{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D7","name":"Architectural Integrity","shortDescription":{"text":"Architectural Integrity"},"helpUri":"https://codehealth.canine.dev/dimensions/D7"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D10","name":"Test Quality","shortDescription":{"text":"Test Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D10"},{"id":"D11","name":"Test Reliability","shortDescription":{"text":"Test Reliability"},"helpUri":"https://codehealth.canine.dev/dimensions/D11"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}]},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D23","name":"Boundary Type-Coupling","shortDescription":{"text":"Boundary Type-Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D23"},{"id":"D25","name":"ADR Conformance","shortDescription":{"text":"ADR Conformance"},"helpUri":"https://codehealth.canine.dev/dimensions/D25"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}]},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29"},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}]},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31"},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D39","name":"IL Efficiency","shortDescription":{"text":"IL Efficiency"},"helpUri":"https://codehealth.canine.dev/dimensions/D39"}]}},"results":[{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 3): src/Modules/Users/Atlas.Users.Infrastructure/Extensions/ServiceCollectionExtensions.cs:38-52 | src/Modules/Plans/Atlas.Plans.Infrastructure/Extensions/ServiceCollectionExtensions.cs:46-60 | src/Modules/Law/Atlas.Law.Infrastructure/Extensions/ServiceCollectionExtensions.cs:45-59"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Modules/Users/Atlas.Users.Infrastructure/Extensions/ServiceCollectionExtensions.cs"},"region":{"startLine":38}}}],"partialFingerprints":{"codehealthFindingId/v1":"a96e222b02b1d00ce13db0a056095021e3cc610c0d3cec2e83de2745fe09be27"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: Atlas.Shared: Atlas.Shared: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and heavily depended-on, so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"61ccbe58736eb77cb3c24d8bcc9b4ebd00dd782ae91887ce91396a78fc4fac10"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: Atlas.Shared.Infrastructure.Razor: Atlas.Shared.Infrastructure.Razor: abstractness 0.00, instability 0.14, distance 0.86 \u2014 zone of pain \u2014 concrete and heavily depended-on, so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"8497699c508de778d5fe3171515f8ae84e9b6c9f3400e845ed7e277c788bbc50"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: Atlas.Plans.IntegrationEvents: Atlas.Plans.IntegrationEvents: abstractness 0.00, instability 0.14, distance 0.86 \u2014 zone of pain \u2014 concrete and heavily depended-on, so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5f38621ea1c8c1a6e8fde76caf9709d923bf77acb270d78d22c06df288266c79"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: Atlas.Users.IntegrationEvents: Atlas.Users.IntegrationEvents: abstractness 0.00, instability 0.14, distance 0.86 \u2014 zone of pain \u2014 concrete and heavily depended-on, so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ac1accc79202f93aaefbc972e7699ee011629fd423e6a849c3c6717106bdd5fa"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: StripeService (LCOM4 6): StripeService\u0027s methods form 6 groups that share no state and don\u0027t call each other \u2014 a sign it may have several responsibilities. Review whether it splits into focused classes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Modules/Plans/Atlas.Plans.Infrastructure/Services/StripeService.cs"},"region":{"startLine":15}}}],"partialFingerprints":{"codehealthFindingId/v1":"12fe9d70023322466a62054af2b0be631fda2602b3de6d7cb210eaecaa909c8b"}},{"ruleId":"D12","level":"error","message":{"text":"Vulnerable: AutoMapper: AutoMapper 13.0.1 \u2014 High severity. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7ad907f4096422e42924a00fab6889d83782c07f3031eeb825e84a391fcadb56"}},{"ruleId":"D12","level":"error","message":{"text":"Vulnerable: MailKit: MailKit 4.3.0 \u2014 Moderate severity. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ad4f2a38eb922510975ba7d88a44c631589975067536fd77080a53584f6d1380"}},{"ruleId":"D12","level":"error","message":{"text":"Vulnerable: MimeKit: MimeKit 4.3.0 \u2014 High severity. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5195208df28d6fc355a1b01a6e73c1479b301e7c51f0f2ce3d623827da86ec90"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.AspNetCore.Mvc.Versioning: Microsoft.AspNetCore.Mvc.Versioning 5.1.0 \u2014 Other Asp.Versioning.Mvc \u003E= 0.0.0"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f503d6856b4df2823c9a5d40c53ba1f0a13e3e5793ef9c617bf66524face2d13"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.AspNetCore.Mvc: Microsoft.AspNetCore.Mvc 2.2.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a99213a55d0bf26f9cb4256cfdeb44dbc489cfaf4f9937e8e93d5d6b38c5b542"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.AspNetCore.Identity: Microsoft.AspNetCore.Identity 2.2.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9192f631de4685bd270902754ea53e838e4060a03b9d6d9c28fe168732d4ec74"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: xunit: xunit 2.4.2 \u2014 Legacy xunit.v3 \u003E= 0.0.0"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d37c8c0e8046c9e8358e976373216abfb78e9fdef63ed53d3edcaa7d2238edcd"}},{"ruleId":"D16","level":"note","message":{"text":"Small-team knowledge concentration: 43 file(s) are concentrated to one author \u2014 the ambient state with 2 active author(s), not 43 separate risks. The signal becomes meaningful as ownership spreads; no per-file action implied now."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"8aa75b6daa18f1b578387fa04036c50b3163d47f957c8f5601bf083ed4489b0c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO - Deprecated. Switch to InvoicePaid \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: PROJ-123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Modules/Plans/Atlas.Plans.Application/CQRS/Webhooks/Commands/HandleStripeWebhook/HandleStripeWebhookCommandHandler.cs"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"b6fb6d9570158e1a9ae395ce1ce55ffdf1e46654f49cfc0c7bfcd6bf7b44f36a"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO - Send email to user, AND specify the reason for the failure. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: PROJ-123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Modules/Plans/Atlas.Plans.Application/CQRS/Webhooks/Commands/HandleStripeWebhook/HandleStripeWebhookCommandHandler.cs"},"region":{"startLine":161}}}],"partialFingerprints":{"codehealthFindingId/v1":"b6fb6d9570158e1a9ae395ce1ce55ffdf1e46654f49cfc0c7bfcd6bf7b44f36a"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO - Get date from IDateTimeProvider \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: PROJ-123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Modules/Shared/Atlas.Shared.Application/Abstractions/Messaging/Queue/QueueMessage.cs"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"70d289b5674240952a871af64dfa02b0e32881c6586e7bef2d09189f1805acd2"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO - Get date from IDateTimeProvider \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: PROJ-123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Modules/Shared/Atlas.Shared.Infrastructure/Integration/Inbox/InboxMessage.cs"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"17b9187a7639b8957d2e24143d2683b5bb3694c319c5ffe8bd4d741eb9f4e0d1"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO - Get date from IDateTimeProvider \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: PROJ-123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Modules/Shared/Atlas.Shared.Infrastructure/Integration/Outbox/OutboxMessage.cs"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"238e6b07df30fd24abf7a4611165b6b0d60b0206cd645f732a0301aaf0307bfd"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO - Make this UtcNow actually interact with some IDateTimeProvider service that can get any datetime \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: PROJ-123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Modules/Shared/Atlas.Shared.IntegratinEvents/IntegrationEvent.cs"},"region":{"startLine":10}}}],"partialFingerprints":{"codehealthFindingId/v1":"7e37d2fad750b1fc41d86f8924924528490edf542a8fd9f2f7b758e7208a7c65"}},{"ruleId":"D18","level":"note","message":{"text":"Shell project: Atlas.Plans.IntegrationEvents: \u0060Atlas.Plans.IntegrationEvents\u0060 contributes only 6 significant line(s) \u2014 an empty/placeholder project is structural noise. Remove it or fold its contents into a real project."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Modules/Plans/Atlas.Plans.IntegrationEvents/Atlas.Plans.IntegrationEvents.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"5ea92a5994f13e037cba6584bddf1ef4b883d9faeab5b6b2f7d2fd3f9ed7b185"}},{"ruleId":"D18","level":"note","message":{"text":"Shell project: Atlas.Users.IntegrationEvents: \u0060Atlas.Users.IntegrationEvents\u0060 contributes only 9 significant line(s) \u2014 an empty/placeholder project is structural noise. Remove it or fold its contents into a real project."