{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D10","name":"Test Quality","shortDescription":{"text":"Test Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D10"},{"id":"D11","name":"Test Reliability","shortDescription":{"text":"Test Reliability"},"helpUri":"https://codehealth.canine.dev/dimensions/D11"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D24","name":"Comment Value","shortDescription":{"text":"Comment Value"},"helpUri":"https://codehealth.canine.dev/dimensions/D24"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"}]}},"results":[{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: Project.Core: Project.Core: abstractness 0.27, instability 0.00, distance 0.73 \u2014 zone of pain \u2014 concrete and depended on by 2 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"2b0ea1f7f7a20cd214db66d492f05dd47d534789904c1e3b3257ad6055284e40"}},{"ruleId":"D8","level":"warning","message":{"text":"Coverage not measured \u2014 test suite did not build: Coverage NOT MEASURED: this repository did not build in our analyzer environment (a C#/MSBuild compiler error), so no coverage could be collected. It is excluded from the score rather than counted as a near-zero defect. We did not read WHERE the failing diagnostic is, so this does not claim the fault is in your test code \u2014 a repository written for an older SDK band can compile for you and not for us. Run \u0060dotnet build\u0060 on this commit; if it succeeds, the gap is ours. Committing the Cobertura/OpenCover/lcov report your CI already produces also lets us measure real coverage without building anything."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"62e63e619c28f057e129f2997c965d32a457366a9ce18ca019ffb6bdfba85c99"}},{"ruleId":"D11","level":"warning","message":{"text":"Test reliability not measured \u2014 test suite did not build: Test reliability NOT MEASURED: this repository did not build in our analyzer environment (a C#/MSBuild compiler error), so no test ever ran and flakiness could not be exercised. It is excluded from the score rather than counted as a defect. We did not read WHERE the failing diagnostic is, so this does not claim the fault is in your test code \u2014 a repository written for an older SDK band can compile for you and not for us. Run \u0060dotnet build\u0060 on this commit: if it succeeds, the gap is ours and nothing here is a defect in your code."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"daf09aaa4e14533ca5ff2442790c6867a248b3a07dae410d48e7d6405d6fec30"}},{"ruleId":"D12","level":"error","message":{"text":"Vulnerable: AutoMapper: AutoMapper 12.0.1 \u2014 High severity. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7ad907f4096422e42924a00fab6889d83782c07f3031eeb825e84a391fcadb56"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.AspNetCore.Identity: Microsoft.AspNetCore.Identity 2.2.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9192f631de4685bd270902754ea53e838e4060a03b9d6d9c28fe168732d4ec74"}},{"ruleId":"D13","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ba2690fd8a865294c43acc38e64ed06b61550e680a8d3e7727320c41c4bd5875"},"taxa":[{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D16","level":"warning","message":{"text":"single-maintainer \u2014 knowledge-concentration (bus factor) risk: single-maintainer \u2014 knowledge-concentration (bus factor) risk (1 author(s) across 39 commit(s) sampled)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b4b49d961df742f0e507f4cc5c8094fb077ba0391a27fd015d18320865187719"}},{"ruleId":"D18","level":"warning","message":{"text":"Build failed: The target solution did not build cleanly (errors: 1), which caps Solution Shape at 3/10 \u2014 the most basic shape signal is that it compiles. First errors: CS7036: There is no argument given that corresponds to the required parameter \u0027memoryCache\u0027 of \u0027ProductController.ProductController(ILogger\u003CProductController\u003E, IProductService, IMemoryCache)\u0027."