{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D7","name":"Architectural Integrity","shortDescription":{"text":"Architectural Integrity"},"helpUri":"https://codehealth.canine.dev/dimensions/D7"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AXB1","name":"Runtime evidence locked \u2014 no reproducible boot","shortDescription":{"text":"Runtime evidence locked \u2014 no reproducible boot"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB1"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P5","name":"DR \u0026 Backup","shortDescription":{"text":"DR \u0026 Backup"},"helpUri":"https://codehealth.canine.dev/dimensions/P5"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X26","name":"Unsynchronised callback handoff","shortDescription":{"text":"Unsynchronised callback handoff"},"helpUri":"https://codehealth.canine.dev/dimensions/X26"},{"id":"X31","name":"Test-only surface in a production module","shortDescription":{"text":"Test-only surface in a production module"},"helpUri":"https://codehealth.canine.dev/dimensions/X31"},{"id":"X32","name":"Type resolved by simple name across every loaded assembly","shortDescription":{"text":"Type resolved by simple name across every loaded assembly"},"helpUri":"https://codehealth.canine.dev/dimensions/X32"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"r3lfe_rlwrap.get_rebar3_command (cyclomatic 17): r3lfe_rlwrap.get_rebar3_command has cyclomatic complexity 17 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_rlwrap.erl"},"region":{"startLine":132}}}],"partialFingerprints":{"codehealthFindingId/v1":"2852b0b2c144d1fccc3e2413ce875939f74579595614277c797f195466289d2f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (29 lines \u00D7 2): src/r3lfe_prv_confabulate.erl:55-83 | src/r3lfe_prv_defabulate.erl:55-83 \u2014 before extracting anything, compare \u0060src/r3lfe_prv_confabulate.erl\u0060 and \u0060src/r3lfe_prv_defabulate.erl\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 64 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_prv_confabulate.erl"},"region":{"startLine":55}}}],"partialFingerprints":{"codehealthFindingId/v1":"28018c5ccad97e0f278ae06e98a9496c6b6fac125e5216979a1c674825870e00"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13\u201316 lines \u00D7 2): src/r3lfe_prv_release.erl:157-169 | src/r3lfe_prv_run_release.erl:183-198 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_prv_release.erl"},"region":{"startLine":157}}}],"partialFingerprints":{"codehealthFindingId/v1":"485d46bb3c3f65d7608fa13b1b99b8f16e263131f07c5cba7ac022964a3e3102"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14\u201315 lines \u00D7 2): src/r3lfe_prv_versions.erl:206-219 | src/r3lfe_prv_versions.erl:222-236 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_prv_versions.erl"},"region":{"startLine":206}}}],"partialFingerprints":{"codehealthFindingId/v1":"de4334c8e2268ddfbc5b32754138660c19240a041428e9d1559d76c9048a55b3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): src/r3lfe_prv_confabulate.erl:131-144 | src/r3lfe_prv_defabulate.erl:131-144 \u2014 before extracting anything, compare \u0060src/r3lfe_prv_confabulate.erl\u0060 and \u0060src/r3lfe_prv_defabulate.erl\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 64 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_prv_confabulate.erl"},"region":{"startLine":131}}}],"partialFingerprints":{"codehealthFindingId/v1":"d8f3cc80e202551388f043050df81d490733cef71e8ab178a4634d63f934f11b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): src/r3lfe_prv_run_escript.erl:174-184 | src/r3lfe_prv_run_release.erl:299-309 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_prv_run_escript.erl"},"region":{"startLine":174}}}],"partialFingerprints":{"codehealthFindingId/v1":"2d77535dd0072b16ff7c13e4a49b02f2c3333ffdc9c0e7d7eba3017668512a62"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): src/r3lfe_prv_run.erl:158-169 | src/r3lfe_prv_run_escript.erl:139-145 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_prv_run.erl"},"region":{"startLine":158}}}],"partialFingerprints":{"codehealthFindingId/v1":"c434ecfac7fc04f7b13ee68b7b05b4b4553374d88eb11119a85dc8bc9cf46388"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): src/r3lfe_config.erl:152-163 | src/r3lfe_config.erl:168-178 