{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D23","name":"Boundary Type-Coupling","shortDescription":{"text":"Boundary Type-Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D23"},{"id":"D24","name":"Comment Value","shortDescription":{"text":"Comment Value"},"helpUri":"https://codehealth.canine.dev/dimensions/D24"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D39","name":"IL Efficiency","shortDescription":{"text":"IL Efficiency"},"helpUri":"https://codehealth.canine.dev/dimensions/D39"}]}},"results":[{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (53 lines \u00D7 2): src/BugTracker.Persistence/Configurations/Identity/DemoUserConfiguration.cs:17-69 | src/BugTracker.Persistence/Configurations/Identity/UserConfiguration.cs:52-109 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/BugTracker.Persistence/Configurations/Identity/DemoUserConfiguration.cs"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c09df105866b2b52b1a8c2ed2266e1107ed73e4aef51459fd73b7dcf3bfc63a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (26 lines \u00D7 2): src/BugTracker.Persistence/Configurations/Identity/UserRolesConfiguration.cs:67-92 | src/BugTracker.Persistence/Configurations/Identity/UserRolesConfiguration.cs:95-126 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/BugTracker.Persistence/Configurations/Identity/UserRolesConfiguration.cs"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"393a9e45b3e483a05cb81866bec787974d92ab5d638bb1c570b3388e70a6f2af"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (20 lines \u00D7 2): src/BugTracker.Application/Features/Tickets/Commands/Create/CreateTicketCommandValidator.cs:19-38 | src/BugTracker.Application/Features/Tickets/Commands/Update/UpdateTicketCommandValidator.cs:19-38 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it wherever the callers may both depend on (the module they already share, or a small common one if they share none) and call it from each site \u2014 until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/BugTracker.Application/Features/Tickets/Commands/Create/CreateTicketCommandValidator.cs"},"region":{"startLine":19}}}],"partialFingerprints":{"codehealthFindingId/v1":"9c98576526f32240624076a497fa8625f32d89335f71da07215421878b3741f6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): src/BugTracker.Persistence/Services/Data/ProjectRepository.cs:132-148 | src/BugTracker.Persistence/Services/Data/ProjectRepository.cs:162-178 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/BugTracker.Persistence/Services/Data/ProjectRepository.cs"},"region":{"startLine":132}}}],"partialFingerprints":{"codehealthFindingId/v1":"a0e5fc71ac2dc5e20bcdaa9fb9e69039f6dfd238694222220a09f968b837e170"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): src/BugTracker.Application/Features/Tickets/Commands/Delete/DeleteTicketCommandHandler.cs:45-59 | src/BugTracker.Application/Features/Tickets/Commands/Update/UpdateTicketCommandHandler.cs:61-75 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it wherever the callers may both depend on (the module they already share, or a small common one if they share none) and call it from each site \u2014 until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/BugTracker.Application/Features/Tickets/Commands/Delete/DeleteTicketCommandHandler.cs"},"region":{"startLine":45}}}],"partialFingerprints":{"codehealthFindingId/v1":"382d58e29c4c05a8a5abdfed7d51199fef71552c8d20ff304ace87e5fdc200b8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): src/BugTracker.Persistence/Services/Data/TicketRepository.cs:228-236 | src/BugTracker.Persistence/Services/Data/TicketRepository.cs:270-278 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/BugTracker.Persistence/Services/Data/TicketRepository.cs"},"region":{"startLine":228}}}],"partialFingerprints":{"codehealthFindingId/v1":"ff64a2c8614be2a0de7dc75ef10cd0e69dd23cac26e78ed173cbabf53bf983cb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): src/BugTracker.Persistence/Services/Data/TicketRepository.cs:242-250 | src/BugTracker.Persistence/Services/Data/TicketRepository.cs:285-293 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/BugTracker.Persistence/Services/Data/TicketRepository.cs"},"region":{"startLine":242}}}],"partialFingerprints":{"codehealthFindingId/v1":"dfd3f1e879f82329a9b0e8bb3e918825847d46f97ebcfbf64e66910037cda0ba"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 