{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D22","name":"Internal API Consistency","shortDescription":{"text":"Internal API Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D22"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AX9","name":"CQS / query purity","shortDescription":{"text":"CQS / query purity"},"helpUri":"https://codehealth.canine.dev/dimensions/AX9"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"DM4","name":"Rich vs anemic domain model","shortDescription":{"text":"Rich vs anemic domain model"},"helpUri":"https://codehealth.canine.dev/dimensions/DM4"},{"id":"DM5","name":"Encapsulated state","shortDescription":{"text":"Encapsulated state"},"helpUri":"https://codehealth.canine.dev/dimensions/DM5"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P2","name":"Observability","shortDescription":{"text":"Observability"},"helpUri":"https://codehealth.canine.dev/dimensions/P2"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P5","name":"DR \u0026 Backup","shortDescription":{"text":"DR \u0026 Backup"},"helpUri":"https://codehealth.canine.dev/dimensions/P5"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"PF3","name":"Async \u0026 latency hygiene","shortDescription":{"text":"Async \u0026 latency hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/PF3"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"prek::run (cyclomatic 43): prek::run has cyclomatic complexity 43 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/main.rs"},"region":{"startLine":154}}}],"partialFingerprints":{"codehealthFindingId/v1":"6014dd896becae8f4c7f2dc1bf64bbfb11d4e4fd10de0001edf3312d66335a17"}},{"ruleId":"D1","level":"warning","message":{"text":"prek::schema::strip_null_acceptance (cyclomatic 27): prek::schema::strip_null_acceptance has cyclomatic complexity 27 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/schema.rs"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"5cbb2c3af7f7a1741d4d339e6a37da26c3ef5f917d035999054af4e052526f8a"}},{"ruleId":"D1","level":"warning","message":{"text":"HookOptions::update (cyclomatic 24): HookOptions::update has cyclomatic complexity 24 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/config/hook.rs"},"region":{"startLine":532}}}],"partialFingerprints":{"codehealthFindingId/v1":"fbfa9265d3750b8794e740d450bec9beec7bc31d9997ea9afeb2966ffef5ce7d"}},{"ruleId":"D1","level":"warning","message":{"text":"Repo::deserialize (cyclomatic 21): Repo::deserialize has cyclomatic complexity 21 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/config/repo.rs"},"region":{"startLine":236}}}],"partialFingerprints":{"codehealthFindingId/v1":"f738beb4dbe311d7634a1c99a16a3586759be679fc326a698096f6c76ee83131"}},{"ruleId":"D1","level":"warning","message":{"text":"prek::hooks::pre_commit_hooks::check_merge_conflict::check_file (cyclomatic 20): prek::hooks::pre_commit_hooks::check_merge_conflict::check_file has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hooks/pre_commit_hooks/check_merge_conflict.rs"},"region":{"startLine":63}}}],"partialFingerprints":{"codehealthFindingId/v1":"8931cdbdf1682face4c5493ee70dd707d6b7d90aa6a5fedb192506e1dfbbcb63"}},{"ruleId":"D1","level":"warning","message":{"text":"prek::cli::cache_gc::cache_gc (cyclomatic 18): prek::cli::cache_gc::cache_gc has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/cache_gc.rs"},"region":{"startLine":145}}}],"partialFingerprints":{"codehealthFindingId/v1":"f8a9f5f4c758c3b19c13b1ae33553dada0c14a382cd6add5dbf35b54e565f153"}},{"ruleId":"D1","level":"warning","message":{"text":"prek::cli::run::run::run (cyclomatic 18): prek::cli::run::run::run has cyclomatic complexity 18 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/run/run.rs"},"region":{"startLine":77}}}],"partialFingerprints":{"codehealthFindingId/v1":"00311277e8f1a8e0ee0fbd14cc8e988d6e68203051e6c620f1932c8a4a0a3b6b"}},{"ruleId":"D1","level":"warning","message":{"text":"HookRunSession::render_hook_details (cyclomatic 17): HookRunSession::render_hook_details has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/run/run.rs"},"region":{"startLine":1040}}}],"partialFingerprints":{"codehealthFindingId/v1":"79a8214f458a359c6d0f466c753812b3f3ca01209e610dd97f9c8788aac857b0"}},{"ruleId":"D1","level":"warning","message":{"text":"prek::cli::install::install_hook_script (cyclomatic 17): prek::cli::install::install_hook_script has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/install.rs"},"region":{"startLine":220}}}],"partialFingerprints":{"codehealthFindingId/v1":"6738535c226b5019acfaa731d62b17823baa765cc21eaee3c02d4bc5fc5a5a72"}},{"ruleId":"D1","level":"warning","message":{"text":"prek::archive::unzip (cyclomatic 17): prek::archive::unzip has cyclomatic complexity 17 (threshold 15). Of this number, 12 points are the body\u0027s own statements and 5 belong to one function item inside it that branches. This file\u0027s own header attributes it to another copyright holder, so it is code this repository carries rather than code it wrote: restructuring the body in place forks it from upstream and turns every future re-sync into a manual merge. The performable moves are to leave the body as close to its upstream form as possible and keep it behind a narrow interface of your own, and to re-sync it when upstream changes \u2014 or, if it has already diverged far enough that you maintain it here, adopt it deliberately and then split the body into named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/archive.rs"},"region":{"startLine":148}}}],"partialFingerprints":{"codehealthFindingId/v1":"5379fa5f55b0267d479f901a7515a6244eeffdbae8bd31c25c1e1a2b1a549629"}},{"ruleId":"D1","level":"warning","message":{"text":"prek::cli::cache_gc::sweep_dir_by_name (cyclomatic 17): prek::cli::cache_gc::sweep_dir_by_name has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/cache_gc.rs"},"region":{"startLine":546}}}],"partialFingerprints":{"codehealthFindingId/v1":"b6d029659f0dc58f34521a277a5130fd2a493cd8b4ce2466f8d18da466691cbe"}},{"ruleId":"D1","level":"warning","message":{"text":"prek::cli::cache_gc::sweep_stale_patch_files (cyclomatic 16): prek::cli::cache_gc::sweep_stale_patch_files has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/cache_gc.rs"},"region":{"startLine":632}}}],"partialFingerprints":{"codehealthFindingId/v1":"d9ffad41fc2809008fe8e6a62a6c018fec2d752c15b1142b5d9fcd9055413ae9"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::schema::strip_null_acceptance (cognitive 51): prek::schema::strip_null_acceptance has cognitive complexity 51 (threshold 15). Drivers by points: if/else 15 (34 pts), loops 3 (8 pts), match/switch 3 (7 pts), boolean chains 2 (nesting depth added 28). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/schema.rs"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"b92aed6fdd5656b866602ffaa1c685d0ae202f684db878d9f37d19b9a042c8f9"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::cli::update::display::apply_repo_updates (cognitive 41): prek::cli::update::display::apply_repo_updates has cognitive complexity 41 (threshold 15). Drivers by points: loops 6 (21 pts), if/else 4 (11 pts), match/switch 2 (7 pts), boolean chains 2 (nesting depth added 27). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/update/display.rs"},"region":{"startLine":201}}}],"partialFingerprints":{"codehealthFindingId/v1":"2f7c78e414cca88b0b440ec4a6301d742d0587e6192002523df68a5da0b636d8"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::cli::update::display::write_display_events (cognitive 36): prek::cli::update::display::write_display_events has cognitive complexity 36 (threshold 15). Drivers by points: if/else 12 (30 pts), loops 2 (3 pts), match/switch 1 (2 pts), boolean chains 1 (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/update/display.rs"},"region":{"startLine":114}}}],"partialFingerprints":{"codehealthFindingId/v1":"807981b0d6d7a8385433fb0ab7c3c91f930a99bb381f837906710d990e2cc2d9"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::hooks::pre_commit_hooks::check_merge_conflict::check_file (cognitive 35): prek::hooks::pre_commit_hooks::check_merge_conflict::check_file has cognitive complexity 35 (threshold 15). Drivers by points: if/else 12 (23 pts), boolean chains 6, loops 2 (4 pts), match/switch 1 (2 pts) (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hooks/pre_commit_hooks/check_merge_conflict.rs"},"region":{"startLine":63}}}],"partialFingerprints":{"codehealthFindingId/v1":"b39f44fc49c9905747c39859d69a454e51b346a53fbb5db3b44b29a527387173"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::cli::cache_gc::sweep_dir_by_name (cognitive 34): prek::cli::cache_gc::sweep_dir_by_name has cognitive complexity 34 (threshold 15). Drivers by points: if/else 13 (29 pts), match/switch 2 (3 pts), boolean chains 1, loops 1 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/cache_gc.rs"},"region":{"startLine":546}}}],"partialFingerprints":{"codehealthFindingId/v1":"5595f4f6d7e9c0e17752d3d4960026babde8ab370d05002e25c01dd1a64919e0"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::cli::cache_gc::cache_gc (cognitive 32): prek::cli::cache_gc::cache_gc has cognitive complexity 32 (threshold 15). Drivers by points: if/else 12 (21 pts), loops 4 (5 pts), match/switch 2 (5 pts), boolean chains 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/cache_gc.rs"},"region":{"startLine":145}}}],"partialFingerprints":{"codehealthFindingId/v1":"20b9eac9bfb3cb19d81056ebc5f7607c579dfa9dd22ba276d6fff23dfa181cd4"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::cli::install::install_hook_script (cognitive 31): prek::cli::install::install_hook_script has cognitive complexity 31 (threshold 15). Drivers by points: if/else 17 (27 pts), loops 2 (4 