnlineV8/FormatCode.fs:168-190 \u2014 \u0060src/server/FantomasOnlineMain/FormatCode.fs\u0060 and \u0060src/server/FantomasOnlinePreview/FormatCode.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 8 separate duplicated blocks between them, totalling at least 256 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/FantomasOnlineMain/FormatCode.fs"},"region":{"startLine":184}}}],"partialFingerprints":{"codehealthFindingId/v1":"f8a881a5a3b7d38b01094eb52e9647d6f0897e404435e368a27a00b29ab8db92"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (18\u201319 lines \u00D7 5): src/server/FantomasOnlineMain/FormatCode.fs:149-167 | src/server/FantomasOnlinePreview/FormatCode.fs:143-161 | src/server/FantomasOnlineV6/FormatCode.fs:86-103 | src/server/FantomasOnlineV7/FormatCode.fs:86-103 | src/server/FantomasOnlineV8/FormatCode.fs:145-162 \u2014 \u0060src/server/FantomasOnlineMain/FormatCode.fs\u0060 and \u0060src/server/FantomasOnlinePreview/FormatCode.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 8 separate duplicated blocks between them, totalling at least 256 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/server/FantomasOnlineMain/FormatCode.fs:149\u0060 it runs out through the closing brace of the declaration holding it and carries on into the declaration that follows \u2014 the window is the tail of one member plus the head of the next, so no call can be substituted for those exact lines, and the smallest declaration that contains all of them is the type they sit in. The repeated unit is the member each site sits in: where those members\u0027 bodies are the same, move one whole member to the shared location and have the others delegate to it; where the copies are a run of near-identical overloads or wrappers that differ only in their signatures, the repetition IS the run \u2014 a one-line delegation has no helper inside it to lift \u2014 so generate the run from the set it enumerates, or accept it and keep each member\u0027s own documentation with it. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/FantomasOnlineMain/FormatCode.fs"},"region":{"startLine":149}}}],"partialFingerprints":{"codehealthFindingId/v1":"f3ed21c5cd7695bf751208d194b643d7869259d1aa4d91c1e5e26d736ec040d3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (19 lines \u00D7 2): src/client/fsharp/FantomasOnline/Decoders.fs:8-26 | src/server/FantomasOnline.Shared/Decoders.fs:8-26 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/client/fsharp/FantomasOnline/Decoders.fs:8\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/FantomasOnline.Shared/Decoders.fs"},"region":{"startLine":8}}}],"partialFingerprints":{"codehealthFindingId/v1":"13af8b8b221b2fca1d92cf85d65438981b6d369cf7bda69fcff50b9997b1227a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 6): src/server/FantomasOnlineMain/FormatCode.fs:148-163 | src/server/FantomasOnlinePreview/FormatCode.fs:142-157 | src/server/FantomasOnlineV6/FormatCode.fs:85-100 | src/server/FantomasOnlineV7/FormatCode.fs:85-100 | src/server/FantomasOnlineV8/FormatCode.fs:144-159 | src/server/OakViewer/GetOak.fs:101-116 \u2014 \u0060src/server/FantomasOnlineMain/FormatCode.fs\u0060 and \u0060src/server/FantomasOnlinePreview/FormatCode.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 8 separate duplicated blocks between them, totalling at least 256 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/server/FantomasOnlineMain/FormatCode.fs:148\u0060 it runs out through the closing brace of the declaration holding it and carries on into the declaration that follows \u2014 the window is the tail of one member plus the head of the next, so no call can be substituted for those exact lines, and the smallest declaration that contains all of them is the type they sit in. The repeated unit is the member each site sits in: where those members\u0027 bodies are the same, move one whole member to the shared location and have the others delegate to it; where the copies are a run of near-identical overloads or wrappers that differ only in their signatures, the repetition IS the run \u2014 a one-line delegation has no helper inside it to lift \u2014 so generate the run from the set it enumerates, or accept it and keep each member\u0027s own documentation with it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/FantomasOnlineMain/FormatCode.fs"},"region":{"startLine":148}}}],"partialFingerprints":{"codehealthFindingId/v1":"0e465c003b5e26ac6d8816bc3b8a9798e6fc3c45458ab76245a92c60c5fd4ff2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 5): src/server/FantomasOnlineMain/Lambda.fs:13-26 | src/server/FantomasOnlinePreview/Lambda.fs:13-26 | src/server/FantomasOnlineV6/Lambda.fs:13-26 | src/server/FantomasOnlineV7/Lambda.fs:13-26 | src/server/FantomasOnlineV8/Lambda.fs:13-26 \u2014 \u0060src/server/FantomasOnlineMain/Lambda.fs\u0060 and \u0060src/server/FantomasOnlinePreview/Lambda.fs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 1 separate duplicated blocks between them, totalling at least 14 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/FantomasOnlineMain/Lambda.fs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"88944b6e09e5ed1f2a3b7b4bc987fe5f879834dca3f8861a9a55c3a8ddce8ebe"}},{"ruleId":"D8","level":"warning","message":{"text":"Coverage not measured \u2014 JavaScript/TypeScript suite: Coverage NOT MEASURED: the JavaScript/TypeScript half could not be measured \u2014 src/client/ runs vitest but declares no coverage provider, so the suite can run and still produce no lcov \u2014 add \u0060@vitest/coverage-v8\u0060 (or \u0060@vitest/coverage-istanbul\u0060) as a devDependency. Coverage is excluded from the score rather than counted as a near-zero. The named suite step is one the repository\u0027s maintainers can perform; once it passes, the real number is measured on the next scan. Alternatively, commit the lcov/Cobertura report your CI produces and it is read without a re-run."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"62e63e619c28f057e129f2997c965d32a457366a9ce18ca019ffb6bdfba85c99"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/client/fsharp/View.fs: src/client/fsharp/View.fs changed 3 times in last 90 days, max cyclomatic complexity 22 in View.rightPane at line 189. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-04..2026-10-02, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-04 10:27:15 \u002B02:00\u0027 --until=\u00272026-10-02 10:27:15 \u002B02:00\u0027 --full-history --no-merges -- src/client/fsharp/View.fs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/View.fs"},"region":{"startLine":189}}}],"partialFingerprints":{"codehealthFindingId/v1":"3aa6f1aceb1549c151367e1a7c20ca28d5aa445ceebc1a433297dea2f8b6be98"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/client/fsharp/State.fs: src/client/fsharp/State.fs changed 2 times in last 90 days, max cyclomatic complexity 22 in State.update at line 62. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-04..2026-10-02, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-04 10:27:15 \u002B02:00\u0027 --until=\u00272026-10-02 10:27:15 \u002B02:00\u0027 --full-history --no-merges -- src/client/fsharp/State.fs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/State.fs"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"20662d523e226dfc27969049ece5d74e817a1a64c272487181cb5de836329545"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/client/fsharp/Oak/GraphView.fs: src/client/fsharp/Oak/GraphView.fs changed 2 times in last 90 days, max cyclomatic complexity 19 in GraphView.view at line 145. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-04..2026-10-02, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-04 10:27:15 \u002B02:00\u0027 --until=\u00272026-10-02 10:27:15 \u002B02:00\u0027 --full-history --no-merges -- src/client/fsharp/Oak/GraphView.fs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/Oak/GraphView.fs"},"region":{"startLine":145}}}],"partialFingerprints":{"codehealthFindingId/v1":"08ad872f58fc116fff693bd1a8a4384fb417fe5cf2a78c3108e5bb41a7d11a50"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/client/fsharp/FantomasOnline/State.fs: src/client/fsharp/FantomasOnline/State.fs changed 2 times in last 90 days, max cyclomatic complexity 18 in State.update at line 198. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-04..2026-10-02, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-04 10:27:15 \u002B02:00\u0027 --until=\u00272026-10-02 10:27:15 \u002B02:00\u0027 --full-history --no-merges -- src/client/fsharp/FantomasOnline/State.fs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/FantomasOnline/State.fs"},"region":{"startLine":198}}}],"partialFingerprints":{"codehealthFindingId/v1":"8b5cbbecb3c256919706cfbc13ea806de34c15995e4f611352d152242344edfb"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found. No recognised ADR directory (\u0060docs/adr/\u0060, \u0060docs/decisions/\u0060, \u0060adr/\u0060, \u0060docs/rfcs/\u0060, an \u0060ADR0001/\u0060 folder, or their siblings) exists anywhere in this tree. What was searched, so you can tell an empty log from a search that missed one: every directory under the tree (build output, dependencies and VCS metadata excepted), for a document that is either any non-index page inside a recognised ADR directory, whatever its name and however deeply nested (\u0060docs/adr/use-postgres.md\u0060, \u0060docs/adr/2024/0001-x.md\u0060); or a file anywhere whose name is ADR-shaped (\u00600001-use-postgres.md\u0060, \u0060adr-012-caching.md\u0060); or, when