3): src/BugTracker.Persistence/Services/Data/TicketRepository.cs:29-36 | src/BugTracker.Persistence/Services/Data/TicketRepository.cs:119-126 | src/BugTracker.Persistence/Services/Data/TicketRepository.cs:149-157 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/BugTracker.Persistence/Services/Data/TicketRepository.cs"},"region":{"startLine":29}}}],"partialFingerprints":{"codehealthFindingId/v1":"380a117831ff60b00cf807fff43f1440c8bdf5f055d1c100fdb07c63b338d9ea"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): src/BugTracker.Persistence/Services/Data/TicketRepository.cs:549-556 | src/BugTracker.Persistence/Services/Data/TicketRepository.cs:563-571 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/BugTracker.Persistence/Services/Data/TicketRepository.cs"},"region":{"startLine":549}}}],"partialFingerprints":{"codehealthFindingId/v1":"2419041391d970a7d1294566b25c63a3f9f883efb44ab72cad33e906dd64152a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): src/BugTracker.Persistence/Services/Data/TicketRepository.cs:45-50 | src/BugTracker.Persistence/Services/Data/TicketRepository.cs:175-180 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/BugTracker.Persistence/Services/Data/TicketRepository.cs"},"region":{"startLine":45}}}],"partialFingerprints":{"codehealthFindingId/v1":"dc1002a4ba0d6d76fbf2830c4cb873f3f58bb0a5171ef9d979bd66bd8d3b1b15"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: BugTracker.Domain: BugTracker.Domain: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and heavily depended-on, so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"85e2e12531d9060d4aa507684ecfd06a284f1ff9a23258f8d5ef357a55909761"}},{"ruleId":"D8","level":"error","message":{"text":"No automated tests: No automated tests \u2014 no test code was found in this repository. Untested code is the largest single risk to changing it safely."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3132564c6310e5d01a231f252a02d5d2f5a542c0a8fa29a14c89693f1e3df871"}},{"ruleId":"D9","level":"note","message":{"text":"No tests found: No test suite could be collected \u2014 nothing here references a test framework (xUnit/NUnit/MSTest, Jest/Vitest, pytest, Go testing, JUnit, \u2026), so there were no discoverable tests to count. Tests written as plain executables or shell/PowerShell harnesses are not collectible this way and are not scored here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c9bf64cbb5a4ae13d6bcd01fa3bc8d2879d860c73bc67f176ee3c2cecb8adce3"}},{"ruleId":"D12","level":"error","message":{"text":"Vulnerable: AutoMapper: AutoMapper 10.1.1 \u2014 High severity. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7ad907f4096422e42924a00fab6889d83782c07f3031eeb825e84a391fcadb56"}},{"ruleId":"D12","level":"error","message":{"text":"Vulnerable: Azure.Identity: Azure.Identity 1.2.2 \u2014 High severity. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4b82a82ead2038444235c5c303e0864f14bd669ef3d03d66c536e0cc097bb0ce"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.AspNetCore.Identity.EntityFrameworkCore: Microsoft.AspNetCore.Identity.EntityFrameworkCore 5.0.11 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6cd381b0bf789c81719f890110e35f67109236489736add3fd5cae4df1fbab17"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.AspNetCore.Diagnostics.EntityFrameworkCore: Microsoft.AspNetCore.Diagnostics.EntityFrameworkCore 5.0.11 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e4894327b8ef61845f05cdfb38d68b153cfdbf84e650c0878ceeb76921ccab70"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.EntityFrameworkCore.SqlServer: Microsoft.EntityFrameworkCore.SqlServer 5.0.11 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1bb48f233190b229ebd5b332fb00e8c5120b49cc5db84ca77e9c40b476415d80"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.EntityFrameworkCore.Tools: Microsoft.EntityFrameworkCore.Tools 5.0.11 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"369a627036aa781f4b5310a26d74815a8e02df358d88c9be44c5516bfa89e46f"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: microsoft.extensions.dependencyinjection: microsoft.extensions.dependencyinjection 5.0.2 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f77bac68c0f1fc3992be8dae3bdf2f305294f65035df80ac100bbd0f2ca8710c"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.Extensions.Options.ConfigurationExtensions: Microsoft.Extensions.Options.ConfigurationExtensions 5.0.