{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D10","name":"Test Quality","shortDescription":{"text":"Test Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D10"},{"id":"D11","name":"Test Reliability","shortDescription":{"text":"Test Reliability"},"helpUri":"https://codehealth.canine.dev/dimensions/D11"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}]},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D23","name":"Boundary Type-Coupling","shortDescription":{"text":"Boundary Type-Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D23"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}]},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29"},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"}]}},"results":[{"ruleId":"D2","level":"warning","message":{"text":"UserRepository.EditUser (cognitive 18): UserRepository.EditUser has cognitive complexity 18 (threshold 15)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Services/DataBaseService/Repositories/UserRepository.cs"},"region":{"startLine":120}}}],"partialFingerprints":{"codehealthFindingId/v1":"435d7c068e3dc46be09038da8e8a0a9654d073849b7a7fcdc69fe1b202c50682"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (25 lines \u00D7 2): Clients/GUI/Pages/BotEdition.razor:140-164 | Clients/GUI/Pages/BotCreation.razor:116-139"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Clients/GUI/Pages/BotEdition.razor"},"region":{"startLine":140}}}],"partialFingerprints":{"codehealthFindingId/v1":"7986c6cb9d2f45da8f77f6e1d5cb2a2e8aa7f5ba7b2d2424179380d469652fb4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (20 lines \u00D7 2): Clients/GUI/Pages/UserInfo.razor:518-537 | Clients/GUI/Pages/Balance.razor:103-122"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Clients/GUI/Pages/UserInfo.razor"},"region":{"startLine":518}}}],"partialFingerprints":{"codehealthFindingId/v1":"148968717607ba9e67c139be8781fdf4fe9cd7eac09f2cfe845913a8b5b09a6c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): Clients/GUI/Pages/Instruments.razor:262-278 | Clients/GUI/Pages/BotRunning.razor:268-284"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Clients/GUI/Pages/Instruments.razor"},"region":{"startLine":262}}}],"partialFingerprints":{"codehealthFindingId/v1":"ff89a5c6a700f02c5b8b502171f51ce8f6d9879b5de8afafd20f557a02d41fae"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): Clients/GUI/Pages/UserInfo.razor:495-510 | Clients/GUI/Pages/Balance.razor:80-95"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Clients/GUI/Pages/UserInfo.razor"},"region":{"startLine":495}}}],"partialFingerprints":{"codehealthFindingId/v1":"fd3087407e29201cb96c0c80f7fa4e1f732fdfc8def8cf6b98f46115a1ede070"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): Services/DataBaseService/Database/Migrations/MigrationEngine.cs:213-227 | Services/DataBaseService/Database/Migrations/MigrationEngine.cs:238-252"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Services/DataBaseService/Database/Migrations/MigrationEngine.cs"},"region":{"startLine":213}}}],"partialFingerprints":{"codehealthFindingId/v1":"508cfacd6d57d0222f1413c0ba517832199c89847c8ce6630c6493ead2148ba1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): Clients/GUI/Pages/Instruments.razor:156-167 | Clients/GUI/Pages/BotRunning.razor:157-168"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Clients/GUI/Pages/Instruments.razor"},"region":{"startLine":156}}}],"partialFingerprints":{"codehealthFindingId/v1":"907e7c21ad5a7a8a8b9dd047011f46f37a3f13be798a0848daebd9abd39d20de"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: DTO: DTO: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and heavily depended-on, so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a377cf5b7f26c4c34bf98b77006fc3c8c838224de1dfdbb8352186192a54d82d"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: Kernel: Kernel: abstractness 0.06, instability 0.09, distance 0.85 \u2014 zone of pain \u2014 concrete and heavily depended-on, so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b12bf2d78e65502a851be048ba76ae0694b6e1423650be512dddb5c1485e0265"}},{"ruleId":"D8","level":"warning","message":{"text":"Coverage not measured \u2014 test suite did not build: Coverage NOT MEASURED: the repo\u0027s own test suite did not build (a C#/MSBuild compiler error in the test code), so no coverage could be collected. It is excluded from the score rather than counted as a near-zero defect. Fix the test build, or commit the Cobertura/OpenCover/lcov report your CI already produces, and real coverage will be measured."