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_config.erl"},"region":{"startLine":152}}}],"partialFingerprints":{"codehealthFindingId/v1":"4c3e435ea31f4e74016cfc517a589536458d7622aa3765571228c5ec93bfb2eb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): src/r3lfe_prv_confabulate.erl:32-42 | src/r3lfe_prv_defabulate.erl:32-42 \u2014 before extracting anything, compare \u0060src/r3lfe_prv_confabulate.erl\u0060 and \u0060src/r3lfe_prv_defabulate.erl\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 64 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_prv_confabulate.erl"},"region":{"startLine":32}}}],"partialFingerprints":{"codehealthFindingId/v1":"6207695daef8f0e8fc9bb169d7c5b126e9832c36125e83cd7f7c21e86241d0ec"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 7): src/r3lfe_prv_confabulate.erl:35-44 | src/r3lfe_prv_defabulate.erl:35-44 | src/r3lfe_prv_eval.erl:34-43 | src/r3lfe_prv_format.erl:30-39 | src/r3lfe_prv_ltest.erl:40-49 | src/r3lfe_prv_repl.erl:62-71 | src/r3lfe_prv_run.erl:43-52 \u2014 before extracting anything, compare \u0060src/r3lfe_prv_confabulate.erl\u0060 and \u0060src/r3lfe_prv_defabulate.erl\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 64 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_prv_confabulate.erl"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"5b8f2f631cf86736e00dac35eb028f9b317ad57914a0c5783be1c15332ab855f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 7): src/r3lfe_prv_clean.erl:33-41 | src/r3lfe_prv_compile.erl:31-39 | src/r3lfe_prv_escriptize.erl:26-34 | src/r3lfe_prv_release.erl:37-45 | src/r3lfe_prv_run_escript.erl:35-43 | src/r3lfe_prv_run_release.erl:41-49 | src/r3lfe_prv_versions.erl:41-49 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from all 7 call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_prv_clean.erl"},"region":{"startLine":33}}}],"partialFingerprints":{"codehealthFindingId/v1":"8fadf049ab714f7f8ef8d1a1d97cd8f68e1baff3dca1bef8c7f2d8057b430964"}},{"ruleId":"D12","level":"warning","message":{"text":"No dependency lockfile committed (rebar.config): rebar.config declares 2 dependencies but no lockfile (rebar.lock or mix.lock) is committed beside it, so \u0060rebar3 compile\u0060 resolves versions afresh on every machine and every CI run \u2014 two builds of this commit are not guaranteed to be the same build. Run \u0060rebar3 compile\u0060 and commit the resulting \u0060rebar.lock\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"8167d684e70969326978dc347dd61843dfe24c2c826307dbb1edecc8ff726c1c"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: src/r3lfe_prv_format.erl: src/r3lfe_prv_format.erl changed 5 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 9 (its worst body is r3lfe_prv_format.run_check at line 168), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201CFix Dialyzer checks for rebar3 plugin builds\u201D; \u201CImplement Arc A6\u00B7S0 \u2014 e2e CLI test \u002B fix bare-provider app discovery\u201D; \u201CImplement Arc A6\u00B7S1 \u2014 property/fuzz/edge hardening \u002B idempotency fix\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-05-10..2026-08-08, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-05-10 13:09:30 -05:00\u0027 --until=\u00272026-08-08 13:09:30 -05:00\u0027 --full-history --no-merges -- src/r3lfe_prv_format.erl\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_prv_format.erl"},"region":{"startLine":168}}}],"partialFingerprints":{"codehealthFindingId/v1":"0bde1bd7b6d99f6f1fd7349f9e2e82238e7246627d0f0a4ce2654c639edc5696"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no project overview: The troubleshooting guide is a single file, not a repository-wide overview, so it cannot claim to explain what the project does or how to use its contents. Add an overview section describing what rebar3_lfe does and where each document lives."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/troubleshooting.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b7136e304321542122c57944fb051be9db014dde3f1711e714af6895ddccd68f"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no architecture or design documentation: The document is a single-phase rename manifest and no architecture or design documentation exists in the suite. Add an architecture overview describing how module namespaces are chosen, renamed, and verified."