{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D11","name":"Test Reliability","shortDescription":{"text":"Test Reliability"},"helpUri":"https://codehealth.canine.dev/dimensions/D11"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D22","name":"Internal API Consistency","shortDescription":{"text":"Internal API Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D22"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D37","name":"Vulnerability-disclosure Policy","shortDescription":{"text":"Vulnerability-disclosure Policy"},"helpUri":"https://codehealth.canine.dev/dimensions/D37","relationships":[{"target":{"id":"CWE-1059","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1059"]}},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX9","name":"CQS / query purity","shortDescription":{"text":"CQS / query purity"},"helpUri":"https://codehealth.canine.dev/dimensions/AX9"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P10","name":"Library API \u0026 versioning","shortDescription":{"text":"Library API \u0026 versioning"},"helpUri":"https://codehealth.canine.dev/dimensions/P10"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P2","name":"Observability","shortDescription":{"text":"Observability"},"helpUri":"https://codehealth.canine.dev/dimensions/P2"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"P7","name":"Outbound HTTP resilience","shortDescription":{"text":"Outbound HTTP resilience"},"helpUri":"https://codehealth.canine.dev/dimensions/P7"},{"id":"PF3","name":"Async \u0026 latency hygiene","shortDescription":{"text":"Async \u0026 latency hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/PF3"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X6","name":"Hand-rolled structured-format parsing","shortDescription":{"text":"Hand-rolled structured-format parsing"},"helpUri":"https://codehealth.canine.dev/dimensions/X6"},{"id":"X7","name":"Silent fallback defaults","shortDescription":{"text":"Silent fallback defaults"},"helpUri":"https://codehealth.canine.dev/dimensions/X7"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"dalfox::cmd::scan::input::resolve_targets (cyclomatic 74): dalfox::cmd::scan::input::resolve_targets has cyclomatic complexity 74 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/input.rs"},"region":{"startLine":118}}}],"partialFingerprints":{"codehealthFindingId/v1":"306d6e7f168ab2a9b71402ef73d0ce594626bad149376dd94e6db6f9e01e1a94"}},{"ruleId":"D1","level":"warning","message":{"text":"DomXssVisitor::call_taint_and_source (cyclomatic 67): DomXssVisitor::call_taint_and_source has cyclomatic complexity 67 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/taint.rs"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"7f62a7fd68bc9a95d48b135e25c3583b76811176fa82c02201f0cca497f88aba"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::parameter_analysis::discovery::form::check_form_discovery_with (cyclomatic 61): dalfox::parameter_analysis::discovery::form::check_form_discovery_with has cyclomatic complexity 61 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/form.rs"},"region":{"startLine":28}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c60dd260d9d71a66fb0bb4b379009765fbbbfd39cd57502196d4a377a1427c9"}},{"ruleId":"D1","level":"warning","message":{"text":"DomXssVisitor::bind_declarator_identifier (cyclomatic 58): DomXssVisitor::bind_declarator_identifier has cyclomatic complexity 58 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/bindings.rs"},"region":{"startLine":15}}}],"partialFingerprints":{"codehealthFindingId/v1":"cc62bbc96a6367f74976e5d1e00f883190c8d471b86e4935275b2ced8329fa27"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::cmd::scan::run_scan (cyclomatic 50): dalfox::cmd::scan::run_scan has cyclomatic complexity 50 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/mod.rs"},"region":{"startLine":200}}}],"partialFingerprints":{"codehealthFindingId/v1":"97def516c945e06f9980f7ec92efee8e448fb76842a54b6339a5233eea38655f"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::main (cyclomatic 49): dalfox::main has cyclomatic complexity 49 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/main.rs"},"region":{"startLine":192}}}],"partialFingerprints":{"codehealthFindingId/v1":"5d49f31a9d8d7154909bf2fe36fccb1c2c2745912de87e26789c7f2eaef91b01"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::payload::js_breakout::compute_js_breakout (cyclomatic 46): dalfox::payload::js_breakout::compute_js_breakout has cyclomatic complexity 46 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/payload/js_breakout.rs"},"region":{"startLine":69}}}],"partialFingerprints":{"codehealthFindingId/v1":"d87a432e1048a222a38e38761a24a98fc45f470f969bb272832937f1a17115f7"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::payload::js_breakout::enclosing_js_quote (cyclomatic 45): dalfox::payload::js_breakout::enclosing_js_quote has cyclomatic complexity 45 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/payload/js_breakout.rs"},"region":{"startLine":213}}}],"partialFingerprints":{"codehealthFindingId/v1":"43f67883cbbfdc5b0c3ba8202e8f2f05f5e02861914878b5ec576dccf23f98e4"}},{"ruleId":"D1","level":"warning","message":{"text":"DomXssVisitor::walk_assignment_expression (cyclomatic 44): DomXssVisitor::walk_assignment_expression has cyclomatic complexity 44 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/sinks.rs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"a042802547fb8ba0059b0eada70a17f52204fae97c10e89ae02517af703b309a"}},{"ruleId":"D1","level":"warning","message":{"text":"DomXssVisitor::walk_expression (cyclomatic 44): DomXssVisitor::walk_expression has cyclomatic complexity 44 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/walk.rs"},"region":{"startLine":238}}}],"partialFingerprints":{"codehealthFindingId/v1":"d1e93c29191d67fcae038db0c7ccd9cb8e58107905e93271a49b5b9ab5d9b4ca"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::js_context_verify::gather_sink_spans_in_expression (cyclomatic 44): dalfox::scanning::js_context_verify::gather_sink_spans_in_expression has cyclomatic complexity 44 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/js_context_verify.rs"},"region":{"startLine":529}}}],"partialFingerprints":{"codehealthFindingId/v1":"95527e12b28f630abb8c443cca9b1380c898063b4c41b81f2d468be09f32c62b"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::parameter_analysis::discovery::query::check_query_discovery (cyclomatic 43): dalfox::parameter_analysis::discovery::query::check_query_discovery has cyclomatic complexity 43 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/query.rs"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"0852c5b85d83ad84b39dd241ced8243778add87286efc328fa52a48c80f04cfc"}},{"ruleId":"D1","level":"warning","message":{"text":"DomXssVisitor::find_source_in_expr (cyclomatic 42): DomXssVisitor::find_source_in_expr has cyclomatic complexity 42 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/bindings.rs"},"region":{"startLine":320}}}],"partialFingerprints":{"codehealthFindingId/v1":"9d115cb37358aca850c22557dd70cfc637d2bf9c4f4b913120640d254244f73f"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::cmd::scan::analysis::preflight_and_analyze_target (cyclomatic 42): dalfox::cmd::scan::analysis::preflight_and_analyze_target has cyclomatic complexity 42 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/analysis.rs"},"region":{"startLine":246}}}],"partialFingerprints":{"codehealthFindingId/v1":"15fa5c74e607bf7055e85bb59de671d05c77725acd26d04e9129f52fa3534b78"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::ast_integration::extract_js_and_script_ids_from_xml_document (cyclomatic 41): dalfox::scanning::ast_integration::extract_js_and_script_ids_from_xml_document has cyclomatic complexity 41 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_integration.rs"},"region":{"startLine":177}}}],"partialFingerprints":{"codehealthFindingId/v1":"e9829e9382877d41c5f8a56cf465c5a345c50b8f70fd84edd620d4f7385c21ac"}},{"ruleId":"D1","level":"warning","message":{"text":"DalfoxMcp::scan_with_dalfox (cyclomatic 39): DalfoxMcp::scan_with_dalfox has cyclomatic complexity 39 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/mcp/mod.rs"},"region":{"startLine":396}}}],"partialFingerprints":{"codehealthFindingId/v1":"43384a0ed052a69092d83f401b6cc57033f1531c514417464e29d1b3c1827983"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::js_context_verify::gather_sink_spans_in_statement (cyclomatic 39): dalfox::scanning::js_context_verify::gather_sink_spans_in_statement has cyclomatic complexity 39 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/js_context_verify.rs"},"region":{"startLine":371}}}],"partialFingerprints":{"codehealthFindingId/v1":"72ac760b470c1ad1e4a10eb4867c579680a9d1aa4da20c7055060b40001ff4ff"}},{"ruleId":"D1","level":"warning","message":{"text":"DomXssVisitor::walk_statement (cyclomatic 38): DomXssVisitor::walk_statement has cyclomatic complexity 38 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/walk.rs"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"51ac8e65e4fc36341f1fa7d124c4c0606aeeecc0bd541ad25287b81cecc8af36"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::cmd::scan::scan_loop::scan_host_group (cyclomatic 38): dalfox::cmd::scan::scan_loop::scan_host_group has cyclomatic complexity 38 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/scan_loop.rs"},"region":{"startLine":366}}}],"partialFingerprints":{"codehealthFindingId/v1":"5e7d2c0e6fae3ec4deab615a09e678b8abe749890222225a8e6b655d6b472de0"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::parameter_analysis::active_probe_param (cyclomatic 38): dalfox::parameter_analysis::active_probe_param has cyclomatic complexity 38 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mod.rs"},"region":{"startLine":857}}}],"partialFingerprints":{"codehealthFindingId/v1":"653d0a21ef6c9c156760e2c9f7efecfa2e2ca04c88b052c55dd3c703f4ed68a6"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::xss_common::generate_dynamic_payloads_uncached (cyclomatic 38): dalfox::scanning::xss_common::generate_dynamic_payloads_uncached has cyclomatic complexity 38 (threshold 15). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/xss_common.rs"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"fd23f82b43077cca0b525f2380ec2e5c01b06e862a6f0f9c8ed4f8d78136a886"}},{"ruleId":"D1","level":"warning","message":{"text":"DomXssVisitor::handle_member_method_sink (cyclomatic 34): DomXssVisitor::handle_member_method_sink has cyclomatic complexity 34 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/sinks.rs"},"region":{"startLine":250}}}],"partialFingerprints":{"codehealthFindingId/v1":"2007cac40201e870da112d1ecfac9355458e173c72124e82586b64124677cb38"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::cmd::scan::poc::generate_poc (cyclomatic 33): dalfox::cmd::scan::poc::generate_poc has cyclomatic complexity 33 (threshold 15). Of this number, 19 points are the body\u0027s own statements and 14 belong to 2 function items inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/poc.rs"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"d3bd0d1a72f1299361f0e293de25f633fa69d9970b2df06b30db364cadea0ed6"}},{"ruleId":"D1","level":"warning","message":{"text":"DomXssVisitor::handle_reflect_apply (cyclomatic 30): DomXssVisitor::handle_reflect_apply has cyclomatic complexity 30 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/sinks.rs"},"region":{"startLine":741}}}],"partialFingerprints":{"codehealthFindingId/v1":"eba66df9b540dc26b84b2b9ede37984fa43cf19fb33ee3248cf39be270e23f0a"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::parameter_analysis::xml_inject::parse_tag (cyclomatic 30): dalfox::parameter_analysis::xml_inject::parse_tag has cyclomatic complexity 30 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/xml_inject.rs"},"region":{"startLine":196}}}],"partialFingerprints":{"codehealthFindingId/v1":"59afa69d82f4160d7327bf204a8431f5cc7105e9749adab7c10ec55d79ac42e2"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::check_reflection::fetch_injection_response_with_client (cyclomatic 30): dalfox::scanning::check_reflection::fetch_injection_response_with_client has cyclomatic complexity 30 (threshold 15). Of this number, 26 points are the body\u0027s own statements and 4 belong to one function item inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_reflection.rs"},"region":{"startLine":2605}}}],"partialFingerprints":{"codehealthFindingId/v1":"55f9b2195d0f998c459f72e5be15a3c696f2cf644c4b0f5864986fea72bdb43b"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::check_dom_verification::classify_dom_evidence_in_xml (cyclomatic 30): dalfox::scanning::check_dom_verification::classify_dom_evidence_in_xml has cyclomatic complexity 30 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_dom_verification.rs"},"region":{"startLine":1016}}}],"partialFingerprints":{"codehealthFindingId/v1":"00e109d1e32e50ccb0353235838841d3aa082925cf97806d2d2ca331a4f57b05"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::url_inject::build_injected_url (cyclomatic 30): dalfox::scanning::url_inject::build_injected_url has cyclomatic complexity 30 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/url_inject.rs"},"region":{"startLine":206}}}],"partialFingerprints":{"codehealthFindingId/v1":"6e58b729d9ced0c3e6ac8b466c5c71483b33d6e62e08ceaf08f99607e9a14bb3"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::param_jobs::generate_param_jobs (cyclomatic 29): dalfox::scanning::param_jobs::generate_param_jobs has cyclomatic complexity 29 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/param_jobs.rs"},"region":{"startLine":78}}}],"partialFingerprints":{"codehealthFindingId/v1":"43a7a19bc6893da566f1c87556236eedc1b44c0d4871d3a84f9b2189db4aed05"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::job::runner::execute_scan (cyclomatic 29): dalfox::job::runner::execute_scan has cyclomatic complexity 29 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/job/runner.rs"},"region":{"startLine":109}}}],"partialFingerprints":{"codehealthFindingId/v1":"f6ad277967ea762687c8a57a37a83121eb8300e0e300ef0dfa74fbfcb5cea844"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::request_render::build_request_text (cyclomatic 29): dalfox::scanning::request_render::build_request_text has cyclomatic complexity 29 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/request_render.rs"},"region":{"startLine":7}}}],"partialFingerprints":{"codehealthFindingId/v1":"7a442029e816f451de98816612d59e84e61e06aa0ef010b52ff6a53c43cdfb52"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::xss_common::generate_adaptive_payloads (cyclomatic 29): dalfox::scanning::xss_common::generate_adaptive_payloads has cyclomatic complexity 29 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/xss_common.rs"},"region":{"startLine":315}}}],"partialFingerprints":{"codehealthFindingId/v1":"f1ba36145d6681a26c012251a7137bd21b538bd35b9e59f3c5cce6c16dfc08c8"}},{"ruleId":"D1","level":"warning","message":{"text":"DomXssVisitor::is_tainted (cyclomatic 28): DomXssVisitor::is_tainted has cyclomatic complexity 28 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/taint.rs"},"region":{"startLine":663}}}],"partialFingerprints":{"codehealthFindingId/v1":"8ff9d2dc70f146073cd4b9547b84fe80606bb85c61b1f9bd35a7a66616454cd2"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::ast_integration::has_self_bootstrap_verification (cyclomatic 28): dalfox::scanning::ast_integration::has_self_bootstrap_verification has cyclomatic complexity 28 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_integration.rs"},"region":{"startLine":1139}}}],"partialFingerprints":{"codehealthFindingId/v1":"fc2c2c1a37c3329edd18f03f30472ab4ba496f7afa2eb7743a1e9ba80b8e1205"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::payload::xss_csp_bypass::analyze_csp (cyclomatic 28): dalfox::payload::xss_csp_bypass::analyze_csp has cyclomatic complexity 28 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/payload/xss_csp_bypass.rs"},"region":{"startLine":170}}}],"partialFingerprints":{"codehealthFindingId/v1":"22ba23efe241a65f9f99fc9b422b85f05c0f30b9f876065a2982ed445dbac15f"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::server::util::validate_scan_options (cyclomatic 28): dalfox::server::util::validate_scan_options has cyclomatic complexity 28 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/util.rs"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"e23d018d2b82444442f471ec8aaaa25be30c44f4096539c8555d50c71b62d9aa"}},{"ruleId":"D1","level":"warning","message":{"text":"Result::results_to_markdown_with_meta (cyclomatic 27): Result::results_to_markdown_with_meta has cyclomatic complexity 27 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/result/format_markdown.rs"},"region":{"startLine":91}}}],"partialFingerprints":{"codehealthFindingId/v1":"76e95e216e7d5601467649955fcb0340b6e19e436c138813c8929572c8dabbd1"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::check_reflection::escaped_echo_is_inert (cyclomatic 27): dalfox::scanning::check_reflection::escaped_echo_is_inert has cyclomatic complexity 27 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_reflection.rs"},"region":{"startLine":1633}}}],"partialFingerprints":{"codehealthFindingId/v1":"d6f2ffce8864a30221ac6f8f3da9f6f55065b71e21b3f15f2958b1303073c446"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::parameter_analysis::mining::probe_json::probe_json_body_params (cyclomatic 27): dalfox::parameter_analysis::mining::probe_json::probe_json_body_params has cyclomatic complexity 27 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/probe_json.rs"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"da5f36bbfbd6671986daec377d698a8ef8bf24a9ae1662532fa40a069b718082"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::parameter_analysis::mining::context_detect::detect_injection_context_with_marker (cyclomatic 27): dalfox::parameter_analysis::mining::context_detect::detect_injection_context_with_marker has cyclomatic complexity 27 (threshold 15). Of this number, 15 points are the body\u0027s own statements and 12 belong to 3 function items inside it that branch. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/context_detect.rs"},"region":{"startLine":105}}}],"partialFingerprints":{"codehealthFindingId/v1":"ab006a2cdcb85b7e450571a2a6b85c444f76fae44a79af1f9667374d749c5761"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::waf::bypass::mutate::multi_slash (cyclomatic 27): dalfox::waf::bypass::mutate::multi_slash has cyclomatic complexity 27 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/waf/bypass/mutate.rs"},"region":{"startLine":664}}}],"partialFingerprints":{"codehealthFindingId/v1":"d69256cea010f9454218cbed977cedcd4a917520fd5e574977af35d43f62422a"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::cmd::scan::output::render_results (cyclomatic 27): dalfox::cmd::scan::output::render_results has cyclomatic complexity 27 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/output.rs"},"region":{"startLine":493}}}],"partialFingerprints":{"codehealthFindingId/v1":"0d619d46bac5c06abe7fc6315240498786eda74d8666f37e72239e9bcb4d7f0a"}},{"ruleId":"D1","level":"warning","message":{"text":"DomXssVisitor::collect_declared_names (cyclomatic 25): DomXssVisitor::collect_declared_names has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/walk.rs"},"region":{"startLine":478}}}],"partialFingerprints":{"codehealthFindingId/v1":"2b8f15ce267baca69e9b7cd04f905c7ceb181980794f60b2f8a7d063c3fff715"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::target_parser::parse_raw_http_request (cyclomatic 25): dalfox::target_parser::parse_raw_http_request has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/target_parser/mod.rs"},"region":{"startLine":539}}}],"partialFingerprints":{"codehealthFindingId/v1":"d078d21d492ea6fbc19b874c404881737f0bd9568be7a6419f7e3966f9baaa89"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::parameter_analysis::mining::probe_query::probe_query_candidates (cyclomatic 25): dalfox::parameter_analysis::mining::probe_query::probe_query_candidates has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/probe_query.rs"},"region":{"startLine":176}}}],"partialFingerprints":{"codehealthFindingId/v1":"65141f90240da0a87e8df4da8fcd8dcf8092416b2ffdbed4a627658fa8c4c8f9"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::cmd::scan::poc::render_finding_block (cyclomatic 25): dalfox::cmd::scan::poc::render_finding_block has cyclomatic complexity 25 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/poc.rs"},"region":{"startLine":474}}}],"partialFingerprints":{"codehealthFindingId/v1":"749e89ba4b5f4cfd08a9d7defbf2322ad1611024ed866ffc7603a20adfb5b44a"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::server::job_runner::run_scan_job (cyclomatic 24): dalfox::server::job_runner::run_scan_job has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/job_runner.rs"},"region":{"startLine":199}}}],"partialFingerprints":{"codehealthFindingId/v1":"9850139c4a3f4bac0ea45c8f58092cd854449d7da49893e316ef32f77399c20e"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::parameter_analysis::mining::probe_query::probe_bucket (cyclomatic 24): dalfox::parameter_analysis::mining::probe_query::probe_bucket has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/probe_query.rs"},"region":{"startLine":401}}}],"partialFingerprints":{"codehealthFindingId/v1":"8d8813ac7fb1809de500ccaddd1f132d60591103e75729328c32afa14ec67b28"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::server::run_server (cyclomatic 24): dalfox::server::run_server has cyclomatic complexity 24 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/mod.rs"},"region":{"startLine":79}}}],"partialFingerprints":{"codehealthFindingId/v1":"59d3f366bd63ba0f9e85700695351ad2e27ae3826a50e037ef2de687539924d5"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::cmd::scan::output::render_dry_run (cyclomatic 24): dalfox::cmd::scan::output::render_dry_run has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/output.rs"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"dab38035bea079ae10f41a958d04f8495974f8f32f9cf3720c9c0c795c8ec1ed"}},{"ruleId":"D1","level":"warning","message":{"text":"DomXssVisitor::handle_wrapper_invocation (cyclomatic 23): DomXssVisitor::handle_wrapper_invocation has cyclomatic complexity 23 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/sinks.rs"},"region":{"startLine":601}}}],"partialFingerprints":{"codehealthFindingId/v1":"87461490a5dc914f8033d15ec6d52a7a6c358c4cbdb15e95e3712dceb6b54c1a"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::parameter_analysis::discovery::path::check_path_discovery (cyclomatic 22): dalfox::parameter_analysis::discovery::path::check_path_discovery has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/path.rs"},"region":{"startLine":6}}}],"partialFingerprints":{"codehealthFindingId/v1":"dffc83cf72ad81b68990586aa29549b17482a5c3ccd4308d07beab4f0d9539e9"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::parameter_analysis::mining::probe_body::probe_body_params (cyclomatic 22): dalfox::parameter_analysis::mining::probe_body::probe_body_params has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/probe_body.rs"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"a154c5e5c1610863814c5291db7934705d6d9f7bcd97fc43a3a2745e2dcc1e71"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::ast_integration::build_dom_xss_manual_poc_hint (cyclomatic 22): dalfox::scanning::ast_integration::build_dom_xss_manual_poc_hint has cyclomatic complexity 22 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_integration.rs"},"region":{"startLine":972}}}],"partialFingerprints":{"codehealthFindingId/v1":"de48c157d8eacd0893e6808b01cb2f54acec1a5dce63ab062df507bcf4ee3495"}},{"ruleId":"D1","level":"warning","message":{"text":"DalfoxMcp::run_job (cyclomatic 21): DalfoxMcp::run_job has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/mcp/mod.rs"},"region":{"startLine":167}}}],"partialFingerprints":{"codehealthFindingId/v1":"68ada40d7c5409882781db02c1370dd7cb583945da6876c4927f25cd8bac1be3"}},{"ruleId":"D1","level":"warning","message":{"text":"Result::results_to_sarif_with_meta (cyclomatic 21): Result::results_to_sarif_with_meta has cyclomatic complexity 21 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/result/format_sarif.rs"},"region":{"startLine":24}}}],"partialFingerprints":{"codehealthFindingId/v1":"8090f07db0181b23cbb23569f403478678326288c5cb12c323ec05f2b557ea62"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::check_reflection::classify_reflection (cyclomatic 21): dalfox::scanning::check_reflection::classify_reflection has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_reflection.rs"},"region":{"startLine":1811}}}],"partialFingerprints":{"codehealthFindingId/v1":"f5e40d63815d0a6d5b22eb02bb7055e6f27b0719a33e49bd00f69925cb7015c1"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::cmd::scan::scan_loop::run_scan_loop (cyclomatic 21): dalfox::cmd::scan::scan_loop::run_scan_loop has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/scan_loop.rs"},"region":{"startLine":103}}}],"partialFingerprints":{"codehealthFindingId/v1":"191621ed142f05ca373460086f9556d9349ba86e4e3895d197ac4831b1ed1675"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::check_dom_verification::has_marker_evidence_in_doc (cyclomatic 21): dalfox::scanning::check_dom_verification::has_marker_evidence_in_doc has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_dom_verification.rs"},"region":{"startLine":386}}}],"partialFingerprints":{"codehealthFindingId/v1":"ba4414203f2a8d86e5043d892dbd370f78ce59fc17bff067bad6bf3df967ad75"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::cmd::scan::analysis::run_target_preflight (cyclomatic 21): dalfox::cmd::scan::analysis::run_target_preflight has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/analysis.rs"},"region":{"startLine":553}}}],"partialFingerprints":{"codehealthFindingId/v1":"850477f403d35f2a09f005a9ed89136233ffe617150c751c79482bb6677849f3"}},{"ruleId":"D1","level":"warning","message":{"text":"DomXssVisitor::handle_summary_and_sink_call (cyclomatic 20): DomXssVisitor::handle_summary_and_sink_call has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/sinks.rs"},"region":{"startLine":407}}}],"partialFingerprints":{"codehealthFindingId/v1":"b5dc3ae35ef841ebe31e2695bca3bc05cb4171b6662073131122e60631a32bff"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::ast_integration::generate_dom_xss_poc (cyclomatic 20): dalfox::scanning::ast_integration::generate_dom_xss_poc has cyclomatic complexity 20 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_integration.rs"},"region":{"startLine":725}}}],"partialFingerprints":{"codehealthFindingId/v1":"4fd8bb7a1d25895e57bbb28d45ace9cef7a17d0739118954a463851f42f5bf91"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::cmd::scan::startup::prepare_and_validate (cyclomatic 20): dalfox::cmd::scan::startup::prepare_and_validate has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/startup.rs"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"616373502193efff8b796833fd37729136e74524a498b0a8607c905dfe338eb3"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::cmd::payload::run_payload (cyclomatic 20): dalfox::cmd::payload::run_payload has cyclomatic complexity 20 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/payload.rs"},"region":{"startLine":431}}}],"partialFingerprints":{"codehealthFindingId/v1":"5eb5bf486870e16fb8f0f7b578296caa8ba768f37483d489bb5bfd3a432d2468"}},{"ruleId":"D1","level":"warning","message":{"text":"DalfoxMcp::preflight_dalfox (cyclomatic 19): DalfoxMcp::preflight_dalfox has cyclomatic complexity 19 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/mcp/mod.rs"},"region":{"startLine":1284}}}],"partialFingerprints":{"codehealthFindingId/v1":"f336554b632d3505218e236202f742143ebed5db171dc24723eaa992b6c6e307"}},{"ruleId":"D1","level":"warning","message":{"text":"DomXssVisitor::register_class_accessor_fields (cyclomatic 19): DomXssVisitor::register_class_accessor_fields has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/summaries.rs"},"region":{"startLine":221}}}],"partialFingerprints":{"codehealthFindingId/v1":"60c76d2e385586cea65d4a64e961f9d2af63b7fc77cd086c7453ec70b0f6707c"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::target_parser::har::parse_har (cyclomatic 19): dalfox::target_parser::har::parse_har has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/target_parser/har.rs"},"region":{"startLine":109}}}],"partialFingerprints":{"codehealthFindingId/v1":"3a3bb23ed6f862c6c41ca0fcb468a0de29c9997f407a8b40f368dcf4ce43d638"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::parameter_analysis::discovery::dedupe_reflection_params (cyclomatic 19): dalfox::parameter_analysis::discovery::dedupe_reflection_params has cyclomatic complexity 19 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/mod.rs"},"region":{"startLine":123}}}],"partialFingerprints":{"codehealthFindingId/v1":"a018aca80400ebdeaa5061c00243b965f52ce66c9555fb85df42b1d69f032b24"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::url_inject::build_hpp_url (cyclomatic 19): dalfox::scanning::url_inject::build_hpp_url has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/url_inject.rs"},"region":{"startLine":406}}}],"partialFingerprints":{"codehealthFindingId/v1":"26059908101b79e9db26662f46a4984e557fe4c9cf75d803d149a610e97b7a78"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::job::send_reachability_probe_inner (cyclomatic 19): dalfox::job::send_reachability_probe_inner has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/job/mod.rs"},"region":{"startLine":792}}}],"partialFingerprints":{"codehealthFindingId/v1":"2020e381e50bc435448cd5e15ea58faa0b70ccccbbf5a838824c30749169dc65"}},{"ruleId":"D1","level":"warning","message":{"text":"DomXssVisitor::walk_call_expression (cyclomatic 18): DomXssVisitor::walk_call_expression has cyclomatic complexity 18 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/sinks.rs"},"region":{"startLine":1139}}}],"partialFingerprints":{"codehealthFindingId/v1":"7f7068273dfb1417152d8dc640be35aea425dcef7eb5fc0c7aa8bf259904b7b2"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::parameter_analysis::xml_inject::xml_injection_points (cyclomatic 18): dalfox::parameter_analysis::xml_inject::xml_injection_points has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/xml_inject.rs"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"7fba83a74387585243ddff078b1eac0ce9a0602436e455293294eb50abbdf60d"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::utils::html::nesting_overflow_offset (cyclomatic 18): dalfox::utils::html::nesting_overflow_offset has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/utils/html.rs"},"region":{"startLine":259}}}],"partialFingerprints":{"codehealthFindingId/v1":"f7d829dbd3fffd7a072dd5dca4bbecf047eac9eac659d77ccadbe00e7861f024"}},{"ruleId":"D1","level":"warning","message":{"text":"DomXssVisitor::promise_kind_of_call (cyclomatic 17): DomXssVisitor::promise_kind_of_call has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/async_flow.rs"},"region":{"startLine":180}}}],"partialFingerprints":{"codehealthFindingId/v1":"8e3fea4971725712ae42de0faae276b6f31e9dc6207fd78c4ac44c4d89258f4a"}},{"ruleId":"D1","level":"warning","message":{"text":"DomXssVisitor::propagate_mutation_taint (cyclomatic 17): DomXssVisitor::propagate_mutation_taint has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/sinks.rs"},"region":{"startLine":531}}}],"partialFingerprints":{"codehealthFindingId/v1":"609d7cbdd6bef6a362056058fc1087776210ee59bfdcae72bfb1e16f4a6c21d0"}},{"ruleId":"D1","level":"warning","message":{"text":"ScanWorkerCtx::run_dom_phase (cyclomatic 17): ScanWorkerCtx::run_dom_phase has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/mod.rs"},"region":{"startLine":1340}}}],"partialFingerprints":{"codehealthFindingId/v1":"660d795a6b4873494ded00c01bbe58e19f898522270631e8dc8c65af4a5909bf"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::parameter_analysis::mining::probe_xml::probe_xml_body_params (cyclomatic 17): dalfox::parameter_analysis::mining::probe_xml::probe_xml_body_params has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/probe_xml.rs"},"region":{"startLine":38}}}],"partialFingerprints":{"codehealthFindingId/v1":"7516705bb4794ef49435cfb1f84e8f3cf2d2312cc493f051f203e65ee932fc8e"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::run_scanning (cyclomatic 17): dalfox::scanning::run_scanning has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/mod.rs"},"region":{"startLine":1781}}}],"partialFingerprints":{"codehealthFindingId/v1":"c256a0ebbd022de0baa8d3b90afdee7f5d7825a7eca239350b8fbd6a16bb20b4"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::parameter_analysis::mining::probe_multipart::probe_multipart_params (cyclomatic 17): dalfox::parameter_analysis::mining::probe_multipart::probe_multipart_params has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/probe_multipart.rs"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"58e342ebf6f981515814f809312752571d01e5b222b3621bbc77c54d2ddffceb"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::ast_integration::build_dom_xss_poc_url (cyclomatic 17): dalfox::scanning::ast_integration::build_dom_xss_poc_url has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_integration.rs"},"region":{"startLine":908}}}],"partialFingerprints":{"codehealthFindingId/v1":"74293ec6d0bf8fef02a8147e9644a804df35a40f771061f696d764a9b36146de"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::encoding::apply_encoders_to_payloads (cyclomatic 17): dalfox::encoding::apply_encoders_to_payloads has cyclomatic complexity 17 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/encoding/mod.rs"},"region":{"startLine":45}}}],"partialFingerprints":{"codehealthFindingId/v1":"d5e79aa6c9774c97616492da8e25391234783dca38fb5e12c5f641cf760e86da"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::xss_blind::blind_scan_forms_with (cyclomatic 17): dalfox::scanning::xss_blind::blind_scan_forms_with has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/xss_blind.rs"},"region":{"startLine":395}}}],"partialFingerprints":{"codehealthFindingId/v1":"2a40b1012b8c255126f855e7e23e2ee4b15a7683788491fb6c9e33c3dfaec28e"}},{"ruleId":"D1","level":"warning","message":{"text":"DomXssVisitor::message_event_source_for_receiver (cyclomatic 16): DomXssVisitor::message_event_source_for_receiver has cyclomatic complexity 16 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/events.rs"},"region":{"startLine":51}}}],"partialFingerprints":{"codehealthFindingId/v1":"cd8088a4ae0e5e731126e2189919a8844f46c7d0eb094f5288d3f2520e16c31b"}},{"ruleId":"D1","level":"warning","message":{"text":"DomXssVisitor::classify_tt_create_method (cyclomatic 16): DomXssVisitor::classify_tt_create_method has cyclomatic complexity 16 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/trusted_types.rs"},"region":{"startLine":107}}}],"partialFingerprints":{"codehealthFindingId/v1":"b10dc7fb9af1133b49c04b1714b5fe580f7bf0144410ddb41e516367c519e109"}},{"ruleId":"D1","level":"warning","message":{"text":"DomXssVisitor::walk_variable_declarator (cyclomatic 16): DomXssVisitor::walk_variable_declarator has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/walk.rs"},"region":{"startLine":177}}}],"partialFingerprints":{"codehealthFindingId/v1":"fd941add8d03b17dcdc73092b2d39bebe7bcd034df9afc68912fd5b886b48268"}},{"ruleId":"D1","level":"warning","message":{"text":"ScanWorkerCtx::scan_param (cyclomatic 16): ScanWorkerCtx::scan_param has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/mod.rs"},"region":{"startLine":626}}}],"partialFingerprints":{"codehealthFindingId/v1":"9c13c79e40b129cdb086c8401452c58ef37b3f362b0feaa4756cd992083be00f"}},{"ruleId":"D1","level":"warning","message":{"text":"ScanWorkerCtx::probe_param (cyclomatic 16): ScanWorkerCtx::probe_param has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/mod.rs"},"region":{"startLine":803}}}],"partialFingerprints":{"codehealthFindingId/v1":"752c53a853c64b4b2d910c6a6339db54f342a0e9ee86eff70c8d31007468f5a5"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::parameter_analysis::discovery::header::check_header_discovery (cyclomatic 16): dalfox::parameter_analysis::discovery::header::check_header_discovery has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/header.rs"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"8967ea96650d3a8c0785249cbb79b86293d46b76b591e32598a000a95cbd22e2"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::parameter_analysis::mining::context_detect::has_knockout_html_clause (cyclomatic 16): dalfox::parameter_analysis::mining::context_detect::has_knockout_html_clause has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/context_detect.rs"},"region":{"startLine":348}}}],"partialFingerprints":{"codehealthFindingId/v1":"b16684232b4f9aa3bc6ea24442356168e6d2a6212070cad9a0eca1a21fa973b8"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::ast_integration::js_blocks_from_document (cyclomatic 16): dalfox::scanning::ast_integration::js_blocks_from_document has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_integration.rs"},"region":{"startLine":337}}}],"partialFingerprints":{"codehealthFindingId/v1":"9c5cdd48474ecebc9a932629c28e50f5e265f90c286ec4d66bdb8b52bd88826f"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::check_dom_verification::payload_has_handler_sink_text (cyclomatic 16): dalfox::scanning::check_dom_verification::payload_has_handler_sink_text has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_dom_verification.rs"},"region":{"startLine":290}}}],"partialFingerprints":{"codehealthFindingId/v1":"6de14348464750c4de66ecc1c333af5b34154a89d4a5932f6a190fcaa5c6d0c2"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::check_dom_verification::has_html_structural_evidence_in_doc (cyclomatic 16): dalfox::scanning::check_dom_verification::has_html_structural_evidence_in_doc has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_dom_verification.rs"},"region":{"startLine":616}}}],"partialFingerprints":{"codehealthFindingId/v1":"5491ff48da63b95d66080f68a74ad899887fee169760212a9a7585d3140886f6"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::scanning::check_dom_verification::classify_dom_evidence (cyclomatic 16): dalfox::scanning::check_dom_verification::classify_dom_evidence has cyclomatic complexity 16 (threshold 15). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_dom_verification.rs"},"region":{"startLine":746}}}],"partialFingerprints":{"codehealthFindingId/v1":"cb8ae7112399d3b7ff6d97f767ee401535ed987df311bfc8d8bdfdcb0e371e1d"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::parameter_analysis::mining::probe_graphql::probe_graphql_params (cyclomatic 16): dalfox::parameter_analysis::mining::probe_graphql::probe_graphql_params has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/probe_graphql.rs"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"e23dff752ca8377783019cc5bab470cc815bdee42f4f27c70ec4b6c42529fe75"}},{"ruleId":"D1","level":"warning","message":{"text":"dalfox::cmd::scan::preflight::describe_reqwest_failure (cyclomatic 16): dalfox::cmd::scan::preflight::describe_reqwest_failure has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/preflight.rs"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"97628f7d732da9015462d38a6270bea4ce4b23ac4f57253c9b8f685e7ce2a98e"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::cmd::scan::input::resolve_targets (cognitive 206): dalfox::cmd::scan::input::resolve_targets has cognitive complexity 206 (threshold 15). Drivers by points: if/else 51 (146 pts), match/switch 12 (38 pts), loops 6 (18 pts), boolean chains 4 (nesting depth added 133). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/input.rs"},"region":{"startLine":118}}}],"partialFingerprints":{"codehealthFindingId/v1":"245eb5fea572ed7e7564964733caee7d3e7834fc3ca85bb4ba72bc6de5767b39"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::discovery::form::check_form_discovery_with (cognitive 185): dalfox::parameter_analysis::discovery::form::check_form_discovery_with has cognitive complexity 185 (threshold 15). Drivers by points: if/else 41 (123 pts), loops 18 (53 pts), boolean chains 6, match/switch 2 (3 pts) (nesting depth added 118). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/form.rs"},"region":{"startLine":28}}}],"partialFingerprints":{"codehealthFindingId/v1":"cfdf85d070ef60557e4313e49a7673a3c8e6540c8160c954ea0e192e96a6be56"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::ast_integration::extract_js_and_script_ids_from_xml_document (cognitive 104): dalfox::scanning::ast_integration::extract_js_and_script_ids_from_xml_document has cognitive complexity 104 (threshold 15). Drivers by points: if/else 22 (79 pts), boolean chains 14, loops 4 (10 pts), match/switch 1 (nesting depth added 63). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_integration.rs"},"region":{"startLine":177}}}],"partialFingerprints":{"codehealthFindingId/v1":"19f7b8a329c433b15f8246b7263687cfafad7bb55eaa83bffd2492b46c81e6ff"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::cmd::scan::analysis::preflight_and_analyze_target (cognitive 104): dalfox::cmd::scan::analysis::preflight_and_analyze_target has cognitive complexity 104 (threshold 15). Drivers by points: if/else 31 (74 pts), loops 8 (23 pts), boolean chains 7 (nesting depth added 58). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/analysis.rs"},"region":{"startLine":246}}}],"partialFingerprints":{"codehealthFindingId/v1":"17996fb789ec7b3dabba9828c522931d388f7b74874649e413d4db5f1b2ad5dd"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::call_taint_and_source (cognitive 100): DomXssVisitor::call_taint_and_source has cognitive complexity 100 (threshold 15). Drivers by points: if/else 37 (66 pts), boolean chains 23, loops 4 (9 pts), match/switch 1 (2 pts) (nesting depth added 35). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/taint.rs"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"99b5570c5f9d080e4b8145058760d323fb9a7d0875fa66400f3552f35982bc14"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::discovery::query::check_query_discovery (cognitive 94): dalfox::parameter_analysis::discovery::query::check_query_discovery has cognitive complexity 94 (threshold 15). Drivers by points: if/else 32 (71 pts), loops 9 (18 pts), boolean chains 5 (nesting depth added 48). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/query.rs"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"d376c0868670f394e1fdf600c0389c641a45279e9de49f1e648ceac201e01cac"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::active_probe_param (cognitive 94): dalfox::parameter_analysis::active_probe_param has cognitive complexity 94 (threshold 15). Drivers by points: if/else 22 (55 pts), loops 9 (26 pts), boolean chains 7, match/switch 3 (6 pts) (nesting depth added 53). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mod.rs"},"region":{"startLine":857}}}],"partialFingerprints":{"codehealthFindingId/v1":"6c69c07203e93b6d4c91898066710a8629c3289a1e29ee39bf2529c998a3ed51"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::handle_reflect_apply (cognitive 89): DomXssVisitor::handle_reflect_apply has cognitive complexity 89 (threshold 15). Drivers by points: if/else 22 (75 pts), boolean chains 7, loops 2 (7 pts) (nesting depth added 58). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/sinks.rs"},"region":{"startLine":741}}}],"partialFingerprints":{"codehealthFindingId/v1":"cee452fc25f3e0d1330fe9b9eefc133029837335d12871340a0ada6e3e27060f"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::cmd::scan::scan_loop::scan_host_group (cognitive 86): dalfox::cmd::scan::scan_loop::scan_host_group has cognitive complexity 86 (threshold 15). Drivers by points: if/else 31 (71 pts), boolean chains 8, loops 4 (7 pts) (nesting depth added 43). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/scan_loop.rs"},"region":{"startLine":366}}}],"partialFingerprints":{"codehealthFindingId/v1":"7c4b82260ffb2dedaf41a6580fdbf1d4b6b6e007243b2d6a5d7c024e85043f58"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::xss_common::generate_dynamic_payloads_uncached (cognitive 86): dalfox::scanning::xss_common::generate_dynamic_payloads_uncached has cognitive complexity 86 (threshold 15). Drivers by points: loops 19 (59 pts), if/else 6 (18 pts), match/switch 5 (9 pts) (nesting depth added 56). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/xss_common.rs"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"f4d9df87ae556890d7e89451bc0fdc8291f512a22e2bd6a710b6d494ceb76449"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::bind_declarator_identifier (cognitive 80): DomXssVisitor::bind_declarator_identifier has cognitive complexity 80 (threshold 15). Drivers by points: if/else 43 (58 pts), boolean chains 16, match/switch 5 (6 pts) (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/bindings.rs"},"region":{"startLine":15}}}],"partialFingerprints":{"codehealthFindingId/v1":"a144af13b82802784c7fefa8afc4c265fa1c2e909ef0e70370748e4f6790234a"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::handle_member_method_sink (cognitive 79): DomXssVisitor::handle_member_method_sink has cognitive complexity 79 (threshold 15). Drivers by points: if/else 22 (62 pts), boolean chains 11, loops 1 (3 pts), match/switch 1 (3 pts) (nesting depth added 44). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/sinks.rs"},"region":{"startLine":250}}}],"partialFingerprints":{"codehealthFindingId/v1":"9a96f723a4390db9298ee8b4315b2fdce0502f34ebb9cc2b57af255cd05ed3df"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::walk_assignment_expression (cognitive 78): DomXssVisitor::walk_assignment_expression has cognitive complexity 78 (threshold 15). Drivers by points: if/else 31 (64 pts), boolean chains 12, match/switch 2 (nesting depth added 33). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/sinks.rs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"83019921c20dabaace2df2183e1b0e84829c3b9e722fea6d3ba60a9bb9a277c8"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::url_inject::build_injected_url (cognitive 73): dalfox::scanning::url_inject::build_injected_url has cognitive complexity 73 (threshold 15). Drivers by points: if/else 25 (60 pts), loops 3 (8 pts), match/switch 2 (3 pts), boolean chains 2 (nesting depth added 41). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/url_inject.rs"},"region":{"startLine":206}}}],"partialFingerprints":{"codehealthFindingId/v1":"4fecfba9d5b8cf4fb88c0a920930234ee2a5283e84a0806cbadfb310cd215208"}},{"ruleId":"D2","level":"warning","message":{"text":"Result::results_to_markdown_with_meta (cognitive 72): Result::results_to_markdown_with_meta has cognitive complexity 72 (threshold 15). Drivers by points: if/else 27 (64 pts), loops 2 (5 pts), boolean chains 3 (nesting depth added 40). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/result/format_markdown.rs"},"region":{"startLine":91}}}],"partialFingerprints":{"codehealthFindingId/v1":"23a94790d24281a45565a286a756c67a1814f0170a816a3cc9051be82633369c"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::check_reflection::fetch_injection_response_with_client (cognitive 70): dalfox::scanning::check_reflection::fetch_injection_response_with_client has cognitive complexity 70 (threshold 15). Drivers by points: if/else 20 (53 pts), boolean chains 7, loops 2 (5 pts), match/switch 2 (5 pts) (nesting depth added 39). Of this number, 63 points are the body\u0027s own statements and 7 belong to one function item inside it that branches. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_reflection.rs"},"region":{"startLine":2605}}}],"partialFingerprints":{"codehealthFindingId/v1":"191355c79c824ebc3af4f140809b5a89e2e2dd3d0e8f3918df6b1807a4ac202b"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::cmd::scan::run_scan (cognitive 70): dalfox::cmd::scan::run_scan has cognitive complexity 70 (threshold 15). Drivers by points: if/else 32 (46 pts), boolean chains 11, match/switch 5 (8 pts), loops 3 (5 pts) (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/mod.rs"},"region":{"startLine":200}}}],"partialFingerprints":{"codehealthFindingId/v1":"626bf9b5e2caf6e9c7e9cd14250be1e7bbdd55af14b2f9b4e35244261ca7c145"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::main (cognitive 69): dalfox::main has cognitive complexity 69 (threshold 15). Drivers by points: if/else 26 (38 pts), match/switch 10 (23 pts), boolean chains 6, loops 1 (2 pts) (nesting depth added 26). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/main.rs"},"region":{"startLine":192}}}],"partialFingerprints":{"codehealthFindingId/v1":"37c890d2fd0d30e425efb4e88081b1c8c5911321bc59a059f874c2ad008ce1ff"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::mining::probe_body::probe_body_params (cognitive 65): dalfox::parameter_analysis::mining::probe_body::probe_body_params has cognitive complexity 65 (threshold 15). Drivers by points: if/else 18 (58 pts), loops 2 (4 pts), boolean chains 3 (nesting depth added 42). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/probe_body.rs"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"91193ece876d6636729da1d93c00fcb979b913835cd51da799a1e05f914b4028"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::find_source_in_expr (cognitive 60): DomXssVisitor::find_source_in_expr has cognitive complexity 60 (threshold 15). Drivers by points: if/else 11 (37 pts), match/switch 5 (12 pts), loops 4 (8 pts), boolean chains 3 (nesting depth added 37). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/bindings.rs"},"region":{"startLine":320}}}],"partialFingerprints":{"codehealthFindingId/v1":"1acbdb0c8f8e2d6dd98ec64bac8958ce884d0773170e6468838c7353e12551dc"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::xml_inject::parse_tag (cognitive 59): dalfox::parameter_analysis::xml_inject::parse_tag has cognitive complexity 59 (threshold 15). Drivers by points: if/else 8 (24 pts), loops 8 (22 pts), boolean chains 11, match/switch 1 (2 pts) (nesting depth added 31). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/xml_inject.rs"},"region":{"startLine":196}}}],"partialFingerprints":{"codehealthFindingId/v1":"1bb53a47ed5240069143de9c24ed7c0eb5cec6d69f4986398a1bf38970b26e7a"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::js_context_verify::gather_sink_spans_in_statement (cognitive 59): dalfox::scanning::js_context_verify::gather_sink_spans_in_statement has cognitive complexity 59 (threshold 15). Drivers by points: if/else 12 (31 pts), loops 9 (24 pts), match/switch 2 (4 pts) (nesting depth added 36). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/js_context_verify.rs"},"region":{"startLine":371}}}],"partialFingerprints":{"codehealthFindingId/v1":"25b2f9f2ffbd998fb4f777c545b8ffc7454bb76d519c2a80421cbee6debe9997"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::handle_wrapper_invocation (cognitive 57): DomXssVisitor::handle_wrapper_invocation has cognitive complexity 57 (threshold 15). Drivers by points: if/else 14 (40 pts), loops 3 (11 pts), boolean chains 6 (nesting depth added 34). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/sinks.rs"},"region":{"startLine":601}}}],"partialFingerprints":{"codehealthFindingId/v1":"bc48dc145dac347d0942a5da1084d1837a2a30483dfd7aed2453fe9005451bbb"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::payload::js_breakout::enclosing_js_quote (cognitive 57): dalfox::payload::js_breakout::enclosing_js_quote has cognitive complexity 57 (threshold 15). Drivers by points: if/else 13 (29 pts), match/switch 4 (11 pts), boolean chains 9, loops 4 (8 pts) (nesting depth added 27). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/payload/js_breakout.rs"},"region":{"startLine":213}}}],"partialFingerprints":{"codehealthFindingId/v1":"62de8c851a970cf898979eeabaa90d731322260b5082e6a14269d5a568d6ec8b"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::register_class_accessor_fields (cognitive 56): DomXssVisitor::register_class_accessor_fields has cognitive complexity 56 (threshold 15). Drivers by points: if/else 13 (47 pts), loops 3 (7 pts), match/switch 1 (2 pts) (nesting depth added 39). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/summaries.rs"},"region":{"startLine":221}}}],"partialFingerprints":{"codehealthFindingId/v1":"03e8dcca16ccf358f88d881854db54626c409de9e5f0796f890b195e79e4509f"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::param_jobs::generate_param_jobs (cognitive 56): dalfox::scanning::param_jobs::generate_param_jobs has cognitive complexity 56 (threshold 15). Drivers by points: if/else 18 (41 pts), boolean chains 10, loops 2 (5 pts) (nesting depth added 26). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/param_jobs.rs"},"region":{"startLine":78}}}],"partialFingerprints":{"codehealthFindingId/v1":"612098f4e39094da07c84b7d1ba79ca27f803eb147256551e39565cedb85f643"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::mining::probe_json::probe_json_body_params (cognitive 54): dalfox::parameter_analysis::mining::probe_json::probe_json_body_params has cognitive complexity 54 (threshold 15). Drivers by points: if/else 20 (45 pts), boolean chains 4, match/switch 2 (3 pts), loops 2 (nesting depth added 26). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/probe_json.rs"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"c4f3cd899df1a6aed66c60f1d1399c602ae161269ff6e6d6a24f40d63ceec311"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::walk_expression (cognitive 53): DomXssVisitor::walk_expression has cognitive complexity 53 (threshold 15). Drivers by points: if/else 10 (25 pts), loops 7 (16 pts), match/switch 4 (11 pts), boolean chains 1 (nesting depth added 31). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/walk.rs"},"region":{"startLine":238}}}],"partialFingerprints":{"codehealthFindingId/v1":"62dc23f7b7004be8a4e06fea6e2f24827efaf97d647f7689515f79ad85bbb962"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::cmd::scan::output::render_dry_run (cognitive 52): dalfox::cmd::scan::output::render_dry_run has cognitive complexity 52 (threshold 15). Drivers by points: if/else 20 (36 pts), loops 6 (15 pts), boolean chains 1 (nesting depth added 25). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/output.rs"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"c5655d9f58004291c255570935b42805aee2d3d217c38ffd1e97fef3b759894e"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::payload::js_breakout::compute_js_breakout (cognitive 50): dalfox::payload::js_breakout::compute_js_breakout has cognitive complexity 50 (threshold 15). Drivers by points: if/else 13 (32 pts), match/switch 5 (12 pts), boolean chains 4, loops 2 (nesting depth added 26). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/payload/js_breakout.rs"},"region":{"startLine":69}}}],"partialFingerprints":{"codehealthFindingId/v1":"d431e8b4df590714e5cdcfae34249e6dc9aa41cc06e043b1aacbe049a3e797ba"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::js_context_verify::gather_sink_spans_in_expression (cognitive 50): dalfox::scanning::js_context_verify::gather_sink_spans_in_expression has cognitive complexity 50 (threshold 15). Drivers by points: if/else 11 (26 pts), loops 7 (15 pts), match/switch 4 (9 pts) (nesting depth added 28). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/js_context_verify.rs"},"region":{"startLine":529}}}],"partialFingerprints":{"codehealthFindingId/v1":"bf4387093f07ede29005577c6115190ff3177b9c2cd5eee36dc6820383f49de0"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::cmd::scan::input::detect_input_type (cognitive 49): dalfox::cmd::scan::input::detect_input_type has cognitive complexity 49 (threshold 15). Drivers by points: if/else 15 (37 pts), match/switch 2 (8 pts), loops 1 (3 pts), boolean chains 1 (nesting depth added 30). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/input.rs"},"region":{"startLine":1383}}}],"partialFingerprints":{"codehealthFindingId/v1":"67fda61a3a6cad6674422e73963d9466fd13d062bde8da19dee4226db061b3fe"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::target_parser::parse_raw_http_request (cognitive 48): dalfox::target_parser::parse_raw_http_request has cognitive complexity 48 (threshold 15). Drivers by points: if/else 17 (37 pts), loops 3 (6 pts), boolean chains 3, match/switch 1 (2 pts) (nesting depth added 24). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/target_parser/mod.rs"},"region":{"startLine":539}}}],"partialFingerprints":{"codehealthFindingId/v1":"efb2acf58f6d30af754bbb663101ed831502cd23db1c461927681a2c57c36e18"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::target_parser::har::parse_har (cognitive 48): dalfox::target_parser::har::parse_har has cognitive complexity 48 (threshold 15). Drivers by points: if/else 14 (37 pts), loops 3 (7 pts), boolean chains 2, match/switch 1 (2 pts) (nesting depth added 28). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/target_parser/har.rs"},"region":{"startLine":109}}}],"partialFingerprints":{"codehealthFindingId/v1":"5239a1591dd62ed28516ef815e04d6a18fc30793234a8aef00dd5b2cb3c969e8"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::walk_statement (cognitive 47): DomXssVisitor::walk_statement has cognitive complexity 47 (threshold 15). Drivers by points: if/else 14 (32 pts), loops 4 (10 pts), match/switch 2 (3 pts), boolean chains 2 (nesting depth added 25). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/walk.rs"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"de7b0d5fe476d4d52654793794ea573c349647de74839ec85bef0057d99e72bc"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::xml_inject::xml_injection_points (cognitive 47): dalfox::parameter_analysis::xml_inject::xml_injection_points has cognitive complexity 47 (threshold 15). Drivers by points: if/else 13 (33 pts), loops 4 (10 pts), match/switch 1 (3 pts), boolean chains 1 (nesting depth added 28). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/xml_inject.rs"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"f7ce3f9153f323eb3d5389b3a36f0bbf9a44efef150195b4beb179abea075831"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::job::send_reachability_probe_inner (cognitive 46): dalfox::job::send_reachability_probe_inner has cognitive complexity 46 (threshold 15). Drivers by points: if/else 14 (27 pts), match/switch 5 (16 pts), boolean chains 2, loops 1 (nesting depth added 24). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/job/mod.rs"},"region":{"startLine":792}}}],"partialFingerprints":{"codehealthFindingId/v1":"94957bfca384bb1ad8667281a92ceb720543dd71ca52434a895ed6ed2148d34c"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::discovery::path::check_path_discovery (cognitive 45): dalfox::parameter_analysis::discovery::path::check_path_discovery has cognitive complexity 45 (threshold 15). Drivers by points: if/else 12 (26 pts), match/switch 2 (11 pts), boolean chains 6, loops 2 (nesting depth added 23). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/path.rs"},"region":{"startLine":6}}}],"partialFingerprints":{"codehealthFindingId/v1":"369cd6e34e86a560c8efb0ca4ebffcd942f5de57006107a8011dd7dca6c83489"}},{"ruleId":"D2","level":"warning","message":{"text":"DalfoxMcp::scan_with_dalfox (cognitive 44): DalfoxMcp::scan_with_dalfox has cognitive complexity 44 (threshold 15). Drivers by points: if/else 26 (32 pts), boolean chains 5, match/switch 4 (5 pts), loops 2 (nesting depth added 7). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/mcp/mod.rs"},"region":{"startLine":396}}}],"partialFingerprints":{"codehealthFindingId/v1":"fc4eba9d0b3c71399cf6582060665de39140595b6d3e0ca94718cafcf0ceb834"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::payload::xss_csp_bypass::analyze_csp (cognitive 44): dalfox::payload::xss_csp_bypass::analyze_csp has cognitive complexity 44 (threshold 15). Drivers by points: if/else 15 (30 pts), loops 4 (10 pts), boolean chains 2, match/switch 1 (2 pts) (nesting depth added 22). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/payload/xss_csp_bypass.rs"},"region":{"startLine":170}}}],"partialFingerprints":{"codehealthFindingId/v1":"7956f12342ee557eb5a702256055d462e77e82e7a12921c15265ad4ac307c2ee"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::mining::probe_query::probe_query_candidates (cognitive 44): dalfox::parameter_analysis::mining::probe_query::probe_query_candidates has cognitive complexity 44 (threshold 15). Drivers by points: if/else 19 (33 pts), loops 4 (9 pts), boolean chains 2 (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/probe_query.rs"},"region":{"startLine":176}}}],"partialFingerprints":{"codehealthFindingId/v1":"3dd7e73cc9dad00f0d9cb7f8a15fd68aabc10d8fd68099181a0e292a3c83d085"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::check_reflection::escaped_echo_is_inert (cognitive 43): dalfox::scanning::check_reflection::escaped_echo_is_inert has cognitive complexity 43 (threshold 15). Drivers by points: if/else 15 (28 pts), loops 5 (9 pts), boolean chains 6 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_reflection.rs"},"region":{"startLine":1633}}}],"partialFingerprints":{"codehealthFindingId/v1":"2583c86e3465d39442424aa8b9d2935c7411ce13c5e5965fb51fcc9104e4d708"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::job::runner::execute_scan (cognitive 43): dalfox::job::runner::execute_scan has cognitive complexity 43 (threshold 15). Drivers by points: if/else 18 (34 pts), boolean chains 7, loops 1, match/switch 1 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/job/runner.rs"},"region":{"startLine":109}}}],"partialFingerprints":{"codehealthFindingId/v1":"99b994ae7c5ae172995fb0e92227e8a65eeaf6e7f3bb94e492d3f43ebbc2d04e"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::xss_common::generate_adaptive_payloads (cognitive 43): dalfox::scanning::xss_common::generate_adaptive_payloads has cognitive complexity 43 (threshold 15). Drivers by points: if/else 10 (19 pts), loops 7 (11 pts), match/switch 4 (11 pts), boolean chains 2 (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/xss_common.rs"},"region":{"startLine":315}}}],"partialFingerprints":{"codehealthFindingId/v1":"f9b8ec94d58e33292d9355b3e7652e7df1f33c8e1324cf7166e05fdc57bdaddb"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::waf::bypass::mutate::multi_slash (cognitive 43): dalfox::waf::bypass::mutate::multi_slash has cognitive complexity 43 (threshold 15). Drivers by points: if/else 13 (29 pts), loops 5 (7 pts), boolean chains 5, match/switch 1 (2 pts) (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/waf/bypass/mutate.rs"},"region":{"startLine":664}}}],"partialFingerprints":{"codehealthFindingId/v1":"b763f83a079ff0c58c65399a220d6777fe14a76900133154088645871b6f2b4e"}},{"ruleId":"D2","level":"warning","message":{"text":"ScanWorkerCtx::run_dom_phase (cognitive 42): ScanWorkerCtx::run_dom_phase has cognitive complexity 42 (threshold 15). Drivers by points: if/else 14 (37 pts), loops 2 (3 pts), boolean chains 2 (nesting depth added 24). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/mod.rs"},"region":{"startLine":1340}}}],"partialFingerprints":{"codehealthFindingId/v1":"bd63dac9c0d89619bafac7a3edf1e6c5dd7728fba40cd43073b415fca5aad454"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::mining::context_detect::detect_injection_context_with_marker (cognitive 42): dalfox::parameter_analysis::mining::context_detect::detect_injection_context_with_marker has cognitive complexity 42 (threshold 15). Drivers by points: if/else 15 (27 pts), loops 5 (7 pts), boolean chains 6, match/switch 1 (2 pts) (nesting depth added 15). Of this number, 29 points are the body\u0027s own statements and 13 belong to 3 function items inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/context_detect.rs"},"region":{"startLine":105}}}],"partialFingerprints":{"codehealthFindingId/v1":"8f89203e34512d798a978b45b909f3b7e7a0172339cec51560619afc308c1d22"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::walk_variable_declarator (cognitive 41): DomXssVisitor::walk_variable_declarator has cognitive complexity 41 (threshold 15). Drivers by points: if/else 10 (32 pts), loops 2 (6 pts), boolean chains 3 (nesting depth added 26). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/walk.rs"},"region":{"startLine":177}}}],"partialFingerprints":{"codehealthFindingId/v1":"2c3e6159c358a561db2a6548d18fc5cb3f242de6d45a0defcb7f85fd1d5570ea"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::cmd::scan::analysis::run_target_preflight (cognitive 41): dalfox::cmd::scan::analysis::run_target_preflight has cognitive complexity 41 (threshold 15). Drivers by points: if/else 18 (38 pts), boolean chains 2, match/switch 1 (nesting depth added 20). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/analysis.rs"},"region":{"startLine":553}}}],"partialFingerprints":{"codehealthFindingId/v1":"40d5d482f2b82cc323ad6c11c2de63f15bc94e9aa7cd7902680cf8554b44fcbb"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::cmd::scan::output::render_results (cognitive 41): dalfox::cmd::scan::output::render_results has cognitive complexity 41 (threshold 15). Drivers by points: if/else 20 (33 pts), loops 3 (5 pts), boolean chains 2, match/switch 1 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/output.rs"},"region":{"startLine":493}}}],"partialFingerprints":{"codehealthFindingId/v1":"96675dbb633378c78f4ffe437740da2cd233a78db8dad43f0c7479682dec4425"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::handle_summary_and_sink_call (cognitive 39): DomXssVisitor::handle_summary_and_sink_call has cognitive complexity 39 (threshold 15). Drivers by points: if/else 14 (27 pts), loops 3 (7 pts), boolean chains 5 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/sinks.rs"},"region":{"startLine":407}}}],"partialFingerprints":{"codehealthFindingId/v1":"b903ca344a0d773a95d8b1c6fcee27e29600175f9621d77d159f806a028f2a65"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::xss_blind::blind_scan_forms_with (cognitive 39): dalfox::scanning::xss_blind::blind_scan_forms_with has cognitive complexity 39 (threshold 15). Drivers by points: if/else 10 (27 pts), loops 5 (9 pts), match/switch 2 (3 pts) (nesting depth added 22). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/xss_blind.rs"},"region":{"startLine":395}}}],"partialFingerprints":{"codehealthFindingId/v1":"bbe000e8f78fbaedeb7191431dd62d576a7773b77e7b37672da3421e6b965615"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::utils::html::nesting_overflow_offset (cognitive 39): dalfox::utils::html::nesting_overflow_offset has cognitive complexity 39 (threshold 15). Drivers by points: if/else 11 (29 pts), match/switch 2 (6 pts), boolean chains 3, loops 1 (nesting depth added 22). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/utils/html.rs"},"region":{"startLine":259}}}],"partialFingerprints":{"codehealthFindingId/v1":"00835516d58b301851383f9a8355dbcf8e29c84d37a0bd695c8db513d9a8544d"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::mining::probe_query::probe_bucket (cognitive 38): dalfox::parameter_analysis::mining::probe_query::probe_bucket has cognitive complexity 38 (threshold 15). Drivers by points: if/else 20 (29 pts), boolean chains 8, loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/probe_query.rs"},"region":{"startLine":401}}}],"partialFingerprints":{"codehealthFindingId/v1":"35a70d062b8b6abbe5f1413fc96425aa8f9601fb93c546d8473f91e67afc903f"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::url_inject::build_hpp_url (cognitive 38): dalfox::scanning::url_inject::build_hpp_url has cognitive complexity 38 (threshold 15). Drivers by points: if/else 12 (30 pts), match/switch 3 (6 pts), boolean chains 1, loops 1 (nesting depth added 21). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/url_inject.rs"},"region":{"startLine":406}}}],"partialFingerprints":{"codehealthFindingId/v1":"d43df030c3cd4812811bffa0215ad5518ed71be3c2ca19a410fe1f80a77fdf9b"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::propagate_mutation_taint (cognitive 37): DomXssVisitor::propagate_mutation_taint has cognitive complexity 37 (threshold 15). Drivers by points: if/else 8 (26 pts), loops 2 (6 pts), boolean chains 3, match/switch 1 (2 pts) (nesting depth added 23). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/sinks.rs"},"region":{"startLine":531}}}],"partialFingerprints":{"codehealthFindingId/v1":"485b87afa42dc0135e91edcad2e19bc024872a537f211e1a0cdd0e37b0ae3a6d"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::ast_integration::js_blocks_from_document (cognitive 37): dalfox::scanning::ast_integration::js_blocks_from_document has cognitive complexity 37 (threshold 15). Drivers by points: if/else 9 (30 pts), loops 3 (4 pts), boolean chains 3 (nesting depth added 22). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_integration.rs"},"region":{"startLine":337}}}],"partialFingerprints":{"codehealthFindingId/v1":"8d1256a5251292963ae2d4a3b8cfdc359eabfceec94d2c4e7409c0945d881b39"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::collect_declared_names (cognitive 35): DomXssVisitor::collect_declared_names has cognitive complexity 35 (threshold 15). Drivers by points: if/else 7 (22 pts), loops 4 (11 pts), match/switch 1 (2 pts) (nesting depth added 23). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/walk.rs"},"region":{"startLine":478}}}],"partialFingerprints":{"codehealthFindingId/v1":"0086caa79452ca81d9d4bd1cdea1b2119b1a6a6c603b79714cf0e0847950225c"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::cmd::scan::scan_loop::run_scan_loop (cognitive 35): dalfox::cmd::scan::scan_loop::run_scan_loop has cognitive complexity 35 (threshold 15). Drivers by points: if/else 14 (25 pts), boolean chains 6, loops 3 (4 pts) (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/scan_loop.rs"},"region":{"startLine":103}}}],"partialFingerprints":{"codehealthFindingId/v1":"3a44efdccea05cf2510149ec9daeecbf08d5585197d8eaf4bdc6ae1081816021"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::check_dom_verification::has_marker_evidence_in_doc (cognitive 34): dalfox::scanning::check_dom_verification::has_marker_evidence_in_doc has cognitive complexity 34 (threshold 15). Drivers by points: if/else 17 (29 pts), boolean chains 5 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_dom_verification.rs"},"region":{"startLine":386}}}],"partialFingerprints":{"codehealthFindingId/v1":"b4db147451982bd5eb5479c66fe072dc48ff862ca5028e0032e758d384e2eb15"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::cmd::scan::poc::render_finding_block (cognitive 33): dalfox::cmd::scan::poc::render_finding_block has cognitive complexity 33 (threshold 15). Drivers by points: if/else 20 (22 pts), loops 2 (6 pts), boolean chains 3, match/switch 1 (2 pts) (nesting depth added 7). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/poc.rs"},"region":{"startLine":474}}}],"partialFingerprints":{"codehealthFindingId/v1":"803f8dca84d0f7d7d2c668c4335218e28eeb64908d7a4d5aedd9fd7ca5c6a1dc"}},{"ruleId":"D2","level":"warning","message":{"text":"DalfoxMcp::run_job (cognitive 32): DalfoxMcp::run_job has cognitive complexity 32 (threshold 15). Drivers by points: if/else 17 (24 pts), match/switch 3 (5 pts), boolean chains 3 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/mcp/mod.rs"},"region":{"startLine":167}}}],"partialFingerprints":{"codehealthFindingId/v1":"42ef7d91fdb0d8d37141cc31b4f28d8248b091e0ccf3e070b7550c3956545be2"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::check_dom_verification::classify_dom_evidence_in_xml (cognitive 32): dalfox::scanning::check_dom_verification::classify_dom_evidence_in_xml has cognitive complexity 32 (threshold 15). Drivers by points: boolean chains 21, if/else 8 (11 pts) (nesting depth added 3). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_dom_verification.rs"},"region":{"startLine":1016}}}],"partialFingerprints":{"codehealthFindingId/v1":"51aba7dae70028e1832cfa9a16c1c3a33392a177fdf4f0e9dad29639e6fa49a6"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::cmd::scan::poc::generate_poc (cognitive 32): dalfox::cmd::scan::poc::generate_poc has cognitive complexity 32 (threshold 15). Drivers by points: if/else 15 (22 pts), match/switch 4 (6 pts), boolean chains 2, loops 2 (nesting depth added 9). Of this number, 25 points are the body\u0027s own statements and 7 belong to 2 function items inside it that branch. To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/poc.rs"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"5f194898f0209adf929661f817cc09d7243775203ffd36fa6af305a330884e57"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::mining::context_detect::has_knockout_html_clause (cognitive 30): dalfox::parameter_analysis::mining::context_detect::has_knockout_html_clause has cognitive complexity 30 (threshold 15). Drivers by points: if/else 8 (20 pts), boolean chains 5, loops 2 (5 pts) (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/context_detect.rs"},"region":{"startLine":348}}}],"partialFingerprints":{"codehealthFindingId/v1":"c716980b0e1b5ddbfe96ec8951fb8f414b45ad25316297d1e18b8c7873b0f70a"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::ast_integration::generate_dom_xss_poc (cognitive 30): dalfox::scanning::ast_integration::generate_dom_xss_poc has cognitive complexity 30 (threshold 15). Drivers by points: if/else 24 (29 pts), boolean chains 1 (nesting depth added 5). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_integration.rs"},"region":{"startLine":725}}}],"partialFingerprints":{"codehealthFindingId/v1":"90d477d6a8daa1266828df9376bc51551b49e2c0ff2e7405352cdaa13b583ad8"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::server::job_runner::run_scan_job (cognitive 30): dalfox::server::job_runner::run_scan_job has cognitive complexity 30 (threshold 15). Drivers by points: if/else 14 (20 pts), boolean chains 6, match/switch 4 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/job_runner.rs"},"region":{"startLine":199}}}],"partialFingerprints":{"codehealthFindingId/v1":"baceb716781ad495575d40e97f291f2f625df6c7714efb0eaeba2264cf7c1962"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::utils::http::send_with_retry (cognitive 30): dalfox::utils::http::send_with_retry has cognitive complexity 30 (threshold 15). Drivers by points: if/else 10 (25 pts), match/switch 2 (4 pts), loops 1 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/utils/http.rs"},"region":{"startLine":846}}}],"partialFingerprints":{"codehealthFindingId/v1":"6804429b7e9f93d84233cf3dfa20417b5ab47133a9bbb4fa3e33edc187191b37"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::cmd::scan::startup::prepare_and_validate (cognitive 30): dalfox::cmd::scan::startup::prepare_and_validate has cognitive complexity 30 (threshold 15). Drivers by points: if/else 13 (24 pts), boolean chains 3, match/switch 1 (2 pts), loops 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/startup.rs"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"57f14eb93792f5c108df63ec334a25b6a2b0126d74a3d44378c2a3cca32ac047"}},{"ruleId":"D2","level":"warning","message":{"text":"ScanWorkerCtx::process_reflection_result (cognitive 29): ScanWorkerCtx::process_reflection_result has cognitive complexity 29 (threshold 15). Drivers by points: if/else 12 (22 pts), boolean chains 4, loops 1 (3 pts) (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/mod.rs"},"region":{"startLine":1076}}}],"partialFingerprints":{"codehealthFindingId/v1":"51ed6d76fca5d1cd2099f7f893779221a0b47bfe33bffbbbe7237f289afde684"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::run_scanning (cognitive 29): dalfox::scanning::run_scanning has cognitive complexity 29 (threshold 15). Drivers by points: if/else 13 (25 pts), boolean chains 2, loops 2 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/mod.rs"},"region":{"startLine":1781}}}],"partialFingerprints":{"codehealthFindingId/v1":"f34d80c032a30ca277b140049f5da2f6f9d8c45a88b655af0dd5f5fc56be8c39"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::ast_integration::has_self_bootstrap_verification (cognitive 29): dalfox::scanning::ast_integration::has_self_bootstrap_verification has cognitive complexity 29 (threshold 15). Drivers by points: if/else 13 (15 pts), boolean chains 14 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_integration.rs"},"region":{"startLine":1139}}}],"partialFingerprints":{"codehealthFindingId/v1":"15d16fa0caf766a461678e93f49cf051752e14a3e7e21499055a949a8f2fcea4"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::request_render::build_request_text (cognitive 29): dalfox::scanning::request_render::build_request_text has cognitive complexity 29 (threshold 15). Drivers by points: if/else 13 (17 pts), boolean chains 7, loops 2 (3 pts), match/switch 2 (nesting depth added 5). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/request_render.rs"},"region":{"startLine":7}}}],"partialFingerprints":{"codehealthFindingId/v1":"09979bcc3bbe16fad401ce3de4344aea528aeb7d1a9d2770a639a4d86b94f022"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::server::util::validate_scan_options (cognitive 29): dalfox::server::util::validate_scan_options has cognitive complexity 29 (threshold 15). Drivers by points: if/else 19 (20 pts), boolean chains 9 (nesting depth added 1). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/util.rs"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"78813aee239390a991eb1221049c8e2bb14ac98d0f29bab5562ed8e7865b10ce"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::promise_kind_of_call (cognitive 28): DomXssVisitor::promise_kind_of_call has cognitive complexity 28 (threshold 15). Drivers by points: if/else 11 (19 pts), loops 3 (6 pts), match/switch 2 (3 pts) (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/async_flow.rs"},"region":{"startLine":180}}}],"partialFingerprints":{"codehealthFindingId/v1":"dc543cb6521a8b1cb760c0cb72859e3f0fb5618f74b593da1e122288c8fc3042"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::resolve_apply_argument_taint_at (cognitive 27): DomXssVisitor::resolve_apply_argument_taint_at has cognitive complexity 27 (threshold 15). Drivers by points: if/else 7 (20 pts), match/switch 1 (3 pts), boolean chains 2, loops 1 (2 pts) (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/bound_calls.rs"},"region":{"startLine":72}}}],"partialFingerprints":{"codehealthFindingId/v1":"91ca0a4ee8439035f6355f472c56382ade4fd8ab89c8b7bcbcd2c184455e6914"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::handle_object_assign_sink (cognitive 27): DomXssVisitor::handle_object_assign_sink has cognitive complexity 27 (threshold 15). Drivers by points: if/else 11 (22 pts), loops 2 (3 pts), boolean chains 2 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/sinks.rs"},"region":{"startLine":997}}}],"partialFingerprints":{"codehealthFindingId/v1":"03d00088f5d6fbf34ea283326837b21bfce5dd1da6f5f71d8c845296211e38d0"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::check_reflection::classify_reflection (cognitive 27): dalfox::scanning::check_reflection::classify_reflection has cognitive complexity 27 (threshold 15). Drivers by points: if/else 15 (21 pts), boolean chains 6 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_reflection.rs"},"region":{"startLine":1811}}}],"partialFingerprints":{"codehealthFindingId/v1":"d13058d2459d07b572f119fff7f909983aa8d1a6836744f417ec2c1c18c99f51"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::mining::probe_multipart::probe_multipart_params (cognitive 27): dalfox::parameter_analysis::mining::probe_multipart::probe_multipart_params has cognitive complexity 27 (threshold 15). Drivers by points: if/else 12 (21 pts), loops 3 (4 pts), boolean chains 2 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/probe_multipart.rs"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"3a3c463da940a295de46151f8fea7efd83cbd6fb421407c871acfa026ff7adeb"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::ast_dom_phase::run_ast_dom_analysis (cognitive 27): dalfox::scanning::ast_dom_phase::run_ast_dom_analysis has cognitive complexity 27 (threshold 15). Drivers by points: if/else 12 (24 pts), loops 2 (3 pts) (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_phase.rs"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"b1fb2c3f90666fa088a4161e1609f3d664cd9853c864a655155d2f5ac2178fb9"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::payload::synthesis::synthesize_payloads (cognitive 26): dalfox::payload::synthesis::synthesize_payloads has cognitive complexity 26 (threshold 15). Drivers by points: if/else 9 (20 pts), loops 2 (3 pts), match/switch 1 (2 pts), boolean chains 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/payload/synthesis.rs"},"region":{"startLine":406}}}],"partialFingerprints":{"codehealthFindingId/v1":"7ac4864acecb546766cc317f79a8b403d684ece72f1d2c1adbadfa3a354d944c"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::discovery::header::check_header_discovery (cognitive 26): dalfox::parameter_analysis::discovery::header::check_header_discovery has cognitive complexity 26 (threshold 15). Drivers by points: if/else 10 (18 pts), loops 4 (6 pts), boolean chains 2 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/header.rs"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"0bda403cbfae6b1acdcbfcf36adc879dbe27316874a2aac163d345acab3c73d9"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::ast_dom_analysis::source_nesting_exceeds_limit (cognitive 26): dalfox::scanning::ast_dom_analysis::source_nesting_exceeds_limit has cognitive complexity 26 (threshold 15). Drivers by points: if/else 7 (19 pts), loops 2 (4 pts), match/switch 1 (2 pts), boolean chains 1 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/mod.rs"},"region":{"startLine":128}}}],"partialFingerprints":{"codehealthFindingId/v1":"ef2c202b46675f03f0bd3f154fd4d08c8aa44d21d2f4a4f669491da8f63ff2f9"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::xss_blind::build_blind_templates (cognitive 25): dalfox::scanning::xss_blind::build_blind_templates has cognitive complexity 25 (threshold 15). Drivers by points: if/else 7 (19 pts), loops 1 (3 pts), match/switch 1 (2 pts), boolean chains 1 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/xss_blind.rs"},"region":{"startLine":117}}}],"partialFingerprints":{"codehealthFindingId/v1":"c750f33a042e25439a15412d964695c4344c533578246b401d9fcb2ccfe333e5"}},{"ruleId":"D2","level":"warning","message":{"text":"ScanWorkerCtx::probe_param (cognitive 24): ScanWorkerCtx::probe_param has cognitive complexity 24 (threshold 15). Drivers by points: if/else 9 (15 pts), loops 2 (4 pts), boolean chains 3, match/switch 1 (2 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/mod.rs"},"region":{"startLine":803}}}],"partialFingerprints":{"codehealthFindingId/v1":"1bec2aeee1cf09853729046581f883e0bb74b5830f0416b420425ca3108fbcca"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::mining::probe_xml::probe_xml_body_params (cognitive 24): dalfox::parameter_analysis::mining::probe_xml::probe_xml_body_params has cognitive complexity 24 (threshold 15). Drivers by points: if/else 11 (18 pts), boolean chains 2, loops 2, match/switch 1 (2 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/probe_xml.rs"},"region":{"startLine":38}}}],"partialFingerprints":{"codehealthFindingId/v1":"3c47e176fe7defa10645b0072e93c5f91a4726d9e8ab72963fed13c325a144cd"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::check_dom_verification::has_html_structural_evidence_in_doc (cognitive 24): dalfox::scanning::check_dom_verification::has_html_structural_evidence_in_doc has cognitive complexity 24 (threshold 15). Drivers by points: if/else 9 (17 pts), boolean chains 4, loops 2 (3 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_dom_verification.rs"},"region":{"startLine":616}}}],"partialFingerprints":{"codehealthFindingId/v1":"b04aafea65d7eca9f54c52b30b0b4d0cd0f4ddc557f3c17f11843deeba55001c"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::check_dom_verification::verify_sxss_dom (cognitive 24): dalfox::scanning::check_dom_verification::verify_sxss_dom has cognitive complexity 24 (threshold 15). Drivers by points: if/else 6 (19 pts), loops 2 (3 pts), boolean chains 2 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_dom_verification.rs"},"region":{"startLine":1195}}}],"partialFingerprints":{"codehealthFindingId/v1":"3e281792ab2504df90667af4a777a5976e909ffe13a2fae48e149daa70875822"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::server::handlers::get_result_handler (cognitive 24): dalfox::server::handlers::get_result_handler has cognitive complexity 24 (threshold 15). Drivers by points: if/else 14 (23 pts), match/switch 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/handlers.rs"},"region":{"startLine":119}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee3c72ab9583eaa0a8428dd54bcba32e9fad452dcbd607ce7473a4e19214050d"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::server::run_server (cognitive 24): dalfox::server::run_server has cognitive complexity 24 (threshold 15). Drivers by points: if/else 10 (13 pts), boolean chains 6, match/switch 4, loops 1 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/mod.rs"},"region":{"startLine":79}}}],"partialFingerprints":{"codehealthFindingId/v1":"acb13ba2f833393d0d656d9fe19850826b88a2ca6bb56cb3b578d9826cad68ac"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::cmd::scan::preflight::preflight_content_type (cognitive 24): dalfox::cmd::scan::preflight::preflight_content_type has cognitive complexity 24 (threshold 15). Drivers by points: if/else 6 (13 pts), match/switch 4 (8 pts), boolean chains 2, loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/preflight.rs"},"region":{"startLine":158}}}],"partialFingerprints":{"codehealthFindingId/v1":"e7120fada71a829524ae45481e2bd5845376017ce63b83f7eaec840187c51481"}},{"ruleId":"D2","level":"warning","message":{"text":"DalfoxMcp::results_json_for_scan (cognitive 23): DalfoxMcp::results_json_for_scan has cognitive complexity 23 (threshold 15). Drivers by points: if/else 16 (22 pts), boolean chains 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/mcp/mod.rs"},"region":{"startLine":877}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b262a63394a27b3b944b8486e527af2d4fb25ca3b086e1698140efa219d0183"}},{"ruleId":"D2","level":"warning","message":{"text":"ScanWorkerCtx::run_hpp_phase (cognitive 23): ScanWorkerCtx::run_hpp_phase has cognitive complexity 23 (threshold 15). Drivers by points: if/else 5 (13 pts), match/switch 1 (5 pts), loops 2 (3 pts), boolean chains 2 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/mod.rs"},"region":{"startLine":1562}}}],"partialFingerprints":{"codehealthFindingId/v1":"1d163b94e84909e3a48700cacf673011e9518ba68c2d297d7a407b980e2d54fa"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::light_verify::verify_dom_xss_light_with_client (cognitive 23): dalfox::scanning::light_verify::verify_dom_xss_light_with_client has cognitive complexity 23 (threshold 15). Drivers by points: if/else 8 (22 pts), boolean chains 1 (nesting depth added 14). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/light_verify.rs"},"region":{"startLine":23}}}],"partialFingerprints":{"codehealthFindingId/v1":"9ebf816d5dfeb3d0fb0bf0ef4c5c9b53045e014aeec747706dfef747b8873b5e"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::ast_integration::build_dom_xss_poc_url (cognitive 23): dalfox::scanning::ast_integration::build_dom_xss_poc_url has cognitive complexity 23 (threshold 15). Drivers by points: if/else 14 (21 pts), boolean chains 2 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_integration.rs"},"region":{"startLine":908}}}],"partialFingerprints":{"codehealthFindingId/v1":"d045797a4d16ccd59f495e5e35e916e47aefc6bb514bec79ca8cd9f1f2f5e899"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::ast_integration::build_dom_xss_manual_poc_hint (cognitive 23): dalfox::scanning::ast_integration::build_dom_xss_manual_poc_hint has cognitive complexity 23 (threshold 15). Drivers by points: if/else 18 (20 pts), boolean chains 3 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_integration.rs"},"region":{"startLine":972}}}],"partialFingerprints":{"codehealthFindingId/v1":"964a7f00d5725863759036b52fb23f35642d02a5efddde31be44fade00e07f36"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::discovery::dedupe_reflection_params (cognitive 23): dalfox::parameter_analysis::discovery::dedupe_reflection_params has cognitive complexity 23 (threshold 15). Drivers by points: if/else 10 (13 pts), boolean chains 6, loops 3 (4 pts) (nesting depth added 4). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/mod.rs"},"region":{"startLine":123}}}],"partialFingerprints":{"codehealthFindingId/v1":"65189f961af2f8f333f92ab40ba103d4b46387daad7c6be34bc0a3c0d7143393"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::waf_strategy::expand_waf_payloads (cognitive 23): dalfox::scanning::waf_strategy::expand_waf_payloads has cognitive complexity 23 (threshold 15). Drivers by points: if/else 7 (18 pts), loops 3 (5 pts) (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/waf_strategy.rs"},"region":{"startLine":203}}}],"partialFingerprints":{"codehealthFindingId/v1":"0df95cb342c111ee68ada4903dd019ada51bdbff66fd3e3794247855f74959a2"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::mining::probe_graphql::probe_graphql_params (cognitive 23): dalfox::parameter_analysis::mining::probe_graphql::probe_graphql_params has cognitive complexity 23 (threshold 15). Drivers by points: if/else 10 (17 pts), boolean chains 2, loops 2, match/switch 1 (2 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/probe_graphql.rs"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"c423d8efab0b805ad58f5970968b1bb278dc868204246146fcab0512ac81592d"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::waf::bypass::mutate::find_sink_call (cognitive 23): dalfox::waf::bypass::mutate::find_sink_call has cognitive complexity 23 (threshold 15). Drivers by points: if/else 3 (12 pts), loops 3 (6 pts), match/switch 1 (4 pts), boolean chains 1 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/waf/bypass/mutate.rs"},"region":{"startLine":28}}}],"partialFingerprints":{"codehealthFindingId/v1":"46dff00fa68e8e8624b23e36aaf8a75997aa6afb5c2044d5303181eba2c133ae"}},{"ruleId":"D2","level":"warning","message":{"text":"ScanWorkerCtx::run_reflection_phase (cognitive 22): ScanWorkerCtx::run_reflection_phase has cognitive complexity 22 (threshold 15). Drivers by points: if/else 6 (14 pts), boolean chains 5, loops 2 (3 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/mod.rs"},"region":{"startLine":943}}}],"partialFingerprints":{"codehealthFindingId/v1":"67e0f0999c5465c72dfeaf4214f4511a43f14b53a24bf5aa127a55d672c71484"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::check_reflection::is_in_safe_context (cognitive 22): dalfox::scanning::check_reflection::is_in_safe_context has cognitive complexity 22 (threshold 15). Drivers by points: if/else 8 (17 pts), loops 3 (4 pts), boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_reflection.rs"},"region":{"startLine":175}}}],"partialFingerprints":{"codehealthFindingId/v1":"1285126a2cb6d933a0f7baf738767e13b1a2c04dcaf052f7e3e5eb39072f2142"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::check_reflection::raw_reflection_inert_in_text (cognitive 22): dalfox::scanning::check_reflection::raw_reflection_inert_in_text has cognitive complexity 22 (threshold 15). Drivers by points: if/else 7 (14 pts), boolean chains 5, loops 2 (3 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_reflection.rs"},"region":{"startLine":1475}}}],"partialFingerprints":{"codehealthFindingId/v1":"4ff3aef5845f7c557dbab52bd2b7a096cb997f1bea06ba6d47f68a55137255d1"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::utils::term::skip_escape_sequence (cognitive 22): dalfox::utils::term::skip_escape_sequence has cognitive complexity 22 (threshold 15). Drivers by points: if/else 6 (11 pts), loops 3 (6 pts), match/switch 2 (4 pts), boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/utils/term.rs"},"region":{"startLine":98}}}],"partialFingerprints":{"codehealthFindingId/v1":"61f511d64a344ef0ef471f5726fee9f243dca5d075710f6624ce18f96a93557a"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::ensure_sxss_candidate_params (cognitive 22): dalfox::parameter_analysis::ensure_sxss_candidate_params has cognitive complexity 22 (threshold 15). Drivers by points: if/else 6 (11 pts), loops 4 (9 pts), boolean chains 2 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mod.rs"},"region":{"startLine":1503}}}],"partialFingerprints":{"codehealthFindingId/v1":"92b0c7d14a067e822156f2f5ba3bbca52253d5b025d750d25d2eeb5840318271"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::check_reflection::sxss_store_probe (cognitive 21): dalfox::scanning::check_reflection::sxss_store_probe has cognitive complexity 21 (threshold 15). Drivers by points: if/else 4 (13 pts), loops 3 (6 pts), boolean chains 2 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_reflection.rs"},"region":{"startLine":2512}}}],"partialFingerprints":{"codehealthFindingId/v1":"3be09558c2203216cd99c99a6fee50d5c7b1652f014775ac3152dcdb38ec96d8"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::check_dom_verification::payload_has_handler_sink_text (cognitive 21): dalfox::scanning::check_dom_verification::payload_has_handler_sink_text has cognitive complexity 21 (threshold 15). Drivers by points: if/else 6 (10 pts), boolean chains 6, loops 3 (5 pts) (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_dom_verification.rs"},"region":{"startLine":290}}}],"partialFingerprints":{"codehealthFindingId/v1":"e3ff53461f4a58284a76219742e8ac4da28e9de07670bee95924fd83ebc0f94c"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::payload_families::get_dom_payloads_for_context (cognitive 21): dalfox::scanning::payload_families::get_dom_payloads_for_context has cognitive complexity 21 (threshold 15). Drivers by points: if/else 9 (17 pts), match/switch 2 (3 pts), boolean chains 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/payload_families.rs"},"region":{"startLine":437}}}],"partialFingerprints":{"codehealthFindingId/v1":"20ccdd24c29a395211115526ba566c5a79e6f4b35973ef814b59bfdb6ad5ec3c"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::vuln_libs::detect_vulnerable_libraries (cognitive 21): dalfox::scanning::vuln_libs::detect_vulnerable_libraries has cognitive complexity 21 (threshold 15). Drivers by points: loops 5 (12 pts), if/else 2 (8 pts), boolean chains 1 (nesting depth added 13). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/vuln_libs.rs"},"region":{"startLine":325}}}],"partialFingerprints":{"codehealthFindingId/v1":"b0c1c1754e71c59b50848439d1e8e90238f8e3e606bd82f53d7ecbf6d5969ab3"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::analyze_parameters (cognitive 21): dalfox::parameter_analysis::analyze_parameters has cognitive complexity 21 (threshold 15). Drivers by points: if/else 12 (15 pts), loops 4 (6 pts) (nesting depth added 5). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mod.rs"},"region":{"startLine":1199}}}],"partialFingerprints":{"codehealthFindingId/v1":"369d8b384476c35919112c8c3f978bc690721be559b8ac9f5337c07776396bb4"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::cmd::scan::analysis::run_preflight_and_analysis (cognitive 21): dalfox::cmd::scan::analysis::run_preflight_and_analysis has cognitive complexity 21 (threshold 15). Drivers by points: if/else 3 (9 pts), loops 4 (9 pts), match/switch 1 (3 pts) (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/analysis.rs"},"region":{"startLine":69}}}],"partialFingerprints":{"codehealthFindingId/v1":"156a586816bf4168394239027879d72ea653a9aeb5fa2997f41e108a363c8c7b"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::walk_call_expression (cognitive 20): DomXssVisitor::walk_call_expression has cognitive complexity 20 (threshold 15). Drivers by points: if/else 13 (16 pts), boolean chains 4 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/sinks.rs"},"region":{"startLine":1139}}}],"partialFingerprints":{"codehealthFindingId/v1":"6e95116c6424fcfb6a915173a324ec92efeb26de71111a538b1bb9d0c1a9ef14"}},{"ruleId":"D2","level":"warning","message":{"text":"ScanWorkerCtx::scan_param (cognitive 20): ScanWorkerCtx::scan_param has cognitive complexity 20 (threshold 15). Drivers by points: if/else 14 (16 pts), boolean chains 3, match/switch 1 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/mod.rs"},"region":{"startLine":626}}}],"partialFingerprints":{"codehealthFindingId/v1":"5e6e27340fc76cbaa0752de8a87c1656e2f41afeed16448a5cccc32bd985a563"}},{"ruleId":"D2","level":"warning","message":{"text":"Result::results_to_sarif_with_meta (cognitive 20): Result::results_to_sarif_with_meta has cognitive complexity 20 (threshold 15). Drivers by points: if/else 12 (14 pts), boolean chains 4, loops 1, match/switch 1 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/result/format_sarif.rs"},"region":{"startLine":24}}}],"partialFingerprints":{"codehealthFindingId/v1":"a7f872663126f6a33878f4a2a0d3642e6032d3705dc6c76e0c1e8f525cdf7960"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::cmd::scan::blind::arm_and_dispatch (cognitive 20): dalfox::cmd::scan::blind::arm_and_dispatch has cognitive complexity 20 (threshold 15). Drivers by points: match/switch 2 (6 pts), if/else 4 (5 pts), loops 2 (5 pts), boolean chains 4 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/blind.rs"},"region":{"startLine":18}}}],"partialFingerprints":{"codehealthFindingId/v1":"b15012a85aa08d7a2d05e0211f568cffe808c7d3f3dd43b7c808011ea30606bd"}},{"ruleId":"D2","level":"warning","message":{"text":"DalfoxMcp::preflight_dalfox (cognitive 19): DalfoxMcp::preflight_dalfox has cognitive complexity 19 (threshold 15). Drivers by points: if/else 11, match/switch 6, boolean chains 1, loops 1. To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/mcp/mod.rs"},"region":{"startLine":1284}}}],"partialFingerprints":{"codehealthFindingId/v1":"5b1e220b1fb0fde9b2a9c728544ceccd431e68fec85c6bb614b4534ea412639a"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::resolve_wrapper_param_argument_taint (cognitive 19): DomXssVisitor::resolve_wrapper_param_argument_taint has cognitive complexity 19 (threshold 15). Drivers by points: if/else 9 (17 pts), boolean chains 2 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/bound_calls.rs"},"region":{"startLine":158}}}],"partialFingerprints":{"codehealthFindingId/v1":"802ce221f6d5ef4ec4cf3aaf6af355d2ebfc1c93bea2d849db4057166dab071c"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::classify_tt_create_method (cognitive 19): DomXssVisitor::classify_tt_create_method has cognitive complexity 19 (threshold 15). Drivers by points: if/else 5 (8 pts), match/switch 6 (8 pts), boolean chains 2, loops 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/trusted_types.rs"},"region":{"startLine":107}}}],"partialFingerprints":{"codehealthFindingId/v1":"77aade57e1e00630a8cf0d6d54c74d3e078e2e4fa34d2535da055bd1ec691fcd"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::tech_detect::detect_technologies (cognitive 19): dalfox::scanning::tech_detect::detect_technologies has cognitive complexity 19 (threshold 15). Drivers by points: if/else 5 (11 pts), loops 2 (3 pts), match/switch 1 (3 pts), boolean chains 2 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/tech_detect.rs"},"region":{"startLine":98}}}],"partialFingerprints":{"codehealthFindingId/v1":"81155844da848dae610dcb728e027be79d975efbac60ca7cb3bafee204922633"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::xss_blind::blind_scanning_with (cognitive 19): dalfox::scanning::xss_blind::blind_scanning_with has cognitive complexity 19 (threshold 15). Drivers by points: loops 7 (11 pts), if/else 3 (7 pts), boolean chains 1 (nesting depth added 8). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/xss_blind.rs"},"region":{"startLine":194}}}],"partialFingerprints":{"codehealthFindingId/v1":"65b3dcc599a67f49009ba326c86f088e4c275ec7b703022d04044f2d8018cd89"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::cmd::scan::baseline::parse_report (cognitive 19): dalfox::cmd::scan::baseline::parse_report has cognitive complexity 19 (threshold 15). Drivers by points: if/else 6 (9 pts), match/switch 3 (7 pts), boolean chains 2, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/baseline.rs"},"region":{"startLine":328}}}],"partialFingerprints":{"codehealthFindingId/v1":"3cf2c9f8f76b29e68acf72b61af94e859fc0467359bec304a1e61ec1286a0928"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::waf::bypass::mutate::find_first_tag_attr_break (cognitive 19): dalfox::waf::bypass::mutate::find_first_tag_attr_break has cognitive complexity 19 (threshold 15). Drivers by points: if/else 4 (11 pts), boolean chains 4, loops 2 (4 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/waf/bypass/mutate.rs"},"region":{"startLine":93}}}],"partialFingerprints":{"codehealthFindingId/v1":"45600cd1740de6275b475e6ce41ef4edc4b99d4c3d042fef25bfb47b49342b3c"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::waf::bypass::mutate::mixed_html_entities (cognitive 19): dalfox::waf::bypass::mutate::mixed_html_entities has cognitive complexity 19 (threshold 15). Drivers by points: if/else 8 (16 pts), match/switch 1 (2 pts), loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/waf/bypass/mutate.rs"},"region":{"startLine":315}}}],"partialFingerprints":{"codehealthFindingId/v1":"8fcf63a0e75bd2b30d5a2f8ca6f3f098100e6ff68e69ef4ad70e40f4608936e9"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::waf::bypass::mutate::is_inside_rawtext_element (cognitive 19): dalfox::waf::bypass::mutate::is_inside_rawtext_element has cognitive complexity 19 (threshold 15). Drivers by points: if/else 7 (16 pts), loops 2 (3 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/waf/bypass/mutate.rs"},"region":{"startLine":516}}}],"partialFingerprints":{"codehealthFindingId/v1":"6c6327ac10ad4b1c3e49b9854e8adaa0d7f37a956d46bd209916036f8033efde"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::cmd::scan::preflight::describe_reqwest_failure (cognitive 19): dalfox::cmd::scan::preflight::describe_reqwest_failure has cognitive complexity 19 (threshold 15). Drivers by points: if/else 11 (14 pts), boolean chains 3, loops 1 (2 pts) (nesting depth added 4). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/preflight.rs"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"ea0b462e6d29e2e1b247ee841eb92fd850f141da2fb2584460c11ac2ed2000d5"}},{"ruleId":"D2","level":"warning","message":{"text":"DomXssVisitor::is_tainted (cognitive 18): DomXssVisitor::is_tainted has cognitive complexity 18 (threshold 15). Drivers by points: if/else 5 (8 pts), boolean chains 5, match/switch 3 (5 pts) (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/taint.rs"},"region":{"startLine":663}}}],"partialFingerprints":{"codehealthFindingId/v1":"42ed0a06f448e4098e8cf42b993d81b4fc5eefd66086892c4db225fb5bac6423"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::check_reflection::check_reflection_with_hpp_url (cognitive 18): dalfox::scanning::check_reflection::check_reflection_with_hpp_url has cognitive complexity 18 (threshold 15). Drivers by points: if/else 9 (14 pts), match/switch 1 (3 pts), boolean chains 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_reflection.rs"},"region":{"startLine":3059}}}],"partialFingerprints":{"codehealthFindingId/v1":"4923e412313f73caa779c5cb5b281485d499ef2652b193be40619f8d8fa4b64a"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::cmd::scan::session::classify (cognitive 18): dalfox::cmd::scan::session::classify has cognitive complexity 18 (threshold 15). Drivers by points: if/else 9 (12 pts), boolean chains 6 (nesting depth added 3). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/session.rs"},"region":{"startLine":402}}}],"partialFingerprints":{"codehealthFindingId/v1":"9b255459d36ae29a0f489e54b2228bdb9b77d54ff836a6d65bbe4d41a2af69c1"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::discovery::cookie::check_cookie_discovery (cognitive 18): dalfox::parameter_analysis::discovery::cookie::check_cookie_discovery has cognitive complexity 18 (threshold 15). Drivers by points: if/else 7 (11 pts), boolean chains 3, loops 2, match/switch 1 (2 pts) (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/cookie.rs"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"47ae2db7a5d4738bc9fd4592cab1d9d0b2d880ea0a565dbfd28ba91e5557fb3c"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::ast_integration::reflected_markup_from_document (cognitive 18): dalfox::scanning::ast_integration::reflected_markup_from_document has cognitive complexity 18 (threshold 15). Drivers by points: if/else 7 (14 pts), loops 3 (4 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_integration.rs"},"region":{"startLine":116}}}],"partialFingerprints":{"codehealthFindingId/v1":"7209495cf85902e92e10d1e3e7f6dfa5644d122e58ee350766056174b1639413"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::payload::xss_csp_bypass::get_csp_bypass_payloads (cognitive 18): dalfox::payload::xss_csp_bypass::get_csp_bypass_payloads has cognitive complexity 18 (threshold 15). Drivers by points: if/else 9, loops 4 (9 pts) (nesting depth added 5). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/payload/xss_csp_bypass.rs"},"region":{"startLine":321}}}],"partialFingerprints":{"codehealthFindingId/v1":"e812f2ae95e0be05c75f103a4dfc52b601ec81e5bdcd3fc73486a7239549cbce"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::vuln_libs::judge (cognitive 18): dalfox::scanning::vuln_libs::judge has cognitive complexity 18 (threshold 15). Drivers by points: if/else 4 (10 pts), loops 2 (4 pts), match/switch 1 (3 pts), boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/vuln_libs.rs"},"region":{"startLine":287}}}],"partialFingerprints":{"codehealthFindingId/v1":"946c8de64f81ed7102007acc779defe4c507e37abac8b82c7a53936e78c91e68"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::server::cors::compile_allowed_origins (cognitive 18): dalfox::server::cors::compile_allowed_origins has cognitive complexity 18 (threshold 15). Drivers by points: if/else 6 (13 pts), match/switch 1 (3 pts), loops 1 (2 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/cors.rs"},"region":{"startLine":51}}}],"partialFingerprints":{"codehealthFindingId/v1":"985f2fa5698f92157fef94b4d5afa306f94f67725e0d63a6062930d7bdb577c7"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::ast_dom_phase::fetch_and_analyze_external_js (cognitive 17): dalfox::scanning::ast_dom_phase::fetch_and_analyze_external_js has cognitive complexity 17 (threshold 15). Drivers by points: if/else 5 (9 pts), match/switch 2 (4 pts), loops 2 (3 pts), boolean chains 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_phase.rs"},"region":{"startLine":202}}}],"partialFingerprints":{"codehealthFindingId/v1":"77a934ac5f440ace73aa7a10fd0da2345adff9ca55eb49c462de028d0e4e4cf6"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::utils::xml::nesting_overflow_offset (cognitive 17): dalfox::utils::xml::nesting_overflow_offset has cognitive complexity 17 (threshold 15). Drivers by points: if/else 3 (9 pts), loops 2 (4 pts), boolean chains 2, match/switch 1 (2 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/utils/xml.rs"},"region":{"startLine":368}}}],"partialFingerprints":{"codehealthFindingId/v1":"f6e47fbfabc9d627f65b235287925d6dda0bfc789c77690c26c029741b8521e0"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::parameter_analysis::ensure_explicit_params (cognitive 17): dalfox::parameter_analysis::ensure_explicit_params has cognitive complexity 17 (threshold 15). Drivers by points: if/else 4 (9 pts), match/switch 2 (5 pts), boolean chains 2, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mod.rs"},"region":{"startLine":1448}}}],"partialFingerprints":{"codehealthFindingId/v1":"f915aeaa9aeb9165cfa06c9f8ba64a0092f4310586042d7d1e2608f53caeb0a4"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::check_reflection::is_payload_inert_in_scripts (cognitive 16): dalfox::scanning::check_reflection::is_payload_inert_in_scripts has cognitive complexity 16 (threshold 15). Drivers by points: if/else 7 (9 pts), boolean chains 4, loops 3 (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_reflection.rs"},"region":{"startLine":924}}}],"partialFingerprints":{"codehealthFindingId/v1":"f4d5a3209c6439dc29f6dd78c79861b5be124d6513cf62c7212905f140022aac"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::scanning::check_dom_verification::classify_dom_evidence (cognitive 16): dalfox::scanning::check_dom_verification::classify_dom_evidence has cognitive complexity 16 (threshold 15). Drivers by points: boolean chains 8, if/else 7 (8 pts) (nesting depth added 1). To reduce it, name the conditions: bind each compound test to a well-named local or a small predicate function, so the body reads as a sequence of named decisions rather than a chain of operators."