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"8beb176c604706486df63d2215f767f50520c8d949b1d464345de14ded442c69"}},{"ruleId":"D13","level":"error","message":{"text":"Leaked secret: high-entropy-secret: high-entropy-secret detected."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Clients/GUI/Pages/Portfolio.razor"},"region":{"startLine":232}}}],"partialFingerprints":{"codehealthFindingId/v1":"c887879a65ef27f98ca657a0e41246c0a16dd8e63a7a13e6430587ba5fdbd4d9"}},{"ruleId":"D13","level":"error","message":{"text":"Leaked secret: high-entropy-secret: high-entropy-secret detected."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Clients/GUI/Pages/Instruments.razor"},"region":{"startLine":133}}}],"partialFingerprints":{"codehealthFindingId/v1":"591296432cd617b77954b356392d597ec6a4bb08a46b6e6d0b3ea39f338e8086"}},{"ruleId":"D13","level":"error","message":{"text":"Leaked secret: high-entropy-secret: high-entropy-secret detected."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Clients/GUI/Pages/InstrumentInfo.razor"},"region":{"startLine":102}}}],"partialFingerprints":{"codehealthFindingId/v1":"0e3fb1e1fbc527e4392ada551c5fdfbf62385e9b260282cd85eaecdba803c714"}},{"ruleId":"D13","level":"error","message":{"text":"Leaked secret: high-entropy-secret: high-entropy-secret detected."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Clients/GUI/Pages/Bots.razor"},"region":{"startLine":74}}}],"partialFingerprints":{"codehealthFindingId/v1":"3b42fcb4ab2172ba74b5bb54907d3fc3d76fe0bf44241668e1d305a16e667db5"}},{"ruleId":"D13","level":"error","message":{"text":"Leaked secret: high-entropy-secret: high-entropy-secret detected."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Clients/GUI/Pages/BotRunning.razor"},"region":{"startLine":128}}}],"partialFingerprints":{"codehealthFindingId/v1":"0538c526f25d63b82c7002c0ee77749a37f71e490233418617e55f3caa3b5823"}},{"ruleId":"D17","level":"error","message":{"text":"EmptyCatchBlock: empty catch block"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"GUITests/Core/Engine.cs"},"region":{"startLine":63}}}],"partialFingerprints":{"codehealthFindingId/v1":"05b37a340911a7c7cf7731d4c25c8229d52f7e267fe6045774638cb23052fd7a"}},{"ruleId":"D17","level":"error","message":{"text":"EmptyCatchBlock: empty catch block"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Services/OperationService/Bots/BotRules/BotRule.cs"},"region":{"startLine":121}}}],"partialFingerprints":{"codehealthFindingId/v1":"cd55483c457c5c1bf8f08620c2f2316f11c20fd819031b4ca7b4fa2725d1b360"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO add logs for executed script \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: PROJ-123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Services/DataBaseService/Database/Migrations/MigrationEngine.cs"},"region":{"startLine":123}}}],"partialFingerprints":{"codehealthFindingId/v1":"3e824b52f1f6e93aa70756b946285c234d329865d675778afb41ec796856a51c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: remove records from bot rules table also (task for one who implements rules) \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: PROJ-123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Services/DataBaseService/Repositories/BotRepository.cs"},"region":{"startLine":49}}}],"partialFingerprints":{"codehealthFindingId/v1":"2deec83e11864236dbe2d07f64a130506cbe4a5411afb78575723c52efecbacf"}},{"ruleId":"D17","level":"warning","message":{"text":"CommentedOutCode: 4 consecutive commented-code lines"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Services/DataBaseService/Startup.cs"},"region":{"startLine":145}}}],"partialFingerprints":{"codehealthFindingId/v1":"4ce40f2e7cc3f7b26875234ae2f923550546bb2151ebd4e1a812ed9ab3e62cb1"}},{"ruleId":"D17","level":"warning","message":{"text":"CommentedOutCode: 4 consecutive commented-code lines"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Services/OperationService/Startup.cs"},"region":{"startLine":116}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b497e72dc6c051b47a5e14047e8992827c72bb56115ebfb93988446e0b00646"}},{"ruleId":"D17","level":"warning","message":{"text":"CommentedOutCode: 