pts) (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/install.rs"},"region":{"startLine":220}}}],"partialFingerprints":{"codehealthFindingId/v1":"9afd60708b286d5012025bcc84ef527b0a9b6d4035c13386ea8bb31bfaa3e4f1"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::archive::unzip (cognitive 31): prek::archive::unzip has cognitive complexity 31 (threshold 15). Drivers by points: if/else 12 (26 pts), loops 3, match/switch 1 (2 pts) (nesting depth added 15). Of this number, 27 points are the body\u0027s own statements and 4 belong to one function item inside it that branches. This file\u0027s own header attributes it to another copyright holder, so it is code this repository carries rather than code it wrote: restructuring the body in place forks it from upstream and turns every future re-sync into a manual merge. The performable moves are to leave the body as close to its upstream form as possible and keep it behind a narrow interface of your own, and to re-sync it when upstream changes \u2014 or, if it has already diverged far enough that you maintain it here, adopt it deliberately and then split the body into named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/archive.rs"},"region":{"startLine":148}}}],"partialFingerprints":{"codehealthFindingId/v1":"b9d0ea10c086f1a8f6565988b85f1360d80e992eeb3d8a1c52e031a87f2858af"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::cli::cache_gc::sweep_stale_patch_files (cognitive 28): prek::cli::cache_gc::sweep_stale_patch_files has cognitive complexity 28 (threshold 15). Drivers by points: if/else 10 (21 pts), match/switch 3 (5 pts), boolean chains 1, loops 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/cache_gc.rs"},"region":{"startLine":632}}}],"partialFingerprints":{"codehealthFindingId/v1":"b907ccb4577561d309f161a665c9491aeef0d69baad4acb0be268d58a8fbd09e"}},{"ruleId":"D2","level":"warning","message":{"text":"HookOptions::update (cognitive 27): HookOptions::update has cognitive complexity 27 (threshold 15). Drivers by points: if/else 25 (27 pts) (nesting depth added 2). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/config/hook.rs"},"region":{"startLine":532}}}],"partialFingerprints":{"codehealthFindingId/v1":"6f007ba89a855df81510dcc0dd6f7db1de35a70784255928a77b6f982bfacb65"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::cli::cache_gc::hook_env_requirements_from_config (cognitive 27): prek::cli::cache_gc::hook_env_requirements_from_config has cognitive complexity 27 (threshold 15). Drivers by points: match/switch 4 (13 pts), if/else 2 (7 pts), loops 3 (7 pts) (nesting depth added 18). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/cache_gc.rs"},"region":{"startLine":360}}}],"partialFingerprints":{"codehealthFindingId/v1":"1cd82955f583859090522135b531bf8a8d693b91c42c931559659ba5a9af9958"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::cli::cache_gc::sweep_tool_bucket_versions (cognitive 26): prek::cli::cache_gc::sweep_tool_bucket_versions has cognitive complexity 26 (threshold 15). Drivers by points: if/else 11 (22 pts), match/switch 2 (3 pts), loops 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/cache_gc.rs"},"region":{"startLine":470}}}],"partialFingerprints":{"codehealthFindingId/v1":"5a1f86749533be29b633ea9129501da2654a119a81d0be5ebd61f66de2069b53"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::languages::golang::gomod::parse_go_mod_directives (cognitive 26): prek::languages::golang::gomod::parse_go_mod_directives has cognitive complexity 26 (threshold 15). Drivers by points: if/else 9 (23 pts), boolean chains 2, loops 1 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/golang/gomod.rs"},"region":{"startLine":11}}}],"partialFingerprints":{"codehealthFindingId/v1":"a12838ded0e9c8f9efae5926e010900b7c1e208cd617af5ecc3df6dd3a233a52"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::languages::rust::rust::install_local_project (cognitive 25): prek::languages::rust::rust::install_local_project has cognitive complexity 25 (threshold 15). Drivers by points: if/else 8 (16 pts), loops 3 (7 pts), boolean chains 1, match/switch 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/rust/rust.rs"},"region":{"startLine":267}}}],"partialFingerprints":{"codehealthFindingId/v1":"fb9b69270ae4f30d3098c286cac3b70f510fc7ad2af96ed4e3d850ab1a8f5bb9"}},{"ruleId":"D2","level":"warning","message":{"text":"ProjectFiles::visit_for_project (cognitive 24): ProjectFiles::visit_for_project has cognitive complexity 24 (threshold 15). Drivers by points: if/else 9 (21 pts), boolean chains 2, loops 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/run/filter.rs"},"region":{"startLine":218}}}],"partialFingerprints":{"codehealthFindingId/v1":"976cb51ac45fe6ea5e891cdee8988d73bfbf99847a4d6fb813655e48653aee7e"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::cli::hook_impl::hook_impl (cognitive 24): prek::cli::hook_impl::hook_impl has cognitive complexity 24 (threshold 15). Drivers by points: if/else 13 (20 pts), boolean chains 2, match/switch 1 (2 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/hook_impl.rs"},"region":{"startLine":25}}}],"partialFingerprints":{"codehealthFindingId/v1":"2301966549111ecf8cf346e45c206b71d447fb290d8279d31c60463070882a26"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::run (cognitive 24): prek::run has cognitive complexity 24 (threshold 15). Drivers by points: if/else 12 (15 pts), match/switch 5 (7 pts), boolean chains 2 (nesting depth added 5). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/main.rs"},"region":{"startLine":154}}}],"partialFingerprints":{"codehealthFindingId/v1":"f728adc5f167eb7d2d8052e353809d4f957b6eaa8f61b240850554d20f444b2c"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::hooks::meta_hooks::check_useless_excludes (cognitive 24): prek::hooks::meta_hooks::check_useless_excludes has cognitive complexity 24 (threshold 15). Drivers by points: if/else 7 (16 pts), loops 4 (7 pts), boolean chains 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hooks/meta_hooks.rs"},"region":{"startLine":242}}}],"partialFingerprints":{"codehealthFindingId/v1":"c95ceb731a1e168abc39717cd82ab78804fc496bcd88da465c423e2723d4a1b3"}},{"ruleId":"D2","level":"warning","message":{"text":"HookRunSession::render_priority_group (cognitive 23): HookRunSession::render_priority_group has cognitive complexity 23 (threshold 15). Drivers by points: if/else 11 (17 pts), boolean chains 3, loops 2 (3 pts) (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/run/run.rs"},"region":{"startLine":967}}}],"partialFingerprints":{"codehealthFindingId/v1":"fac5799aa6057e35fe140272557e89fec20042b92025c924aa090fb7b798ec8e"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::hooks::meta_hooks::check_hooks_apply (cognitive 23): prek::hooks::meta_hooks::check_hooks_apply has cognitive complexity 23 (threshold 15). Drivers by points: if/else 7 (16 pts), loops 3 (5 pts), boolean chains 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hooks/meta_hooks.rs"},"region":{"startLine":108}}}],"partialFingerprints":{"codehealthFindingId/v1":"9ef9a1eb52d5113fde87610983c115d8340fadd35062dfd90d1c192f8fe3e340"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::cli::run::run::run (cognitive 23): prek::cli::run::run::run has cognitive complexity 23 (threshold 15). Drivers by points: if/else 15 (18 pts), boolean chains 2, match/switch 1 (2 pts), loops 1 (nesting depth added 4). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/run/run.rs"},"region":{"startLine":77}}}],"partialFingerprints":{"codehealthFindingId/v1":"fd02ec196ae6de4fce3ebc2eece7f370e0dfe11b0b1d0046c93b59176d474dd9"}},{"ruleId":"D2","level":"warning","message":{"text":"Repo::deserialize (cognitive 21): Repo::deserialize has cognitive complexity 21 (threshold 15). Drivers by points: match/switch 7 (14 pts), if/else 3 (6 pts), loops 1 (nesting depth added 10). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/config/repo.rs"},"region":{"startLine":236}}}],"partialFingerprints":{"codehealthFindingId/v1":"53c44f9646def0469cfa3fa3df9d8244613f815b71a617f3e61f6bc127a9bccd"}},{"ruleId":"D2","level":"warning","message":{"text":"Project::build_hooks (cognitive 21): Project::build_hooks has cognitive complexity 21 (threshold 15). Drivers by points: loops 5 (13 pts), if/else 1 (4 pts), match/switch 2 (4 pts) (nesting depth added 13). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/workspace.rs"},"region":{"startLine":373}}}],"partialFingerprints":{"codehealthFindingId/v1":"dcc28fb8bee172ee0336e25736246efe64622e9fd9bec499e21b38eeab37583b"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::cli::run::run::select_runnable_env_hooks (cognitive 21): prek::cli::run::run::select_runnable_env_hooks has cognitive complexity 21 (threshold 15). Drivers by points: if/else 4 (12 pts), loops 3 (5 pts), boolean chains 2, match/switch 1 (2 pts) (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/run/run.rs"},"region":{"startLine":419}}}],"partialFingerprints":{"codehealthFindingId/v1":"60d76d0269bc5aaa6bd3183ddc3d103ae4ce00f014449ae94b2edea2da71feaf"}},{"ruleId":"D2","level":"warning","message":{"text":"HookRunSession::render_hook_details (cognitive 20): HookRunSession::render_hook_details has cognitive complexity 20 (threshold 15). Drivers by points: if/else 14 (15 pts), boolean chains 4, loops 1 (nesting depth added 1). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/run/run.rs"},"region":{"startLine":1040}}}],"partialFingerprints":{"codehealthFindingId/v1":"9ccf4383f09c4ec40a2588259c948cf1ac5b6153e55f8beda6869a2ca71832ec"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::cli::list::list (cognitive 20): prek::cli::list::list has cognitive complexity 20 (threshold 15). Drivers by points: if/else 4 (11 pts), loops 2 (6 pts), boolean chains 2, match/switch 1 (nesting depth added 11). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/list.rs"},"region":{"startLine":28}}}],"partialFingerprints":{"codehealthFindingId/v1":"2fab6c28f2da63c555e801e6698936e2058c45783425c967f85fb9a58450f7dd"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::cli::install::uninstall (cognitive 19): prek::cli::install::uninstall has cognitive complexity 19 (threshold 15). Drivers by points: if/else 9 (15 pts), match/switch 1 (2 pts), boolean chains 1, loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/install.rs"},"region":{"startLine":402}}}],"partialFingerprints":{"codehealthFindingId/v1":"7e9d86ca2871bce8df45aaf24bcbd0727aa2220d9bb5af1cce42e73e354b6f2d"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::cli::self_update::self_update (cognitive 19): prek::cli::self_update::self_update has cognitive complexity 19 (threshold 15). Drivers by points: if/else 13 (17 pts), boolean chains 1, match/switch 1 (nesting depth added 4). This file\u0027s own header attributes it to another copyright holder, so it is code this repository carries rather than code it wrote: restructuring the body in place forks it from upstream and turns every future re-sync into a manual merge. The performable moves are to leave the body as close to its upstream form as possible and keep it behind a narrow interface of your own, and to re-sync it when upstream changes \u2014 or, if it has already diverged far enough that you maintain it here, adopt it deliberately and then split the body into named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/self_update.rs"},"region":{"startLine":53}}}],"partialFingerprints":{"codehealthFindingId/v1":"0947fb314337b431ba0b63b6b85eacf9b776edc2b54dc7f61a9a383a0ea80066"}},{"ruleId":"D2","level":"warning","message":{"text":"ParsedRequirements::parse (cognitive 18): ParsedRequirements::parse has cognitive complexity 18 (threshold 15). Drivers by points: if/else 7 (13 pts), boolean chains 3, loops 1, match/switch 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hooks/pre_commit_hooks/requirements_txt_fixer.rs"},"region":{"startLine":112}}}],"partialFingerprints":{"codehealthFindingId/v1":"2fc872ca22a1faf7cc6ee5d93ae4dad05588e57b06b85638045f1807aa85a31a"}},{"ruleId":"D2","level":"warning","message":{"text":"CargoCliDependency::from_str (cognitive 18): CargoCliDependency::from_str has cognitive complexity 18 (threshold 15). Drivers by points: if/else 8 (15 pts), match/switch 1 (2 pts), boolean chains 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/rust/rust.rs"},"region":{"startLine":51}}}],"partialFingerprints":{"codehealthFindingId/v1":"1fd785af8e1d5e49a1cc1557330acc3691e189913f1f9bf950265cacaf651f8c"}},{"ruleId":"D2","level":"warning","message":{"text":"Store::clone_repos (cognitive 18): Store::clone_repos has cognitive complexity 18 (threshold 15). Drivers by points: if/else 6 (12 pts), loops 3, match/switch 2 (3 pts) (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/store.rs"},"region":{"startLine":156}}}],"partialFingerprints":{"codehealthFindingId/v1":"eb257ec8b020820595c3d44b7bd6d41b3de3de66bb651d1902c5de095631ad6d"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::hooks::pre_commit_hooks::fix_trailing_whitespace::fix_file (cognitive 18): prek::hooks::pre_commit_hooks::fix_trailing_whitespace::fix_file has cognitive complexity 18 (threshold 15). Drivers by points: if/else 9 (15 pts), boolean chains 2, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hooks/pre_commit_hooks/fix_trailing_whitespace.rs"},"region":{"startLine":94}}}],"partialFingerprints":{"codehealthFindingId/v1":"5587beae13b2abd08a3108a8a8d1d436fa4ded70656d56db31e448ddc8070c55"}},{"ruleId":"D2","level":"warning","message":{"text":"SelectorCompleter::project_candidates (cognitive 17): SelectorCompleter::project_candidates has cognitive complexity 17 (threshold 15). Drivers by points: if/else 8 (14 pts), loops 2, boolean chains 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/completion.rs"},"region":{"startLine":143}}}],"partialFingerprints":{"codehealthFindingId/v1":"d829a404f05f837ae060fd34d7da87a5c5428ec28f88956591ed16906baf3c9b"}},{"ruleId":"D2","level":"warning","message":{"text":"Selectors::matches_path (cognitive 17): Selectors::matches_path has cognitive complexity 17 (threshold 15). Drivers by points: if/else 6 (13 pts), loops 2, match/switch 1 (2 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/run/selector.rs"},"region":{"startLine":384}}}],"partialFingerprints":{"codehealthFindingId/v1":"53f0fa107a29a24dab4471ce365847c86b52499e169a80283822615e739036f2"}},{"ruleId":"D2","level":"warning","message":{"text":"prek::cli::hook_impl::parse_pre_push_info (cognitive 17): prek::cli::hook_impl::parse_pre_push_info has cognitive complexity 17 (threshold 15). Drivers by points: if/else 7 (15 pts), boolean chains 1, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/hook_impl.rs"},"region":{"startLine":301}}}],"partialFingerprints":{"codehealthFindingId/v1":"fa3d45a32ebbb93f5645700e021282901d008c2ebfcad237960273e385aaaabc"}},{"ruleId":"D2","level":"warning","message":{"text":"Workspace::discover (cognitive 16): Workspace::discover has cognitive complexity 16 (threshold 15). Drivers by points: if/else 10 (12 pts), match/switch 2 (4 pts) (nesting depth added 4). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/workspace.rs"},"region":{"startLine":644}}}],"partialFingerprints":{"codehealthFindingId/v1":"d96a63b472c700f9715ca60fb49db599c9f7cc9a7b533529db5e75dd4e96c527"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: BuiltinHook.from_id: MethodTooLong \u2014 from_id runs 324 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 224 over it, 3.24\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hooks/builtin_hooks/mod.rs"},"region":{"startLine":159}}}],"partialFingerprints":{"codehealthFindingId/v1":"67893260249b9a2725f24341a6ed44949517716bfb64715341e44b8e8f3ce39b"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: prek::run: FunctionTooLong \u2014 prek::run runs 237 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 137 over it, 2.37\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/main.rs"},"region":{"startLine":154}}}],"partialFingerprints":{"codehealthFindingId/v1":"2efb9e14540a34f3b55b9917037f16b358bd6c68a49d1f0586d412457b3bc32d"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: run/run.rs: FileTooLong \u2014 1134 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 634 over it, 2.27\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/run/run.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"8874e6d3316361f428bb990d7acecf061fe9e8db72f4b809ac4b981b51f98bca"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/git.rs: FileTooLong \u2014 800 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), declaring 49 free functions. The bar is 500 significant lines; this is 300 over it, 1.60\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/git.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"906a457ff9059563982f4e6e8e45cc2f4ea08c71776db3436a1d5137df23f58f"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: prek::cli::run::run::run: FunctionTooLong \u2014 prek::cli::run::run::run runs 154 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 54 over it, 1.54\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/run/run.rs"},"region":{"startLine":77}}}],"partialFingerprints":{"codehealthFindingId/v1":"86f72901b59f9944b89cc57fcb4873f09a797ffd3d61d7bf5bceef506b0ea6d3"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: cli/mod.rs: FileTooLong \u2014 638 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 138 over it, 1.28\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/mod.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee0c3c77508378fa53730f803db8437fff7cf181f6c5c75a527023e58b30c75e"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Cmd: TooManyMethods \u2014 38 methods. The bar is 30 methods; this is 8 over it, 1.27\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/process.rs"},"region":{"startLine":128}}}],"partialFingerprints":{"codehealthFindingId/v1":"3f2ac0c5ab66ce63d3e82cc2429299b2f47f3e9e352a1bee9ae720154c4f8312"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: prek::cli::cache_gc::cache_gc: FunctionTooLong \u2014 prek::cli::cache_gc::cache_gc runs 125 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 25 over it, 1.25\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/cache_gc.rs"},"region":{"startLine":145}}}],"partialFingerprints":{"codehealthFindingId/v1":"af744c6310c429c65bc0ba762986d14476b2abe9f1424d4337846f74c00d7441"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: prek::cli::update::display::apply_repo_updates: FunctionTooLong \u2014 prek::cli::update::display::apply_repo_updates runs 125 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 25 over it, 1.25\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/update/display.rs"},"region":{"startLine":201}}}],"partialFingerprints":{"codehealthFindingId/v1":"be6f505e3735f2b7aa2f46b3da49d17c6ce814ab601a29ecf2d7dcb9d1e08006"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: config/hook.rs: FileTooLong \u2014 624 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 124 over it, 1.25\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/config/hook.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"96088d03a4efb6e9f932015e527fb45eadb2365ff44ec47ae747ffb1b5c0c81d"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/workspace.rs: FileTooLong \u2014 574 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 74 over it, 1.15\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/workspace.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e561a17176b7d6f71dbacc060a0a2bf81e0862567a22e56572cc09abf827c003"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/hook.rs: FileTooLong \u2014 551 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 51 over it, 1.10\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hook.