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/design/014-r3lfe_phase9.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"40c934e83f71b2e588236b54f377329b395ca6c8e07758cc2d4c362166ea94d9"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no architecture or design documentation: The document is a bug analysis of rebar3_lfe ltest hanging; no architecture or design documentation exists in the suite. Add an architecture section describing how package preparation and test execution interact."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/design/015-ltest-hang-analysis.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"686324e6a00f1f4296c231debf2ab5181f06fd9062819a59f645bbf771959273"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"703b990f6d9a60db46de372b4bc3713bc769740b61be7dfed2b23b523664ac12"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5bfc84bc7e9122d56e0485ca14414562f8404990600d02f93ba76894316f6085"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"53041d0452eb7a0f6d7363cca46cccfc47fe77904a465fee573e39f7c59d9395"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bf6e654aae86dc886c5a2e651d1be07a1252f28560ba57c82c6b15ac3d1f9c30"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2b50d6185f231a28fa9959e31861b0be76667502f1a2f794cc5c60d4fa797cb7"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"db1bc6299330048582794a702bfc6e0611cfcf2c2e5e80b1722cacddc690422c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bc26593caf509b487cb3dff9d1a587737a02c72fc5e13e59c1a151f7d6412ad4"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"74460cbea394b84ecfe9911fa8032052bc367b000332e5b65787c972d5b0a148"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6bc3b539f953f180f304780b633bbb65e6d2911ce57503f2f0e4a05dfd504060"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f9820f5d7288af48fc4f1b5bb24dd6adef20b13339d48241ddd4e5d288ee0c0d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"efc39a49473f1e824d48794be23c7b3158fffac501dfef7b444b6a1b56713396"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6be387f273cbb2002ce57b41a7d126e1529198e6b61bd03639e002d1ecdf9447"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1b213f6eedd4b140d0bc37bdf1496f72811a643f34064f12518b32e9e83bcfc7"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e17f71490e4d120a48b2b2881ab866c93b272bef2febb673a3e8e42b2c288ab"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eb00976a698a5d68999b7ee6d27206fd374e916853e7ff1ead5eed42386f043f"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"90f83b4fa27db32740afe9540c905f3c0499caed87f61049a8a903ecc95b41c3"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9658270ba49f37ed04e99ab1263b6393cd42aed8bdfb7aafd9fa1070f5491895"}},{"ruleId":"P12","level":"warning","message":{"text":"Coverage collected but not gated: CI collects a coverage report but no step enforces a minimum \u2014 coverage could halve and CI stays green. Add a step that fails the build when coverage drops below a floor (your coverage tool\u0027s minimum-threshold flag, or a coverage-gate action) so the number guards something. What was searched, so you can tell an absence from a miss: this repository\u0027s CI files AND its coverage configuration \u2014 the well-known coverage and test-runner config files, read at the repository root and inside workspace package directories two levels down, so a floor declared beside the tests rather than in the pipeline is credited \u2014 matched against the threshold settings this check knows by name. A floor set in your coverage service\u0027s web UI rather than in a committed file, or under a setting whose name is not one of those, is not seen here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7f63c06044cf998d9a0698692df30d8873e29bc9b0c98ee829255017c1193d33"}},{"ruleId":"P4","level":"note","message":{"text":"No release approval gate: The release is automated and no gate that pauses it for a human is DECLARED IN THIS REPOSITORY\u0027S PIPELINE FILES. What was read: every file under \u0060.github/workflows/\u0060, \u0060.forgejo/workflows/\u0060, \u0060.gitea/workflows/\u0060, \u0060.azuredevops/\u0060 and \u0060.azure-pipelines/\u0060, plus \u0060.gitlab-ci*\u0060 and \u0060azure-pipelines*\u0060 \u2014 with comment text stripped, so