4 consecutive commented-code lines"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Tests/AuthServiceTests/Validators/UserEmailPasswordValidatorTests.cs"},"region":{"startLine":22}}}],"partialFingerprints":{"codehealthFindingId/v1":"e343861b6d4870b9e529f83730f8b9ef77a4fc2ce071b432d0a4aa38473d966d"}},{"ruleId":"D17","level":"warning","message":{"text":"CommentedOutCode: 4 consecutive commented-code lines"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Tests/AuthServiceTests/Validators/UserEmailPasswordValidatorTests.cs"},"region":{"startLine":28}}}],"partialFingerprints":{"codehealthFindingId/v1":"e343861b6d4870b9e529f83730f8b9ef77a4fc2ce071b432d0a4aa38473d966d"}},{"ruleId":"D17","level":"warning","message":{"text":"CommentedOutCode: 5 consecutive commented-code lines"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Services/UserService/Startup.cs"},"region":{"startLine":101}}}],"partialFingerprints":{"codehealthFindingId/v1":"b395ee30db025143a5323fa59b328b5755acd02bdab2bdd6ee3dd984b24f6bca"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO return all logic \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: PROJ-123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Tests/AuthServiceTests/Validators/UserEmailPasswordValidatorTests.cs"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"02810fd3667ce0c82bf640f9a6af8714f2bc99bec87537e98bcbc582500a3139"}},{"ruleId":"D18","level":"note","message":{"text":"Shell project: OperationServiceTests: \u0060OperationServiceTests\u0060 contributes only 0 significant line(s) \u2014 an empty/placeholder project is structural noise. Remove it or fold its contents into a real project."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Tests/OperationServiceTests/OperationServiceTests.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a11af81c34c5a6ec82fc5da2443442d45ea3fe03f5e974a6c29ef2943003c614"}},{"ruleId":"D18","level":"note","message":{"text":"Thin analysable surface across projects: 3 project(s) carry only a thin slice of real code (e.g. \u0060RssIntegrationLib\u0060 with 26 significant line(s)). The mean analysable-surface weight is 89 %, lowering Solution Shape by about 0.9 point(s). Consolidate thin projects or grow them into substantial, well-scoped assemblies."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"dd0b92fd965c2065080f16843920964ee00f7696ea03d87cdf61aed4cd2c746a"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found at common paths; consider documenting architectural decisions in Docs/ADL/ or similar."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent entity naming for Bot-related database models. \u0027DbBot\u0027 is used in one place, while \u0027DbBotRule\u0027 is used in another, suggesting a potential naming inconsistency or lack of standardization for Bot entities.: Standardize Bot entity naming, e.g., always use \u0027DbBot\u0027 or \u0027DbBotEntity\u0027. (symbols: DataBaseService.Database.Models.DbBotRule, DataBaseService.Database.Models.DbBot)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c005a0f0374cf9fb145c015e0eabce2a995b1720453b209d48d6e4cf6f85d9b8"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent naming for internal broker requests. Some use \u0027Internal\u0027 prefix (e.g., InternalCreateUserRequest), while others do not (e.g., GetUserBalanceRequest, GetInstrumentFromPortfolioRequest).: Consistently apply the \u0027Internal\u0027 prefix to all internal broker requests or remove it entirely. (symbols: DTO.BrokerRequests.InternalGetUserByIdRequest, DTO.BrokerRequests.InternalGetBotsRequest, DTO.BrokerRequests.InternalSaveRuleRequest, DTO.BrokerRequests.InternalEditUserInfoRequest, DTO.BrokerRequests.InternalEditBotRequest, DTO.BrokerRequests.InternalDeleteUserRequest, DTO.BrokerRequests.InternalCreateUserRequest, DTO.BrokerRequests.InternalGetBotRulesRequest, DTO.BrokerRequests.InternalTradeRequest, DTO.BrokerRequests.GetUserBalanceRequest, DTO.BrokerRequests.GetInstrumentFromPortfolioRequest)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"8a3319ecfed6834f5dcfb57d57d9a1eced8fbdec8dd8e07d6789ca9310b50c43"}},{"ruleId":"D23","level":"note","message":{"text":"Bounded contexts not declared: At 8314 LoC across 21 projects the codebase is large and multi-module, so explicit bounded contexts are needed. Declare architecture.contexts (\u22652) in config to assess cross-boundary type coupling."