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"92ce2cb71876f12a4a693faff7d0c256865f11a415b0d7b8b1803bc01970f993"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: run/selector.rs: FileTooLong \u2014 545 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 45 over it, 1.09\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/run/selector.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1e20d277c6a364ce8e0f3135fe3c5aa13efa865bcce23d4c51d43417b850f53f"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: languages/mod.rs: FileTooLong \u2014 536 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 36 over it, 1.07\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/mod.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"73d943d0adf3f6e2859c3d4d837f6c107f7cded24055743780f666f5ec25229a"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: cli/cache_gc.rs: FileTooLong \u2014 532 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 32 over it, 1.06\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/cache_gc.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"54b89cce54da0c2e79a3ef1619d18be06a395b0c37e4455500cd574a949e8a2f"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: run/reporter.rs: FileTooLong \u2014 501 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 1 over it, 1.00\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/run/reporter.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"6381058dd99805fd3e3f779e09bad165e58e10ce1e78f042254814b54fe60ba8"}},{"ruleId":"D4","level":"warning","message":{"text":"Members sharing a duplicated core (6 members, 50\u002B identical tokens): crates/prek/src/languages/bun/installer.rs:114-144 | crates/prek/src/languages/deno/installer.rs:126-156 | crates/prek/src/languages/dotnet/installer.rs:120-150 | crates/prek/src/languages/golang/installer.rs:153-185 | crates/prek/src/languages/mise/installer.rs:142-182 | crates/prek/src/languages/node/installer.rs:146-176 \u2014 These 6 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below \u2014 it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 6 times. The repair is at the members\u0027 grain \u2014 factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 6 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/bun/installer.rs"},"region":{"startLine":114}}}],"partialFingerprints":{"codehealthFindingId/v1":"5fe881d4985cb9cd6488fd91f1236c297a62028cd1b4c84859ea23e46fbc34a6"}},{"ruleId":"D4","level":"warning","message":{"text":"Members sharing a duplicated core (4 members, 50\u002B identical tokens): crates/prek/src/languages/docker.rs:446-492 | crates/prek/src/languages/docker_image.rs:40-74 | crates/prek/src/languages/julia.rs:107-145 | crates/prek/src/languages/mod.rs:122-148 \u2014 These 4 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below \u2014 it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 4 times. The repair is at the members\u0027 grain \u2014 factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 4 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/docker.rs"},"region":{"startLine":446}}}],"partialFingerprints":{"codehealthFindingId/v1":"c852fde641a3049dc1aa3c10771336f663a0fb81e081f80ae998ee5f1e8a8202"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (20 lines \u00D7 2): crates/prek/src/languages/rust/rustup.rs:194-213 | crates/prek/src/languages/rust/rustup.rs:227-246 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/rust/rustup.rs"},"region":{"startLine":194}}}],"partialFingerprints":{"codehealthFindingId/v1":"797d907e1e82f332337f5077c87df5b0159c837feff61f6e07bfd373b87f9088"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15\u201316 lines \u00D7 2): crates/prek/src/cli/cache_gc.rs:492-507 | crates/prek/src/cli/cache_gc.rs:565-579 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/cache_gc.rs"},"region":{"startLine":492}}}],"partialFingerprints":{"codehealthFindingId/v1":"4fd2d208639d85750ecc1f9a57a03554aa87e3fad61adda1c9ef646283e4d5b9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): crates/prek/src/config/hook.rs:867-882 | crates/prek/src/config/hook.rs:929-944 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/config/hook.rs"},"region":{"startLine":867}}}],"partialFingerprints":{"codehealthFindingId/v1":"929de16630af790c0cb0a3c5d0dc5062aaceac99b557443b639d1a4503580f44"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): crates/prek/src/cli/validate.rs:24-39 | crates/prek/src/cli/validate.rs:58-73 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/validate.rs"},"region":{"startLine":24}}}],"partialFingerprints":{"codehealthFindingId/v1":"84f635b14588e7b3139b70323777f4fd4210ef2bf5a561f2cee8af4368c749e6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): crates/prek/src/cli/run/selector.rs:359-373 | crates/prek/src/cli/run/selector.rs:391-408 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/run/selector.rs"},"region":{"startLine":359}}}],"partialFingerprints":{"codehealthFindingId/v1":"1d7073cd7a02005e89765dd1b0ff41897932d50392aa5d21adb9be672ebb787b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10\u201314 lines \u00D7 2): crates/prek/src/hooks/meta_hooks.rs:113-122 | crates/prek/src/hooks/meta_hooks.rs:243-256 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hooks/meta_hooks.rs"},"region":{"startLine":113}}}],"partialFingerprints":{"codehealthFindingId/v1":"232c06ecf9c8ff7cb432b5cc93db21393a8f0c41f92ca46f452245e5055c80c5"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 4): crates/prek/src/languages/docker.rs:480-492 | crates/prek/src/languages/docker_image.rs:62-74 | crates/prek/src/languages/julia.rs:133-145 | crates/prek/src/languages/mod.rs:136-148 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from all 4 call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/docker.rs"},"region":{"startLine":480}}}],"partialFingerprints":{"codehealthFindingId/v1":"95b8deb203d564569aec5816ee3b54c6ba0066ceaac6dfb060fedda8bbe59088"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 5): crates/prek/src/languages/bun/installer.rs:115-125 | crates/prek/src/languages/deno/installer.rs:127-137 | crates/prek/src/languages/dotnet/installer.rs:121-131 | crates/prek/src/languages/golang/installer.rs:154-164 | crates/prek/src/languages/node/installer.rs:147-157 \u2014 \u0060crates/prek/src/languages/bun/installer.rs\u0060 and \u0060crates/prek/src/languages/deno/installer.rs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 5 separate duplicated blocks between them, totalling at least 42 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/bun/installer.rs"},"region":{"startLine":115}}}],"partialFingerprints":{"codehealthFindingId/v1":"2ee694daf69232bdc04c08152d835ceb171f6dff237093ea93d2ca2ec1a889fa"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/prek/src/languages/python/uv.rs:618-628 | crates/prek/src/languages/python/uv.rs:645-655 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/python/uv.rs"},"region":{"startLine":618}}}],"partialFingerprints":{"codehealthFindingId/v1":"e82e5df5d91d6ed1a9cc1d01495833b5fa710908bedc4b5ef179442776c3e768"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/prek/src/config/hook.rs:673-682 | crates/prek/src/config/hook.rs:781-790 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/config/hook.rs"},"region":{"startLine":673}}}],"partialFingerprints":{"codehealthFindingId/v1":"02fe9de2f7878b3c68ffbcc7c220fd7e624674ab856b47cee174e98c7846d08d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9\u201310 lines \u00D7 2): crates/prek/src/hooks/pre_commit_hooks/check_json.rs:25-33 | crates/prek/src/hooks/pre_commit_hooks/check_toml.rs:23-32 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hooks/pre_commit_hooks/check_json.rs"},"region":{"startLine":25}}}],"partialFingerprints":{"codehealthFindingId/v1":"61638979612f5b1d01606fbfaa74b60ae7384f9f0a5d4e7517ff2e64d68574f5"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/prek/src/languages/bun/installer.rs:208-217 | crates/prek/src/languages/node/installer.rs:229-238 \u2014 \u0060crates/prek/src/languages/bun/installer.rs\u0060 and \u0060crates/prek/src/languages/node/installer.rs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 7 separate duplicated blocks between them, totalling at least 64 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/bun/installer.rs"},"region":{"startLine":208}}}],"partialFingerprints":{"codehealthFindingId/v1":"e887ee270bdf1226d3aacc046970dcec7b4fcaa63a1e1c49b7691ff9f5fa755b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/prek/src/languages/bun/version.rs:105-114 | crates/prek/src/languages/deno/version.rs:109-118 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/bun/version.rs"},"region":{"startLine":105}}}],"partialFingerprints":{"codehealthFindingId/v1":"1a73850e06aae75c8d6edb2a957397be25f79b444a40ccc3c92538ddb2d202e4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/prek/src/hooks/builtin_hooks/mod.rs:112-119 | crates/prek/src/hooks/pre_commit_hooks/mod.rs:166-173 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hooks/builtin_hooks/mod.rs"},"region":{"startLine":112}}}],"partialFingerprints":{"codehealthFindingId/v1":"f65362367c641f35d37230b89387fec09c647c807b98347fd2657f2983e05e6d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/prek/src/languages/docker.rs:447-454 | crates/prek/src/languages/docker_image.rs:41-48 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/docker.rs"},"region":{"startLine":447}}}],"partialFingerprints":{"codehealthFindingId/v1":"a8371c66f6458e90f96c68478716c46cbb4d6ac81dbd788ed5139982f2e7864d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6\u20138 lines \u00D7 2): crates/prek/src/languages/docker.rs:463-470 | crates/prek/src/languages/docker_image.rs:50-55 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/docker.rs"},"region":{"startLine":463}}}],"partialFingerprints":{"codehealthFindingId/v1":"231a656f39fd288ccc396ada82d44aeed20ba704233db7e42fca327fbddfaccf"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 