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_dom_verification.rs"},"region":{"startLine":746}}}],"partialFingerprints":{"codehealthFindingId/v1":"add2acab3db35c9800b78cc5a2ade44ab86f7434fa00a19de1317bcc2f1f5dc8"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::cmd::scan::input::apply_out_of_scope_filter (cognitive 16): dalfox::cmd::scan::input::apply_out_of_scope_filter has cognitive complexity 16 (threshold 15). Drivers by points: if/else 4 (8 pts), match/switch 2 (4 pts), loops 1 (3 pts), boolean chains 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/input.rs"},"region":{"startLine":1245}}}],"partialFingerprints":{"codehealthFindingId/v1":"4cd5a0ed10c6f60f469c24452df929b7635e35697d1af0e12910757f13766f09"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::waf::bypass::mutate::sink_in_attr_context (cognitive 16): dalfox::waf::bypass::mutate::sink_in_attr_context has cognitive complexity 16 (threshold 15). Drivers by points: if/else 3 (7 pts), loops 3 (5 pts), boolean chains 4 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/waf/bypass/mutate.rs"},"region":{"startLine":603}}}],"partialFingerprints":{"codehealthFindingId/v1":"03316d3ce986ccca8db61930b719d460d9cbae60335cac7aef4717e1e1ece29d"}},{"ruleId":"D2","level":"warning","message":{"text":"dalfox::cmd::scan::output::render_only_discovery (cognitive 16): dalfox::cmd::scan::output::render_only_discovery has cognitive complexity 16 (threshold 15). Drivers by points: loops 5 (10 pts), if/else 3 (5 pts), match/switch 1 (nesting depth added 7). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/output.rs"},"region":{"startLine":217}}}],"partialFingerprints":{"codehealthFindingId/v1":"1e694c5983882ca118635683bce77528865907c7d9044c54b2253edaddf34f92"}},{"ruleId":"D4","level":"warning","message":{"text":"Near-duplicate member pair (70 shared lines): src/server/handlers.rs:17-117 | src/server/handlers.rs:320-544 \u2014 These two members are variants of one another: 70 of their lines are already reported as duplicated blocks below, spread through both bodies rather than gathered into one. Read them as a single construct written twice. The repair is at the members\u0027 grain \u2014 factor the shared pipeline into one implementation the two call with their differences as parameters or as an injected step, or, where the difference is systematic (sync against async, one transport against another), generate one from the other. Extracting the individual blocks below is not the same fix: it leaves the two bodies in place and the next edit still has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/handlers.rs"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"5783ac064b46a080510a4a164f14a1254659f1806752772a6540610e80693841"}},{"ruleId":"D4","level":"warning","message":{"text":"Members sharing a duplicated core (8 members, 50\u002B identical tokens): src/parameter_analysis/discovery/cookie.rs:10-106 | src/parameter_analysis/discovery/header.rs:67-184 | src/parameter_analysis/discovery/query.rs:35-352 | src/parameter_analysis/mining/probe_body.rs:11-183 | src/parameter_analysis/mining/probe_graphql.rs:23-135 | src/parameter_analysis/mining/probe_json.rs:11-207 | src/parameter_analysis/mining/probe_multipart.rs:20-131 | src/parameter_analysis/mining/probe_xml.rs:44-165 \u2014 These 8 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below \u2014 it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 8 times. The repair is at the members\u0027 grain \u2014 factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 8 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/cookie.rs"},"region":{"startLine":10}}}],"partialFingerprints":{"codehealthFindingId/v1":"e4f84ac32a3a72432bd009f26c2badef0144fc023d5bda7bef56fea58e9b74e2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (22\u201327 lines \u00D7 2): src/scanning/check_dom_verification.rs:1208-1229 | src/scanning/check_reflection.rs:2739-2765 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_dom_verification.rs"},"region":{"startLine":1208}}}],"partialFingerprints":{"codehealthFindingId/v1":"963c5554385c8c549dbfbeb23f41b9a332f3ab1efe31f5878468923c4ce19d9b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (24\u201325 lines \u00D7 2): src/mcp/mod.rs:961-985 | src/server/handlers.rs:161-184 \u2014 before extracting anything, compare \u0060src/mcp/mod.rs\u0060 and \u0060src/server/handlers.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 76 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/mcp/mod.rs"},"region":{"startLine":961}}}],"partialFingerprints":{"codehealthFindingId/v1":"cd9ffd9cc7d59e31d25fc8f419aead7be2002ce8b795d36f5dcf2381a37c600c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (23 lines \u00D7 2): src/parameter_analysis/mining/probe_graphql.rs:109-131 | src/parameter_analysis/mining/probe_xml.rs:139-161 \u2014 before extracting anything, compare \u0060src/parameter_analysis/mining/probe_graphql.rs\u0060 and \u0060src/parameter_analysis/mining/probe_xml.rs\u0060 as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 79 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/probe_graphql.rs"},"region":{"startLine":109}}}],"partialFingerprints":{"codehealthFindingId/v1":"e0f20cdfb5ffefb2a45a028d3e30f77d8b44527870bf3bcbe50a0d8c98ae61ed"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (20\u201321 lines \u00D7 2): src/mcp/mod.rs:1144-1163 | src/server/handlers.rs:796-816 \u2014 before extracting anything, compare \u0060src/mcp/mod.rs\u0060 and \u0060src/server/handlers.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 76 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/mcp/mod.rs"},"region":{"startLine":1144}}}],"partialFingerprints":{"codehealthFindingId/v1":"475b87af5be1bb856bcbb7ddd78663413008de383b4a45f69b12885821d05f20"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (19\u201320 lines \u00D7 2): src/server/handlers.rs:46-65 | src/server/handlers.rs:348-366 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/handlers.rs"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"7422201e326778bf031a58bb2896f546dbf97849808835fc56ab37d8a8bddece"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17\u201320 lines \u00D7 2): src/server/handlers.rs:80-99 | src/server/handlers.rs:509-525 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/handlers.rs"},"region":{"startLine":80}}}],"partialFingerprints":{"codehealthFindingId/v1":"edf7be20381f6a2b6582d56730d50236d47a078458e91eafbb0663b20f0ab471"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12\u201320 lines \u00D7 2): src/scanning/param_jobs.rs:211-230 | src/scanning/param_jobs.rs:256-267 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/param_jobs.rs"},"region":{"startLine":211}}}],"partialFingerprints":{"codehealthFindingId/v1":"e494b56c4a4c9d735aea6e1fb36ffd9431de04bb526c719894cca166768692f4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (19 lines \u00D7 2): src/payload/remote.rs:309-327 | src/payload/remote.rs:371-389 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/payload/remote.rs"},"region":{"startLine":309}}}],"partialFingerprints":{"codehealthFindingId/v1":"b718e144074346bbd312b8cb0f276f4cf43b86b9d4a714576014fb16eab97164"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17\u201318 lines \u00D7 5): src/parameter_analysis/discovery/cookie.rs:89-105 | src/parameter_analysis/discovery/header.rs:167-183 | src/parameter_analysis/discovery/path.rs:177-193 | src/parameter_analysis/mining/probe_body.rs:156-173 | src/parameter_analysis/mining/probe_json.rs:182-199 \u2014 before extracting anything, compare \u0060src/parameter_analysis/discovery/cookie.rs\u0060 and \u0060src/parameter_analysis/discovery/header.rs\u0060 as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 73 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/cookie.rs"},"region":{"startLine":89}}}],"partialFingerprints":{"codehealthFindingId/v1":"082138c41dc6e343df60f5841712a47ca5c5305b123879d4773a45c73c0b3f8b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15\u201318 lines \u00D7 2): src/mcp/mod.rs:1615-1632 | src/server/handlers.rs:673-687 \u2014 before extracting anything, compare \u0060src/mcp/mod.rs\u0060 and \u0060src/server/handlers.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 76 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/mcp/mod.rs"},"region":{"startLine":1615}}}],"partialFingerprints":{"codehealthFindingId/v1":"abf2ad0e3e75222f2e269336785b7e6b3b2de40d00c8af485ae7b5fc3cd7ea08"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (18 lines \u00D7 2): src/payload/remote.rs:237-254 | src/payload/remote.rs:318-335 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/payload/remote.rs"},"region":{"startLine":237}}}],"partialFingerprints":{"codehealthFindingId/v1":"034d6b6c05b63ce86b120454819222857f346512540e7d5022e1bd85aa768415"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (18 lines \u00D7 2): src/payload/remote.rs:276-293 | src/payload/remote.rs:380-397 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/payload/remote.rs"},"region":{"startLine":276}}}],"partialFingerprints":{"codehealthFindingId/v1":"58448768c915a65e2be2b2f32405007723157199aff17ab49b72977f3a634c89"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14\u201317 lines \u00D7 3): src/parameter_analysis/discovery/cookie.rs:37-53 | src/parameter_analysis/discovery/header.rs:125-140 | src/parameter_analysis/mining/probe_body.rs:76-89 \u2014 before extracting anything, compare \u0060src/parameter_analysis/discovery/cookie.rs\u0060 and \u0060src/parameter_analysis/discovery/header.rs\u0060 as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 73 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/cookie.rs"},"region":{"startLine":37}}}],"partialFingerprints":{"codehealthFindingId/v1":"e00eec6141d87b554601cb0b656f880ed8f779e3c1a35e33ed58ea438a6a8d41"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): src/mcp/mod.rs:242-258 | src/server/job_runner.rs:359-375 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/mcp/mod.rs"},"region":{"startLine":242}}}],"partialFingerprints":{"codehealthFindingId/v1":"16483944e8dff8a7db5a20ea32f1079b90537fa927c3333145b27b12bddd5c5a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): src/scanning/ast_integration.rs:233-249 | src/scanning/ast_integration.rs:284-300 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_integration.rs"},"region":{"startLine":233}}}],"partialFingerprints":{"codehealthFindingId/v1":"22dfe9b53af5f7ad348daa485b944b8df16da5eea1b24b1422d88d835566bad2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): src/server/handlers.rs:20-36 | src/server/handlers.rs:886-902 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/handlers.rs"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"1d43011c652bb6dd83fdcc3da445087e1a5cd7d90d8471431baa7e05c214e35f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14\u201316 lines \u00D7 4): src/parameter_analysis/mining/probe_body.rs:147-162 | src/parameter_analysis/mining/probe_graphql.rs:113-126 | src/parameter_analysis/mining/probe_json.rs:173-188 | src/parameter_analysis/mining/probe_xml.rs:143-156 \u2014 before extracting anything, compare \u0060src/parameter_analysis/mining/probe_body.rs\u0060 and \u0060src/parameter_analysis/mining/probe_json.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 54 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/probe_body.rs"},"region":{"startLine":147}}}],"partialFingerprints":{"codehealthFindingId/v1":"018eaa2591c7103778ad88ad224ac24d090bec8c3f89d6defe7f1882a680f6d1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 3): src/parameter_analysis/mining/probe_graphql.rs:120-135 | src/parameter_analysis/mining/probe_multipart.rs:116-131 | src/parameter_analysis/mining/probe_xml.rs:150-165 \u2014 before extracting anything, compare \u0060src/parameter_analysis/mining/probe_graphql.rs\u0060 and \u0060src/parameter_analysis/mining/probe_xml.rs\u0060 as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 79 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/probe_graphql.rs"},"region":{"startLine":120}}}],"partialFingerprints":{"codehealthFindingId/v1":"4bce18d1901c9272679508e096634b4499777a157224b074d98c7251757b25c4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15\u201316 lines \u00D7 2): src/scanning/check_reflection.rs:589-603 | src/scanning/check_reflection.rs:704-719 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_reflection.rs"},"region":{"startLine":589}}}],"partialFingerprints":{"codehealthFindingId/v1":"54f850f54cd5fa61bb9ef93d6d39b64e002eb66ebe1e6f7012b29d9d34873329"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15\u201316 lines \u00D7 2): src/scanning/ast_dom_analysis/sinks.rs:612-626 | src/scanning/ast_dom_analysis/sinks.rs:755-770 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/sinks.rs"},"region":{"startLine":612}}}],"partialFingerprints":{"codehealthFindingId/v1":"e8a7a46d4d3ea6fee5f841d19bc3fa28d5c0278d82a1141b724ab9a01744ae7e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): src/cmd/scan/input.rs:434-448 | src/cmd/scan/input.rs:1406-1420 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/input.rs"},"region":{"startLine":434}}}],"partialFingerprints":{"codehealthFindingId/v1":"55a7fae92a62cd2dec477438851d419f8e9fe0d8800bd0145a2926ebdd566d9f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): src/encoding/pipeline.rs:259-273 | src/encoding/pipeline.rs:287-301 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/encoding/pipeline.rs"},"region":{"startLine":259}}}],"partialFingerprints":{"codehealthFindingId/v1":"44361960e4d07f0f3fda7b972ebdb35f04d5f5130275e44357c8f8b18d22637c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): src/payload/remote.rs:232-246 | src/payload/remote.rs:271-285 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/payload/remote.rs"},"region":{"startLine":232}}}],"partialFingerprints":{"codehealthFindingId/v1":"eaef03bed45a2429c60a4a38ddd78f55c7e4f9619475bafc3decacacb5b3874a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): src/scanning/check_reflection.rs:220-234 | src/scanning/check_reflection.rs:897-911 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_reflection.rs"},"region":{"startLine":220}}}],"partialFingerprints":{"codehealthFindingId/v1":"138570d994d1438a4e20e9dfaee31ff70a67b6c1e604846bb86f2ec7cd1b390c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13\u201314 lines \u00D7 3): src/parameter_analysis/discovery/cookie.rs:81-94 | src/parameter_analysis/discovery/header.rs:159-172 | src/parameter_analysis/mining/probe_multipart.rs:110-122 \u2014 before extracting anything, compare \u0060src/parameter_analysis/discovery/cookie.rs\u0060 and \u0060src/parameter_analysis/discovery/header.rs\u0060 as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 73 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/cookie.rs"},"region":{"startLine":81}}}],"partialFingerprints":{"codehealthFindingId/v1":"bf1f264dd25d5fe66785f95a914a186eb9e8a10f477ffe59110b9b55d067e82b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): src/server/handlers.rs:104-117 | src/server/handlers.rs:531-544 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/handlers.rs"},"region":{"startLine":104}}}],"partialFingerprints":{"codehealthFindingId/v1":"3fb34cdf94b97796d2e3fc2a129fd36c5ab83cfef63d047bcafe9a12dbd79b22"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13\u201314 lines \u00D7 2): src/parameter_analysis/mining/probe_graphql.rs:64-77 | src/parameter_analysis/mining/probe_xml.rs:97-109 \u2014 before extracting anything, compare \u0060src/parameter_analysis/mining/probe_graphql.rs\u0060 and \u0060src/parameter_analysis/mining/probe_xml.rs\u0060 as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 79 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/probe_graphql.rs"},"region":{"startLine":64}}}],"partialFingerprints":{"codehealthFindingId/v1":"0cec93583fac04ded4e3675dc55fa9bcc020d78f4177f8be84870423455cdd22"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): src/parameter_analysis/discovery/form.rs:429-442 | src/parameter_analysis/discovery/form.rs:500-513 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/form.rs"},"region":{"startLine":429}}}],"partialFingerprints":{"codehealthFindingId/v1":"cb7aba105bad9dcd7a62083ddf0af65e76e6526dd63be1a2180aead26004bdeb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10\u201313 lines \u00D7 4): src/parameter_analysis/discovery/cookie.rs:41-53 | src/parameter_analysis/discovery/header.rs:129-140 | src/parameter_analysis/discovery/query.rs:67-78 | src/parameter_analysis/mining/probe_body.rs:80-89 \u2014 before extracting anything, compare \u0060src/parameter_analysis/discovery/cookie.rs\u0060 and \u0060src/parameter_analysis/discovery/header.rs\u0060 as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 73 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/cookie.rs"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"ebb218a29398aeafcaea77104917ad1104dcc127192d138277b33e260083dab6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10\u201313 lines \u00D7 2): src/cmd/scan/analysis.rs:822-834 | src/cmd/scan/analysis.rs:867-876 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/analysis.rs"},"region":{"startLine":822}}}],"partialFingerprints":{"codehealthFindingId/v1":"45b65f2fd25e25571279201f20348232f792e1945e8880854d19ee1a41b3ad23"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): src/job/mod.rs:94-106 | src/job/mod.rs:723-735 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/job/mod.rs"},"region":{"startLine":94}}}],"partialFingerprints":{"codehealthFindingId/v1":"2c3570c3f57e2be78168a800d0fbc17b7d9b27131110009dbecb3a95bf04d7fd"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8\u201312 lines \u00D7 3): src/scanning/check_dom_verification.rs:1217-1228 | src/scanning/check_reflection.rs:2558-2565 | src/scanning/check_reflection.rs:2752-2763 \u2014 there are 3 copies across 2 file(s) \u2014 more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 3 sites; resolving a subset leaves the remainder to drift apart."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_dom_verification.rs"},"region":{"startLine":1217}}}],"partialFingerprints":{"codehealthFindingId/v1":"5ad1937bb0eeb0dd437bd6af7607e75090d097fb7f460bc8977aa8c79158e81f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11\u201312 lines \u00D7 2): src/mcp/mod.rs:935-946 | src/server/handlers.rs:149-159 \u2014 before extracting anything, compare \u0060src/mcp/mod.rs\u0060 and \u0060src/server/handlers.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 76 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/mcp/mod.rs"},"region":{"startLine":935}}}],"partialFingerprints":{"codehealthFindingId/v1":"ad84af0e63df6c76d0bfe70db4ff5667574afccd21bb2ba2387319a737efaa92"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11\u201312 lines \u00D7 2): src/payload/remote.rs:223-233 | src/payload/remote.rs:299-310 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/payload/remote.rs"},"region":{"startLine":223}}}],"partialFingerprints":{"codehealthFindingId/v1":"cdec5f587e59b766e2659a6bcfa43bc2a66f267fb225dbe18819f9ce0fa7c8b4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11\u201312 lines \u00D7 2): src/payload/remote.rs:262-272 | src/payload/remote.rs:361-372 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/payload/remote.rs"},"region":{"startLine":262}}}],"partialFingerprints":{"codehealthFindingId/v1":"0dd3dc91c3820ee62c7c42102d9cd966018578ea6343b318336924b52e6ab196"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): src/server/handlers.rs:18-29 | src/server/handlers.rs:321-332 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/handlers.rs"},"region":{"startLine":18}}}],"partialFingerprints":{"codehealthFindingId/v1":"bf41d2ee859bb3da6d641d414548fe971f1ae89c63865eb26444039c9128ef79"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11\u201312 lines \u00D7 2): src/server/handlers.rs:63-73 | src/server/handlers.rs:915-926 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/handlers.rs"},"region":{"startLine":63}}}],"partialFingerprints":{"codehealthFindingId/v1":"dfb663f497c2e560f42a706b22c49d3a3066f8527d9f81e630c22c519989afbb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): src/utils/fs.rs:73-84 | src/utils/fs.rs:122-133 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/utils/fs.rs"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"1facc5ce8ec0f9239db652cd0537718983c7b102c9af640fa63dd154eb62225b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): src/cmd/scan/logging.rs:77-88 | src/cmd/scan/logging.rs:138-149 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/logging.rs"},"region":{"startLine":77}}}],"partialFingerprints":{"codehealthFindingId/v1":"b731d2cd98cb1745f42a74b7a8730f462338e4c58cbdd06a974cd78beeb51430"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10\u201311 lines \u00D7 6): src/parameter_analysis/discovery/cookie.rs:40-50 | src/parameter_analysis/discovery/header.rs:128-138 | src/parameter_analysis/mining/probe_body.rs:79-88 | src/parameter_analysis/mining/probe_json.rs:84-93 | src/parameter_analysis/mining/probe_multipart.rs:63-72 | src/parameter_analysis/mining/probe_xml.rs:96-105 \u2014 before extracting anything, compare \u0060src/parameter_analysis/discovery/cookie.rs\u0060 and \u0060src/parameter_analysis/discovery/header.rs\u0060 as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 73 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/cookie.rs"},"region":{"startLine":40}}}],"partialFingerprints":{"codehealthFindingId/v1":"e73db89c8262824dc19b67d6fc70309535ed4e2ca69d3ef61bf4b84ecf92c043"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 3): src/scanning/ast_dom_analysis/sinks.rs:426-436 | src/scanning/ast_dom_analysis/sinks.rs:620-630 | src/scanning/ast_dom_analysis/sinks.rs:764-774 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/sinks.rs"},"region":{"startLine":426}}}],"partialFingerprints":{"codehealthFindingId/v1":"b09f80f1b0c4c6729840b4554e02eae4a811bda50b5fe8620d8427002ec974f2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): src/cmd/scan/analysis.rs:130-140 | src/cmd/scan/scan_loop.rs:500-510 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/analysis.rs"},"region":{"startLine":130}}}],"partialFingerprints":{"codehealthFindingId/v1":"d1274aabfc73d28aa13ea2a39c67c935268ba38feba7592aeb37642ecf26d898"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): src/payload/remote.rs:442-452 | src/payload/remote.rs:458-468 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/payload/remote.rs"},"region":{"startLine":442}}}],"partialFingerprints":{"codehealthFindingId/v1":"727e3c5a5c0646954cfa6b38b2c7922bf8d209d471132c2fb7dcc8eb8d312278"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): src/scanning/check_reflection.rs:1510-1520 | src/scanning/check_reflection.rs:1735-1746 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_reflection.rs"},"region":{"startLine":1510}}}],"partialFingerprints":{"codehealthFindingId/v1":"3f65de3de21ab4e46fbf799030672092a919fd4ea0dd61a3a70039c3087f2884"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): src/scanning/url_inject.rs:832-842 | src/scanning/url_inject.rs:857-867 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/url_inject.rs"},"region":{"startLine":832}}}],"partialFingerprints":{"codehealthFindingId/v1":"b6cb758c1509411ba562ec75ee00584a94edf52585100148b506254082c73d24"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9\u201310 lines \u00D7 3): src/parameter_analysis/discovery/form.rs:171-179 | src/parameter_analysis/discovery/form.rs:244-253 | src/parameter_analysis/discovery/form.rs:315-323 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/form.rs"},"region":{"startLine":171}}}],"partialFingerprints":{"codehealthFindingId/v1":"bccc4f3d82acc7abdf57a4dc02c810579aa368212917290eb1ca29fdcd19264d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9\u201310 lines \u00D7 2): src/cmd/scan/output.rs:43-52 | src/scanning/param_jobs.rs:25-33 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/output.rs"},"region":{"startLine":43}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a18f12a6b7376d475b59e60f902b7db6baa8ee76bd57aa984e4566bf5bc85cc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): src/scanning/url_inject.rs:457-466 | src/scanning/url_inject.rs:471-480 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/url_inject.rs"},"region":{"startLine":457}}}],"partialFingerprints":{"codehealthFindingId/v1":"67c148483675cabe9eb9e9d2fe088d45a82c1d7ccd0a33dd31287ea6e9f29e64"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): src/payload/xss_html.rs:115-124 | src/payload/xss_html.rs:161-170 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/payload/xss_html.rs"},"region":{"startLine":115}}}],"partialFingerprints":{"codehealthFindingId/v1":"1ac5639e15ce11c68adfb78d3c01ed9827b63e0a8594aec308ae980cd359afaf"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (4\u201310 lines \u00D7 4): src/parameter_analysis/discovery/query.rs:151-160 | src/parameter_analysis/discovery/query.rs:230-239 | src/parameter_analysis/discovery/query.rs:286-289 | src/parameter_analysis/discovery/query.rs:326-329 \u2014 all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/query.rs"},"region":{"startLine":151}}}],"partialFingerprints":{"codehealthFindingId/v1":"40dbb1f82842e0267b2d707e515dc9eb9bd99cb901cc79eee1ac10fe84a77470"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8\u20139 lines \u00D7 2): src/cmd/scan/output.rs:249-257 | src/cmd/scan/output.rs:266-273 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/output.rs"},"region":{"startLine":249}}}],"partialFingerprints":{"codehealthFindingId/v1":"a647df6f5508306af5798514bb5d5f9d160eb917925fe95d62b8a972e9b183ad"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): src/mcp/job_runtime.rs:56-64 | src/server/job_runner.rs:121-129 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/mcp/job_runtime.rs"},"region":{"startLine":56}}}],"partialFingerprints":{"codehealthFindingId/v1":"59cb6f38cd01e96360385729d93df12b2c66ba3439e4a203bcee9aa6dcefb717"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): src/scanning/check_dom_verification.rs:747-755 | src/scanning/check_dom_verification.rs:784-792 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_dom_verification.rs"},"region":{"startLine":747}}}],"partialFingerprints":{"codehealthFindingId/v1":"a04f01e788e9e212131e9d2eadf497ff37ee34651b839160d1223b0a43c76ded"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): src/scanning/url_inject.rs:511-519 | src/scanning/url_inject.rs:523-531 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/url_inject.rs"},"region":{"startLine":511}}}],"partialFingerprints":{"codehealthFindingId/v1":"5080a550453ac7c8c7fe741100d0d2b80c828afc2ee18e13c4f819b3abdb0c95"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): src/parameter_analysis/discovery/form.rs:417-425 | src/parameter_analysis/discovery/form.rs:488-496 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/form.rs"},"region":{"startLine":417}}}],"partialFingerprints":{"codehealthFindingId/v1":"23db6dd8905055ee8265c644084e441620dee25f95dd3c98b7124e9fae083198"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): src/parameter_analysis/discovery/form.rs:444-452 | src/parameter_analysis/discovery/form.rs:515-523 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/form.rs"},"region":{"startLine":444}}}],"partialFingerprints":{"codehealthFindingId/v1":"23c4efd50155314d3aeac86280a537c2787fb1c39066f9fe289f86ac28ab67db"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 3): src/encoding/pipeline.rs:259-266 | src/encoding/pipeline.rs:287-294 | src/encoding/pipeline.rs:340-347 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/encoding/pipeline.rs"},"region":{"startLine":259}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c5fd690cb262fe6f9cf1a3d5ada1c3448c3248b19d7bea6f1ef2136d04e5d37"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 3): src/encoding/pipeline.rs:264-272 | src/encoding/pipeline.rs:292-300 | src/encoding/pipeline.rs:370-377 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/encoding/pipeline.rs"},"region":{"startLine":264}}}],"partialFingerprints":{"codehealthFindingId/v1":"71f4eca28ca36bbe51f51b2f84a4b6558528961e28a8969cf94553a1bc3fe136"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 3): src/mcp/job_runtime.rs:56-63 | src/server/job_runner.rs:121-128 | src/server/job_runner.rs:164-171 \u2014 there are 3 copies across 2 file(s) \u2014 more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 3 sites; resolving a subset leaves the remainder to drift apart."