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1c7e276c9c682731f01819ed5378b90ca320cde1b583c90920172911598362b3"}},{"ruleId":"D28","level":"error","message":{"text":"Secret: generic-api-key: matched rule \u0027generic-api-key\u0027"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Clients/GUI/Pages/Bots.razor"},"region":{"startLine":74}}}],"partialFingerprints":{"codehealthFindingId/v1":"102ac051a32200564d89a71159c0d3e8ae09509237d569bc7fad439a721f2382"}},{"ruleId":"D28","level":"error","message":{"text":"Secret: generic-api-key: matched rule \u0027generic-api-key\u0027"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Clients/GUI/Pages/BotRunning.razor"},"region":{"startLine":128}}}],"partialFingerprints":{"codehealthFindingId/v1":"a40fe74fe4fd7adfd4dec17fe9492d31b9eaaedeb73f758e141cf8c002d7b571"}},{"ruleId":"D28","level":"error","message":{"text":"Secret: generic-api-key: matched rule \u0027generic-api-key\u0027"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Clients/GUI/Pages/Portfolio.razor"},"region":{"startLine":232}}}],"partialFingerprints":{"codehealthFindingId/v1":"6b87572704404e89ca24cb95440128a295f5dc60908dac65a27ece072be7bc58"}},{"ruleId":"D28","level":"error","message":{"text":"Secret: generic-api-key: matched rule \u0027generic-api-key\u0027"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Clients/GUI/Pages/Instruments.razor"},"region":{"startLine":251}}}],"partialFingerprints":{"codehealthFindingId/v1":"9cd8ccbaddd8b7e5c764f141c8360e6aae9ee8225afef389ff3c7d003fe01a0d"}},{"ruleId":"D28","level":"error","message":{"text":"Secret: generic-api-key: matched rule \u0027generic-api-key\u0027"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Clients/GUI/Pages/InstrumentInfo.razor"},"region":{"startLine":102}}}],"partialFingerprints":{"codehealthFindingId/v1":"07bfd3b3371a4e1f3bb2a9fd3e0d2e3f235c341b8842f0ad71d552c1f92713b4"}},{"ruleId":"D28","level":"note","message":{"text":"Rotate the exposed credentials \u2014 git history can\u0027t be un-committed: Some of these secrets are in git HISTORY: deleting the file does not remove them (the commit persists on every clone, fork and backup). The remediation is to ROTATE each historically-exposed credential and treat it as compromised \u2014 not to delete the file. Rewriting history is disruptive and unreliable across existing forks. (Working-tree-only secrets \u2014 no commit \u2014 can instead be removed from the file and moved to a secret store.)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3cdfd7beb31b791ae18dcb425e21eb157c842e7bbcd522cc330573c1a6538db1"}},{"ruleId":"D34","level":"note","message":{"text":"Dormant codebase: 26 of 26 significant files have no living knowledge \u2014 the codebase as a whole is dormant, not 26 separate risks. Re-engage owners or document before change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4c69f1e54b7dd6fe9029dd02df6ba8f8145b789f2f18dbdaa086c40ded49dba6"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: RussianCBInfo.cs \u2194 GetCurrenciesCommand.cs: \u0060Integrations/CentralBankIntegrationLib/RussianCBInfo.cs\u0060 (context Integrations) and \u0060Services/NewsService/Commands/GetCurrenciesCommand.cs\u0060 (context Services) live in DIFFERENT modules yet change together 90% of the time (9 shared commits) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Integrations/CentralBankIntegrationLib/RussianCBInfo.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"7a5d79498a2f064197a935130a9d6c85f872037e9bb18702a9641ad6737a7e2f"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: UserGetter.cs \u2194 IGetUserByIdCommand.cs: \u0060Clients/GUI/Scripts/UserGetter.cs\u0060 (context Clients) and \u0060Services/UserService/Interfaces/IGetUserByIdCommand.cs\u0060 (context Services) live in DIFFERENT modules yet change together 82% of the time (9 shared commits) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Clients/GUI/Scripts/UserGetter.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a14ce3ac78d0b3c65e2ed4023cdd554719025c2392cec87ba1b72c3930a0f791"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: ErrorResponse.cs \u2194 Startup.cs: \u0060Common/DTO/ErrorResponse.cs\u0060 (context Common) and \u0060Services/UserService/Startup.cs\u0060 (context Services) live in DIFFERENT modules yet change together 81% of the time (13 shared commits) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Common/DTO/ErrorResponse.