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"24ff41d1fc14d3a19b969001a7e9697d13d34fc0453d84646f56c980eff97f2b"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found at common paths; consider documenting architectural decisions in Docs/ADL/ or similar."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D21","level":"note","message":{"text":"The interface \u0060IBaseRepository\u003CT\u003E\u0060 contains methods with inconsistent naming conventions. Specifically, \u0060IsExists\u0060 is used for existence checks, while \u0060GetAll\u0060, \u0060GetById\u0060, \u0060CreateRange\u0060, and \u0060GetPaginatedData\u0060 follow a \u0027Get/Create\u0027 pattern. However, \u0060Update\u0060 and \u0060PriceCheck\u0060 do not follow the \u0027Get/Create/Update\u0027 pattern consistently (e.g., \u0060Update\u0060 vs \u0060CreateRange\u0060). More importantly, the method \u0060IsExists\u0060 is a non-standard name for a repository query method, whereas \u0060GetAll\u0060 and \u0060GetById\u0060 are standard. A more consistent approach would be to use \u0060Exists\u0060 or \u0060GetBy...\u0060 for all query methods, or \u0060Find\u0060/\u0060Get\u0060 for all. The mix of \u0060IsExists\u0060 with \u0060Get...\u0060 methods is inconsistent.: Standardize query methods to use \u0060Get...\u0060 or \u0060Find...\u0060 pattern (e.g., \u0060Exists\u0060 or \u0060GetBy...\u0060) and update \u0060IsExists\u0060 to \u0060Exists\u0060 or \u0060GetBy...\u0060 to match the rest of the repository interface. (symbols: Project.Core.Interfaces.IRepositories.IBaseRepository\u003CT\u003E.IsExists\u003CTvalue\u003E(string, Tvalue, System.Threading.CancellationToken), Project.Core.Interfaces.IRepositories.IBaseRepository\u003CT\u003E.GetAll(System.Threading.CancellationToken), Project.Core.Interfaces.IRepositories.IBaseRepository\u003CT\u003E.GetAll(System.Collections.Generic.List\u003CSystem.Linq.Expressions.Expression\u003CSystem.Func\u003CT, object\u003E\u003E\u003E, System.Threading.CancellationToken), Project.Core.Interfaces.IRepositories.IBaseRepository\u003CT\u003E.GetById\u003CTid\u003E(Tid, System.Threading.CancellationToken), Project.Core.Interfaces.IRepositories.IBaseRepository\u003CT\u003E.CreateRange(System.Collections.Generic.List\u003CT\u003E, System.Threading.CancellationToken), Project.Core.Interfaces.IRepositories.IBaseRepository\u003CT\u003E.GetPaginatedData(int, int, System.Collections.Generic.List\u003CProject.Core.Common.ExpressionFilter\u003E, string, string, System.Threading.CancellationToken), Project.Core.Interfaces.IRepositories.IBaseRepository\u003CT\u003E.GetOrderByExpression\u003CT\u003E(string), Project.Core.Interfaces.IRepositories.IBaseRepository\u003CT\u003E.Update(Project.Core.Entities.Business.UserUpdateViewModel), Project.Core.Interfaces.IRepositories.IBaseRepository\u003CT\u003E.PriceCheck(int, System.Threading.CancellationToken))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6bed1f19076d9720c6eed4e753db468404ee212431d0957eaf4c54c991abcc89"}},{"ruleId":"D21","level":"note","message":{"text":"The \u0060IUserService\u0060 interface uses a mix of naming conventions for its methods. It uses \u0060GetAll\u0060, \u0060GetById\u0060, \u0060Create\u0060, \u0060Update\u0060, \u0060Delete\u0060 which is a standard CRUD pattern. However, it also includes \u0060ResetPassword\u0060 which is a specific action, not a standard CRUD operation. While not strictly an inconsistency in the CRUD verbs, the interface mixes standard repository-like verbs (\u0060Get\u0060, \u0060Create\u0060, \u0060Update\u0060, \u0060Delete\u0060) with domain-specific actions (\u0060ResetPassword\u0060). A more consistent approach might be to separate domain actions from generic CRUD operations, or ensure all methods follow a similar naming