4): crates/prek/src/languages/bun/installer.rs:130-136 | crates/prek/src/languages/deno/installer.rs:142-148 | crates/prek/src/languages/dotnet/installer.rs:136-142 | crates/prek/src/languages/golang/installer.rs:169-175 \u2014 \u0060crates/prek/src/languages/bun/installer.rs\u0060 and \u0060crates/prek/src/languages/deno/installer.rs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 5 separate duplicated blocks between them, totalling at least 42 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/bun/installer.rs"},"region":{"startLine":130}}}],"partialFingerprints":{"codehealthFindingId/v1":"ffde09759faf1a005da92171d88b4fab21d2c6e1d77d4a95f1bd9dd2a31e96ee"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): crates/prek/src/hooks/pre_commit_hooks/check_executables_have_shebangs.rs:19-23 | crates/prek/src/hooks/pre_commit_hooks/check_shebang_scripts_are_executable.rs:18-22 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hooks/pre_commit_hooks/check_executables_have_shebangs.rs"},"region":{"startLine":19}}}],"partialFingerprints":{"codehealthFindingId/v1":"6f61f07fb9886de8c58087a42a0f9b08e0a6d56283ee7b2ed3917e8af59a5a5c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): crates/prek-pty/src/pty.rs:336-340 | crates/prek-pty/src/pty.rs:352-356 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek-pty/src/pty.rs"},"region":{"startLine":336}}}],"partialFingerprints":{"codehealthFindingId/v1":"cf8a2e507971a3a25a390fcf7831fc061301190287ebb2dee913a7088c5563a2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 4): crates/prek/src/hooks/pre_commit_hooks/check_json.rs:13-22 | crates/prek/src/hooks/pre_commit_hooks/check_toml.rs:11-20 | crates/prek/src/hooks/pre_commit_hooks/check_xml.rs:11-20 | crates/prek/src/hooks/pre_commit_hooks/detect_private_key.rs:45-54 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from all 4 call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hooks/pre_commit_hooks/check_json.rs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"5533e654f52526561eaf06dc4fa21afad6b1f304521fa68ac6446028b16d352a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 3): crates/prek/src/hooks/pre_commit_hooks/fix_byte_order_marker.rs:13-22 | crates/prek/src/hooks/pre_commit_hooks/fix_end_of_file.rs:11-20 | crates/prek/src/hooks/pre_commit_hooks/requirements_txt_fixer.rs:192-202 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from all 3 call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hooks/pre_commit_hooks/fix_byte_order_marker.rs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"6eff77833fbc2c499f044212371c03b0e6c762eedbaf178c3e2a8d6bf0c1c2a6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/prek/src/languages/bun/installer.rs:146-157 | crates/prek/src/languages/node/installer.rs:178-189 \u2014 \u0060crates/prek/src/languages/bun/installer.rs\u0060 and \u0060crates/prek/src/languages/node/installer.rs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 7 separate duplicated blocks between them, totalling at least 64 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/bun/installer.rs"},"region":{"startLine":146}}}],"partialFingerprints":{"codehealthFindingId/v1":"a8ced07a716315cd3d682c5c05804ed076b749a29825aa16754b220da4acf7b8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/prek/src/languages/bun/installer.rs:283-289 | crates/prek/src/languages/node/installer.rs:334-340 \u2014 \u0060crates/prek/src/languages/bun/installer.rs\u0060 and \u0060crates/prek/src/languages/node/installer.rs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 7 separate duplicated blocks between them, totalling at least 64 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/bun/installer.rs"},"region":{"startLine":283}}}],"partialFingerprints":{"codehealthFindingId/v1":"c720f566a8bb2fe5ea311b19d79e843186fb94be4058d4ada94300be176df031"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): crates/prek/src/languages/mod.rs:91-96 | crates/prek/src/languages/script.rs:37-45 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/mod.rs"},"region":{"startLine":91}}}],"partialFingerprints":{"codehealthFindingId/v1":"d980e39d431321360f2fae59074a514128969c1ebc3bc11ab96a4f53563e6a1c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/prek/src/git.rs:771-781 | crates/prek/src/git.rs:801-811 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/git.rs"},"region":{"startLine":771}}}],"partialFingerprints":{"codehealthFindingId/v1":"a2b101ffc721c3389e708eb916ca4d70f7e57553af2d0cd87fa10b66d9dc4d26"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/prek/src/cli/cache_gc.rs:534-544 | crates/prek/src/cli/cache_gc.rs:696-706 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/cache_gc.rs"},"region":{"startLine":534}}}],"partialFingerprints":{"codehealthFindingId/v1":"4af4303afb25f8bdbaf846f23527a080b04c6808f869b4e66183dd79cd3b700c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/prek/src/cli/self_update.rs:74-81 | crates/prek/src/cli/self_update.rs:89-99 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/self_update.rs"},"region":{"startLine":74}}}],"partialFingerprints":{"codehealthFindingId/v1":"ba2dc0d5321610c323463fe87e6c6793035254e5acd9d24bc12b444b89713af0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/prek/src/cli/cache_gc.rs:527-535 | crates/prek/src/cli/cache_gc.rs:610-619 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/cache_gc.rs"},"region":{"startLine":527}}}],"partialFingerprints":{"codehealthFindingId/v1":"6a5a3f1ba6d8b65a59b5087a2b5bb9b4dfb39749c00c9a099265f277c0a4b298"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 6): crates/prek/src/languages/bun/installer.rs:116-125 | crates/prek/src/languages/deno/installer.rs:128-137 | crates/prek/src/languages/dotnet/installer.rs:122-131 | crates/prek/src/languages/golang/installer.rs:155-164 | crates/prek/src/languages/mise/installer.rs:144-153 | crates/prek/src/languages/node/installer.rs:148-157 \u2014 \u0060crates/prek/src/languages/bun/installer.rs\u0060 and \u0060crates/prek/src/languages/deno/installer.rs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 5 separate duplicated blocks between them, totalling at least 42 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/bun/installer.rs"},"region":{"startLine":116}}}],"partialFingerprints":{"codehealthFindingId/v1":"49795e19fa984a0a0a89f35cceaa578f4aa404c6b730837c1e8170a0b14dc45b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/prek/src/languages/golang/installer.rs:214-222 | crates/prek/src/languages/node/installer.rs:206-214 \u2014 \u0060crates/prek/src/languages/golang/installer.rs\u0060 and \u0060crates/prek/src/languages/node/installer.rs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 4 separate duplicated blocks between them, totalling at least 36 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/golang/installer.rs"},"region":{"startLine":214}}}],"partialFingerprints":{"codehealthFindingId/v1":"b232d087e27e6b4cb3f095c72179d4d5581b5b061bd2804063a54095b5738ba0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 4): crates/prek/src/languages/bun/installer.rs:211-218 | crates/prek/src/languages/mise/installer.rs:234-241 | crates/prek/src/languages/node/installer.rs:232-239 | crates/prek/src/languages/python/uv.rs:342-349 \u2014 \u0060crates/prek/src/languages/bun/installer.rs\u0060 and \u0060crates/prek/src/languages/node/installer.rs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 7 separate duplicated blocks between them, totalling at least 64 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/bun/installer.rs"},"region":{"startLine":211}}}],"partialFingerprints":{"codehealthFindingId/v1":"97ffc0a07fc99eea2456f81ed2299f8d1f8e151320721050401850addb8bbe6e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/prek/src/languages/dotnet/installer.rs:275-282 | crates/prek/src/languages/dotnet/installer.rs:308-315 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/dotnet/installer.rs"},"region":{"startLine":275}}}],"partialFingerprints":{"codehealthFindingId/v1":"fbcbb36d7716b0603541d9d64f8cf4c5d30b0b4ee79a718520588d53b613b738"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): crates/prek/src/languages/bun/installer.rs:207-214 | crates/prek/src/languages/deno/installer.rs:216-221 \u2014 \u0060crates/prek/src/languages/bun/installer.rs\u0060 and \u0060crates/prek/src/languages/deno/installer.rs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 5 separate duplicated blocks between them, totalling at least 42 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/bun/installer.rs"},"region":{"startLine":207}}}],"partialFingerprints":{"codehealthFindingId/v1":"c234c0ee69336aba109b084387e99d36d4f9feeee34dcc3cf0008ca333774b7b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): crates/prek/src/cli/sample_config.rs:95-99 | crates/prek/src/cli/yaml_to_toml.rs:84-91 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/sample_config.rs"},"region":{"startLine":95}}}],"partialFingerprints":{"codehealthFindingId/v1":"504aa830ef9f663175888a3ffa4fa3dd2f90e1e1212bd1aa5b3d21695ac2128c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/prek/src/languages/python/uv.rs:592-598 | crates/prek/src/languages/python/uv.rs:618-624 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/python/uv.rs"},"region":{"startLine":592}}}],"partialFingerprints":{"codehealthFindingId/v1":"685b3bd78b0ad3752793b9bcf4053a30466bc83777734ec90a8b76dd8c416393"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 3): crates/prek/src/languages/bun/bun.rs:46-51 | crates/prek/src/languages/mise/mise.rs:86-91 | crates/prek/src/languages/ruby/ruby.rs:38-44 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 3 call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made 3 