neither turned anything up, a document carrying the decision-record signature (an \u0022Architecture Decision Record\u0022 heading, or Status / Context / Decision / Consequences as section headings). A decision log that clears none of these \u2014 unnumbered files outside any recognised directory, without those headings \u2014 is not seen by this check and this row is then wrong. If that is your case, say so rather than renaming anything; otherwise, consider recording architectural decisions in \u0060docs/adr/\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d5b8f11381d61a58459ffc7c595fd52d09c03c711894a63a9578043d2338412b"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6cd7dd8ce2cb5c04a2c1d6ebe0d105c0ff37322563dcca85e129c8d762d0c027"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"90c93dd251d74ef5a0eb2ae6e1541b1fd4c7a7645560c3f32714c8d1fc12b96b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1e6162a1b061c1b50efd93064bc877420159b700e23707fa30c713e7579c0ffd"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4a84d907fcb31b5405b69f1f78f4429bec02c4586a4d4fd195c09c6e7c097ef7"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0a34c25e05d824149b750aad72b392fcdc85f031daf869f60b3cb5e5dabc366c"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f998eb03d7d3083205248cc57cf463fff65b7ddc91980d1abd4d1c382458727b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e07df64b4310b469b296705f43c9b7ca7b17f92588f83a8fd7ba45a9c5c19c59"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ee9680f3683ac93a218f0a93dca6e6953bc46e12d3325fb3ed37cf9d7f4f4dde"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dae7b90dd52342639ae31eec3812cccf76fd7b3848b92f29f58a160315fd28c7"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"97d56610095b2fa2e7ad2d850f70938acc9968e50bfe2966a1effeb20cb7a2c4"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"90744bf6db8fad143cf8a99f7cfc2172f3c9c97931ae81b77343feb91ef9a336"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0d69e3beab226c373b7bd1d84dd05efb1dfab99c067a123e2df341897ba4f5b0"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ba8542078b544c25cb2ba73de0bbde8047582b7fb481fcea4177d5f44455c7cd"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"76ef12c132eb5723337a65d91195067a08588670a4bdf1604904712b95472f68"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"049934f307b3b15aab8afd22c82b2246c8e05a2c0f7c7075fd2c24748b6b67a9"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"490f09f69524e247ca95d8a0692ab1c95b4fcc00586ae17f1e48818610a196ad"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4b1f559e88e36f04bf03681585a2373fcf133389a32fbcee5c41c69a410cb302"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"44d872487c19a5845d04cc8a7367ed60778b911c4885c009314639afce6c938f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"99e42ab6e0a25b997fe310dcd7f296c1ab97749b7d252d2d3f2f1f3fef5979f2"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a93e2b450a993d3dde1e5f5a37669a94d0d43d04ddd64188d239f9f04d218735"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"532cd39dd224d67217b807320ec9ac82818a21668df5ddad2c1f0a4a824e9361"},"properties":{"dependency":{"package":"uuid","version":"9.0.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0752d0df7434000fcabf1048e2de30a7a1a8b982b3db9a19898c4dec199856b4"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d068c977b62d9a977df1bb6f53e8b00b586c3abee955f91d715f92b8e019d624"}},{"ruleId":"AC1","level":"error","message":{"text":"\u003Cimg\u003E without a text alternative: An image with no alt (and no aria-label/aria-labelledby) is unreadable to assistive tech. Add alt \u2014 alt=\u0022\u0022 if it\u0027s purely decorative."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/View.fs"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"32d3f3f59837c610df563e995f8090f33ab720d4fb49493d4fa6448393d626bd"}},{"ruleId":"AC1","level":"error","message":{"text":"\u003Cimg\u003E without a text alternative: An image with no alt (and no aria-label/aria-labelledby) is unreadable to assistive tech. Add alt \u2014 alt=\u0022\u0022 if it\u0027s purely decorative."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/View.fs"},"region":{"startLine":72}}}],"partialFingerprints":{"codehealthFindingId/v1":"72f39833dc716401d77ddb16b4c4ba5c5f8305f2fce102d626698d340e3d6d8e"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Clabel\u003E that labels no control: This \u003Clabel\u003E has no for and wraps no form control, so it names nothing: assistive tech never announces it, and clicking the caption focuses no field. Note that an id on the label is not an association \u2014 it is the TARGET of one, so a control still has to point at it. Give the label for=\u0022\u003Cthe control\u0027s id\u003E\u0022, move the control inside the label, or point the control\u0027s aria-labelledby at this label\u0027s id."