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"8ca98cb4cca91d3c8c086ddd1914d7f9c5f6e58310f7e367a60c6cd508567df3"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.Extensions.Configuration.Abstractions: Microsoft.Extensions.Configuration.Abstractions 5.0.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7f8883aa785da40e3a27332ddedc3e9570fb43a3379c62dbc06a8b10a685f5d1"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: FluentValidation.AspNetCore: FluentValidation.AspNetCore 10.3.4 \u2014 Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c121fe39eaa15140bc3e6db44975ad976f90ca0ef505592ab96df7811261bcf1"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Azure.Identity: Azure.Identity 1.2.2 \u2014 Other"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"2c48b8b518e33f322169a01b4e304c093ae4e143a4f32e23f92274ffeccb9051"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.AspNetCore.Mvc.Core: Microsoft.AspNetCore.Mvc.Core 2.2.5 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"dc1a5ec0b0556e62dc8d49534a396ccc24dc2552dc4843db15ad9854629bdc55"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.AspNetCore.Mvc.Razor.RuntimeCompilation: Microsoft.AspNetCore.Mvc.Razor.RuntimeCompilation 5.0.11 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0a54c0bd9eeafc78d958aed880466d16828c816e7aeac52efae3304dd568130c"}},{"ruleId":"D13","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1886374ede610938eff533d0bbc3a6680e5a11fc2ad700135670a42c139303e1"},"taxa":[{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D16","level":"warning","message":{"text":"dormant codebase \u2014 no living knowledge left to concentrate: All 29 significant source file(s) were last meaningfully changed so long ago that no living knowledge remains \u2014 nothing since has been substantial enough to re-establish ownership (a broad, mechanical sweep that touches many files shallowly does not count, and neither does no activity at all). There is no concentration to measure, so the bus factor is not scored. This is not a clean bill: nobody currently holds working knowledge of this code (see D34 Knowledge Freshness)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"569d55ea5cb0330f13c125b289d07e5abdfcceac947a2c2645277937942e7d5f"}},{"ruleId":"D17","level":"warning","message":{"text":"CommentedOutCode: 4 consecutive commented-code lines"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/BugTracker.Application/Features/Audits/Queries/LogToViewHelper.cs"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"107c4b571243e22ffa35b5d72f54e6848ecbf427dd69a2b643d79d501ef348e2"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO manage errors \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/WebApp/BugsTracker/Areas/Tracker/Controllers/UserController.cs"},"region":{"startLine":61}}}],"partialFingerprints":{"codehealthFindingId/v1":"86c29bac6b13d56d3abe57e74159c2225cf4a06436f77727ce94fa4d09863367"}},{"ruleId":"D19","level":"note","message":{"text":"No quick start or installation instructions; only a demo link and no clone command.: Add a \u0027Getting started\u0027 section covering how to clone the repo, set up the data store (SQL Server/Redis), and run the application."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"5746abfa385ba28caac997823986d9dd5160e4c2f29adf43782fc640b56d6451"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found at common paths; consider documenting architectural decisions in Docs/ADL/ or similar."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D23","level":"note","message":{"text":"Bounded contexts not declared: At 6440 LoC across 5 projects the codebase is large and multi-module, so explicit bounded contexts are needed. Name this codebase\u0027s bounded contexts (\u22652 module groups, e.g. per subsystem) so cross-boundary type coupling can be assessed. Declare them in \u0060.codehealth/config.yaml\u0060 at the repository root (create it if absent), mapping each context name to the namespace prefixes that belong to it \u2014 e.g. \u0060architecture:\u0060 \u2192 \u0060contexts:\u0060 \u2192 \u0060Billing: [\u0022Acme.Billing\u0022]\u0060, \u0060Catalog: [\u0022Acme.Catalog\u0022]\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1c7e276c9c682731f01819ed5378b90ca320cde1b583c90920172911598362b3"}},{"ruleId":"D26","level":"note","message":{"text":"Split