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Modules/Users/Atlas.Users.IntegrationEvents/Atlas.Users.IntegrationEvents.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"4d3f19f7f2defe4953d87fc9d3c4d0b7203c4745728e7c3efe7f7a5110aab707"}},{"ruleId":"D18","level":"note","message":{"text":"Thin analysable surface across projects: 4 project(s) carry only a thin slice of real code (e.g. \u0060Atlas.Shared.IntegrationEvents\u0060 with 14 significant line(s)). The mean analysable-surface weight is 75 %, lowering Solution Shape by about 2.0 point(s). Consolidate thin projects or grow them into substantial, well-scoped assemblies."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"dd0b92fd965c2065080f16843920964ee00f7696ea03d87cdf61aed4cd2c746a"}},{"ruleId":"D20","level":"warning","message":{"text":"Consequences are mostly prescriptive (\u0027must be deployed as single process\u0027, \u0027must communicate asynchronously\u0027) without any rationale for the trade-offs: Add a Consequences section explaining the trade-offs of running everything as one monolith: operational complexity (single process to scale), vendor lock-in, and the cost of future migrations"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/architecture-decision-log/0001-adopting-modular-monolith-architecture copy.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"6326253bea4e36a1d5b6c1925be2e950200454e41bf7e535c78a55283f4e67aa"}},{"ruleId":"D20","level":"warning","message":{"text":"Consequences list only \u0022API and modules are loosely coupled.\u0022; the second one that \u0022API can *only* communicate with the module via the facade\u0022 is a strong coupling trade-off but not stated in detail: Add a Consequences section on how to handle cases where an API needs to interact with outside systems or services directly (e.g. through non-facade calls) while still being loosely coupled"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/architecture-decision-log/0003-facade-pattern-between-api-and-module.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c337a6b925fd0e810f78b63dc9154d2d86a05752251736d529fd2533755a419a"}},{"ruleId":"D20","level":"warning","message":{"text":"Consequences are thin: \u0022Read and write oprations are completely segregated.\u0022 with no trade-offs (e.g. query latency, scaling of read replicas) and no mention of how queries/commands are routed through the facade: Expand consequences to cover operational cost (read replicas needed), performance impact (query load on separate tier), and maintainability tradeoffs (queries cannot modify data, requiring separate indexing)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/architecture-decision-log/0004-cqrs.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"fdd5983375793210f775dd11ce1f6dd6a1462ceb0cb0412a511082d8306b4111"}},{"ruleId":"D20","level":"warning","message":{"text":"Decision is a single bare word (\u0027The mediator pattern shall be implemented.\u0027) with no consequences and no context (why the CQRS class/record exists): Replace the decision with an explicit implementation description (e.g. \u0027A Mediator class will receive commands/query events and forward them to their respective handlers\u0027) and add a Consequences section covering trade-offs such as increased boilerplate, loss of dependency visibility, and the cost of maintaining the mediator"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/architecture-decision-log/0005-mediator-pattern.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"6936f86359505bc3c3677e8a6649c0849cd4dc04e70ba5fb2f51c6c1750fc60a"}},{"ruleId":"D20","level":"warning","message":{"text":"Decision is boilerplate (\u0027Commands are allowed to return data after processing.\u0027) and consequences list two trade-offs but give no rationale for why this change was made (e.g. real use case) or any alternatives considered: Add a Context section explaining the concrete scenarios where commands need to return data, and in the Consequences add a fourth item on how to guard against misuse of this feature"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/architecture-decision-log/0006-allow-cqrs-commands-to-return-data.