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/FantomasOnline/View.fs"},"region":{"startLine":353}}}],"partialFingerprints":{"codehealthFindingId/v1":"5c12fe2441e09747f9e4b70f6686de8f54e5b74a01806b7e66f16562cc525d17"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Cinput\u003E without a programmatic label: This control has only a placeholder \u2014 a placeholder is not a label (it vanishes on input and many AT ignore it). Add a \u003Clabel for\u003E, a wrapping \u003Clabel\u003E, or aria-label."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/FantomasOnline/View.fs"},"region":{"startLine":354}}}],"partialFingerprints":{"codehealthFindingId/v1":"fb68fe26e0135117f4f45f214886d1ab20a8b9c5a79535ad850ecd775ef9269d"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Clabel\u003E that labels no control: This \u003Clabel\u003E has no for and wraps no form control, so it names nothing: assistive tech never announces it, and clicking the caption focuses no field. Note that an id on the label is not an association \u2014 it is the TARGET of one, so a control still has to point at it. Give the label for=\u0022\u003Cthe control\u0027s id\u003E\u0022, move the control inside the label, or point the control\u0027s aria-labelledby at this label\u0027s id."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/SettingControls.fs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"ef9084639d43e5c08ec2aed44135486bdcf2ec71fdf05d58e35e72b67caf8f44"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Cinput\u003E without a programmatic label: This control has only a placeholder \u2014 a placeholder is not a label (it vanishes on input and many AT ignore it). Add a \u003Clabel for\u003E, a wrapping \u003Clabel\u003E, or aria-label."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/SettingControls.fs"},"region":{"startLine":10}}}],"partialFingerprints":{"codehealthFindingId/v1":"77f0866947c44376ab207e967f452196f78a7f6bc343f5d825e691e2b7da26b2"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Clabel\u003E that labels no control: This \u003Clabel\u003E has no for and wraps no form control, so it names nothing: assistive tech never announces it, and clicking the caption focuses no field. Note that an id on the label is not an association \u2014 it is the TARGET of one, so a control still has to point at it. Give the label for=\u0022\u003Cthe control\u0027s id\u003E\u0022, move the control inside the label, or point the control\u0027s aria-labelledby at this label\u0027s id."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/SettingControls.fs"},"region":{"startLine":25}}}],"partialFingerprints":{"codehealthFindingId/v1":"e2534d99b45cdb0e30318654a7bf35851c878163b9889887a477e8da06fddfc5"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Clabel\u003E that labels no control: This \u003Clabel\u003E has no for and wraps no form control, so it names nothing: assistive tech never announces it, and clicking the caption focuses no field. Note that an id on the label is not an association \u2014 it is the TARGET of one, so a control still has to point at it. Give the label for=\u0022\u003Cthe control\u0027s id\u003E\u0022, move the control inside the label, or point the control\u0027s aria-labelledby at this label\u0027s id."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/SettingControls.fs"},"region":{"startLine":45}}}],"partialFingerprints":{"codehealthFindingId/v1":"91e474a7cbb42901065e6f313a31bc814a9d877d60ceb28836e7eea6f2bcb0c7"}},{"ruleId":"AC2","level":"error","message":{"text":"Clickable \u003Ca\u003E with no accessible name: This \u003Ca\u003E has no href, so it exposes no link role \u2014 but it carries a click handler, which makes it a control. It has no text, aria-label or labelled child (the icon-only case), so assistive tech has no name to announce for it. Note that switching it to \u003Cbutton type=\u0022button\u0022\u003E \u2014 the right fix for its keyboard operability \u2014 does not give it a name either: an icon-only button still needs one. Add visible text or an aria-label."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/View.fs"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"c63db7ca6aebf1e88b21ef0b928c9bef0a7f6ca60b17d615b62964f663279ded"}},{"ruleId":"AC2","level":"error","message":{"text":"Clickable \u003Ca\u003E with no accessible name: This \u003Ca\u003E has no href, so it exposes no link role \u2014 but it carries a click handler, which makes it a control. It has no text, aria-label or labelled child (the icon-only case), so assistive tech has no name to announce for it. Note that switching it to \u003Cbutton type=\u0022button\u0022\u003E \u2014 the right fix for its keyboard operability \u2014 does not give it a name either: an icon-only button still needs one. Add visible text or an aria-label."