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/bun/bun.rs"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"e7c94e3185ec4fb617ffb37eebf7a91559102ce34a1fc707867e51943c8f0e02"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): crates/prek/src/languages/bun/bun.rs:48-53 | crates/prek/src/languages/deno/deno.rs:76-82 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/bun/bun.rs"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a4c619d791cbd2b50cf8450a524a4a9aefc9782bb561d2a7b2ee51cd6905aae"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 7): crates/prek/src/languages/bun/installer.rs:88-93 | crates/prek/src/languages/deno/installer.rs:100-105 | crates/prek/src/languages/dotnet/installer.rs:98-102 | crates/prek/src/languages/golang/installer.rs:125-130 | crates/prek/src/languages/mise/installer.rs:119-123 | crates/prek/src/languages/node/installer.rs:120-125 | crates/prek/src/languages/ruby/installer.rs:202-206 \u2014 \u0060crates/prek/src/languages/bun/installer.rs\u0060 and \u0060crates/prek/src/languages/deno/installer.rs\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 5 separate duplicated blocks between them, totalling at least 42 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/bun/installer.rs"},"region":{"startLine":88}}}],"partialFingerprints":{"codehealthFindingId/v1":"d85a8c8ef9c26f623517080ee6619e8740d873b4832d7fdf9ea68ec8ee2fe8c4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): crates/prek/src/languages/coursier.rs:69-73 | crates/prek/src/languages/julia.rs:31-35 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/coursier.rs"},"region":{"startLine":69}}}],"partialFingerprints":{"codehealthFindingId/v1":"4e5e84355a6d0741a0d905ba330c6bf2024e6c86783c39250b2c5bf582b95b11"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (18 lines \u00D7 2): scripts/update-macports-portfile.py:183-200 | scripts/update-schemastore-schema.py:45-62 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/update-macports-portfile.py"},"region":{"startLine":183}}}],"partialFingerprints":{"codehealthFindingId/v1":"7398f9a160d98218b0975eb86a10c70a0f1dfcfc33e0334d6daf790a8f8be7a8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): scripts/update-macports-portfile.py:113-121 | scripts/update-schemastore-schema.py:27-35 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"scripts/update-macports-portfile.py"},"region":{"startLine":113}}}],"partialFingerprints":{"codehealthFindingId/v1":"a39c0d4f6ff8b3701e5e30ca9b6efaa5c907c94d42e863fbb0585a33e6b1d2c5"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: prek-identify: prek-identify: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and depended on by 1 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4fcd281ac39f8dc451c1fac806873b18865eaba3ae885b97174b36e8aad3318a"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: prek-pty: prek-pty: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and depended on by 1 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3bbf742184dd7df758d98e6c730d45870de5a83cd24f3d4e6b471916795389e3"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/prek/src/main.rs: crates/prek/src/main.rs changed 14 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 43 in prek::run at line 154. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 15:07:53 \u002B08:00\u0027 --until=\u00272026-09-29 15:07:53 \u002B08:00\u0027 --full-history --no-merges -- crates/prek/src/main.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/main.rs"},"region":{"startLine":154}}}],"partialFingerprints":{"codehealthFindingId/v1":"e1b383ac57deb46c6330f2a9059e703ae1da0b7e65b4fc31d4a7906d6a5dbe46"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/prek/src/cli/run/run.rs: crates/prek/src/cli/run/run.rs changed 27 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 18 in prek::cli::run::run::run at line 77. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 15:07:53 \u002B08:00\u0027 --until=\u00272026-09-29 15:07:53 \u002B08:00\u0027 --full-history --no-merges -- crates/prek/src/cli/run/run.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/run/run.rs"},"region":{"startLine":77}}}],"partialFingerprints":{"codehealthFindingId/v1":"8bde2fef20da2346916585b1f9d6ceec12edd7a898caaff16fff6417413de4cf"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/prek/src/languages/mod.rs: crates/prek/src/languages/mod.rs changed 15 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 25 in Language::backend at line 300. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 15:07:53 \u002B08:00\u0027 --until=\u00272026-09-29 15:07:53 \u002B08:00\u0027 --full-history --no-merges -- crates/prek/src/languages/mod.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/mod.rs"},"region":{"startLine":300}}}],"partialFingerprints":{"codehealthFindingId/v1":"de836cb48ac82cc0a37d7e43a33c65718746436752ff8177451578f0d25d1b6d"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/prek/src/hooks/builtin_hooks/mod.rs: crates/prek/src/hooks/builtin_hooks/mod.rs changed 11 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 29 in BuiltinHook::from_id at line 159. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 15:07:53 \u002B08:00\u0027 --until=\u00272026-09-29 15:07:53 \u002B08:00\u0027 --full-history --no-merges -- crates/prek/src/hooks/builtin_hooks/mod.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hooks/builtin_hooks/mod.rs"},"region":{"startLine":159}}}],"partialFingerprints":{"codehealthFindingId/v1":"e7c1c0b620a059d31498a2985eae7949d416f13bffa85cea419656b1ab26a6bf"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/prek/src/hooks/pre_commit_hooks/mod.rs: crates/prek/src/hooks/pre_commit_hooks/mod.rs changed 13 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 22 in PreCommitHooks::run at line 158. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 15:07:53 \u002B08:00\u0027 --until=\u00272026-09-29 15:07:53 \u002B08:00\u0027 --full-history --no-merges -- crates/prek/src/hooks/pre_commit_hooks/mod.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hooks/pre_commit_hooks/mod.rs"},"region":{"startLine":158}}}],"partialFingerprints":{"codehealthFindingId/v1":"fdb149396c74640d96373b280813e04d7afe0af189494524e49483a08e7a05eb"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/prek/src/hooks/pre_commit_hooks/check_merge_conflict.rs: crates/prek/src/hooks/pre_commit_hooks/check_merge_conflict.rs changed 9 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 20 in prek::hooks::pre_commit_hooks::check_merge_conflict::check_file at line 63. 1 of those changes was a fix/bug commit, and the other 8 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 15:07:53 \u002B08:00\u0027 --until=\u00272026-09-29 15:07:53 \u002B08:00\u0027 --full-history --no-merges -- crates/prek/src/hooks/pre_commit_hooks/check_merge_conflict.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hooks/pre_commit_hooks/check_merge_conflict.rs"},"region":{"startLine":63}}}],"partialFingerprints":{"codehealthFindingId/v1":"ca2ef920f039fc57782a6b91e21567a4e7060d04d8f200317df409f15c020bf9"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/prek/src/config/hook.rs: crates/prek/src/config/hook.rs changed 6 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 24 in HookOptions::update at line 532. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 15:07:53 \u002B08:00\u0027 --until=\u00272026-09-29 15:07:53 \u002B08:00\u0027 --full-history --no-merges -- crates/prek/src/config/hook.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/config/hook.rs"},"region":{"startLine":532}}}],"partialFingerprints":{"codehealthFindingId/v1":"e0ea1a1877e2ed8ab8a53b3fefa105597a498afd3bd7b17e81a106fe7792fad6"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/prek/src/languages/node/installer.rs: crates/prek/src/languages/node/installer.rs changed 8 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 17 in NodeInstaller::download at line 200. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 15:07:53 \u002B08:00\u0027 --until=\u00272026-09-29 15:07:53 \u002B08:00\u0027 --full-history --no-merges -- crates/prek/src/languages/node/installer.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/node/installer.rs"},"region":{"startLine":200}}}],"partialFingerprints":{"codehealthFindingId/v1":"51cbbb12862b4dea2ddc3b82090b8fb5b12cb2a25ae9a6eade73259fad5b5122"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/prek/src/cli/install.rs: crates/prek/src/cli/install.rs changed 7 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 17 in prek::cli::install::install_hook_script at line 220. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 15:07:53 \u002B08:00\u0027 --until=\u00272026-09-29 15:07:53 \u002B08:00\u0027 --full-history --no-merges -- crates/prek/src/cli/install.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/install.rs"},"region":{"startLine":220}}}],"partialFingerprints":{"codehealthFindingId/v1":"ffc83d132ba0181bdb3cdfef3f6b4188253cef85af5ca540e09e8417916d0128"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/prek/src/languages/golang/installer.rs: crates/prek/src/languages/golang/installer.rs changed 4 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 18 in GoInstaller::download at line 209. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 15:07:53 \u002B08:00\u0027 --until=\u00272026-09-29 15:07:53 \u002B08:00\u0027 --full-history --no-merges -- crates/prek/src/languages/golang/installer.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/golang/installer.rs"},"region":{"startLine":209}}}],"partialFingerprints":{"codehealthFindingId/v1":"e0177c5403ef6987819dd1d8f95e46307b78f9f298601555b2cdb022c9557291"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: add more information \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hook.rs"},"region":{"startLine":658}}}],"partialFingerprints":{"codehealthFindingId/v1":"a05ad5dcef4cb820afc6cf0b35f50b8f9173ec60059e71e9d521f117b1799e4c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: default to prek.toml in the future? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/sample_config.rs"},"region":{"startLine":75}}}],"partialFingerprints":{"codehealthFindingId/v1":"8423e1bce36f2ed6a87e95b9f02ece168e429b449b9f7fcc88a54b22e09c3576"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: show repo path and environment path (if installed) \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/list.rs"},"region":{"startLine":74}}}],"partialFingerprints":{"codehealthFindingId/v1":"4772e01c7aee48bb0bfb96987c782eabc21b3d04def4c90bda53bc23035880b9"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: xargs \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/run/keeper.rs"},"region":{"startLine":44}}}],"partialFingerprints":{"codehealthFindingId/v1":"714d969434a2e2fb7b6384e72f6f6b9bdd49dfafec9518b854ba418d69761e09"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: xargs \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/run/keeper.rs"},"region":{"startLine":69}}}],"partialFingerprints":{"codehealthFindingId/v1":"f4f61c4df1c7975b6a6e0000396b9ab73b6778e20e8f8426cee54317f3aef83c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Support include_deleted during merge conflict resolution, \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/run/filter.rs"},"region":{"startLine":742}}}],"partialFingerprints":{"codehealthFindingId/v1":"ccccbcb793d09be81873ff6a5e3ae15cda0f21b2d1ec88c0a8595a11c23a97cd"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: support selectors? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/cli/update/mod.rs"},"region":{"startLine":451}}}],"partialFingerprints":{"codehealthFindingId/v1":"656435f260b1ef31f6c0b1e05caddd3c3a4d85af3589f7950753d74517184236"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: warn sensible regex \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/config/mod.rs"},"region":{"startLine":45}}}],"partialFingerprints":{"codehealthFindingId/v1":"a90e1d521928bc86b40a1699baa8b26e7b56142a5168614b4c3780150efb153b"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Decide whether fast-path hooks should honor or ignore a configured \u0060shell\u0060. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hooks/mod.rs"},"region":{"startLine":82}}}],"partialFingerprints":{"codehealthFindingId/v1":"b2037864b561064f19ca195c9a831f4b084a1370703044326323b813f67af7c0"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: compare rev \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hooks/pre_commit_hooks/mod.rs"},"region":{"startLine":199}}}],"partialFingerprints":{"codehealthFindingId/v1":"7e963d5a6202e889fda9bcb64cacc4d84d63dd410658ee6b8db9fea28cb610ab"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: \u0060granit-parser\u0060 resolves aliases while producing parser events, so this is stricter \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/hooks/pre_commit_hooks/check_yaml.rs"},"region":{"startLine":144}}}],"partialFingerprints":{"codehealthFindingId/v1":"6a5029c648c292e94c8b457b69d57b69f4a9e315a29825780a75b5929ab71a02"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: all other languages default to semver for now. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/version.rs"},"region":{"startLine":93}}}],"partialFingerprints":{"codehealthFindingId/v1":"19888b6f72d5c7fc48a89b0e1a9d74f8deedd4e1ddfe45597f9284e744e73e7f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Remove these pre-commit compatibility variables in the next breaking release. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/conda.rs"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"9a0705c6604eea2db6a6156bb86c12e13c629c63b1a2b8d8f8f81f7a84b0719f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Install a managed Pixi when no Conda installer is available, like mise and uv. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/conda.rs"},"region":{"startLine":84}}}],"partialFingerprints":{"codehealthFindingId/v1":"17ff7b8df6de0d4f86d1dc6bd55930486e5060816c2a662d49c1f28b8ef5e130"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: go1.20.0b1, go1.20.0rc1? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/golang/version.rs"},"region":{"startLine":30}}}],"partialFingerprints":{"codehealthFindingId/v1":"8bf0d8c873787e40e0a3ead16aaae5fd72d772b8ce4945b643317f1d2a61d927"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: support prerelease versions like \u0060go1.20.0b1\u0060, \u0060go1.20rc1\u0060 \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/golang/version.rs"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"b7cd8d996324d2272e167f11c7afdaf1b36c0903614bf9fce92d7f43c7dc1aa2"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: support pre-release versions properly. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/golang/gomod.rs"},"region":{"startLine":66}}}],"partialFingerprints":{"codehealthFindingId/v1":"2fd06fa1f7707ff0857067567e55f64e2a98fbf030882a9c00a40b9964000982"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(#2022): Support provisioning remote hooks from the repository\u0027s \u0060mise.toml\u0060."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/mise/mise.rs"},"region":{"startLine":97}}}],"partialFingerprints":{"codehealthFindingId/v1":"31465c087c4dde6fec3ed00957a13bff37c0166cd7eb78aaa8d086cb6064e50d"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(#2022): Preserve non-UTF-8 PATH entries omitted by \u0060mise env --json\u0060."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/mise/mise.rs"},"region":{"startLine":200}}}],"partialFingerprints":{"codehealthFindingId/v1":"98819faf7018910abb2427b89cbb6ca2b214ab14eae35ffc64f0d7bf1d331678"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: support mirror? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/node/installer.rs"},"region":{"startLine":198}}}],"partialFingerprints":{"codehealthFindingId/v1":"190534eb60cb87abe0b913c43ebe59d07ea6915293a533e4d8dc429e7438fe6e"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: avoid this clone if possible. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/pygrep/pygrep.rs"},"region":{"startLine":220}}}],"partialFingerprints":{"codehealthFindingId/v1":"ede0e48ecf1ca03ed95110ecba77905ff0e772f18fa64f114531fb8526f26f51"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: support version like \u00603.8b1\u0060, \u00603.8rc2\u0060, \u0060python3.8t\u0060, \u0060python3.8-64\u0060, \u0060pypy3.8\u0060. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/python/version.rs"},"region":{"startLine":29}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7c6eb310c1ea87c767503a1eb29accc1eead30a2bfa64a14f348ff581779870"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: support \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/python/version.rs"},"region":{"startLine":192}}}],"partialFingerprints":{"codehealthFindingId/v1":"7fa6e9491cf0c1c34357164b1e2a12661e811df9d015bfef9948d1d65ab2257d"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: support reading pypi source user config, or allow user to set mirror \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/python/uv.rs"},"region":{"startLine":219}}}],"partialFingerprints":{"codehealthFindingId/v1":"c19c3987cd68cc05ec9a689760b4922cd6b560cf8535450588a3cd09c45368fe"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: allow opt-out uv \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/python/uv.rs"},"region":{"startLine":220}}}],"partialFingerprints":{"codehealthFindingId/v1":"3b0f9790e6af1d08ab96d25a7652a62b922a42e8b4f5af111ac7eb219733721a"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no project overview: The opening About section describes prek as a reimagined version of pre-commit but does not state what the project does or what it is for, leaving an unshown overview gap. State what hooks prek runs on (files, commits), its main features (single-binary distribution, security safeguards), and why it replaces pre-commit."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"66dbf18d06aa983c06246108610908ba99aae6784280b3aacd1a6655733d71be"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no licence statement: No licence statement appears in any of the visible documents. Insert a License section describing the project\u0027s open-source license."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/security.