pattern (e.g., \u0060ResetPassword\u0060 is fine, but \u0060GetAll\u0060 and \u0060GetById\u0060 are also fine. The real inconsistency is between \u0060IUserService\u0060 and \u0060IProductService\u0060/\u0060IRoleService\u0060 which might have different patterns. Let\u0027s look at \u0060IProductService\u0060.: Ensure all service interfaces follow the same CRUD pattern. If \u0060IUserService\u0060 has \u0060GetAll\u0060, \u0060GetById\u0060, \u0060Create\u0060, \u0060Update\u0060, \u0060Delete\u0060, then \u0060IProductService\u0060 and \u0060IRoleService\u0060 should also follow this pattern. Check if \u0060IProductService\u0060 uses \u0060GetAll\u0060/\u0060GetById\u0060 or \u0060Find\u0060/\u0060Get\u0060. If \u0060IProductService\u0060 uses \u0060GetAll\u0060/\u0060GetById\u0060, then it is consistent. If it uses \u0060FindAll\u0060/\u0060FindById\u0060, then there is an inconsistency between services. (symbols: Project.Core.Interfaces.IServices.IUserService.GetAll(System.Threading.CancellationToken), Project.Core.Interfaces.IServices.IUserService.GetById(int, System.Threading.CancellationToken), Project.Core.Interfaces.IServices.IUserService.Create(Project.Core.Entities.Business.UserCreateViewModel, System.Threading.CancellationToken), Project.Core.Interfaces.IServices.IUserService.Update(Project.Core.Entities.Business.UserUpdateViewModel, System.Threading.CancellationToken), Project.Core.Interfaces.IServices.IUserService.Delete(int, System.Threading.CancellationToken), Project.Core.Interfaces.IServices.IUserService.ResetPassword(Project.Core.Entities.Business.ResetPasswordViewModel), Project.Core.Interfaces.IServices.IUserService.GetPaginatedData(int, int, System.Collections.Generic.List\u003CProject.Core.Common.ExpressionFilter\u003E, string, string, System.Threading.CancellationToken))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"57283efc73850dd09499092db8ff274c53261a15db444af500c758a45bb71a00"}},{"ruleId":"D21","level":"note","message":{"text":"The \u0060IProductService\u0060 interface uses \u0060GetAll\u0060, \u0060GetById\u0060, \u0060Create\u0060, \u0060Update\u0060, \u0060Delete\u0060. This is consistent with \u0060IUserService\u0060. However, \u0060IProductService\u0060 also has \u0060PriceCheck\u0060 and \u0060GetPaginatedData\u0060. \u0060IUserService\u0060 has \u0060GetPaginatedData\u0060 as well. The inconsistency is not within the interface but potentially between \u0060IUserService\u0060 and \u0060IRoleService\u0060. Let\u0027s check \u0060IRoleService\u0060.: Ensure all service interfaces (\u0060IUserService\u0060, \u0060IProductService\u0060, \u0060IRoleService\u0060) use the same set of CRUD verbs (\u0060GetAll\u0060, \u0060GetById\u0060, \u0060Create\u0060, \u0060Update\u0060, \u0060Delete\u0060). If \u0060IRoleService\u0060 uses \u0060FindAll\u0060 or \u0060Get\u0060 instead of \u0060GetAll\u0060/\u0060GetById\u0060, that is an inconsistency. (symbols: Project.Core.Interfaces.IServices.IProductService.GetAll(System.Threading.CancellationToken), Project.Core.Interfaces.IServices.IProductService.GetById(int, System.Threading.CancellationToken), Project.Core.Interfaces.IServices.IProductService.Create(Project.Core.Entities.Business.ProductCreateViewModel, System.Threading.CancellationToken), Project.Core.Interfaces.IServices.IProductService.Update(Project.Core.Entities.Business.ProductUpdateViewModel, System.Threading.CancellationToken), Project.Core.Interfaces.IServices.IProductService.Delete(int, System.Threading.CancellationToken), Project.Core.Interfaces.IServices.IProductService.PriceCheck(int, System.Threading.CancellationToken), Project.Core.Interfaces.IServices.IProductService.GetPaginatedData(int, int, System.Collections.Generic.List\u003CProject.Core.Common.ExpressionFilter\u003E, string, string, System.Threading.CancellationToken))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a88b4359118ac066d1074a4b4647635579823ef1a153904cebc1688af096f3fe"}},{"ruleId":"D21","level":"note","message":{"text":"The \u0060IRoleService\u0060 interface is missing \u0060GetAll\u0060 and \u0060GetById\u0060 methods, or they are not listed in the sample. If \u0060IRoleService\u0060 does not have \u0060GetAll\u0060/\u0060GetById\u0060 while \u0060IUserService\u0060 and \u0060IProductService\u0060 do, this is an inconsistency in the service layer\u0027s public API. Additionally, \u0060IRoleService\u0060 has \u0060Create\u0060, \u0060Update\u0060, \u0060Delete\u0060. It lacks \u0060Get...\u0060 methods in the provided list, which might be a missing implementation or a different naming convention (e.g., \u0060Find\u0060 vs \u0060Get\u0060).: Add \u0060GetAll\u0060 and \u0060GetById\u0060 (or \u0060FindAll\u0060/\u0060FindById\u0060) to \u0060IRoleService\u0060 to match \u0060IUserService\u0060 and \u0060IProductService\u0060. Ensure the naming convention for retrieval methods is consistent across all service interfaces. (symbols: Project.Core.Interfaces.IServices.IRoleService.Create(Project.Core.Entities.Business.RoleCreateViewModel, System.Threading.CancellationToken), Project.Core.Interfaces.IServices.IRoleService.Delete(int, System.Threading.CancellationToken), Project.Core.Interfaces.IServices.IRoleService.Update(Project.Core.Entities.Business.RoleUpdateViewModel, System.Threading.CancellationToken))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"49a5d1124e439aed3588d286225318639dd47f2788c91f2eb0ca7b2cee96138e"}},{"ruleId":"D24","level":"note","message":{"text":"redundant comment: \u0022Add this line to configure routing\u0022 \u2014 delete - the Configure/UseEndpoints call is self-describing"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Project.API/Program.cs"},"region":{"startLine":121}}}],"partialFingerprints":{"codehealthFindingId/v1":"ab30f1e37111c94e45b76a4d026d867deafd6a25a5c368570cb17ab31c8307c2"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"af68361f566d9af6491528730c92a313e2ab033d897584dad7c7bcd24d56f13a"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0a4c79ce0c1e30f2901a51873bfd09eada2da214d85e757d321ae2c37071969a"}},{"ruleId":"D28","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3cdfd7beb31b791ae18dcb425e21eb157c842e7bbcd522cc330573c1a6538db1"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2ab6c36f9ba2959809d6b740f8a18ff7828f8fb8bf1e55a125029d888bdd3b3f"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d3458738a9b505811049a751f4012492d190bd65163306d4a068a5ebbf0982b5"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4c94809c085ac35cc135761562f4a464dd8c6b43f7146f8316c735244873ae2b"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"567764a082af612710719f71720c5dd4a1db8d45e1fb706df8ac9f9761d73529"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"11bef7a0f33734f6d8e1041e921e5abe75b858bcc23479f335de5c4a8dcf5179"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"03b31df8570933308505a1624e4fd5ee0390537c65b94f5898a4ad85f2c0b177"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e92ef47a93ca21416350b56c62426eaba052eb41d0e7c047d55f55bb678a833c"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5e17d551a578f0af574bb240d223c109cc0afadbd36e92e1607a8fab0b5f0013"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e6ac157ac3e50ab2ab6e0a21f45498abd0f95ecb9c04090adcc89864b8198e0b"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"39c127f59cc561b1d98fae00066c73a2c5639400f64bf35abceee7ea1ae5c6f2"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ced8503d2f7d90f62176241965b98d8b0fe7a357afd64eaea0391b19812d14ae"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"980f2166c13e3dcf8a85cee8e9f96b57957e94fb1607ef95391355b34cc8becf"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":16,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}