{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AX9","name":"CQS / query purity","shortDescription":{"text":"CQS / query purity"},"helpUri":"https://codehealth.canine.dev/dimensions/AX9"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"ES1","name":"Fold determinism","shortDescription":{"text":"Fold determinism"},"helpUri":"https://codehealth.canine.dev/dimensions/ES1"},{"id":"ES2","name":"Immutable events","shortDescription":{"text":"Immutable events"},"helpUri":"https://codehealth.canine.dev/dimensions/ES2"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P10","name":"Library API \u0026 versioning","shortDescription":{"text":"Library API \u0026 versioning"},"helpUri":"https://codehealth.canine.dev/dimensions/P10"},{"id":"P2","name":"Observability","shortDescription":{"text":"Observability"},"helpUri":"https://codehealth.canine.dev/dimensions/P2"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"SC1","name":"Supply-chain hygiene","shortDescription":{"text":"Supply-chain hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/SC1"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X24","name":"Document value interpolated into markup unescaped","shortDescription":{"text":"Document value interpolated into markup unescaped"},"helpUri":"https://codehealth.canine.dev/dimensions/X24"},{"id":"X25","name":"Inert configuration knob","shortDescription":{"text":"Inert configuration knob"},"helpUri":"https://codehealth.canine.dev/dimensions/X25"},{"id":"X26","name":"Unsynchronised callback handoff","shortDescription":{"text":"Unsynchronised callback handoff"},"helpUri":"https://codehealth.canine.dev/dimensions/X26"},{"id":"X29","name":"Per-element action decided by a fixed element","shortDescription":{"text":"Per-element action decided by a fixed element"},"helpUri":"https://codehealth.canine.dev/dimensions/X29"},{"id":"X31","name":"Test-only surface in a production module","shortDescription":{"text":"Test-only surface in a production module"},"helpUri":"https://codehealth.canine.dev/dimensions/X31"},{"id":"X32","name":"Type resolved by simple name across every loaded assembly","shortDescription":{"text":"Type resolved by simple name across every loaded assembly"},"helpUri":"https://codehealth.canine.dev/dimensions/X32"},{"id":"X6","name":"Hand-rolled structured-format parsing","shortDescription":{"text":"Hand-rolled structured-format parsing"},"helpUri":"https://codehealth.canine.dev/dimensions/X6"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"kafine_producer.handle_event (cyclomatic 23): kafine_producer.handle_event has cyclomatic complexity 23 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/producer/kafine_producer.erl"},"region":{"startLine":322}}}],"partialFingerprints":{"codehealthFindingId/v1":"b8c1fc46a9feb1eb813b62eee0b3a0c4e123b071badc8af58d50eb793c692744"}},{"ruleId":"D2","level":"warning","message":{"text":"kafine_producer.handle_event (cognitive 28): kafine_producer.handle_event has cognitive complexity 28 (threshold 15). Drivers by points: match/switch 10 (16 pts), loops 5 (12 pts) (nesting depth added 13). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/producer/kafine_producer.erl"},"region":{"startLine":322}}}],"partialFingerprints":{"codehealthFindingId/v1":"9b5871fe4813b4fb8fb1eff92876d40fe38fa9623e6118e53aa394e4de7b675b"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: consumer/kafine_fetcher.erl: FileTooLong \u2014 745 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 245 over it, 1.49\u00D7 the bar. In this language a module is exactly one source file, so its length cannot be moved into sibling files of the same module. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no one module has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/consumer/kafine_fetcher.erl"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1332d38d293c788e96e101f22fbeae31a88c02d7edd6b520772551e43cbebea9"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: producer/kafine_producer.erl: FileTooLong \u2014 707 significant lines (blank, comment-only and punctuation-only lines excluded), declaring 42 functions. The bar is 500 significant lines; this is 207 over it, 1.41\u00D7 the bar. In this language a module is exactly one source file, so its length cannot be moved into sibling files of the same module. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no one module has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/producer/kafine_producer.erl"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b4e7ee21c5214fa7b1c88f82fc6e4adaccd1b3030eeb8f89c1b9d1d61ed9ceee"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: producer/kafine_produce_accumulator.erl: FileTooLong \u2014 670 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 170 over it, 1.34\u00D7 the bar. In this language a module is exactly one source file, so its length cannot be moved into sibling files of the same module. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no one module has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/producer/kafine_produce_accumulator.erl"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ed115e2e929628ec61b9e3309c4faa55ea764b75134a83baab8f9ead8ff310eb"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: consumer/kafine_coordinator.erl: FileTooLong \u2014 654 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 154 over it, 1.31\u00D7 the bar. In this language a module is exactly one source file, so its length cannot be moved into sibling files of the same module. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no one module has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/consumer/kafine_coordinator.erl"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"df81e809ff1e086bd2d3a63f3b2acf6b784e1ec1cd8670db0652844ba772f7a8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11\u201317 lines \u00D7 2): src/consumer/kafine_consumer_sup.erl:62-78 | src/producer/kafine_producer_sup.erl:27-37 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/consumer/kafine_consumer_sup.erl"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"dd87f958dfa1d19c5a8d6ae051f1fb2d43e66bf108f11cc3b60f4e243473ca4d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): src/consumer/kafine_fetcher.erl:282-292 | src/consumer/kafine_fetcher.erl:309-319 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/consumer/kafine_fetcher.erl"},"region":{"startLine":282}}}],"partialFingerprints":{"codehealthFindingId/v1":"a10e881bd3eb7ceca9f405f0be6234d52906db8bb8076fdb84772f18f222d699"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 4): src/consumer/kafine_consumer_sup.erl:106-111 | src/consumer/kafine_fetcher_sup.erl:47-52 | src/consumer/kafine_node_fetcher.erl:58-63 | src/consumer/kafine_parallel_subscription_impl.erl:64-69 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from all 4 call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/consumer/kafine_consumer_sup.erl"},"region":{"startLine":106}}}],"partialFingerprints":{"codehealthFindingId/v1":"f118bfcd0fa773d66789252243907d0554360262467f8dc609f2f64f3239e15f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): src/consumer/kafine_node_fetcher.erl:48-56 | src/consumer/kafine_parallel_handler.erl:51-59 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/consumer/kafine_node_fetcher.erl"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"dca65ba8b102c3e94555a46c0819b5d09688bd219c8f2e6d55a23d40a2079c43"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): src/consumer/kafine_node_fetcher_sup.erl:57-63 | src/producer/kafine_node_producer_sup.erl:52-58 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/consumer/kafine_node_fetcher_sup.erl"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"f142f2b6c094d2d959ab3d41bdf8aa633ab635a72c778e15b5e723f4d0a5dddb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): src/consumer/kafine_range_assignor.erl:52-59 | src/consumer/kafine_round_robin_assignor.erl:59-66 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/consumer/kafine_range_assignor.erl"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"d40805c3d9b70e4477550bc7cd202987f2c080047abbe4407626a08dcb00bfcc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): src/diagnostics/kafine_trace_logger.erl:65-76 | src/diagnostics/kafine_trace_logger.erl:78-89 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/diagnostics/kafine_trace_logger.erl"},"region":{"startLine":65}}}],"partialFingerprints":{"codehealthFindingId/v1":"5243efe82e296d370749ea8110b4c79c6cfe7167a01dca57fb8a7b8495da82e6"}},{"ruleId":"D12","level":"warning","message":{"text":"Floating source dependency: eqwalizer_support: Runtime dependency \u0060eqwalizer_support\u0060 is fetched from source in rebar.config and tracks branch \u0060main\u0060 \u2014 the declaration pins no immutable revision, so \u0060rebar3 upgrade\u0060 moves this dependency to code nobody reviewed. Pin it with \u0060{tag, \u0022v1.2.3\u0022}\u0060 or \u0060{ref, \u0022\u003Cfull commit SHA\u003E\u0022}\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e3ec5cc6e79243250560507614d0ba1cc5eff2a1c526aaac7fb2858f7d0c7583"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: rename to \u0027ensure_topic_exists\u0027? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"integration/src/fixtures/kafka_fixtures.erl"},"region":{"startLine":15}}}],"partialFingerprints":{"codehealthFindingId/v1":"b83b79102d96cc4b2c8f0be793cca8c359316b46364a80d4886d558427896724"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: Invent \u0027using_connection\u0027 function. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"integration/src/fixtures/kafka_fixtures.erl"},"region":{"startLine":117}}}],"partialFingerprints":{"codehealthFindingId/v1":"25b619fdd438a20280fed7e0ee6c6c1ea878b571031c1acf0a30a690c2a0e790"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: DRY \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"integration/test/topic_consumer_SUITE.erl"},"region":{"startLine":187}}}],"partialFingerprints":{"codehealthFindingId/v1":"39a8e20e2aaba9cca6d8538926399cb66d845cb0cbce573d1849e1c8a4d31fcc"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: DRY \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"integration/test/topic_consumer_SUITE.erl"},"region":{"startLine":198}}}],"partialFingerprints":{"codehealthFindingId/v1":"ed50b514c2447f4c6b6c36acd7fb2681c5874d8e8189b555b7dafad63f462a07"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: DRY \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"integration/test/negative_initial_offset_SUITE.erl"},"region":{"startLine":192}}}],"partialFingerprints":{"codehealthFindingId/v1":"cd595aaf6c8dbb98e7085dd0f5dc7d673df30cc15fe4698c090b0e4d86af9231"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: DRY \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"integration/test/negative_initial_offset_SUITE.erl"},"region":{"startLine":203}}}],"partialFingerprints":{"codehealthFindingId/v1":"d287ae7b786ddba8d143cb4a02c33aba023feae8e8f5235e670c6af6d1c7451e"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: DRY \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"integration/test/group_consumer_offset_SUITE.erl"},"region":{"startLine":127}}}],"partialFingerprints":{"codehealthFindingId/v1":"e8c4fc94cd8d9a95e41ea01cff50616501a0ba1cf85ca5b8c09374ef703c3ed4"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: DRY \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"integration/test/group_consumer_offset_SUITE.erl"},"region":{"startLine":138}}}],"partialFingerprints":{"codehealthFindingId/v1":"78b4c49bcc78466e7b0f71ba6b49cd1a539320e7876fb00ac3321b25e4a76e9d"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: DRY \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"integration/test/group_consumer_SUITE.erl"},"region":{"startLine":207}}}],"partialFingerprints":{"codehealthFindingId/v1":"7fc4aeb5b5d52c12d22e2cbca119babaabc22dad4da3bed3a4e413c6179acdd9"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: DRY \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"integration/test/group_consumer_SUITE.erl"},"region":{"startLine":218}}}],"partialFingerprints":{"codehealthFindingId/v1":"961be26df640a48b2f2e1544f554e5f8db305267838ef3d8efa08c9739cb2f85"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO? Assert the consumer lag while we\u0027ve got some? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"integration/test/group_consumer_offset_SUITE.erl"},"region":{"startLine":91}}}],"partialFingerprints":{"codehealthFindingId/v1":"483fc9fcb1975263e01898b00663309dae37b087868799139d102fa4706a3731"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: There\u0027s a lot to be said for *not* cleaning up afterwards -- it\u0027s easier to debug. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"integration/test/direct_fetch_SUITE.erl"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"63dcff01d8bb9e906826ff4f1f377f052711e020b9ce3907e02be5927100516d"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: Loop until the message appears. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"integration/test/direct_fetch_SUITE.erl"},"region":{"startLine":133}}}],"partialFingerprints":{"codehealthFindingId/v1":"73d43bb5e4cb1efbba48719a4c605f6ad5debd4d5beea503d987ecceac72f38f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: Actually assert that the topic was created and placed where we asked. For now, manual inspection\u0027s fine, \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"integration/test/direct_create_topic_SUITE.erl"},"region":{"startLine":87}}}],"partialFingerprints":{"codehealthFindingId/v1":"80182dfcf3f03f8a605d578292febd1089152d7e5663537624bc55bcf667be6d"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: backoff isn\u0027t actually used by kafine_connection. This should live somewhere else \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/kafine.erl"},"region":{"startLine":79}}}],"partialFingerprints":{"codehealthFindingId/v1":"4b8428678fe72a535a501cb59644f9d9539af3a15df8d5125f913c86bdc02521"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: fetch_options, instead? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/kafine.erl"},"region":{"startLine":83}}}],"partialFingerprints":{"codehealthFindingId/v1":"0b1b239ed836c30cc1d2c0183fee0fff5bf1f6fba358001f66e68959123c0251"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: These types should be in kafcod, maybe? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/kafine.erl"},"region":{"startLine":206}}}],"partialFingerprints":{"codehealthFindingId/v1":"a294572b80b869559536bf2be0b95616e00b7d26dbe229cd7ae8fdfecf01ec2a"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: This isn\u0027t actually the correct type; it keeps eqalizer happy. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/kafine.erl"},"region":{"startLine":226}}}],"partialFingerprints":{"codehealthFindingId/v1":"36e336f806256da7bd23f2914992e719d59ec5d746ab3049233dbed43899297f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: not yet implemented \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/consumer/kafine_parallel_subscription_impl.erl"},"region":{"startLine":223}}}],"partialFingerprints":{"codehealthFindingId/v1":"db33bc3aeb370df50a3ffa8011f0f1c75f21e79bf168fba6755bb73b23c00150"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: Do we need to handle missing offsets being in requests but not responses? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/consumer/kafine_parallel_subscription_impl.erl"},"region":{"startLine":397}}}],"partialFingerprints":{"codehealthFindingId/v1":"d5003fccfc666c3f4444bd0c5711dd7a576a91136d9cb8481f9d116e63ccf35f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: preferred read replica. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/consumer/kafine_fetch.erl"},"region":{"startLine":49}}}],"partialFingerprints":{"codehealthFindingId/v1":"67b6bbb5e4f521db217733848430361b8b4abbd32feff6f5d5d5e2cb1e75cc23"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: We don\u0027t care about the leader epoch. At some point we might. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/consumer/kafine_fetch.erl"},"region":{"startLine":68}}}],"partialFingerprints":{"codehealthFindingId/v1":"78ac9f79990a49cbb6ebd3746d41afd756a33d96f9033ccc04ac67fb46097b06"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: gen_server has {in, \u0027$gen_call\u0027, \u0027$gen_cast\u0027}, out, noreply \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/diagnostics/kafine_trace_logger.erl"},"region":{"startLine":15}}}],"partialFingerprints":{"codehealthFindingId/v1":"859fd3e591b6141b3527e27f26c1fd932b954f4af256cd908e766a10cfa077c3"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: module, state_timer, insert_timeout \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/diagnostics/kafine_trace_logger.erl"},"region":{"startLine":55}}}],"partialFingerprints":{"codehealthFindingId/v1":"e7d0301f7e1c8b5a614b3b2ff7fc84f511be1845867eb6ce985721acba5f9d60"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: handle $gen_call, $gen_cast here...? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/diagnostics/kafine_trace_logger.erl"},"region":{"startLine":98}}}],"partialFingerprints":{"codehealthFindingId/v1":"ec0d15bb4e2e80654b33203604a6492c53bfeb1abb39d1eeae4a8f7aa0621a4e"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: We\u0027d actually like to enforce this being \u003E max_batch_size_bytes \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/producer/kafine_producer_options.erl"},"region":{"startLine":55}}}],"partialFingerprints":{"codehealthFindingId/v1":"35e13f6e1fd3ebfd774cc3db01657aee77d97ac612d6ec01f41b2f8452b86c40"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: Should we linger for other partitions which may have started a backoff at the same time? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/producer/kafine_producer.erl"},"region":{"startLine":445}}}],"partialFingerprints":{"codehealthFindingId/v1":"e50894f7983fbb6b37476244fd5320c11cb64e88bca2ba380f2363585c82555d"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: The partition doesn\u0027t exist. Should we expect an error here? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"test/kafine_fetcher_sup_tests.erl"},"region":{"startLine":202}}}],"partialFingerprints":{"codehealthFindingId/v1":"81a97aaa8a7b4b2f8391c4e7900b4a75d82f3d86dcd938f1dd2e3858b08cfeb9"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: Some tests around subscribing to things you\u0027re _already_ subscribed to... \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"test/kafine_fetcher_set_topic_partitions_tests.erl"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"0c99e6ce1a8d2de18b572df076c1cba01d91d5e8ffc3ba6944cefed1913c43e0"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: not sure this test adds anything now that the skipping is in handle_partition_data \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"test/kafine_fetch_response_tests.erl"},"region":{"startLine":215}}}],"partialFingerprints":{"codehealthFindingId/v1":"27fece58f8fdc95bf50ca10e00644ab8a720d44ac5d6a6a273597e4e9bca08cf"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: not sure this test adds anything now that the skipping is in handle_partition_data \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"test/kafine_fetch_response_tests.erl"},"region":{"startLine":292}}}],"partialFingerprints":{"codehealthFindingId/v1":"c22b446871ad5acd15003bf6264a36152c6783070b378ee02fac67d71adaef51"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: There\u0027s quite a lot of shared setup here; can we jump start to \u0027leader\u0027 somehow? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"test/kafine_eager_rebalance_tests.erl"},"region":{"startLine":297}}}],"partialFingerprints":{"codehealthFindingId/v1":"c7215fbae069d0792b219ad289adcdb48d216a14b6b0a8b337296c1dac7fd638"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: Single produce, multiple messages, tail offset. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"test/kafine_consumer_fetch_tests.erl"},"region":{"startLine":331}}}],"partialFingerprints":{"codehealthFindingId/v1":"3cf8cdbd2b4a19c9d8459d5fd6315a4d571d6350f50fe9f2c6b3f87dc60879b7"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: Produce, Fetch, Produce, Fetch, repeatedly. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"test/kafine_consumer_fetch_tests.erl"},"region":{"startLine":333}}}],"partialFingerprints":{"codehealthFindingId/v1":"9d0c6f3f6e6fa156f5e1946b8a013b2abb3b2a548447ed66aed4ab72c7ae9c53"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: Multiple messages, returned over multiple Fetch (i.e. NextOffset and HighWatermark aren\u0027t the same until the \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"test/kafine_consumer_fetch_tests.erl"},"region":{"startLine":335}}}],"partialFingerprints":{"codehealthFindingId/v1":"79702537ddd9e576093acd693326cd13ad9577394126cef20ff0efe9cf05da9c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: % TODO: At some point, we\u0027ll need to replicate a partition that _starts_ at a non-zero offset. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060% REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"test/kafine_consumer_fetch_tests.erl"},"region":{"startLine":441}}}],"partialFingerprints":{"codehealthFindingId/v1":"99c3598e38d02185abeb00e87dbb845c6d3b4fada8e79d38b4314e04fdfb668c"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no project overview: The first paragraph under the title gives only a one-line description (\u0027Kafine is a Kafka client for Erlang\u0027) without stating what the project does or its scope beyond \u0027better performance and compatibility than existing Kafka client libraries in the BEAM ecosystem\u0027. Expand with an overview section explaining the problem (Kafka\u0027s complexity, BEAM ecosystem limitations) and the value proposition of kafine."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"66dbf18d06aa983c06246108610908ba99aae6784280b3aacd1a6655733d71be"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"083a088097c25e5edfc36cf6eda865b45f4d6fd6743051e11154ff4887b48f28"},"taxa":[{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"23eace91417f5a10ee6ebcd92c369f3e153370222d69c55314f39e4dbd251854"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c05dd276ec3828f395ecc889e9c70d3029a658cb96b7930332ab9b777c987d1b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fc106d0d8d115f72ecc508f388a4a0b6ed0f42c17151284a9164408a2309adcc"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"P1","level":"warning","message":{"text":"No CI pipeline: No CI workflow found (.github/workflows, azure-pipelines.yml, .gitlab-ci.yml, \u2026) \u2014 changes aren\u0027t gated by an automated build/test."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"44f01af96e50474fba2df84d95ddf4f7e1d34c29c307830b9efc9057daa6b670"}},{"ruleId":"P4","level":"note","message":{"text":"No rollback/health safety: Deployment is orchestrated by compose, but no service declares a \u0060healthcheck:\u0060 and nothing pins a previous image to fall back to \u2014 the runtime can tell that the container is up, not that it is serving, so a bad release is harder to detect and reverse."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"db6bab8a28a2145f47e5a4e6683cda39d2ba0296c723238e8057da979ae1c706"}},{"ruleId":"P6","level":"note","message":{"text":"No changelog: No CHANGELOG/HISTORY/RELEASES file \u2014 what shipped when isn\u0027t easy to reconstruct for support or audit. (Versioning/tagging makes releases traceable, but a changelog records the what.)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"dda5aa5aed8cbb292c3ef2b733bc138f614293ae6426c85e98bf31ef330d9415"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":4,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}