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"829ad5b2272155b035fa68477a698371f0e064a78884d669357701eb9a4c552f"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found. The recognised ADR directories in this tree were read \u2014 \u0060docs/proposals\u0060 \u2014 and none of their files is a decision record (a README, index or template page does not count). What was searched, so you can tell an empty log from a search that missed one: every directory under the tree (build output, dependencies and VCS metadata excepted), for a document that is either any non-index page inside a recognised ADR directory, whatever its name and however deeply nested (\u0060docs/adr/use-postgres.md\u0060, \u0060docs/adr/2024/0001-x.md\u0060); or a file anywhere whose name is ADR-shaped (\u00600001-use-postgres.md\u0060, \u0060adr-012-caching.md\u0060); or, when neither turned anything up, a document carrying the decision-record signature (an \u0022Architecture Decision Record\u0022 heading, or Status / Context / Decision / Consequences as section headings). A decision log that clears none of these \u2014 unnumbered files outside any recognised directory, without those headings \u2014 is not seen by this check and this row is then wrong. If that is your case, say so rather than renaming anything; otherwise, consider recording architectural decisions in \u0060docs/adr/\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D22","level":"warning","message":{"text":"Redundant method exposure across split types. \u0060Pty\u0060 splits into \u0060ReadPty\u0060 and \u0060WritePty\u0060. Since resizing a PTY is a property of the underlying file descriptor (shared by both ends), exposing \u0060resize\u0060 on \u0060WritePty\u0060 and \u0060OwnedWritePty\u0060 is redundant if \u0060Pty\u0060 already exposes it. Furthermore, \u0060OwnedWritePty\u0060 duplicates the functionality of \u0060WritePty\u0060 (which is likely a reference-counted or borrowed view), creating API surface bloat where \u0060WritePty.resize\u0060 should suffice for both owned and borrowed contexts, or \u0060Pty.resize\u0060 should be the canonical entry point.: Remove \u0060resize\u0060 from \u0060WritePty\u0060 and \u0060OwnedWritePty\u0060. Rely on \u0060Pty.resize\u0060 for the unified interface, or if ownership semantics require it, ensure \u0060WritePty\u0060 is the sole interface for write-side operations and \u0060OwnedWritePty\u0060 delegates to it without re-exposing the same method signature. (signatures: Pty.resize(size: Size): Result | WritePty.resize(size: Size): Result | OwnedWritePty.resize(size: Size): Result)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"632f1b88f0e32361768e033cc5412580d0a88993ca1e0696e69fa630b37a441f"}},{"ruleId":"D26","level":"note","message":{"text":"Projects may be oversized for their cohesion: 1 of 4 project(s) overshoot their size bounds, lowering Project Cohesion to 5.0/10. The most over is \u0060crates/prek\u0060 (46305 LoC, 144 public types across 19 directories). Review these for cohesion \u2014 draw the boundary inside the module first (group each responsibility into its own package or directory and keep the cross-boundary members non-public), since splitting a published package moves types between packages and breaks consumers."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d5a94650dc74886a0f1f08eb9fb6775f1fc395279ef7e901c970c9d26f767a72"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"385b28d12d43e87bb7a2306e6c377597ec2b7f1035724a803dafc24d741b88ed"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8a7c60d84ec124dea0266da2cf23510056e10aadd6ac2dae11dd81d8528da72e"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ce03149def57ce0b5f3ec7a04394a472d579d57e8c2c464b2bc0a6079269883d"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f1b966c70d2e5f6ab697ac6d268d54938c60e802d8ea58ea6ff9cb7e10a35f70"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fd34071f0a37397b22950926e6e7d533f19a1ab2e35c80a3ec230eef7195ce4c"},"taxa":[{"id":"CWE-250","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a5a94de598d5f66dcc4ccfd4adeb9bbd82d59e61120ddfa86a1354ef816f7094"},"taxa":[{"id":"CWE-250","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"94112b1d706b2f9d9118c577518290919c2d702aa0b944fa06a5bcbb51101185"},"taxa":[{"id":"CWE-250","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5cd6ba725d4cfdefa0b9a1fc9a630396a4a700aff93699a8233f4a088607d6d7"},"taxa":[{"id":"CWE-250","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a77a628c056f00bc475a03de6d7c923f8e07a855e9b4fc652986cc61cd3be665"},"taxa":[{"id":"CWE-250","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eaa991e27c368b8daecadf5547bf3191d11594140eebc1c6646e7d6472385133"},"taxa":[{"id":"CWE-250","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e9844509aac6c1cc8f68a0aa4f363efdfb95d6581f82a0b9461659111d83b27"},"taxa":[{"id":"CWE-250","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6c668fda278b1e3f96d06b320aaee84004f1ac56935ced39d9e1754d9c5a729c"},"taxa":[{"id":"CWE-250","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6ed059458dc0d864f79fffc2c8cd3f09ac2213f256b255ba1e07734350228541"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bf9b3890cba73cd3c5d5270d1976bd1bae94596a1c510482b94fe9367ef871f2"},"properties":{"dependency":{"package":"memmap2","version":"0.9.10","advisory":"RUSTSEC-2026-0186","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5585c48a8c4ed670247ebaa40a533d385248c4e49079fee700e7b93cbab137a9"},"properties":{"dependency":{"package":"quick-xml","version":"0.26.0","advisory":"RUSTSEC-2026-0194","aliases":["RUSTSEC-2026-0195"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c4a0c58aca13bc848c37d4c3d5bcb90f8e046f8df5b386f5a3743d0625ad8dae"},"properties":{"dependency":{"package":"crossbeam-epoch","version":"0.9.18","advisory":"RUSTSEC-2026-0204","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3035e85b1a9c0c33df37dc333f490439b3fa52aefda24a401e2e75a177cdf778"},"properties":{"dependency":{"package":"rustls","version":"0.23.40","advisory":"RUSTSEC-2026-0285","aliases":["[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fe2d688610b51e0a5a02c7c5dd1724a4986e40f2689fb84510e2ec0164c27d6a"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"be9c57e2fb625c43c271d051f76b97f27b6976f4ec358ef8fea1d9cb5205f460"},"taxa":[{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"62ba3f391b97d680ac34e630794a6a7fc0f3b16bd44bab9e323085ff4fa2c944"}},{"ruleId":"D34","level":"note","message":{"text":"Orphaned files with no living knowledge: 1 of 134 analysed file(s) have no living knowledge left \u2014 their last meaningful change has decayed away, so if one breaks, no one currently understands it (counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 134 of the 160 production source files in this repository met that bar). None is large enough to earn a read-through of its own, so this row stands in for the per-file rows rather than raising one each \u2014 most significant first: python/prek/_find_prek.py. Attach the read to the next change that touches one of them: have a second person review that change, and leave behind a short comment or test recording what the file is for, so the knowledge comes back at the cost of a change you were making anyway."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ce861fd78f6935114d3a342cb90ad25870f984e1042954fcbbe27c0e23be3658"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: node.rs \u2194 ruby.rs: \u0060crates/prek/src/languages/node/node.rs\u0060 and \u0060crates/prek/src/languages/ruby/ruby.rs\u0060 change together 50% of the time (5 of the 10 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 5 shared commits counted here, the most recent 3 are \u0060c0ed56d9\u0060 Preserve system download policy when applying metadata (#2395); \u0060cc3d76eb\u0060 Remove some \u0060.expect()\u0060 (#1495); \u00600e934c38\u0060 Do not resolve entry for docker_image (#1386) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/node/node.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c327221cbba9b598948a09dc47bb7e4b94ed0e6d246d52dbd896e71e86d26318"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: golang.rs \u2194 ruby.rs: \u0060crates/prek/src/languages/golang/golang.rs\u0060 and \u0060crates/prek/src/languages/ruby/ruby.rs\u0060 change together 50% of the time (5 of the 10 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 5 shared commits counted here, the most recent 3 are \u0060c0ed56d9\u0060 Preserve system download policy when applying metadata (#2395); \u0060cc3d76eb\u0060 Remove some \u0060.expect()\u0060 (#1495); \u00600e934c38\u0060 Do not resolve entry for docker_image (#1386) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/prek/src/languages/golang/golang.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"2fc7279b05cf183797d4f548f9b5c3aac11fc87520ad621b690d81b8c9b06eca"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"61d9c64c1de88e7edb9c757178d6ec3103868cef4ae7e825aeeac5d15e61fb7d"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d068c977b62d9a977df1bb6f53e8b00b586c3abee955f91d715f92b8e019d624"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4f1e7684f8281bd255ddef97105c7055c2ebae06964c8745716b83e174debe83"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"P12","level":"warning","message":{"text":"Coverage collected but not gated: CI collects a coverage report but no step enforces a minimum \u2014 coverage could halve and CI stays green. Add a step that fails the build when coverage drops below a floor (your coverage tool\u0027s minimum-threshold flag, or a coverage-gate action) so the number guards something. What was searched, so you can tell an absence from a miss: this repository\u0027s CI files AND its coverage configuration \u2014 the well-known coverage and test-runner config files, read at the repository root and inside workspace package directories two levels down, so a floor declared beside the tests rather than in the pipeline is credited \u2014 matched against the threshold settings this check knows by name. A floor set in your coverage service\u0027s web UI rather than in a committed file, or under a setting whose name is not one of those, is not seen here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7f63c06044cf998d9a0698692df30d8873e29bc9b0c98ee829255017c1193d33"}},{"ruleId":"P2","level":"note","message":{"text":"Logging is not universal: Only 2/3 runnable modules use logging (modules with no entry point or server are excluded \u2014 they are libraries a runnable module hosts). Silent: \u0060.\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"91a94e21d6d4d0e6a2003f94505b0b02b157176f0b24c4820f3f82b4447a97fe"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-250","guid":"52ee12e8-390a-7351-b1e6-388afa694e54","name":"CWE-250","shortDescription":{"text":"CWE-250"},"helpUri":"https://cwe.mitre.org/data/definitions/250.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-829","guid":"13c33925-97fb-5a5e-b40c-56d328b8a4d7","name":"CWE-829","shortDescription":{"text":"CWE-829"},"helpUri":"https://cwe.mitre.org/data/definitions/829.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":23,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}