documenting a gate is not declaring one. What would have counted: GitLab\u0027s \u0060when: manual\u0060, CircleCI\u0027s \u0060type: approval\u0060, an Azure \u0060ManualValidation@\u0060 task or an \u0060approvals:\u0060 block, a Jenkins \u0060input\u0060 step, a \u0060uses:\u0060 step naming an approval action, an \u0060environment:\u0060 paired with \u0060reviewers\u0060 / \u0060required_reviewers\u0060 / \u0060protection\u0060 / \u0060wait-timer\u0060 / \u0060deployment_branch_policy\u0060, a draft-release step, a \u0060workflow_dispatch\u0060 promotion, or a release-event gate. \u2605 What this cannot see, because none of it is a file: a GitHub environment whose required reviewers are configured in repo SETTINGS, a branch protection rule, or an organisation deployment policy \u2014 all of them real, enforced gates that live outside the repository. If yours is one of those, this row is wrong and nothing in the tree could have told us. Otherwise: whatever the release trigger points at is published to users unreviewed, so a mistagged or unverified commit ships and the only remedy is a follow-up release."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6c11e2dbd483b4b423b95ac61bfcc7af1d55351b28a20d2b1105b31cfe38cc60"}},{"ruleId":"X31","level":"note","message":{"text":"Test-only surface in a production module: \u0060r3lfe_compiler_mod:needs_compilation/3\u0060 is exported unconditionally, and the comment directly above the \u0060-export\u0060 on this line says the exports below it are for testing. Erlang has no visibility below \u0060-export\u0060, so this is part of the module\u0027s public contract: it cannot be changed without a compatibility argument. This arm read the comment, not the call graph: if the comment is right and only tests call it, wrapping the attribute in \u0060-ifdef(TEST). \u2026 -endif.\u0060 keeps the test\u0027s access and removes it from the shipped module. If production code calls it, the comment is stale and wrapping the export would break the build \u2014 delete the comment and document the function as part of the module\u0027s API."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_compiler_mod.erl"},"region":{"startLine":15}}}],"partialFingerprints":{"codehealthFindingId/v1":"89d93ce9699be20d358bd93af447ea9e36ffc8495e16511f82747e94fb5e8bb5"}},{"ruleId":"X31","level":"note","message":{"text":"Test-only surface in a production module: \u0060r3lfe_compiler_mod:source_to_target/2\u0060 is exported unconditionally, and the comment directly above the \u0060-export\u0060 on this line says the exports below it are for testing. Erlang has no visibility below \u0060-export\u0060, so this is part of the module\u0027s public contract: it cannot be changed without a compatibility argument. This arm read the comment, not the call graph: if the comment is right and only tests call it, wrapping the attribute in \u0060-ifdef(TEST). \u2026 -endif.\u0060 keeps the test\u0027s access and removes it from the shipped module. If production code calls it, the comment is stale and wrapping the export would break the build \u2014 delete the comment and document the function as part of the module\u0027s API."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_compiler_mod.erl"},"region":{"startLine":15}}}],"partialFingerprints":{"codehealthFindingId/v1":"7e1c92c0686b4a02ebb2ef06c1aa56deeeed25dc97dc4b6882c2244a6a273d42"}},{"ruleId":"X31","level":"note","message":{"text":"Test-only surface in a production module: \u0060r3lfe_compiler_mod:check_dependencies_newer/3\u0060 is exported unconditionally, and the comment directly above the \u0060-export\u0060 on this line says the exports below it are for testing. Erlang has no visibility below \u0060-export\u0060, so this is part of the module\u0027s public contract: it cannot be changed without a compatibility argument. This arm read the comment, not the call graph: if the comment is right and only tests call it, wrapping the attribute in \u0060-ifdef(TEST). \u2026 -endif.\u0060 keeps the test\u0027s access and removes it from the shipped module. If production code calls it, the comment is stale and wrapping the export would break the build \u2014 delete the comment and document the function as part of the module\u0027s API."