BugTracker.Application: A generic catch-all name that is huge (3k LoC) and sprawls over 56 unrelated namespaces. Suggested: by namespace: BugTracking/Core, BugTracking/Reporting, BugTracking/Workflow"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3050be27fb364b8bf6baf7d2e65248a5d71754bb8c3123629e65f1f1ba0afb19"}},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"07e34661a17676a32b0690ae2a2284bdad25c1256972c02249c4b79d718c117d"},"taxa":[{"id":"CWE-862","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0033fe39bf765087d8e53dd312f8e18b4fec4775a447110e85c0d1d8f487023e"},"taxa":[{"id":"CWE-862","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"82cd1eb8a4f9b421be110642681e3f914449615bebc8cbf2d80e92d351fbb7be"},"taxa":[{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ab45095fb9f3f8daddcf10f1b4585481759772b8ab8b1a0af30895ab3a5e155e"},"taxa":[{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"93171527efeb9cf56fdc35bf64cc638e6d931b411419cfdb67e8d6c1351156e8"},"taxa":[{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7efe2b96867f96e7a44c329908ceecba4d5b80fe3ba9296724c611fd03d80223"},"taxa":[{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1f79a595d62add568feda19f54d04fdad0273f072ae213a4e4ad714127a8a2fe"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8814dcdf3e0265c154109323ebb1021c3a164acc2ac3e06dec94b4f1489f3745"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4e4448b31e8b4dd1a6489e264df38146de5afb770ee8e6556d999f07ae5800a8"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"81d70374024ff22e11cf5598879a317ed70ee1bc2d998f8f8933659faa3ca8ec"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"30d58bfb3c5b5381b099fe7c7213473404221cdaeb03235cb29287f6c9f0bb44"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b96b7173c4377d5bea4d6fd7b52323631c631c44172b743bec6f266c10a4e538"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dfafed29f9db9c37ef998ae276a09f4bbc5b7f685d970a4f962752fc98cdf1dc"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f028f533a7cd9b811f22399ada2b0ff86ea59565aadfa6de650f3d5820b19110"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b636c797e667abc99114d8220722f875ade9271729ede99cfa215fdf96631226"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"486e2d43aa26452cff8350614c638572e2f6b2144e4c21c889261cc491fda68e"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f279c68f84071f768f46e3141c2a4f2b2892ba451ad501390510048f64b35f49"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"89c9af6339ed61c69006f51a74487ce317830e5b03e63834d5f72f7bd5b42a6e"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0d7b2e89c5e31ff24950c27eba33fcd50b9ebf69ca41d61b7cd4cc2f0fd300b0"}},{"ruleId":"D34","level":"note","message":{"text":"Dormant codebase: 29 of 29 significant files have no living knowledge \u2014 the codebase as a whole is dormant, not 29 separate risks. Re-engage owners or document before change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4c69f1e54b7dd6fe9029dd02df6ba8f8145b789f2f18dbdaa086c40ded49dba6"}},{"ruleId":"D34","level":"note","message":{"text":"Largest orphaned file: One of the largest files with no living knowledge remaining \u2014 a reasonable place to start a read-through before the aggregate risk above bites."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/BugTracker.Persistence/Services/Data/TicketRepository.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"17f016bdc61343964fe3165df866869804d0d77003c9c956bac8a04df9446f67"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: GetProjectTicketsQueryHandler.cs \u2194 TicketController.cs: \u0060src/BugTracker.Application/Features/Tickets/Queries/GetProjectTickets/GetProjectTicketsQueryHandler.cs\u0060 (context BugTracker) and \u0060src/WebApp/BugsTracker/Areas/Tracker/Controllers/TicketController.cs\u0060 (context WebApp) sit in DIFFERENT parts of the tree yet change together 91% of the time (10 of the 11 commits that touched the less-changed of the two, renames followed) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/BugTracker.Application/Features/Tickets/Queries/GetProjectTickets/GetProjectTicketsQueryHandler.