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"6fb1768d0c60ba68b03205cd8d78aafc3f4c7d1737a3662a46f3a2e8db3987a2"}},{"ruleId":"D20","level":"warning","message":{"text":"Consequences are thin: only one concrete consequence (\u0027We need to have a BusinessRuleException\u0027) plus the general performance note and an \u0027if/else chains\u0027 metaphor; trade-offs beyond this are not flagged: Expand consequences by naming alternatives (e.g. rule-sets tables, contracts) that could replace the exception approach for non-critical rules"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/architecture-decision-log/0011-business-rules.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"97ce3a6cfc9ac8040f41814244b72d3a66c43a0f622638f9ed0fe14615a3e642"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent namespace for the Persistance folder/namespace: \u0027Atlas.Shared.Infrastructure.Persistance\u0027 vs \u0027Atlas.Infrastructure.Persistance\u0027. One uses \u0027Shared\u0027 in the path, the other does not, despite both referring to persistence infrastructure.: Standardize on \u0027Atlas.Shared.Infrastructure.Persistance\u0027 or \u0027Atlas.Infrastructure.Persistance\u0027 consistently across all persistence-related types. (symbols: Atlas.Shared.Infrastructure.Persistance.Interceptors.DomainEventPublisherInterceptor.SavingChangesAsync, Atlas.Infrastructure.Persistance.Interceptors.UpdateAuditableEntitiesInterceptor.SavingChangesAsync)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c7d121ee03e3450e4586ff9db832be9b2ad30823af641de089db78e98b883ee0"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent naming for the Inbox message handling components. Some are prefixed with \u0027Inbox\u0027 (e.g., InboxMessage, InboxReader, InboxWriter), while others use \u0027Inbox\u0027 as a namespace but the types themselves might be named differently or lack the prefix in a confusing way. Specifically, \u0027InboxMessage\u0027 is used for the message type, but the reader/writer interfaces and classes are named \u0027IInboxReader\u0027, \u0027IInboxWriter\u0027, \u0027InboxReader\u0027, \u0027InboxWriter\u0027. This is mostly consistent, but the parameter name \u0027InboxMessageId\u0027 in an anonymous type suggests a potential confusion with a simple ID property vs the full message object.: Ensure all inbox-related types follow the \u0027Inbox\u0027 prefix or pattern consistently. The current naming is mostly consistent, but the use of \u0027InboxMessage\u0027 for the message type while readers/writers are \u0027InboxReader\u0027/\u0027InboxWriter\u0027 is acceptable. However, check if \u0027InboxMessage\u0027 is the correct term vs \u0027InboxRecord\u0027 or similar. (symbols: Atlas.Shared.Infrastructure.Integration.Inbox.InboxMessage.PublishError, Atlas.Shared.Infrastructure.Integration.Inbox.InboxMessage.CreateFromIntegrationEvent, Atlas.Shared.Infrastructure.Integration.Inbox.InboxMessageHandlerAcknowledgement.HandlerName, Atlas.Shared.Infrastructure.Integration.Inbox.IInboxReader.MarkFailedAsync, Atlas.Shared.Infrastructure.Integration.Inbox.IInboxWriter, Atlas.Shared.Infrastructure.Integration.Inbox.InboxWriter\u003CTDatabaseContext\u003E, Atlas.Shared.Infrastructure.Integration.Inbox.InboxReader\u003CTDatabaseContext\u003E.MarkFailedAsync, Atlas.Shared.Infrastructure.Integration.Inbox.InboxReader\u003CTDatabaseContext\u003E.ListPendingAsync, Atlas.Shared.Infrastructure.Integration.Inbox.InboxMessage)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9901c4db1b5c32d35833933695f8abf904749bcf431f5629065d1eba898cfd38"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent spelling of \u0027Colour\u0027 vs \u0027Color\u0027. The codebase uses British spelling \u0027Colour\u0027 in \u0027CreatePlanCommand.TextColour\u0027 and \u0027UpdatePlanCommand.IconColour\u0027. However, if there are other places using \u0027Color\u0027, it would be an inconsistency. In this specific list, \u0027Colour\u0027 is used consistently. Wait, looking closer: \u0027TextColour\u0027 and \u0027IconColour\u0027 are used. This is consistent with British spelling. No inconsistency here unless \u0027Color\u0027 appears elsewhere. Let\u0027s look for other inconsistencies.: N/A (symbols: Atlas.Plans.Application.CQRS.Plans.Commands.CreatePlan.CreatePlanCommand.Active, Atlas.Plans.Application.CQRS.Plans.Commands.CreatePlan.CreatePlanCommand.TrialPeriodDays, Atlas.Plans.Application.CQRS.Plans.Commands.CreatePlan.CreatePlanCommand.InheritsFromId, Atlas.Plans.Application.CQRS.Plans.Commands.CreatePlan.CreatePlanCommand.TextColour, Atlas.Plans.Application.CQRS.Plans.Commands.CreatePlan.UpdatePlanCommand.IconColour)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f8c776af5c0a320b3a5f74bf14475ca9b4b13da9c2228ec1f3d7982bf33d09c1"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent naming for the Inbox message handling components. Some are prefixed with \u0027Inbox\u0027 (e.g., InboxMessage, InboxReader, InboxWriter), while others use \u0027Inbox\u0027 as a namespace but the types themselves might be named differently or lack the prefix in a confusing way. Specifically, \u0027InboxMessage\u0027 is used for the message type, but the reader/writer interfaces and classes are named \u0027IInboxReader\u0027, \u0027IInboxWriter\u0027, \u0027InboxReader\u0027, \u0027InboxWriter\u0027. This is mostly consistent, but the use of \u0027InboxMessage\u0027 for the message type while readers/writers are \u0027InboxReader\u0027/\u0027InboxWriter\u0027 is acceptable. However, the parameter name \u0027InboxMessageId\u0027 in an anonymous type suggests a potential confusion with a simple ID property vs the full message object.: Ensure all inbox-related types follow the \u0027Inbox\u0027 prefix or pattern consistently. (symbols: Atlas.Shared.Infrastructure.Integration.Inbox.InboxMessage.PublishError, Atlas.Shared.Infrastructure.Integration.Inbox.InboxMessage.CreateFromIntegrationEvent, Atlas.Shared.Infrastructure.Integration.Inbox.InboxMessageHandlerAcknowledgement.HandlerName, Atlas.Shared.Infrastructure.Integration.Inbox.IInboxReader.MarkFailedAsync, Atlas.Shared.Infrastructure.Integration.Inbox.IInboxWriter, Atlas.Shared.Infrastructure.Integration.Inbox.InboxWriter\u003CTDatabaseContext\u003E, Atlas.Shared.Infrastructure.Integration.Inbox.InboxReader\u003CTDatabaseContext\u003E.MarkFailedAsync, Atlas.Shared.Infrastructure.Integration.Inbox.InboxReader\u003CTDatabaseContext\u003E.ListPendingAsync, Atlas.Shared.Infrastructure.Integration.Inbox.InboxMessage)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"49e8cef9ee04c0c987af629f2b4a4e91416014eb4a61c59efc2981c27712d88d"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type CreateLegalDocumentsCommand (Law \u2192 Atlas.Web): CreateLegalDocumentsCommand (context Law) is exposed in Atlas.Web\u0027s public surface via LegalDocumentController.CreateDocuments \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a90b3d4550c835e36ca0ef0561877a6548b369cc1aa68ff6a176f92a82c27241"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type CreateFeatureCommand (Plans \u2192 Atlas.Web): CreateFeatureCommand (context Plans) is exposed in Atlas.Web\u0027s public surface via FeatureController.CreateFeature \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"42174a5bfc8f59569018246154a9b4b0303d074f5c47490529677e2a6c019534"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type UpdateFeatureCommand (Plans \u2192 Atlas.Web): UpdateFeatureCommand (context Plans) is exposed in Atlas.Web\u0027s public surface via FeatureController.UpdateFeature \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"74600457f5f8f9151356f321d125334ba7214c5bd44938b34b86c525d51f3975"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type CreatePlanCommand (Plans \u2192 Atlas.Web): CreatePlanCommand (context Plans) is exposed in Atlas.Web\u0027s public surface via PlanController.CreatePlan \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"887388a6b64c2d6bcb3e827bf1383a6bb0d503aaed803b62eeeefdebaa654b86"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type UpdatePlanCommand (Plans \u2192 Atlas.Web): UpdatePlanCommand (context Plans) is exposed in Atlas.Web\u0027s public surface via PlanController.UpdatePlan \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7b00b783a5cd28306cadcf5b5556638f64cf0d073673f68f312f03d0a258a470"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type AddFeatureToPlanCommand (Plans \u2192 Atlas.Web): AddFeatureToPlanCommand (context Plans) is exposed in Atlas.Web\u0027s public surface via PlanController.AddFeatureToPlan \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"67733d65598fc062b6dcb673baf7d734a80028de46def4d68b0cebf577c971dd"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type RemoveFeatureFromPlanCommand (Plans \u2192 Atlas.Web): RemoveFeatureFromPlanCommand (context Plans) is exposed in Atlas.Web\u0027s public surface via PlanController.RemoveFeatureFromPlan \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6d34993cbbb7880ed853ae58740ddea7c2fd7d4f34d72db7d1a15d6513fe6979"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type UpdateFeatureOnPlanCommand (Plans \u2192 Atlas.Web): UpdateFeatureOnPlanCommand (context Plans) is exposed in Atlas.Web\u0027s public surface via PlanController.UpdateFeatureOnPlan \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1fc0cdba3feafe82f51628ea7038c03cffa44ed43db95909229d0952305f04e1"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type AttachPaymentMethodCommand (Plans \u2192 