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"cbfc7c4c5a7fb6ed4ccadf5a13c3c02831925c29a0801486728ab7fae72cd172"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: LogMessage.cs \u2194 LoginCommand.cs: \u0060Common/Kernel/LoggingEngine/LogMessage.cs\u0060 (context Common) and \u0060Services/AuthenticationService/Commands/LoginCommand.cs\u0060 (context Services) live in DIFFERENT modules yet change together 77% of the time (10 shared commits) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Common/Kernel/LoggingEngine/LogMessage.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"6a4a3b61f5849be5b07de60661590b8092c11ea877f1e8fc80fc347e2081a494"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: LogMessage.cs \u2194 AuthenticationController.cs: \u0060Common/Kernel/LoggingEngine/LogMessage.cs\u0060 (context Common) and \u0060Services/AuthenticationService/Controllers/AuthenticationController.cs\u0060 (context Services) live in DIFFERENT modules yet change together 77% of the time (10 shared commits) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Common/Kernel/LoggingEngine/LogMessage.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"22af6cf786ac4160e8a7e32ce0effe0f4f30587ebf7283e9664921c4ec22cd69"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: InternalCreateUserRequest.cs \u2194 IUserRepository.cs: \u0060Common/DTO/BrokerRequests/InternalCreateUserRequest.cs\u0060 (context Common) and \u0060Services/DataBaseService/Repositories/Interfaces/IUserRepository.cs\u0060 (context Services) live in DIFFERENT modules yet change together 73% of the time (11 shared commits) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Common/DTO/BrokerRequests/InternalCreateUserRequest.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"4859a59e7692a217010dc02c3d4c8cf78141e0f273b0faf59e84c45e53ab6f4a"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: UserInfoViewModel.cs \u2194 IGetUserByIdCommand.cs: \u0060Clients/GUI/ViewModels/UserInfoViewModel.cs\u0060 (context Clients) and \u0060Services/UserService/Interfaces/IGetUserByIdCommand.cs\u0060 (context Services) live in DIFFERENT modules yet change together 73% of the time (8 shared commits) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Clients/GUI/ViewModels/UserInfoViewModel.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e0499ce6bb462f04b641752d34f1f74e1a71a51557e0d56c7fcb04ca500e1d7e"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: TinkoffBankBroker.cs \u2194 CandleHub.cs: \u0060Integrations/TinkoffIntegrationLib/TinkoffBankBroker.cs\u0060 (context Integrations) and \u0060Services/OperationService/Hubs/CandleHub.cs\u0060 (context Services) live in DIFFERENT modules yet change together 71% of the time (15 shared commits) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Integrations/TinkoffIntegrationLib/TinkoffBankBroker.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3cf0d04ae0c9c7283d217d84be57bb9100607c5ef86301931cbd7eca426f30a2"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: Node.cs \u2194 CreateUserCommand.cs: \u0060LogReader/LogReader/Models/Node.cs\u0060 (context LogReader) and \u0060Services/UserService/Commands/CreateUserCommand.cs\u0060 (context Services) live in DIFFERENT modules yet change together 70% of the time (7 shared commits) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"LogReader/LogReader/Models/Node.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b20d82854127d91f8a3a10021de60f51a92a967aa66effa52ac493af0fa72339"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: LogMessage.cs \u2194 App.xaml.cs: \u0060Common/Kernel/LoggingEngine/LogMessage.cs\u0060 (context Common) and \u0060LogReader/LogReader/App.xaml.cs\u0060 (context LogReader) live in DIFFERENT modules yet change together 70% of the time (7 shared commits) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Common/Kernel/LoggingEngine/LogMessage.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f8d593cb9c0c1c184d4b63ed07118bdb337365f571c659a57548145acf7919e9"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-798","name":"Use of Hard-coded Credentials"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":0,"secretScannerRunsExcluded":0}}}]}