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0d548f2d50ea04cf010d10523057af1ee50a72c793f9b4eba2c7542a63f5af9b"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: ITicketRepository.cs \u2194 TicketController.cs: \u0060src/BugTracker.Application/Contracts/Data/ITicketRepository.cs\u0060 (context BugTracker) and \u0060src/WebApp/BugsTracker/Areas/Tracker/Controllers/TicketController.cs\u0060 (context WebApp) sit in DIFFERENT parts of the tree yet change together 73% of the time (11 of the 15 commits that touched the less-changed of the two, renames followed) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/BugTracker.Application/Contracts/Data/ITicketRepository.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"96014aee3fda892614fac4ef71d6420b270f69b8046cd091812a493ec1f63ab0"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: TicketRepository.cs \u2194 TicketController.cs: \u0060src/BugTracker.Persistence/Services/Data/TicketRepository.cs\u0060 (context BugTracker) and \u0060src/WebApp/BugsTracker/Areas/Tracker/Controllers/TicketController.cs\u0060 (context WebApp) sit in DIFFERENT parts of the tree yet change together 59% of the time (17 of the 29 commits that touched the less-changed of the two, renames followed) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/BugTracker.Persistence/Services/Data/TicketRepository.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"fdf8b55a3f7c75793ae91323692ead91149fa5716519d2c8ce9f3dfe2e2a76b9"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: IIdentityService.cs \u2194 UserController.cs: \u0060src/BugTracker.Application/Contracts/Identity/IIdentityService.cs\u0060 (context BugTracker) and \u0060src/WebApp/BugsTracker/Areas/Tracker/Controllers/UserController.cs\u0060 (context WebApp) sit in DIFFERENT parts of the tree yet change together 54% of the time (7 of the 13 commits that touched the less-changed of the two, renames followed) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/BugTracker.Application/Contracts/Identity/IIdentityService.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"aeb6b30c16da003eb0367de40610c6d19fbe9714f552f72f0e41c775620d90a1"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: IdentityService.cs \u2194 UserController.cs: \u0060src/BugTracker.Persistence/Services/Identity/IdentityService.cs\u0060 (context BugTracker) and \u0060src/WebApp/BugsTracker/Areas/Tracker/Controllers/UserController.cs\u0060 (context WebApp) sit in DIFFERENT parts of the tree yet change together 54% of the time (7 of the 13 commits that touched the less-changed of the two, renames followed) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/BugTracker.Persistence/Services/Identity/IdentityService.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f7e08889c0c0638f4786957e957525a511a7af16f3ff40e3ddd44d25fb3e4977"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: GetProjectTicketsQueryHandler.cs \u2194 TicketRepository.cs: \u0060src/BugTracker.Application/Features/Tickets/Queries/GetProjectTickets/GetProjectTicketsQueryHandler.cs\u0060 and \u0060src/BugTracker.Persistence/Services/Data/TicketRepository.cs\u0060 change together 64% of the time (7 of the 11 commits that touched the less-changed of the two, renames followed) with no explicit dependency \u2014 a hidden/logical coupling. If they belong together, co-locate them; if not, break the coupling."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/BugTracker.Application/Features/Tickets/Queries/GetProjectTickets/GetProjectTicketsQueryHandler.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"16e5ddf8c21df6637fd92afb46ea9a09f88563fc71ca3a3d98366f6df8ad01c5"}},{"ruleId":"D39","level":"note","message":{"text":"IL efficiency: 2 authored method(s) exceed the IL budget: 2 of 387 first-party methods compile to oversized IL bodies (\u003E 250 instructions); worst: BugTracker.Application.Profiles.MappingProfile..ctor @ src/BugTracker.Application/Profiles/MappingProfile.cs:31, 385 IL instructions; large bodies don\u0027t JIT-inline, which pulled this dimension to 9.9/10; splitting the hottest bodies recovers the most."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/BugTracker.Application/Profiles/MappingProfile.cs"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"39db6a5fa111013e4bbda39456248573eb53a66e555f84cd39ad8a4c23dfdf2e"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-862","guid":"2d96ecd7-f7f1-7f55-9f3a-43bb5bafdf33","name":"CWE-862","shortDescription":{"text":"CWE-862"},"helpUri":"https://cwe.mitre.org/data/definitions/862.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":20,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}