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_compiler_mod.erl"},"region":{"startLine":15}}}],"partialFingerprints":{"codehealthFindingId/v1":"117fbcb24677c690614560a8d55a8e42049a1233859deee9e357fb63b5fb4658"}},{"ruleId":"X31","level":"note","message":{"text":"Test-only surface in a production module: \u0060r3lfe_config:normalize_src_dirs/2\u0060 is exported unconditionally, and the comment directly above the \u0060-export\u0060 on this line says the exports below it are for testing. Erlang has no visibility below \u0060-export\u0060, so this is part of the module\u0027s public contract: it cannot be changed without a compatibility argument. This arm read the comment, not the call graph: if the comment is right and only tests call it, wrapping the attribute in \u0060-ifdef(TEST). \u2026 -endif.\u0060 keeps the test\u0027s access and removes it from the shipped module. If production code calls it, the comment is stale and wrapping the export would break the build \u2014 delete the comment and document the function as part of the module\u0027s API."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_config.erl"},"region":{"startLine":15}}}],"partialFingerprints":{"codehealthFindingId/v1":"1f476fa4559ac0a75e75143ae636dfb9b024f84209a207fbb56e1a485764bc5a"}},{"ruleId":"X31","level":"note","message":{"text":"Test-only surface in a production module: \u0060r3lfe_config:normalize_include_dirs/2\u0060 is exported unconditionally, and the comment directly above the \u0060-export\u0060 on this line says the exports below it are for testing. Erlang has no visibility below \u0060-export\u0060, so this is part of the module\u0027s public contract: it cannot be changed without a compatibility argument. This arm read the comment, not the call graph: if the comment is right and only tests call it, wrapping the attribute in \u0060-ifdef(TEST). \u2026 -endif.\u0060 keeps the test\u0027s access and removes it from the shipped module. If production code calls it, the comment is stale and wrapping the export would break the build \u2014 delete the comment and document the function as part of the module\u0027s API."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_config.erl"},"region":{"startLine":15}}}],"partialFingerprints":{"codehealthFindingId/v1":"effb9936957a98f4d06a5ca5d144611c598f9ae952cb7617b52eecc5862e86f4"}},{"ruleId":"X31","level":"note","message":{"text":"Test-only surface in a production module: \u0060r3lfe_dependency_scanner:parse_include_forms/1\u0060 is exported unconditionally, and the comment directly above the \u0060-export\u0060 on this line says the exports below it are for testing. Erlang has no visibility below \u0060-export\u0060, so this is part of the module\u0027s public contract: it cannot be changed without a compatibility argument. This arm read the comment, not the call graph: if the comment is right and only tests call it, wrapping the attribute in \u0060-ifdef(TEST). \u2026 -endif.\u0060 keeps the test\u0027s access and removes it from the shipped module. If production code calls it, the comment is stale and wrapping the export would break the build \u2014 delete the comment and document the function as part of the module\u0027s API."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_dependency_scanner.erl"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"e2cd5fed4b762bfbe335868499fcacc2ef3acd6a19d9b4574eef4f6a073ad870"}},{"ruleId":"X31","level":"note","message":{"text":"Test-only surface in a production module: \u0060r3lfe_dependency_scanner:extract_include_path/1\u0060 is exported unconditionally, and the comment directly above the \u0060-export\u0060 on this line says the exports below it are for testing. Erlang has no visibility below \u0060-export\u0060, so this is part of the module\u0027s public contract: it cannot be changed without a compatibility argument. This arm read the comment, not the call graph: if the comment is right and only tests call it, wrapping the attribute in \u0060-ifdef(TEST). \u2026 -endif.\u0060 keeps the test\u0027s access and removes it from the shipped module. If production code calls it, the comment is stale and wrapping the export would break the build \u2014 delete the comment and document the function as part of the module\u0027s API."