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/mcp/job_runtime.rs"},"region":{"startLine":56}}}],"partialFingerprints":{"codehealthFindingId/v1":"0fb6af2a0b2bba314a19d4a58404e8585ea82ac9ca63853b6e357e53f68ac188"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 3): src/parameter_analysis/discovery/form.rs:355-362 | src/parameter_analysis/discovery/form.rs:436-443 | src/parameter_analysis/discovery/form.rs:507-514 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/form.rs"},"region":{"startLine":355}}}],"partialFingerprints":{"codehealthFindingId/v1":"0d74651023daa7fbfb723102c3e8217799a09e2dac41139b956f38008a8d8536"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): src/cmd/scan/preflight.rs:95-102 | src/cmd/scan/preflight.rs:136-143 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/preflight.rs"},"region":{"startLine":95}}}],"partialFingerprints":{"codehealthFindingId/v1":"fcc6c090d4f5b7721ea0e011b9352f6207f376bcac041d53c43fd2d0cae18a8f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): src/scanning/mod.rs:983-990 | src/scanning/mod.rs:1395-1402 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/mod.rs"},"region":{"startLine":983}}}],"partialFingerprints":{"codehealthFindingId/v1":"85481f0972a66d97694b964e5fd80305f6036a328e580ea847b0c702ade0bc09"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): src/server/handlers.rs:70-77 | src/server/handlers.rs:500-507 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/handlers.rs"},"region":{"startLine":70}}}],"partialFingerprints":{"codehealthFindingId/v1":"888c2a216d7863dfc7f1e093b00989f980290e6f0f91ff2b759ae6ac81514462"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): src/waf/bypass/mutate.rs:650-657 | src/waf/bypass/mutate.rs:789-796 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/waf/bypass/mutate.rs"},"region":{"startLine":650}}}],"partialFingerprints":{"codehealthFindingId/v1":"6daf8b497cbf504a5cc65e7b00c93e024e7889fde9327c2e7ca164689fbc28c3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 3): src/cmd/scan/input.rs:595-601 | src/cmd/scan/input.rs:1156-1162 | src/job/runner.rs:46-52 \u2014 there are 3 copies across 2 file(s) \u2014 more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 3 sites; resolving a subset leaves the remainder to drift apart."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/input.rs"},"region":{"startLine":595}}}],"partialFingerprints":{"codehealthFindingId/v1":"894dae86c50d83b4cb3f73d3dfe7f769bac453ec0bc5d4fb4edeaffff29c42a5"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): src/cmd/scan/analysis.rs:472-478 | src/parameter_analysis/mod.rs:1342-1348 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/analysis.rs"},"region":{"startLine":472}}}],"partialFingerprints":{"codehealthFindingId/v1":"e0ea2bfa9cd030e7134b39112fe5d65fce666b1733978478e6526413dba1194f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): src/scanning/check_reflection.rs:2687-2693 | src/scanning/check_reflection.rs:2836-2842 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_reflection.rs"},"region":{"startLine":2687}}}],"partialFingerprints":{"codehealthFindingId/v1":"94bc1a7afdd2c873b01d85ae3e39d2ea9b2c9ddca4394e759c59ac34ef902136"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): src/scanning/url_inject.rs:633-639 | src/scanning/xss_blind.rs:280-286 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/url_inject.rs"},"region":{"startLine":633}}}],"partialFingerprints":{"codehealthFindingId/v1":"4889e014a0311098f522c37c0f03804b4a372d135a811e60d118db8da26fed65"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): src/utils/shimmer.rs:155-161 | src/utils/shimmer.rs:177-183 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/utils/shimmer.rs"},"region":{"startLine":155}}}],"partialFingerprints":{"codehealthFindingId/v1":"2c2cbec7a84137d20192be938574be29ed6a060841c9e890806cdf21f869d08f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): src/utils/log.rs:50-56 | src/utils/term.rs:182-188 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/utils/log.rs"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"e8d83390a3187776c61c23c0fed05b71bf265c05304aab092fefdd03e9fee4c3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): src/parameter_analysis/mining/context_detect.rs:198-204 | src/parameter_analysis/mining/context_detect.rs:213-219 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/context_detect.rs"},"region":{"startLine":198}}}],"partialFingerprints":{"codehealthFindingId/v1":"510816d15b287a92f0074e62f8de99249f28e6a9ff91980da99d4207ffc9111b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): src/cmd/scan/analysis.rs:83-88 | src/cmd/scan/scan_loop.rs:113-118 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/analysis.rs"},"region":{"startLine":83}}}],"partialFingerprints":{"codehealthFindingId/v1":"688cd60f72419cc88f2bc4f22b1114bc5b042b420d23a4e19b5cd3c5e321f295"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): src/parameter_analysis/discovery/form.rs:95-100 | src/scanning/xss_blind.rs:471-476 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/form.rs"},"region":{"startLine":95}}}],"partialFingerprints":{"codehealthFindingId/v1":"363889e187b1534633610e07a647a32c09b295495bcbe34bea4fadad38390556"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): src/utils/xml.rs:427-432 | src/utils/xml.rs:445-450 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/utils/xml.rs"},"region":{"startLine":427}}}],"partialFingerprints":{"codehealthFindingId/v1":"86728858da9a34dc8a4a802f9ee3ea25cff287832c13db7473488a905f7226d4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (3\u20136 lines \u00D7 3): src/parameter_analysis/discovery/query.rs:164-173 | src/parameter_analysis/discovery/query.rs:243-248 | src/parameter_analysis/discovery/query.rs:289-291 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/query.rs"},"region":{"startLine":164}}}],"partialFingerprints":{"codehealthFindingId/v1":"50d0f83ee7615fa70a2b2c144aab5fe81ed95c7a7a8b14a5e2c89059bb7e2946"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): src/cmd/scan/logging.rs:57-62 | src/cmd/scan/logging.rs:113-118 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/logging.rs"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"dfe69fd202a1e9653729187d8168ffd89364700bc962c8d028d3d381c4e285e3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): src/scanning/ast_dom_analysis/sinks.rs:120-125 | src/scanning/ast_dom_analysis/sinks.rs:164-169 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/sinks.rs"},"region":{"startLine":120}}}],"partialFingerprints":{"codehealthFindingId/v1":"2ef8a114f81cd1ab26bdcdc2ec2685f2c4c94d5edc1a6303224faab3d742190c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 3): src/parameter_analysis/discovery/form.rs:443-447 | src/parameter_analysis/discovery/form.rs:514-518 | src/parameter_analysis/discovery/query.rs:330-334 \u2014 there are 3 copies across 2 file(s) \u2014 more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 3 sites; resolving a subset leaves the remainder to drift apart."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/form.rs"},"region":{"startLine":443}}}],"partialFingerprints":{"codehealthFindingId/v1":"89a436ba854ffae006fb71b311b7f27903cbb2997509029e9072bba0dd16ce4f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): src/oob/interactsh/mod.rs:163-167 | src/oob/interactsh/mod.rs:208-212 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/oob/interactsh/mod.rs"},"region":{"startLine":163}}}],"partialFingerprints":{"codehealthFindingId/v1":"82c84485433e8da684c989a67c0de3b9b6b2027e2c0f2f4c5a974eaaed01b888"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): src/encoding/mod.rs:235-239 | src/encoding/mod.rs:268-272 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/encoding/mod.rs"},"region":{"startLine":235}}}],"partialFingerprints":{"codehealthFindingId/v1":"94b1c77fa06839d4d02f14b349c124965262def82f65fe2abb886cdd3b9438b9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 3): src/cmd/file.rs:36-44 | src/cmd/pipe.rs:31-39 | src/cmd/url.rs:37-45 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from all 3 call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/file.rs"},"region":{"startLine":36}}}],"partialFingerprints":{"codehealthFindingId/v1":"7a3e774e93611d45dd8e69eb558a607f12254f24cc74b73d22478f4af1640d26"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (19 lines \u00D7 2): src/scanning/xss_common.rs:70-92 | src/scanning/xss_common.rs:120-138 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/xss_common.rs"},"region":{"startLine":70}}}],"partialFingerprints":{"codehealthFindingId/v1":"849c81710ce138ca538328d552886bb5a3a7adfb7e0c91a66ab8d913da8e45d0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 3): src/scanning/ast_dom_analysis/sinks.rs:476-489 | src/scanning/ast_dom_analysis/sinks.rs:668-681 | src/scanning/ast_dom_analysis/sinks.rs:803-816 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/sinks.rs"},"region":{"startLine":476}}}],"partialFingerprints":{"codehealthFindingId/v1":"9134ed3cbc41bbba183ff13d63640a7169949896b5a761b1ced6ce0150aeab32"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): src/scanning/xss_blind.rs:352-364 | src/scanning/xss_blind.rs:539-551 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/xss_blind.rs"},"region":{"startLine":352}}}],"partialFingerprints":{"codehealthFindingId/v1":"1bb06a8b397e382ee9dfb62afb62c83fe64721a9b904555d382c43039dcfe56d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): src/parameter_analysis/discovery/form.rs:230-241 | src/parameter_analysis/discovery/form.rs:349-358 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/form.rs"},"region":{"startLine":230}}}],"partialFingerprints":{"codehealthFindingId/v1":"55e76ed31efdd30cc5c7572954623d74684b22c289efede4c5c7ea37d5b614e7"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 6): src/server/handlers.rs:19-29 | src/server/handlers.rs:126-136 | src/server/handlers.rs:322-332 | src/server/handlers.rs:616-626 | src/server/handlers.rs:726-736 | src/server/handlers.rs:885-895 \u2014 all 6 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/handlers.rs"},"region":{"startLine":19}}}],"partialFingerprints":{"codehealthFindingId/v1":"209d922f6c8f1379fa2c4cc1fe58a5cfd339d48be4f9e1e4a2d91aaf6374a036"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): src/parameter_analysis/discovery/query.rs:48-58 | src/parameter_analysis/discovery/query.rs:277-284 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/query.rs"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"c30e9ed992058d7c7cba288a9154ac293b195fbcf5a111d9419b029dd21910f3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): src/parameter_analysis/mining/probe_graphql.rs:29-38 | src/parameter_analysis/mining/probe_xml.rs:53-62 \u2014 before extracting anything, compare \u0060src/parameter_analysis/mining/probe_graphql.rs\u0060 and \u0060src/parameter_analysis/mining/probe_xml.rs\u0060 as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 79 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/probe_graphql.rs"},"region":{"startLine":29}}}],"partialFingerprints":{"codehealthFindingId/v1":"873e50d170415d8e84855012c4ddc519f23e0f10ea8305169d5726e0f59188dd"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): src/parameter_analysis/mining/probe_body.rs:21-29 | src/parameter_analysis/mining/probe_json.rs:45-51 \u2014 before extracting anything, compare \u0060src/parameter_analysis/mining/probe_body.rs\u0060 and \u0060src/parameter_analysis/mining/probe_json.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 54 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/probe_body.rs"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"e50a539312c6e4ce232f34a2a043a6c61cbf2a88ae74a758868920104c8bf2bb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): src/oob/interactsh/mod.rs:158-165 | src/oob/interactsh/mod.rs:272-279 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/oob/interactsh/mod.rs"},"region":{"startLine":158}}}],"partialFingerprints":{"codehealthFindingId/v1":"dd72a59a240e20bd442c95bf4f7e419f980a8f03629df1bfa01853fe7c9fbe1d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): src/server/handlers.rs:464-468 | src/server/handlers.rs:470-474 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/handlers.rs"},"region":{"startLine":464}}}],"partialFingerprints":{"codehealthFindingId/v1":"6885114c734ecead90e1ead9cdf8e7cbb8bcf682c1be3b3544aa8936fc6723a0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): src/utils/xml.rs:340-345 | src/utils/xml.rs:377-382 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/utils/xml.rs"},"region":{"startLine":340}}}],"partialFingerprints":{"codehealthFindingId/v1":"6533d035d4b60b5df4e2085cd87f4bbea48179eada4851e45daca6c6c10e43e7"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/mcp/mod.rs: src/mcp/mod.rs changed 32 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 39 in DalfoxMcp::scan_with_dalfox at line 396. 19 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/mcp/mod.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/mcp/mod.rs"},"region":{"startLine":396}}}],"partialFingerprints":{"codehealthFindingId/v1":"12b5503ada02934d1a73af5a0190a8f1857759ba1d673b1ec881a1a3c5897cd9"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/cmd/scan/mod.rs: src/cmd/scan/mod.rs changed 23 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 50 in dalfox::cmd::scan::run_scan at line 200. 11 of those changes were fix/bug commits, and the other 12 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/cmd/scan/mod.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/mod.rs"},"region":{"startLine":200}}}],"partialFingerprints":{"codehealthFindingId/v1":"8e41733beffe7d18ee52a91b185af447e86fb3c71ba223090137936d98a36cd3"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/cmd/scan/input.rs: src/cmd/scan/input.rs changed 11 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 74 in dalfox::cmd::scan::input::resolve_targets at line 118. 8 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/cmd/scan/input.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/input.rs"},"region":{"startLine":118}}}],"partialFingerprints":{"codehealthFindingId/v1":"5dd96c978afdced52fcae27b96e4f4ae30ebcd58773f6dbafa61e7eaa00d6d95"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/parameter_analysis/mod.rs: src/parameter_analysis/mod.rs changed 21 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 38 in dalfox::parameter_analysis::active_probe_param at line 857. 8 of those changes were fix/bug commits, and the other 13 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/parameter_analysis/mod.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mod.rs"},"region":{"startLine":857}}}],"partialFingerprints":{"codehealthFindingId/v1":"f8c0605bbfa9b475903693d7e64ab017010d3faf70bad2f938af2356b165fee1"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/scanning/check_reflection.rs: src/scanning/check_reflection.rs changed 21 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 30 in dalfox::scanning::check_reflection::fetch_injection_response_with_client at line 2605. 13 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/scanning/check_reflection.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_reflection.rs"},"region":{"startLine":2605}}}],"partialFingerprints":{"codehealthFindingId/v1":"72f9c45e79cdca17f852f91aa7bb8d9ef1c6a077d2502b17b85312f4140278b3"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/cmd/scan/output.rs: src/cmd/scan/output.rs changed 21 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 27 in dalfox::cmd::scan::output::render_results at line 493. 12 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/cmd/scan/output.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/output.rs"},"region":{"startLine":493}}}],"partialFingerprints":{"codehealthFindingId/v1":"17dcc7ecc5f769d60e2a0a1d264bd1cc2bf339c2f66a35031ff8c20bcef0ccd2"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/cmd/scan/analysis.rs: src/cmd/scan/analysis.rs changed 13 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 42 in dalfox::cmd::scan::analysis::preflight_and_analyze_target at line 246. 8 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/cmd/scan/analysis.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/analysis.rs"},"region":{"startLine":246}}}],"partialFingerprints":{"codehealthFindingId/v1":"6605c4b593cb0925cd08649c667005cfdae8cd53b4ddedd24494ef6176ad82c4"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/scanning/mod.rs: src/scanning/mod.rs changed 29 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 17 in ScanWorkerCtx::run_dom_phase at line 1340. 15 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/scanning/mod.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/mod.rs"},"region":{"startLine":1340}}}],"partialFingerprints":{"codehealthFindingId/v1":"0ff54e818bbdfcf2b305ad83e07b6f320247d8e6bb723989614924b8224fc1cd"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/scanning/url_inject.rs: src/scanning/url_inject.rs changed 14 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 30 in dalfox::scanning::url_inject::build_injected_url at line 206. 7 of those changes were fix/bug commits, and the other 7 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/scanning/url_inject.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/url_inject.rs"},"region":{"startLine":206}}}],"partialFingerprints":{"codehealthFindingId/v1":"673cad84964ff68c7b8c52466497298ebb060cc8e8d8ff4c2ffdadf199c0d52a"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/scanning/ast_dom_analysis/taint.rs: src/scanning/ast_dom_analysis/taint.rs changed 6 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 67 in DomXssVisitor::call_taint_and_source at line 42. 2 of those changes were fix/bug commits, and the other 4 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/scanning/ast_dom_analysis/taint.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/taint.rs"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"de7796c15c6515bcc04a7711d4aea6aa2c797dda287a87869e431fc75e794f92"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/target_parser/mod.rs: src/target_parser/mod.rs changed 14 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 25 in dalfox::target_parser::parse_raw_http_request at line 539. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/target_parser/mod.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/target_parser/mod.rs"},"region":{"startLine":539}}}],"partialFingerprints":{"codehealthFindingId/v1":"539719b7e0858ce5550aee423b79c6585b7970a338ee8eff647723486b8379d8"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/server/job_runner.rs: src/server/job_runner.rs changed 14 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 24 in dalfox::server::job_runner::run_scan_job at line 199. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/server/job_runner.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/job_runner.rs"},"region":{"startLine":199}}}],"partialFingerprints":{"codehealthFindingId/v1":"ff698a434572cb19f4bde79f4c31a46c2fee9f3cceda9b8db3b0d4f3f946863f"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/server/util.rs: src/server/util.rs changed 10 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 28 in dalfox::server::util::validate_scan_options at line 17. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/server/util.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/util.rs"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"989feddd265fd11de1b0a6112bdf8c652bfd6c2e1111fae030a33d2150783761"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/scanning/check_dom_verification.rs: src/scanning/check_dom_verification.rs changed 17 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 16 in dalfox::scanning::check_dom_verification::classify_dom_evidence at line 746. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/scanning/check_dom_verification.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_dom_verification.rs"},"region":{"startLine":746}}}],"partialFingerprints":{"codehealthFindingId/v1":"811c09f3f4760d838153526d27404fe529e8ff0ecc93258f07a897883e28c01f"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/cmd/scan/scan_loop.rs: src/cmd/scan/scan_loop.rs changed 7 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 38 in dalfox::cmd::scan::scan_loop::scan_host_group at line 366. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/cmd/scan/scan_loop.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/scan_loop.rs"},"region":{"startLine":366}}}],"partialFingerprints":{"codehealthFindingId/v1":"b3afc7c96aa09b8469629e77f68d9cdf5f17e83182be9eb05ce43ded34868c29"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/scanning/ast_integration.rs: src/scanning/ast_integration.rs changed 12 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 22 in dalfox::scanning::ast_integration::build_dom_xss_manual_poc_hint at line 972. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/scanning/ast_integration.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_integration.rs"},"region":{"startLine":972}}}],"partialFingerprints":{"codehealthFindingId/v1":"cbda2c01373d37ef4a2793d80e680ce90dffe6d3c5ac39f55600e2e766f037e7"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/parameter_analysis/discovery/form.rs: src/parameter_analysis/discovery/form.rs changed 4 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 61 in dalfox::parameter_analysis::discovery::form::check_form_discovery_with at line 28. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/parameter_analysis/discovery/form.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/form.rs"},"region":{"startLine":28}}}],"partialFingerprints":{"codehealthFindingId/v1":"35bc23aa947320a5864af5c2f4aa928a16a7cea4d99e0dd99edf15bcd8a241c0"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/scanning/ast_dom_analysis/bindings.rs: src/scanning/ast_dom_analysis/bindings.rs changed 4 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 58 in DomXssVisitor::bind_declarator_identifier at line 15. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/scanning/ast_dom_analysis/bindings.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/bindings.rs"},"region":{"startLine":15}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee13c60aeabe1851af673514ea8541afea7510a04f4a32c238459a829db0aa1e"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/job/runner.rs: src/job/runner.rs changed 7 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 29 in dalfox::job::runner::execute_scan at line 109. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/job/runner.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/job/runner.rs"},"region":{"startLine":109}}}],"partialFingerprints":{"codehealthFindingId/v1":"bb4c9252fa3131d882cad2ebf16762550ecfe952ba6fe448527ab6560ad4bd07"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/cmd/scan/poc.rs: src/cmd/scan/poc.rs changed 6 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 33 in dalfox::cmd::scan::poc::generate_poc at line 67. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/cmd/scan/poc.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/poc.rs"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"7d5b29a5728492f24b6ef214741b2d25c1d9e16003d05a046dcea0ce6449e30b"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/scanning/ast_dom_analysis/sinks.rs: src/scanning/ast_dom_analysis/sinks.rs changed 4 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 44 in DomXssVisitor::walk_assignment_expression at line 9. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/scanning/ast_dom_analysis/sinks.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/sinks.rs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"c496226f2d66dec4e07521784ac26e65279922aca535db991edd87068181b003"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/scanning/xss_common.rs: src/scanning/xss_common.rs changed 6 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 29 in dalfox::scanning::xss_common::generate_adaptive_payloads at line 315. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/scanning/xss_common.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/xss_common.rs"},"region":{"startLine":315}}}],"partialFingerprints":{"codehealthFindingId/v1":"cdf3f5f6012eccd23d41c094665a261c247cb1584c132e95df7045e61fd2e466"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/server/mod.rs: src/server/mod.rs changed 7 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 24 in dalfox::server::run_server at line 79. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/server/mod.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/mod.rs"},"region":{"startLine":79}}}],"partialFingerprints":{"codehealthFindingId/v1":"84d2b88e3855e885965f1bc163f4e052b626a7ca0dcecc84b0141ab643965c52"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/cmd/payload.rs: src/cmd/payload.rs changed 8 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 20 in dalfox::cmd::payload::run_payload at line 431. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/cmd/payload.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/payload.rs"},"region":{"startLine":431}}}],"partialFingerprints":{"codehealthFindingId/v1":"e9d32f927f6e1861962dd3ef49345070943bf152978ca230a4b4ac8e896bc580"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/payload/xss_csp_bypass.rs: src/payload/xss_csp_bypass.rs changed 5 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 28 in dalfox::payload::xss_csp_bypass::analyze_csp at line 170. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/payload/xss_csp_bypass.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/payload/xss_csp_bypass.rs"},"region":{"startLine":170}}}],"partialFingerprints":{"codehealthFindingId/v1":"d10e4557c16d13af37957964b606d09baef26fe7df61330b4586d4ea5aed2af3"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/payload/js_breakout.rs: src/payload/js_breakout.rs changed 3 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 46 in dalfox::payload::js_breakout::compute_js_breakout at line 69. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/payload/js_breakout.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/payload/js_breakout.rs"},"region":{"startLine":69}}}],"partialFingerprints":{"codehealthFindingId/v1":"be0990402af763a78748f74afde07d303854cfbc913e671b70c601242bdcdb41"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/waf/bypass/mutate.rs: src/waf/bypass/mutate.rs changed 5 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 27 in dalfox::waf::bypass::mutate::multi_slash at line 664. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/waf/bypass/mutate.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/waf/bypass/mutate.rs"},"region":{"startLine":664}}}],"partialFingerprints":{"codehealthFindingId/v1":"240277d31a480cd6fabd9e3b8f4eeadafcf4715e83cc411bfa97eb7c2255ed75"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/scanning/ast_dom_analysis/walk.rs: src/scanning/ast_dom_analysis/walk.rs changed 2 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 44 in DomXssVisitor::walk_expression at line 238. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/scanning/ast_dom_analysis/walk.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_dom_analysis/walk.rs"},"region":{"startLine":238}}}],"partialFingerprints":{"codehealthFindingId/v1":"a09c31a100d3e5bacb35e38953c649ba8fa2fe7416ece0b9c7ac384cd9f39b0a"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/scanning/xss_blind.rs: src/scanning/xss_blind.rs changed 5 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 17 in dalfox::scanning::xss_blind::blind_scan_forms_with at line 395. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/scanning/xss_blind.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/xss_blind.rs"},"region":{"startLine":395}}}],"partialFingerprints":{"codehealthFindingId/v1":"14e2dd80cac363cc84657a1cb9ed6d0b445b78b5884ac0eed98838a834fef49b"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/scanning/result/format_markdown.rs: src/scanning/result/format_markdown.rs changed 3 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 27 in Result::results_to_markdown_with_meta at line 91. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/scanning/result/format_markdown.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/result/format_markdown.rs"},"region":{"startLine":91}}}],"partialFingerprints":{"codehealthFindingId/v1":"25e1f8a5a526ab4b18952fdc3b5c7949639aab2d7f66787e604f0a79ac610b70"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/cmd/scan/validation.rs: src/cmd/scan/validation.rs changed 4 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 15 in dalfox::cmd::scan::validation::validate_numeric_args at line 34. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/cmd/scan/validation.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/validation.rs"},"region":{"startLine":34}}}],"partialFingerprints":{"codehealthFindingId/v1":"61c12c6cf05fceeb6a8146bc278af4fa4d78c6e6dfd1ba65ff1b1a0ab2302569"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/scanning/param_jobs.rs: src/scanning/param_jobs.rs changed 2 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 29 in dalfox::scanning::param_jobs::generate_param_jobs at line 78. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/scanning/param_jobs.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/param_jobs.rs"},"region":{"startLine":78}}}],"partialFingerprints":{"codehealthFindingId/v1":"bf44a2fbb6a0819e7692e558daa55f65e0d5dd7bbe6d380a3f462602f72486ef"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/scanning/request_render.rs: src/scanning/request_render.rs changed 2 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 29 in dalfox::scanning::request_render::build_request_text at line 7. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/scanning/request_render.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/request_render.rs"},"region":{"startLine":7}}}],"partialFingerprints":{"codehealthFindingId/v1":"d0e416bc24f9dbae971459d6d50f5651ab32bed14ece924b3ca3c23ab3c6ffba"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/target_parser/har.rs: src/target_parser/har.rs changed 3 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 19 in dalfox::target_parser::har::parse_har at line 109. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/target_parser/har.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/target_parser/har.rs"},"region":{"startLine":109}}}],"partialFingerprints":{"codehealthFindingId/v1":"4795a0df683e9f5c7f075cc46ba76b62b0742540487a7dc5b4a944dddc097c9d"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/parameter_analysis/mining/context_detect.rs: src/parameter_analysis/mining/context_detect.rs changed 2 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 27 in dalfox::parameter_analysis::mining::context_detect::detect_injection_context_with_marker at line 105. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/parameter_analysis/mining/context_detect.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mining/context_detect.rs"},"region":{"startLine":105}}}],"partialFingerprints":{"codehealthFindingId/v1":"8298e6e859f01d02d9c1d8c6bba892e9d89c1d3e25feb3eb03382cbec93d90d5"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/cmd/scan/startup.rs: src/cmd/scan/startup.rs changed 2 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 20 in dalfox::cmd::scan::startup::prepare_and_validate at line 67. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/cmd/scan/startup.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/startup.rs"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"fc480019ab1258a110a824294dacb6e5730bf0a9bb87d9363e5201f71ed1164e"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: src/server/handlers.rs: src/server/handlers.rs changed 11 times in last 90 days and 10 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 13 (its worst body is dalfox::server::handlers::preflight_handler at line 874), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix(jobs): align reachability probes with CLI (#1491)\u201D; \u201Cfix: six defects found reviewing the 2026-09-02 merges (#1405-#1424) (#1425)\u201D; \u201Cfix(server): anchor origin patterns, and harden the API\u0027s secret handling (#1423)\u201D; \u201Cfix(server,mcp,payload): daemon-lifecycle defects \u2014 preflight pacing, per-job remote cache, draining-job retention, MCP capacity slot (#1406)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/server/handlers.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/handlers.rs"},"region":{"startLine":874}}}],"partialFingerprints":{"codehealthFindingId/v1":"45115a9c8aee9ae5ce8fa3c0f8f07579ed0b141ae45ce3852a2e510cd7ad41c8"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: src/utils/http.rs: src/utils/http.rs changed 11 times in last 90 days and 8 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 11 (its worst body is dalfox::utils::http::send_with_retry at line 846), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix(scanner): gate XSS findings by response content type (#1494)\u201D; \u201Cfix: follow a form action\u0027s same-host TLS upgrade (#1461)\u201D; \u201Cfix: six defects found reviewing the 2026-09-02 merges (#1405-#1424) (#1425)\u201D; \u201Cfix(scan): count requests that never reached the target (#1413)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/utils/http.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/utils/http.rs"},"region":{"startLine":846}}}],"partialFingerprints":{"codehealthFindingId/v1":"c85c9bf4ed6feeee3e035e965d8ef85d50b8866707e795b3e748c7a64f1ba8fb"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: src/utils/mod.rs: src/utils/mod.rs changed 9 times in last 90 days and 6 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 6 (its worst body is dalfox::utils::finding_belongs_to_target at line 137), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix(scanner): gate XSS findings by response content type (#1494)\u201D; \u201Cfix: follow a form action\u0027s same-host TLS upgrade (#1461)\u201D; \u201Cfix: six defects found reviewing the 2026-09-02 merges (#1405-#1424) (#1425)\u201D; \u201Cfix(scan,server): harden request construction and input validation (#1404)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/utils/mod.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/utils/mod.rs"},"region":{"startLine":137}}}],"partialFingerprints":{"codehealthFindingId/v1":"37f9750660dba4e70a6fb17af1a51187846c52d4890971e3e62d6c0fc4318e46"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: src/server/types.rs: src/server/types.rs changed 6 times in last 90 days and 5 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 3 (its worst body is dalfox::server::types::string_or_seq_cookie at line 204), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix: six defects found reviewing the 2026-09-02 merges (#1405-#1424) (#1425)\u201D; \u201Cfix(server): anchor origin patterns, and harden the API\u0027s secret handling (#1423)\u201D; \u201Cfix: harden against crashes, hangs, and silently-clean scans (#1361)\u201D; \u201Cfix(server): refuse browser-driven cross-site and rebound requests (#1356)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/server/types.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/types.rs"},"region":{"startLine":204}}}],"partialFingerprints":{"codehealthFindingId/v1":"62789b47c80086e857298642bb00525cc3839ecd572d6db4bfc949bef64e8c2a"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: src/scanning/waf_strategy.rs: src/scanning/waf_strategy.rs changed 4 times in last 90 days and 4 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 11 (its worst body is dalfox::scanning::waf_strategy::expand_waf_payloads at line 203), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix: multi-policy CSP, quoted \u0027\u003E\u0027 in script tags, template-literal delimiter, credential-rotation resume, assigned-over parseInt (#1486)\u201D; \u201Cfix(scanner): preserve payload selection and valid WAF variants (#1490)\u201D; \u201Cfix: CSP meta/report-only precedence and WAF status misdetection (#1481)\u201D; \u201Cfix: bug-hunt batch \u2014 blind XSS request builders, batch-mining attribution, server/MCP parity, and CLI silent-clean holes (#1476)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/scanning/waf_strategy.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/waf_strategy.rs"},"region":{"startLine":203}}}],"partialFingerprints":{"codehealthFindingId/v1":"f72dc34dc117661f8de4bed9715b18416a0bce2a2ff29b3a90223a943792e554"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: src/scanning/payload_families.rs: src/scanning/payload_families.rs changed 5 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 12 (its worst body is dalfox::scanning::payload_families::get_dom_payloads_for_context at line 437), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix(scanner): gate XSS findings by response content type (#1494)\u201D; \u201Cfix(scanner): preserve payload selection and valid WAF variants (#1490)\u201D; \u201Cfix(dom-verify): false [V] on inert JS-string / data-block reflections, numeric A findings (#1478)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/scanning/payload_families.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/payload_families.rs"},"region":{"startLine":437}}}],"partialFingerprints":{"codehealthFindingId/v1":"bd7e6ebc27e6164b8506658df98cdee3bc5fb22a6c59f3202110a9dc4ea9b849"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: src/lib.rs: src/lib.rs changed 4 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 6 (its worst body is dalfox::with_job_scopes at line 230), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix(http): honor request pacing and user-agent overrides (#1487)\u201D; \u201Cfix: six defects found reviewing the 2026-09-02 merges (#1405-#1424) (#1425)\u201D; \u201Cfix(scan): count requests that never reached the target (#1413)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/lib.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/lib.rs"},"region":{"startLine":230}}}],"partialFingerprints":{"codehealthFindingId/v1":"97b47812f117895aeb33f0bc4c77ed7938993cf23007fc3b808fbc39723328a0"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: src/cmd/scan/state_file.rs: src/cmd/scan/state_file.rs changed 3 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 10 (its worst body is StateFile::append at line 620), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix: multi-policy CSP, quoted \u0027\u003E\u0027 in script tags, template-literal delimiter, credential-rotation resume, assigned-over parseInt (#1486)\u201D; \u201Cfix(scan): preserve incomplete results and resume state (#1485)\u201D; \u201Cfix(config): stop config from overriding explicitly typed CLI flags; unrot agent guides (#1372)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/cmd/scan/state_file.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/state_file.rs"},"region":{"startLine":620}}}],"partialFingerprints":{"codehealthFindingId/v1":"b4d10a90d2c3bf751499192196e15edfe96cca30dc469ec1dd7b904847c729f3"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: src/payload/remote.rs: src/payload/remote.rs changed 3 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 7 (its worst body is dalfox::payload::remote::fetch_multiple_text_lists at line 472), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix: bug-hunt batch \u2014 blind XSS request builders, batch-mining attribution, server/MCP parity, and CLI silent-clean holes (#1476)\u201D; \u201Cfix(server,mcp,payload): daemon-lifecycle defects \u2014 preflight pacing, per-job remote cache, draining-job retention, MCP capacity slot (#1406)\u201D; \u201Cfix: harden against crashes, hangs, and silently-clean scans (#1361)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/payload/remote.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/payload/remote.rs"},"region":{"startLine":472}}}],"partialFingerprints":{"codehealthFindingId/v1":"4d6889e8194accb363d979c19b813980e818bc05b301fae0f92fbb63912d9655"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: src/server/cors.rs: src/server/cors.rs changed 3 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 8 (its worst body is dalfox::server::cors::compile_allowed_origins at line 51), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix(server): anchor origin patterns, and harden the API\u0027s secret handling (#1423)\u201D; \u201Cfix(server): refuse browser-driven cross-site and rebound requests (#1356)\u201D; \u201Cfix(server,mcp): validate and normalize method/encoders at the API boundary (#1269)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 00:56:41 \u002B09:00\u0027 --until=\u00272026-09-29 00:56:41 \u002B09:00\u0027 --full-history --no-merges -- src/server/cors.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/server/cors.rs"},"region":{"startLine":51}}}],"partialFingerprints":{"codehealthFindingId/v1":"ad023a4bd90bcecb5085286c859d4a3c96cf7d9c90b2f4d2da0a2d6393e86a5c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: /// TODO: \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/mod.rs"},"region":{"startLine":387}}}],"partialFingerprints":{"codehealthFindingId/v1":"28c2622fc2d96e143e3b64683f906e6dda1ce01deabad80310b15141af16f660"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found. No recognised ADR directory (\u0060docs/adr/\u0060, \u0060docs/decisions/\u0060, \u0060adr/\u0060, \u0060docs/rfcs/\u0060, an \u0060ADR0001/\u0060 folder, or their siblings) exists anywhere in this tree. What was searched, so you can tell an empty log from a search that missed one: every directory under the tree (build output, dependencies and VCS metadata excepted), for a document that is either any non-index page inside a recognised ADR directory, whatever its name and however deeply nested (\u0060docs/adr/use-postgres.md\u0060, \u0060docs/adr/2024/0001-x.md\u0060); or a file anywhere whose name is ADR-shaped (\u00600001-use-postgres.md\u0060, \u0060adr-012-caching.md\u0060); or, when neither turned anything up, a document carrying the decision-record signature (an \u0022Architecture Decision Record\u0022 heading, or Status / Context / Decision / Consequences as section headings). A decision log that clears none of these \u2014 unnumbered files outside any recognised directory, without those headings \u2014 is not seen by this check and this row is then wrong. If that is your case, say so rather than renaming anything; otherwise, consider recording architectural decisions in \u0060docs/adr/\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D22","level":"warning","message":{"text":"Inconsistent return type for validation methods. \u0060Config.normalize_and_validate\u0060 returns \u0060String\u0060 (likely an error message or empty string), while \u0060ScanConfig.normalize_and_validate\u0060 also returns \u0060String\u0060. However, standard Rust API conventions for validation usually return \u0060Result\u003C(), Error\u003E\u0060 or \u0060Result\u003CSelf, Error\u003E\u0060. Returning a \u0060String\u0060 for success/failure is ambiguous and inconsistent with idiomatic Rust error handling, especially when other parts of the API (like \u0060parse_target\u0060) return \u0060Result\u0060. Furthermore, having validation logic in both the parent and child config types suggests duplication of intent.: Change both methods to return \u0060Result\u003C(), ValidationError\u003E\u0060 or \u0060Result\u003CSelf, ValidationError\u003E\u0060. Remove \u0060normalize_and_validate\u0060 from \u0060ScanConfig\u0060 if it is purely called by \u0060Config\u0060, or ensure they have distinct, non-overlapping responsibilities with clear return types. (signatures: dalfox.config.ScanConfig.normalize_and_validate(): String | dalfox.config.Config.normalize_and_validate(): String)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e314213f1089c1bba83cc25ba6076d054c5601ddac5a31ad244a114f2212e768"}},{"ruleId":"D22","level":"warning","message":{"text":"Naming inconsistency in reflection checking functions. \u0060check_reflection_with_response\u0060 and \u0060check_reflection_with_response_tracked\u0060 differ only by the \u0027tracked\u0027 suffix (likely adding concurrency tracking), but \u0060check_reflection_with_hpp_url\u0060 uses a different pattern (\u0060with_hpp_url\u0060) instead of \u0060with_response\u0060 or \u0060with_client\u0060. This makes it unclear if \u0060hpp_url\u0060 is a variant of response checking or a distinct operation. The naming convention is not uniform across similar operations.: Unify naming to \u0060check_reflection_with_\u003Cvariant\u003E\u0060. If \u0060hpp_url\u0060 is just a specific way to get a response, consider \u0060check_reflection_with_hpp\u0060 or ensure the \u0027with_\u0027 prefix consistently denotes the input source (e.g., \u0060with_response\u0060, \u0060with_hpp_response\u0060). Alternatively, use a single function with an enum argument for the source type. (signatures: dalfox.scanning.check_reflection.check_reflection_with_response(...) | dalfox.scanning.check_reflection.check_reflection_with_response_tracked(...) | dalfox.scanning.check_reflection.check_reflection_with_hpp_url(...))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e5140b78929cbe742acb3e27f80589046f10678e70af6c51351925e2141dd62e"}},{"ruleId":"D22","level":"warning","message":{"text":"Inconsistent naming and return types for DOM verification. \u0060check_dom_verification\u0060 and \u0060check_dom_verification_with_client\u0060 return \u0060(bool, Option\u003CString\u003E)\u0060, while \u0060check_dom_verification_with_client_outcome\u0060 returns \u0060DomVerifyOutcome\u0060. The \u0027outcome\u0027 suffix is inconsistent with the other \u0027with_client\u0027 variants. Additionally, having three functions for essentially the same operation with different return types (primitive tuple vs. struct) is confusing.: Standardize on a single function signature, preferably returning \u0060DomVerifyOutcome\u0060. Remove the variants that return tuples unless they are strictly internal helpers, or rename them to clearly indicate they are legacy/compatibility wrappers. (signatures: dalfox.scanning.check_dom_verification.check_dom_verification(...) | dalfox.scanning.check_dom_verification.check_dom_verification_with_client(...) | dalfox.scanning.check_dom_verification.check_dom_verification_with_client_outcome(...))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"967c4635c1c75ea5666a746c0aaaf206855affec9378909fe34c8ae0660641a0"}},{"ruleId":"D22","level":"warning","message":{"text":"Inconsistent naming pattern for light verification. The functions are named \u0060verify_dom_xss_light\u0060 and \u0060verify_dom_xss_light_with_client\u0060. In other modules (like \u0060check_reflection\u0060), the pattern is \u0060check_..._with_response\u0060 vs \u0060check_..._with_response_tracked\u0060. Here, the base function doesn\u0027t specify the client source, implying it might use a global or default client, while the \u0060_with_client\u0060 variant is explicit. This is a minor inconsistency in naming philosophy compared to other modules.: Unify naming to \u0060verify_dom_xss_light_with_\u003Cvariant\u003E\u0060. If the base function uses a default client, rename it to \u0060verify_dom_xss_light_default\u0060 for clarity. (signatures: dalfox.scanning.light_verify.verify_dom_xss_light(...) | dalfox.scanning.light_verify.verify_dom_xss_light_with_client(...))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7d371cace9952d276621dd7024f0d3f2e64352f1cffba6aa1f9ebe68ba399b60"}},{"ruleId":"D22","level":"warning","message":{"text":"Inconsistent method naming for remote resource initialization. There are \u0060init_remote_payloads\u0060 and \u0060init_remote_wordlists\u0060 (no options), and \u0060init_remote_payloads_with\u0060 and \u0060init_remote_wordlists_with\u0060 (with options). The \u0027with\u0027 suffix is used for the options variant, but the base methods don\u0027t have a clear counterpart like \u0060init_remote_payloads_default\u0060. More importantly, \u0060init_remote_payloads\u0060 and \u0060init_remote_wordlists\u0060 are separate methods, whereas \u0060init_remote_resources\u0060 in \u0060utils\u0060 combines them. This duplication of intent (initializing remote resources) across different modules (\u0060remote\u0060 vs \u0060utils\u0060) is confusing.: Consolidate remote resource initialization into a single API surface. Either expose \u0060init_remote_resources\u0060 in the \u0060remote\u0060 module or remove the \u0060utils\u0060 wrapper. Ensure method names are consistent (e.g., \u0060init_payloads\u0060 vs \u0060init_wordlists\u0060 vs \u0060init_resources\u0060). Consider using a single \u0060init_remote_resources(options: RemoteFetchOptions)\u0060 method that handles both payloads and wordlists. (signatures: dalfox.payload.remote.init_remote_payloads(...) | dalfox.payload.remote.init_remote_wordlists(...) | dalfox.payload.remote.init_remote_payloads_with(...) | dalfox.payload.remote.init_remote_wordlists_with(...))