Atlas.Web): AttachPaymentMethodCommand (context Plans) is exposed in Atlas.Web\u0027s public surface via StripeController.AttachPaymentMethod \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6eb2d7d55ba65826fc5714ee5a1c0743ceee3e03424ce60b54877be7d75eb745"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type GetSubscriptionQuoteInvoiceQuery (Plans \u2192 Atlas.Web): GetSubscriptionQuoteInvoiceQuery (context Plans) is exposed in Atlas.Web\u0027s public surface via StripeController.GetSubscriptionQuoteInvoice \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3b092dae16ac86c776241c1684da1f218562488c6608dfd25191dad2967ca171"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type CreateSubscriptionCommand (Plans \u2192 Atlas.Web): CreateSubscriptionCommand (context Plans) is exposed in Atlas.Web\u0027s public surface via StripeController.CreateSubscription \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"fc31f817e1e03d9dfcdf7e8053579bdbaa53044ebfb1b1cdefcf57b06e7233b3"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type UpdateSubscriptionCommand (Plans \u2192 Atlas.Web): UpdateSubscriptionCommand (context Plans) is exposed in Atlas.Web\u0027s public surface via StripeController.UpdateSubscription \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4622a0dcd1f6315a1269bdad5dbcd5f2d39a12c3336a28aac74b3a89a7ca4981"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type CanSignInQuery (Users \u2192 Atlas.Web): CanSignInQuery (context Users) is exposed in Atlas.Web\u0027s public surface via AuthenticationController.SignInUser \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3fc723c180a4d0abaff2c1fdaf922a22803f8ef97495e08056e75b08c8a97148"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type CanSignInWithTokenQuery (Users \u2192 Atlas.Web): CanSignInWithTokenQuery (context Users) is exposed in Atlas.Web\u0027s public surface via AuthenticationController.SignInUserWithToken \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"bb974042ba49f2aeeed7a877de6fe42eed4b49aef318c36f522aa049c2b338c9"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type CreateUserCommand (Users \u2192 Atlas.Web): CreateUserCommand (context Users) is exposed in Atlas.Web\u0027s public surface via UserController.CreateUser \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"882303585e1a3181abcf8e05d3302a476e371d9de10ba55f54288405897f24a5"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type UpdateUserCommand (Users \u2192 Atlas.Web): UpdateUserCommand (context Users) is exposed in Atlas.Web\u0027s public surface via UserController.UpdateUser \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e5f566d9eb2380a45e255d61ebe8752374b79d4d151aad1af07c3dc78cd74ea4"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type DeleteUserCommand (Users \u2192 Atlas.Web): DeleteUserCommand (context Users) is exposed in Atlas.Web\u0027s public surface via UserController.DeleteUser \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"cc1a81956df533c1e42201e1aa6c9236e64096caa2cf58ee9c3dde9c2522756a"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type ConfirmUserEmailCommand (Users \u2192 Atlas.Web): ConfirmUserEmailCommand (context Users) is exposed in Atlas.Web\u0027s public surface via UserController.ConfirmUserEmail \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"167b629677d6758e87df2a901fc6bf2494fce3121c43eceba0ecc725f95d7e88"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type ResetPasswordCommand (Users \u2192 Atlas.Web): ResetPasswordCommand (context Users) is exposed in Atlas.Web\u0027s public surface via UserController.ResetPassword \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6da37b8e0bb07313efc1028a8488b5fed2ce73a6d9f24c7d7104986f44b81551"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type ChangePasswordCommand (Users \u2192 Atlas.Web): ChangePasswordCommand (context Users) is exposed in Atlas.Web\u0027s public surface via UserController.ChangePassword \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"be1a7fa2a8f5b6cc2c5c2b22a5452368c1e7b7cb2d60e135b896eebc1e316680"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type PaymentFailedIntegrationEvent (Plans \u2192 Users): PaymentFailedIntegrationEvent (context Plans) is exposed in Users\u0027s public surface via RemovePlanOnPaymentFailed.Handle \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"05d064076e450705f7ab332333b94ccad660597fea4764205897f79b496dd0b1"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type PaymentSuccessIntegrationEvent (Plans \u2192 Users): PaymentSuccessIntegrationEvent (context Plans) is exposed in