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/View.fs"},"region":{"startLine":55}}}],"partialFingerprints":{"codehealthFindingId/v1":"c7b4e85981e67ae3510ecaa8ca412dada8190cd6eb1360c00abda3827e0b8d8a"}},{"ruleId":"AC2","level":"error","message":{"text":"Custom control with no accessible name on \u003Ci\u003E: This \u003Ci\u003E carries a click handler, which makes it a control, but it has no text, aria-label or labelled child (the icon-only case), so assistive tech has no name to announce for it. Note that switching it to \u003Cbutton type=\u0022button\u0022\u003E \u2014 the right fix for its keyboard operability \u2014 does not give it a name either: an icon-only button still needs one. Add visible text or an aria-label."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/View.fs"},"region":{"startLine":101}}}],"partialFingerprints":{"codehealthFindingId/v1":"da01f5367e73dbad5b941e80aaeda1bd081e194032cc6705c37a3ce392b3da3e"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Ctextarea\u003E without a programmatic label: This control has no associated label. Add a \u003Clabel for\u003E / wrapping \u003Clabel\u003E / aria-label / aria-labelledby so assistive tech can name it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/public/debug.html"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"00be8859edbb7a7bd0afd3d0e84ad16df4c1de81bdf7f4e536518e8f67963a6a"}},{"ruleId":"AC3","level":"warning","message":{"text":"Page without a main landmark: No \u003Cmain\u003E (or role=\u0022main\u0022) means no \u0022skip to content\u0022 target and a weaker landmark map. Wrap the primary content in \u003Cmain\u003E."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/public/debug.html"},"region":{"startLine":2}}}],"partialFingerprints":{"codehealthFindingId/v1":"68c8ad0dc11ba0126a9e210c3e189d16f996eedfc52e6933e4e83c0c5ed0b300"}},{"ruleId":"AC4","level":"error","message":{"text":"Click handler on a non-interactive \u003Cdiv\u003E: A click handler on a plain element isn\u0027t keyboard-operable. Use a \u003Cbutton\u003E, or add role \u002B tabindex=\u00220\u0022 \u002B a key handler."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/Oak/View.fs"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"c617ffb112c0dcd44faf67262d51f986879a76cb0f7382a194bf1630b741bd54"}},{"ruleId":"AC4","level":"error","message":{"text":"Click handler on a non-interactive \u003Cdiv\u003E: A click handler on a plain element isn\u0027t keyboard-operable. Use a \u003Cbutton\u003E, or add role \u002B tabindex=\u00220\u0022 \u002B a key handler."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/Oak/View.fs"},"region":{"startLine":86}}}],"partialFingerprints":{"codehealthFindingId/v1":"21e9b2633a16b43a56cb53fcc1616266a24ef0acc94a0b2c9121c15243b91b52"}},{"ruleId":"AC4","level":"warning","message":{"text":"Anchor without href: An \u003Ca\u003E with no href, role or tabindex isn\u0027t focusable or keyboard-activatable. Give it a real href, or use a \u003Cbutton\u003E for an action."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/View.fs"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"242dcb97b99a9180cba783dfda3110475e562d6193238774e8a5d5a406e0ee27"}},{"ruleId":"AC4","level":"warning","message":{"text":"Anchor without href: An \u003Ca\u003E with no href, role or tabindex isn\u0027t focusable or keyboard-activatable. Give it a real href, or use a \u003Cbutton\u003E for an action."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/View.fs"},"region":{"startLine":55}}}],"partialFingerprints":{"codehealthFindingId/v1":"da5917515cb5e9a9ff3a83d3f9e0db13da63e8a2aef95b8932779f8e6abe0c77"}},{"ruleId":"AC4","level":"error","message":{"text":"Click handler on a non-interactive \u003Cdiv\u003E: A click handler on a plain element isn\u0027t keyboard-operable. Use a \u003Cbutton\u003E, or add role \u002B tabindex=\u00220\u0022 \u002B a key handler."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/View.fs"},"region":{"startLine":91}}}],"partialFingerprints":{"codehealthFindingId/v1":"cb3ece47792de10dc7cfb74df5fa031e0d482200cd9e7b4d426878493db17652"}},{"ruleId":"AC4","level":"error","message":{"text":"Click handler on a non-interactive \u003Ci\u003E: A click handler on a plain element isn\u0027t keyboard-operable. Use a \u003Cbutton\u003E, or add role \u002B tabindex=\u00220\u0022 \u002B a key handler."