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"2a9be74d171edda1beb7e8bce6012c6cd74a964496eb795046e13bff1cecc8d9"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6d4c9df5d9590f3bcbb57e52464c9c7a084b0eab2a68e7cea0baa0f964910c17"},"taxa":[{"id":"CWE-269","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8a1282a9e831c2121ffd19db29a13a85ef7271052c8245ac187afd6db985012b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"89d678b978c21e1f42fbf3dca71675041336796a67fd28322f48acceb001885c"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0d0374b001cd028a910dab51dd938c9f5bc222ad08f3f445099c082b014f5549"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3cbcb06274e0abd9e0ff768cd734ba336f0ff6e950e78aaf094428ab287a7696"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"015c1fc25e7e1427bab57a098d64b56c6be45093ecde8280f20b137775ce15ca"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"169ea31fd264e76a44d7e89f44f131c92254fc15ef8ff57b72b549e23538692a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a7e2531749705702e82b9a32127273e1dc58141eea619ca93b47a908fb7acc23"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6d651ff176d93b04a02295db432baf7513aed8e8641a56dfbb0e8f0a2ca15f58"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dc511651864497bf753d084265b56d2e8b45587611c192e699f44bf2f8d70be5"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"82ace98e4526e05990ff671013fb10344d617adcb799ae3cf799e52839a43b00"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dada811c960f4834ed269278b870f1a5ab4977e6f5831cb3096e8dff16ec807e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4f328bdf2073068571e2c07fee63aa7e574b3b3fb596ad7609eca334bee34093"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"111377d79a995de5fab421ebcf41727782f47c210f5fb832bbb7a6f58a45f5ac"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a1cc6f700fbddca8d61492a41b970af1989142d6ab89b89a933528e927b67c4c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"78c624d8c3647ac0203a7204bd0b57a651b2e437d96cdb3a29e0783c71ae40c3"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"75eda33f8b25a1ea9288feee482a283be79fd24b7fc7473bb3da70c10c24257e"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a448635e265e875f88c6425f75923505de8971e4d8faeb3c48fe1f58c620a04e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"87117c9514cf7f1d7cf8fde9ba24db8451b2f49ba511531656e4d3edbba00f55"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"50aa042bffc9352b53c2b65c80f8d8013047efc73bf4a37c0fab3558303d74f1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"802d9984887cb0b240ca4484afb4db45cc9a86c8bf948e2653b8bd7b9792db1f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"81ccfae0b0119a73b22357f4e77125e65b7cb43044f130cbef2ea58b1b629103"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"07f13397af34e74a2723b3324ded2ad75b8d28e0654fa4a003891bb5563ebed4"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"66c92451ee358a00e0e636e4059e56a3648415d5cd2cbeb4baa463c8a2bd9ebf"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"83af1291a0aa4fa6d1bb49a7f54d521c5cf8edacb8512c50d1998fe5a39c026a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e8fbbe0fe37439b4c40dddd6271376f70f1bab0084abca92deec646198cc22c1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8c8d78d3e28de950dcb5c8e8ba2a17f798919133530906a891d938d0f642c6f3"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"75ad9d34a5c169960f0be44e546ceed97566e1a3df3b86e94d8abd3b84485ff7"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a642fb6a5cf9d77af0f7600f906ba5cde3eca9d686774983e2b99900719c329d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bb2956f1d8f6d2c08f999c5f7cc1c4122571797653645540af18083d40e33231"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1c1b65bb252294d7e9917359f77c900080f759b503e4b4b467fddf7fdfa3630a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"edcd917a6ad2b7ef4a310c06a343ec61678606b83be29585cbb73985adab153a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1aef7a5fdeafd451640133c61dfc9f026e4b42c5a3d8bef718dba9a1660b4150"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7af3b46e035bf00785128747075bba5dadbb7709aa18f52aa6353b99b0cd4502"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c435ffd6ff277d1a9d49b7f5cc0fdadd254373f2af6b7fbf0ef2cf4271ceefa0"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"41c4b77c1a032a260835a1bc0f0c3df63f2c4c4e8454b69994e934adba5dfaf0"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"123065173cdfc7799191b93d473e17252a5358663ea0adb949f6046d3f0a67b1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3ad48bb6d99a8ed3f9d1435901b5ce2e612bea222bdf7ba5b0bb27cf84669e7b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"276075b923f2d0fa3b21c889dcaf35e833b7915cecdf439d75c5f231b687d494"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ac92b0397759e09f45c35fc4ebcefb35a861ff589bce67fba7376da672f4da10"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"373f5e18e012a63a854c240569f5fcc85c8616979f094e921dc885dda2f7e2f9"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"450449d0efe6ccaea6f95fe6eaab2006a1c7505351022f09c8461ea8c8df3980"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4c6942614a02bd571a8a098dc563417a76346a73732c72ac35ba83afd9686b6a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ca29d987cedd07af00dfea86c263d8eeb20191f8f5bc8b44da192e5e9b389fb6"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c3143104c80e7bed1c9352938394a92d01ae830f9f48f213dd09961ea6fa27f8"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9ce7f6dc1d4475cb7d1153d5fb3d70b9920c061c1c6ca0660ea18c50458db4d0"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d448bf15113977fbae08ebf7a6f0b1297f44c77a3a6eb014fccf725d4d43e980"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"13408a095d9ee0c008fb0ef3b4d6d5fdeab6e974bc045808a08925da217238c2"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d6995a9d8828b982a2a21c541bfab6bfe19b6b834398e06d7c82c131d8f8c668"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6bbc9073f03deab12f69900d7d979b234be3f2e8e20521ad4a9a0f2aa03f92d7"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8c8a6140a48caeb27d0148067c31bf602c910c50317fb3412cbb8ddcb798b803"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ce458ce7aeaf228713e09e4e50b93c02676bead9de05e48c5164cf0026c62c1b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ebc2e156c637bdda45558ae5c329d3c4b04cbc2f99be5890a85a354e812982a2"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"507cb0f922db608ba16d7e33ca27c2d2da39a0f1ec44ade673828e9b07738176"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5e7be3d1751fecc9d1a4fec3696138736c486d5b5a2cff107219ba3bc0f29429"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"259a4907d994a97f75ccf6bde3c035fbef1b21a8e8a51f410e54d31475a3b410"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4eaf4b55637d32801baff665649ab8f0b8f4b0b15d65d5d238891056d39f0ed6"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"aaf5e47326b08bf5bdff194a70c14252f143225496845b1ef11529d2683acf5f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6146063c71aabef167a9d5760f91a4ed5cc1756795ccfd702e6df84ccb244ebf"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a7ccbe597b7cf7531bc9ae00432f50c1974b9399ca289aac8cf703a391a69c84"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c1e1f4e515082016c9ceac8bee6031eaeba3b125c7045bcf33c9c60781b44093"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f46e058f579aec674501ec41e1afc4d37e4f9d7e3b8d78d238f0ad83ca2ec195"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a7c1ffc5a464dcca1f6df51eb1ccf4a800250ffd8083d090523aea06e1af6fbc"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d0ac09d7daf016882f8553afc4a07171715277496fdc913731922e9e6b25db14"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4d9ed998437f13b3f1aeda1c1f9a26fa941cfc91bff7936a98b908b812805fc8"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1aca84950677de65f4c52ad56dd6bcab07be34420560ab9e258c633e12e54a6f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"115c7c9edd992d7567020c83862fe86d35b1e56dc491a1ae842eaf73aa596b5e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"36cde6b9fac4280fc6b824d31bc71441e12925c1bd94b8f633bb553de28602dd"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a21768f55589b4cac015ec5a08ddc7d6c6a171ad5ac254ef282b33d383816e7a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cbc10fe9d10a8ad35989f946268d4fc6db2b1ecd3c25188ba9c5fe1457d4bd66"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3df50d5da53eb7152b733e503638c335b7e9ce3c02d3b650d5d63248a5286c08"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"25aca4a92617c586d3062913c09fe909484ee04984ccecf82bbdbef0b6294645"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d2db172b1172ebacd63755f3149c5d28d9d99c4d6931a1b5a62f1e6f854fd093"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"995ae527d39fd2fe4545883b40f767933d717387592331293b56ad819b3362a2"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a1f31e3fc38e806c632551480508ae27b2701acddad0a9d80c648ba1fc9463b3"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c1bb7814097052b3b9e49cf20adb5ffa3c94da3abc00863955683dc4725b2e91"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6beb1dbf722dfdeac8e49068fd6c16b05da43c9488627b3c5c02adaf3651ab03"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ae4b19a624088a80ae967fa19fc6e2d3b4d86bf95f6afb9918729adad8224e32"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ac8eb79dfa01848c9591d4d3d4639a6823be4bbb96d16a40df23728da77d6f08"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d4168013b8ecf6910036b749f05ac6572bf48869b947cc50164fc911209515b3"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bf6e654aae86dc886c5a2e651d1be07a1252f28560ba57c82c6b15ac3d1f9c30"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"96f88121b035a898a6759141862415469563ae4858d3bd2449d90d5e5ba04a57"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"550b18e2fa3cb1ec96e83f2a35548bdff9f6f75bc7c9c75a4dd82dde45ae9c1a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"159b349952a4c646d2c94dd0107fc4f17d42ba11828e79bc6cce4af6d14e2bda"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ac8848694534995f6a8b3f9c391f355fe243dfa17894be3d48b2aa5b5f0bda18"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6757980a3bb8264ab7cb29af762d904316fe66bd310c1be76ea0298ec3582c2b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c3ca1f95f762e02c6a9edff533e7353a521676330dc4413636d4ae5149777096"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"44b132c54fb96ed8961cea0e106fd1cdeaea56a66e79b304b5ff8eafe62d28ea"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-552","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"74fc1b457189adc0301e02968c8f18df75aebe3192950e48c7bd702f49109730"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9b15183b821b0d8f2a8a9a4a501e7e6d43815f083fe597ec3f99fb39c4628148"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8b07f7579076628bd79d209a9a37ee15b3727086be16ddfbcf8b1646dd9b10be"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: pipe.rs \u2194 mod.rs: \u0060src/cmd/pipe.rs\u0060 (context cmd) and \u0060src/parameter_analysis/mod.rs\u0060 (context parameter_analysis) sit in DIFFERENT parts of the tree yet change together 55% of the time (12 of the 22 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see. You can check this without leaving the row: of the 12 shared commits counted here, the most recent 3 are \u006011b3aafd\u0060 Add encoder selection and base64 encoding for payloads; \u0060b064f8c2\u0060 Add param filtering option to scan command and tests; \u00606373ff66\u0060 Add output options and request/response info to scan results \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/pipe.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ddd40ead96d377dea1bb4877e2fcbc2f986378e4a0ac63660e58789515418085"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: tests.rs \u2194 tests.rs: \u0060src/cmd/scan/tests.rs\u0060 (context cmd) and \u0060src/config/tests.rs\u0060 (context config) sit in DIFFERENT parts of the tree yet change together 55% of the time (6 of the 11 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see. You can check this without leaving the row: of the 6 shared commits counted here, the most recent 3 are \u0060557cb6a0\u0060 fix(config): stop config from overriding explicitly typed CLI flags; \u2026; \u0060c8f30734\u0060 refactor(args): give ScanArgs a Default so adding a flag touches one \u2026; \u0060d4cb9b03\u0060 fix(scanning,server,waf): close 10 latent bugs found by source audit \u2026 \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/scan/tests.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"12f09868ead7bc1537823add9341a8da0652b703ea379fe0f3283614033236d2"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: file.rs \u2194 mod.rs: \u0060src/cmd/file.rs\u0060 (context cmd) and \u0060src/parameter_analysis/mod.rs\u0060 (context parameter_analysis) sit in DIFFERENT parts of the tree yet change together 52% of the time (12 of the 23 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see. You can check this without leaving the row: of the 12 shared commits counted here, the most recent 3 are \u006011b3aafd\u0060 Add encoder selection and base64 encoding for payloads; \u0060b064f8c2\u0060 Add param filtering option to scan command and tests; \u00606373ff66\u0060 Add output options and request/response info to scan results \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/file.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"9f790e5dc28fd62cca25b447c73aca5a309554e2adc65f6d53b93c45c1b0f8ce"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: url.rs \u2194 mod.rs: \u0060src/cmd/url.rs\u0060 (context cmd) and \u0060src/parameter_analysis/mod.rs\u0060 (context parameter_analysis) sit in DIFFERENT parts of the tree yet change together 50% of the time (12 of the 24 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see. You can check this without leaving the row: of the 12 shared commits counted here, the most recent 3 are \u006011b3aafd\u0060 Add encoder selection and base64 encoding for payloads; \u0060b064f8c2\u0060 Add param filtering option to scan command and tests; \u00606373ff66\u0060 Add output options and request/response info to scan results \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/url.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"849379fdbcf3faef8f3237f6239e9c64fce65ab1d62ca442c17479d291057e5b"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: tests.rs \u2194 tests.rs: \u0060src/parameter_analysis/discovery/tests.rs\u0060 (context parameter_analysis) and \u0060src/scanning/check_reflection/tests.rs\u0060 (context scanning) sit in DIFFERENT parts of the tree yet change together 50% of the time (8 of the 16 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see. You can check this without leaving the row: of the 8 shared commits counted here, the most recent 3 are \u0060a602ebb0\u0060 fix: stop sending operator credentials to page-controlled origins (#1\u2026; \u0060c8f30734\u0060 refactor(args): give ScanArgs a Default so adding a flag touches one \u2026; \u00608776f318\u0060 feat(scanning): compute JS breakout from the observed script prefix (\u2026 \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/tests.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"28a734eb88f36671e6599a315f7e9bc75f61e933d1ee819ca89f4dc28275afc4"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: file.rs \u2194 pipe.rs: \u0060src/cmd/file.rs\u0060 and \u0060src/cmd/pipe.rs\u0060 change together 95% of the time (21 of the 22 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking. You can check this without leaving the row: of the 21 shared commits counted here, the most recent 3 are \u0060557cb6a0\u0060 fix(config): stop config from overriding explicitly typed CLI flags; \u2026; \u0060016c22e9\u0060 fix(cli): apply config \u002B global flags \u002B --include-all in url/file/pip\u2026; \u00602bbb661b\u0060 fix(cli): make url/file/pipe subcommands respect an explicit -i/--inp\u2026 \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/cmd/file.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"7fa8c4bffad4aaa5185c2b537bc34fd7132d3f3b406bafd3b82c69ab9e173dd5"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: mod.rs \u2194 job_runner.rs: \u0060src/mcp/mod.rs\u0060 and \u0060src/server/job_runner.rs\u0060 change together 93% of the time (13 of the 14 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 13 shared commits counted here, the most recent 3 are \u0060f57533e3\u0060 fix(jobs): align reachability probes with CLI (#1491); \u0060676f492d\u0060 fix(server,mcp): run the remote payload fetch inside the scan budget \u2026; \u00608617b5ab\u0060 fix(server,mcp): stop silently discarding proxy/callback_url and corr\u2026 \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/mcp/mod.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"4c9208742a97ca40261665492bdb4846f990bfe7a358ac8178fdb5b9a24f00a9"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: tests.rs \u2194 tests.rs: \u0060src/parameter_analysis/discovery/tests.rs\u0060 and \u0060src/parameter_analysis/mining/tests.rs\u0060 change together 50% of the time (8 of the 16 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 8 shared commits counted here, the most recent 3 are \u0060c8f30734\u0060 refactor(args): give ScanArgs a Default so adding a flag touches one \u2026; \u00608a16cc20\u0060 test(parameter_analysis): cover untested pure helpers (#1189); \u00608776f318\u0060 feat(scanning): compute JS breakout from the observed script prefix (\u2026 \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/parameter_analysis/discovery/tests.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"bf9945b909455ef0efd1e78e93bdd5a6c79d775616dafe8a43f7313c0e575dd0"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1b213f6eedd4b140d0bc37bdf1496f72811a643f34064f12518b32e9e83bcfc7"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"90f83b4fa27db32740afe9540c905f3c0499caed87f61049a8a903ecc95b41c3"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0752d0df7434000fcabf1048e2de30a7a1a8b982b3db9a19898c4dec199856b4"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"329f0ef4132322722fbf83ac33f5bb7ad638ed99d037a66c3aa244b1e2ee654e"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d068c977b62d9a977df1bb6f53e8b00b586c3abee955f91d715f92b8e019d624"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"P12","level":"warning","message":{"text":"Coverage collected but not gated: CI collects a coverage report but no step enforces a minimum \u2014 coverage could halve and CI stays green. Add a step that fails the build when coverage drops below a floor (your coverage tool\u0027s minimum-threshold flag, or a coverage-gate action) so the number guards something. What was searched, so you can tell an absence from a miss: this repository\u0027s CI files AND its coverage configuration \u2014 the well-known coverage and test-runner config files, read at the repository root and inside workspace package directories two levels down, so a floor declared beside the tests rather than in the pipeline is credited \u2014 matched against the threshold settings this check knows by name. A floor set in your coverage service\u0027s web UI rather than in a committed file, or under a setting whose name is not one of those, is not seen here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7f63c06044cf998d9a0698692df30d8873e29bc9b0c98ee829255017c1193d33"}},{"ruleId":"X10","level":"note","message":{"text":"Duplicated predicate: \u0060end \u003C bytes.len() \u0026\u0026 (bytes[end].is_ascii_alphanumeric() || bytes[end] == b\u0027-\u0027)\u0060 appears character-identically in 2 files \u2014 src/scanning/check_reflection.rs, src/utils/html.rs. It is one line, so the duplication detector\u0027s token window never sees it; the copies drift when only one is corrected. Give the condition a name and one home."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_reflection.rs"},"region":{"startLine":1358}}}],"partialFingerprints":{"codehealthFindingId/v1":"8aea40563606c493abb0480c31fa8de3a27b964d65bfeffe073c32c7c652e5fc"}},{"ruleId":"X10","level":"note","message":{"text":"Duplicated predicate: \u0060err.contains(\u0022blind\u0022) \u0026\u0026 err.contains(\u0022http\u0022)\u0060 appears character-identically in 2 files \u2014 src/job/tests.rs, src/server/tests.rs. It is one line, so the duplication detector\u0027s token window never sees it; the copies drift when only one is corrected. Give the condition a name and one home."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/job/tests.rs"},"region":{"startLine":845}}}],"partialFingerprints":{"codehealthFindingId/v1":"c922bb8cd8d5d86df87df7804885b2eb07db1d9440ca88343dfa40b01ce34f9e"}},{"ruleId":"X10","level":"note","message":{"text":"Duplicated predicate: \u0060target.insecure \u0026\u0026 target.url.scheme().eq_ignore_ascii_case(\u0022https\u0022)\u0060 appears character-identically in 2 files \u2014 src/mcp/mod.rs, src/server/job_runner.rs. It is one line, so the duplication detector\u0027s token window never sees it; the copies drift when only one is corrected. Give the condition a name and one home."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/mcp/mod.rs"},"region":{"startLine":213}}}],"partialFingerprints":{"codehealthFindingId/v1":"92ccca2e275b32d6ad58c4fdc8af06647bf7488a19429c59ec968af5454e17a1"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060results_to_json\u0060 turns every \u0060Err\u0060 into \u0060\u0022[]\u0022.to_string()\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/result/format_json.rs"},"region":{"startLine":25}}}],"partialFingerprints":{"codehealthFindingId/v1":"e4e0eb1ccd4d716c7fbbad5a1bf2830dd2a79a0e1af65f1d43940a330093061a"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060results_to_sarif_with_meta\u0060 turns every \u0060Err\u0060 into \u0060\u0022{}\u0022.to_string()\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/result/format_sarif.rs"},"region":{"startLine":189}}}],"partialFingerprints":{"codehealthFindingId/v1":"332cb50e4f2e94d91079ac21cdb80d919ae3fcbb23a49143b1250ca63edb119f"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060results_to_toml_with_meta\u0060 turns every \u0060Err\u0060 into \u0060\u0022\u0022.to_string()\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/result/format_toml.rs"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"d5e2521a83f46c47f237de5cd8a2e3851f534105bc6b9a754b39eb6529e09b93"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060analyze_javascript_for_dom_xss_with_html_context\u0060 turns every \u0060Err\u0060 into \u0060Vec::new()\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_integration.rs"},"region":{"startLine":1321}}}],"partialFingerprints":{"codehealthFindingId/v1":"00b1a68d2074229020af0ea1a61351c1898d40fd9b0d52e82d372e2e51e1cf64"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060check_dom_verification_with_evidence\u0060 turns every \u0060Err\u0060 into \u0060DomVerifyEvidenceOutcome::default()\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/check_dom_verification.rs"},"region":{"startLine":1548}}}],"partialFingerprints":{"codehealthFindingId/v1":"c0486044ae0d1f7ed24bfa9782e3aa7b645b24486d0a4ba9f18cd20628b6b0ec"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060infer_b64_json\u0060 turns every \u0060Err\u0060 into \u0060Vec::new()\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/encoding/pipeline.rs"},"region":{"startLine":258}}}],"partialFingerprints":{"codehealthFindingId/v1":"7eed04118adfbaf11c5dfeda50a3e6a4b3e9ef609013fd9f3b9988ff65362705"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060infer_b64url_json\u0060 turns every \u0060Err\u0060 into \u0060Vec::new()\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/encoding/pipeline.rs"},"region":{"startLine":286}}}],"partialFingerprints":{"codehealthFindingId/v1":"b2ea3c68c8762cb2133492b9285da8b6dda2e10df6610a09d00bed3100d466d7"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060infer_jwt\u0060 turns every \u0060Err\u0060 into \u0060Vec::new()\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/encoding/pipeline.rs"},"region":{"startLine":339}}}],"partialFingerprints":{"codehealthFindingId/v1":"a5fc22d01f2ff2940e72a12cd781bad77cc5204f6fdd69a506e8ff72724ffcf7"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060parse_version\u0060 turns every \u0060Err\u0060 into \u00600\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/vuln_libs.rs"},"region":{"startLine":252}}}],"partialFingerprints":{"codehealthFindingId/v1":"b75c09ebd065d5f0da84dd1172e8667a6b4088e89fa289e810d2f44660f751fd"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060default_json_template\u0060 turns every \u0060Err\u0060 into \u0060\u0022{\\n  \\\u0022scan\\\u0022: {}\\n}\u0022.to_string()\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/config.rs"},"region":{"startLine":815}}}],"partialFingerprints":{"codehealthFindingId/v1":"b9cc167fe952fd7709b7158d6f8a7e9c51fd1142190798ceb20d800c888ed019"}},{"ruleId":"X9","level":"note","message":{"text":"Subsumed condition operand: \u0060source.contains(\u0022SharedWorker.message\u0022)\u0060 can never decide this \u0060||\u0060 \u2014 every value satisfying \u0060source.contains(\u0022SharedWorker.message\u0022)\u0060 also satisfies \u0060source.contains(\u0022Worker.message\u0022)\u0060, so the \u0060||\u0060 chain is already decided by the latter. The expression is equivalent to the chain without it, which means it is wider than it reads. Delete the dead operand, or narrow the surviving one if IT is the accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_integration.rs"},"region":{"startLine":1050}}}],"partialFingerprints":{"codehealthFindingId/v1":"638263381fde239f4c634c8c028354850e4702de4f253dfab4406e1ec9bfef6f"}},{"ruleId":"X9","level":"note","message":{"text":"Subsumed condition operand: \u0060source.contains(\u0022SharedWorker.message\u0022)\u0060 can never decide this \u0060||\u0060 \u2014 every value satisfying \u0060source.contains(\u0022SharedWorker.message\u0022)\u0060 also satisfies \u0060source.contains(\u0022Worker.message\u0022)\u0060, so the \u0060||\u0060 chain is already decided by the latter. The expression is equivalent to the chain without it, which means it is wider than it reads. Delete the dead operand, or narrow the surviving one if IT is the accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/scanning/ast_integration.rs"},"region":{"startLine":1245}}}],"partialFingerprints":{"codehealthFindingId/v1":"5d9e693152efc892bb66d0f05784bd0a687dbb9354bdbca6eee15d14e8ce7a38"}},{"ruleId":"X9","level":"note","message":{"text":"Subsumed condition operand: \u0060payload.contains(\u0022\u003Cimg\u0022)\u0060 can never decide this \u0060||\u0060 \u2014 every value satisfying \u0060payload.contains(\u0022\u003Cimg\u0022)\u0060 also satisfies \u0060payload.contains(\u0022\u003Cim\u0022)\u0060, so the \u0060||\u0060 chain is already decided by the latter. The expression is equivalent to the chain without it, which means it is wider than it reads. Delete the dead operand, or narrow the surviving one if IT is the accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/waf/bypass/mutate.rs"},"region":{"startLine":405}}}],"partialFingerprints":{"codehealthFindingId/v1":"684c5a83d716dcef2e31fb70e36b1ec7b7b8a5b18e5a8cca51ecbd8bdb798e71"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-1059","guid":"a2381a08-60f6-9554-a8b8-f3018cfaaca5","name":"Insufficient Technical Documentation","shortDescription":{"text":"Insufficient Technical Documentation"},"helpUri":"https://cwe.mitre.org/data/definitions/1059.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-269","guid":"70e1f5f6-81e5-4e5a-ba40-b541c3a346e2","name":"CWE-269","shortDescription":{"text":"CWE-269"},"helpUri":"https://cwe.mitre.org/data/definitions/269.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-522","guid":"71fb233e-ce6a-ae57-9419-ef8373540b09","name":"CWE-522","shortDescription":{"text":"CWE-522"},"helpUri":"https://cwe.mitre.org/data/definitions/522.html"},{"id":"CWE-552","guid":"3492436b-eca2-9c54-9ba3-5dade427c903","name":"CWE-552","shortDescription":{"text":"CWE-552"},"helpUri":"https://cwe.mitre.org/data/definitions/552.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-829","guid":"13c33925-97fb-5a5e-b40c-56d328b8a4d7","name":"CWE-829","shortDescription":{"text":"CWE-829"},"helpUri":"https://cwe.mitre.org/data/definitions/829.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":96,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}