Users\u0027s public surface via SetPlanOnPaymentSuccess.Handle \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"eb15a8842ca7032d8f52374ad4a5c2dc42a470633edffd3b498245490a1ad9bc"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type UserEmailConfirmedIntegrationEvent (Users \u2192 Plans): UserEmailConfirmedIntegrationEvent (context Users) is exposed in Plans\u0027s public surface via CreateCreditTrackerOnUserEmailConfirmed.Handle \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"aef3a4509d52ea0231418a3ecfe895ff06ca78591ef2b33428176847430c70e5"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type UserDeletedIntegrationEvent (Users \u2192 Plans): UserDeletedIntegrationEvent (context Users) is exposed in Plans\u0027s public surface via DeleteCreditTrackerOnUserDeleted.Handle \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b7f804d70ce850c0f62656db72d85fc2cfcb5024ee8691280582a3dad92cfc58"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type UserEmailConfirmedIntegrationEvent (Users \u2192 Plans): UserEmailConfirmedIntegrationEvent (context Users) is exposed in Plans\u0027s public surface via CreateStripeCustomerOnUserEmailConfirmed.Handle \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"aef3a4509d52ea0231418a3ecfe895ff06ca78591ef2b33428176847430c70e5"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type UserDeletedIntegrationEvent (Users \u2192 Plans): UserDeletedIntegrationEvent (context Users) is exposed in Plans\u0027s public surface via DeleteStripeCustomerOnUserDeleted.Handle \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b7f804d70ce850c0f62656db72d85fc2cfcb5024ee8691280582a3dad92cfc58"}},{"ruleId":"D23","level":"warning","message":{"text":"Cross-context type UserUpdatedIntegrationEvent (Users \u2192 Plans): UserUpdatedIntegrationEvent (context Users) is exposed in Plans\u0027s public surface via UpdateStripeCustomerOnUserUpdated.Handle \u2014 couples the contexts."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"67236b1ef3907e474e61a837d1eabda0a0964b222b87b028e9c4e6d152d95851"}},{"ruleId":"D30","level":"error","message":{"text":"Critical CVE: System.Text.Encodings.Web 4.5.0: System.Text.Encodings.Web 4.5.0 (transitive) has a Critical advisory; affects 3 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4e4448b31e8b4dd1a6489e264df38146de5afb770ee8e6556d999f07ae5800a8"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: AutoMapper 13.0.1: AutoMapper 13.0.1 (transitive) has a High advisory; affects 10 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5abd77846531e18f75398fdb348c13595eef847ee67bc77d39dc5775b3bd774b"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: Azure.Identity 1.7.0: Azure.Identity 1.7.0 (transitive) has a High advisory; affects 6 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b74ed2402a32a3483f0222438e364162079e47e69d6fc647f12c48e4e51634de"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: Microsoft.Data.SqlClient 5.1.1: Microsoft.Data.SqlClient 5.1.1 (transitive) has a High advisory; affects 6 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9b1edc6c5709bced9c1610ceea5038d37f22592f9e1b77be60513c55be5f6020"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: Microsoft.Extensions.Caching.Memory 8.0.0: Microsoft.Extensions.Caching.Memory 8.0.0 (transitive) has a High advisory; affects 8 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"232013a63d845603c2a626f52ada8d8ad59691f3c568e940aad78d11f17c4f7b"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: MimeKit 4.3.0: MimeKit 4.3.0 (transitive) has a High advisory; affects 6 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"92ecbbe6239883511716fc87fc2172ba7b6bbe16bddb5b2893bae19b65877837"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: System.Formats.Asn1 7.0.0: System.Formats.Asn1 7.0.0 (transitive) has a High advisory; affects 6 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0ec952ada219fe5a028e3a8aa8d56d26ded08861b1152c70e1e8a6609e9450b6"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: System.Net.Http 4.3.0: System.Net.Http 4.3.0 (transitive) has a High advisory; affects 9 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7cf85abffe732f2645ef95a624d6badc26f0263616284d6a4cc46ca8e983031d"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: System.Text.Json 8.0.0: System.Text.Json 8.0.0 (transitive) has a High advisory; affects 6 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c475b5d776175d1181892c3e7e72c31acdbe224ac300e32808399947498db6c9"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: System.Text.Json 8.0.0: System.Text.Json 8.0.0 (transitive) has