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/fsharp/View.fs"},"region":{"startLine":101}}}],"partialFingerprints":{"codehealthFindingId/v1":"4d4022928a6f8213f87b32174e07dc5f5d6cdd19ed86ce4c0d078ce3ccfea8a0"}},{"ruleId":"AC6","level":"warning","message":{"text":"Low contrast colour pair in CSS (2.3:1): \u0060\u0026:hover, \u0026.active\u0060 sets color: #ffffff on background-color: #2fbadc \u2014 2.3:1, below the 4.5:1 WCAG AA minimum for normal text. Darken or lighten one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/src/styles/style.css"},"region":{"startLine":660}}}],"partialFingerprints":{"codehealthFindingId/v1":"2234ee664b25c303b751d69c69e71a8e01e81c7b150168106170b0d27ba9d783"}},{"ruleId":"AC7","level":"warning","message":{"text":"Accessibility enforcement below the top rung: No accessibility enforcement found \u2014 no a11y linter (eslint-plugin-jsx-a11y) and no axe/pa11y/Lighthouse in tests or CI. Start with the linter to catch issues at author time. What was searched, so you can tell an absence from a miss: the 13 markup file(s) this pass actually assessed, the linter configuration checked in beside them, and this repository\u0027s test and CI files \u2014 matched by name against the accessibility checkers this dimension carries. An audit run outside the repository, a hosted scanner, or a check whose name is not one of those, is not seen here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d46019b86eff5ddad9db289e6802ac158899e980df54c34f67722442787ead62"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"M2","level":"note","message":{"text":"No architecture diagram/doc: No C4/Structurizr/PlantUML/Mermaid/Graphviz/D2 diagram, no drawn diagram named for the architecture, no file named \u0060architecture\u0060 or \u0060design\u0060 in any markup this check reads, and nothing in the README, docs or contributor guides that announces the shape \u2014 no \u0060## Architecture\u0060 heading, no \u0022architecture overview\u0022/\u0022high-level design\u0022 phrasing, no \u0022the architecture is \u2026\u0022 introduction, no guided code tour. A shape laid out in prose that never names itself as the architecture is not visible to this check, and neither is one kept outside the repository, so this row reports the absence of a re-findable shape document \u2014 not evidence that nobody wrote the shape down."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0c190e7c159d1850ee706c3ac4486e151e8a4fe169de4bf61436b9f399654f06"}},{"ruleId":"M4","level":"note","message":{"text":"README/code drift: README omits the client-side Vite dev server (vite.config.js/preview) \u2014 reported by the model that read the README against this repository; no term search was run for this one, so nothing here has been checked against the tree. Treat it as a reading to confirm, not as a measured contradiction: verify it against the code before acting on it, and if the footprint it describes does exist, this row is wrong."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5cce1bd1cbbc3ac486022e3ca53c8765a7b1efced8d3ae432ef1a448659619f1"}},{"ruleId":"M4","level":"note","message":{"text":"README/code drift: README omits the shared package.json with oxfmt linting \u2014 reported by the model that read the README against this repository; no term search was run for this one, so nothing here has been checked against the tree. Treat it as a reading to confirm, not as a measured contradiction: verify it against the code before acting on it, and if the footprint it describes does exist, this row is wrong."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5713cc6c94f411437b98412627b59aa050421e01dca459d09a08565c6568f2bb"}},{"ruleId":"S1","level":"warning","message":{"text":"Third-party script without Subresource Integrity: \u0060https://kit.fontawesome.com/aadbaa5e13.js\u0060 is executed by this page with no Subresource Integrity. Whoever can answer that request \u2014 the CDN, anyone who compromises it, anyone on the network path \u2014 runs arbitrary script in this page\u0027s origin, with its session. The URL also names no version, so it resolves to whatever that origin serves at fetch time \u2014 the executed bytes can change with nobody touching this repository."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/client/index.html"},"region":{"startLine":7}}}],"partialFingerprints":{"codehealthFindingId/v1":"1840b84dd9febbb5dd8b50e52431cacce17c2e07128caa5d469c012a617708cb"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-522","guid":"71fb233e-ce6a-ae57-9419-ef8373540b09","name":"CWE-522","shortDescription":{"text":"CWE-522"},"helpUri":"https://cwe.mitre.org/data/definitions/522.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-829","guid":"13c33925-97fb-5a5e-b40c-56d328b8a4d7","name":"CWE-829","shortDescription":{"text":"CWE-829"},"helpUri":"https://cwe.mitre.org/data/definitions/829.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":24,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}