a High advisory; affects 6 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c475b5d776175d1181892c3e7e72c31acdbe224ac300e32808399947498db6c9"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: System.Text.RegularExpressions 4.3.0: System.Text.RegularExpressions 4.3.0 (transitive) has a High advisory; affects 9 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b96b7173c4377d5bea4d6fd7b52323631c631c44172b743bec6f266c10a4e538"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: Newtonsoft.Json 11.0.2: Newtonsoft.Json 11.0.2 (transitive) has a High advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"58c61fd9b239c2505b291f9f0b42d311bc1fbae0ccfea9c8d6841fe9eba0ba49"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: Newtonsoft.Json 12.0.3: Newtonsoft.Json 12.0.3 (transitive) has a High advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9ae15deacd8d65304febbc4286307d74123e6c6fe9b7a2d543fbda4f0528528a"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: Azure.Identity 1.7.0: Azure.Identity 1.7.0 (transitive) has a Medium advisory; affects 6 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"fbc2fccd3dd6a4b7accf87ad813b38ffe114177cd609f0382f95a35eaba0c550"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: Azure.Identity 1.7.0: Azure.Identity 1.7.0 (transitive) has a Medium advisory; affects 6 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"fbc2fccd3dd6a4b7accf87ad813b38ffe114177cd609f0382f95a35eaba0c550"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: BouncyCastle.Cryptography 2.2.1: BouncyCastle.Cryptography 2.2.1 (transitive) has a Medium advisory; affects 6 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"14f200cfc986157974a5db80565947dc2c38eec1aa443056632491ecf70618d3"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: BouncyCastle.Cryptography 2.2.1: BouncyCastle.Cryptography 2.2.1 (transitive) has a Medium advisory; affects 6 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"14f200cfc986157974a5db80565947dc2c38eec1aa443056632491ecf70618d3"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: BouncyCastle.Cryptography 2.2.1: BouncyCastle.Cryptography 2.2.1 (transitive) has a Medium advisory; affects 6 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"14f200cfc986157974a5db80565947dc2c38eec1aa443056632491ecf70618d3"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: MailKit 4.3.0: MailKit 4.3.0 (transitive) has a Medium advisory; affects 6 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"875991af1d30c7d9ab802abc53d9c685d0ca9934ffd5ad7d5f5d2eb32e4a8df7"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: Microsoft.IdentityModel.JsonWebTokens 6.24.0: Microsoft.IdentityModel.JsonWebTokens 6.24.0 (transitive) has a Medium advisory; affects 6 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"8c5befb86e53034ab72e241f96f9bcdd1112c97a565b97a680e23a0ef98049c9"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: MimeKit 4.3.0: MimeKit 4.3.0 (transitive) has a Medium advisory; affects 6 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c132b998930b71f3c6379d2ef6b07948e343d47391f37b543876716d0ef2b020"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: System.IdentityModel.Tokens.Jwt 6.24.0: System.IdentityModel.Tokens.Jwt 6.24.0 (transitive) has a Medium advisory; affects 6 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9edcd1fe22279a6cdb47df108e8a3cf0b833bb878bb5bc4a9e1a92f2ae090c4d"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: System.Security.Cryptography.Xml 4.5.0: System.Security.Cryptography.Xml 4.5.0 (transitive) has a Medium advisory; affects 9 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"980f2166c13e3dcf8a85cee8e9f96b57957e94fb1607ef95391355b34cc8becf"}},{"ruleId":"D31","level":"note","message":{"text":"Low IaC: DS-0026: No HEALTHCHECK defined"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Atlas.Web/Dockerfile"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"98e61d3f27a5dea99ada4361907d25d327d791a241b24ab7f25cfe3bceefd026"}},{"ruleId":"D34","level":"note","message":{"text":"Dormant codebase: 53 of 55 significant files have no living knowledge \u2014 the codebase as a whole is dormant, not 53 separate risks. Re-engage owners or document before change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4c69f1e54b7dd6fe9029dd02df6ba8f8145b789f2f18dbdaa086c40ded49dba6"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1395","name":"Dependency on Vulnerable Third-Party Component"},{"id":"CWE-798","name":"Use of Hard-coded Credentials"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":0,"secretScannerRunsExcluded":0}}}]}