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_dependency_scanner.erl"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"e521abec8b269798577f6451f015a3c269c5894414ab77dcc27c5109c314d0fd"}},{"ruleId":"X31","level":"note","message":{"text":"Test-only surface in a production module: \u0060r3lfe_dependency_scanner:classify_include/1\u0060 is exported unconditionally, and the comment directly above the \u0060-export\u0060 on this line says the exports below it are for testing. Erlang has no visibility below \u0060-export\u0060, so this is part of the module\u0027s public contract: it cannot be changed without a compatibility argument. This arm read the comment, not the call graph: if the comment is right and only tests call it, wrapping the attribute in \u0060-ifdef(TEST). \u2026 -endif.\u0060 keeps the test\u0027s access and removes it from the shipped module. If production code calls it, the comment is stale and wrapping the export would break the build \u2014 delete the comment and document the function as part of the module\u0027s API."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_dependency_scanner.erl"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"2a90ba40c02a4bf2951ea53b806b4d2b0dcd5122d954cdad14f9b1dcf1325f25"}},{"ruleId":"X31","level":"note","message":{"text":"Test-only surface in a production module: \u0060r3lfe_package:calculate_module_name/2\u0060 is exported unconditionally, and the comment directly above the \u0060-export\u0060 on this line says the exports below it are for testing. Erlang has no visibility below \u0060-export\u0060, so this is part of the module\u0027s public contract: it cannot be changed without a compatibility argument. This arm read the comment, not the call graph: if the comment is right and only tests call it, wrapping the attribute in \u0060-ifdef(TEST). \u2026 -endif.\u0060 keeps the test\u0027s access and removes it from the shipped module. If production code calls it, the comment is stale and wrapping the export would break the build \u2014 delete the comment and document the function as part of the module\u0027s API."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_package.erl"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"2e5684ee27f4d11dab13e3ab5f7956cdaf9cf793277c46484a65fc4199f00319"}},{"ruleId":"X31","level":"note","message":{"text":"Test-only surface in a production module: \u0060r3lfe_package:is_nested_file/2\u0060 is exported unconditionally, and the comment directly above the \u0060-export\u0060 on this line says the exports below it are for testing. Erlang has no visibility below \u0060-export\u0060, so this is part of the module\u0027s public contract: it cannot be changed without a compatibility argument. This arm read the comment, not the call graph: if the comment is right and only tests call it, wrapping the attribute in \u0060-ifdef(TEST). \u2026 -endif.\u0060 keeps the test\u0027s access and removes it from the shipped module. If production code calls it, the comment is stale and wrapping the export would break the build \u2014 delete the comment and document the function as part of the module\u0027s API."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_package.erl"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"05a38798d3ac9bd0fb91c3b7c760ecb5e8ada4c1fc94a5272651de174b7f2864"}},{"ruleId":"X31","level":"note","message":{"text":"Test-only surface in a production module: \u0060r3lfe_package:validate_module_name/1\u0060 is exported unconditionally, and the comment directly above the \u0060-export\u0060 on this line says the exports below it are for testing. Erlang has no visibility below \u0060-export\u0060, so this is part of the module\u0027s public contract: it cannot be changed without a compatibility argument. This arm read the comment, not the call graph: if the comment is right and only tests call it, wrapping the attribute in \u0060-ifdef(TEST). \u2026 -endif.\u0060 keeps the test\u0027s access and removes it from the shipped module. If production code calls it, the comment is stale and wrapping the export would break the build \u2014 delete the comment and document the function as part of the module\u0027s API."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_package.erl"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"1559d6075641ac2aba36fc10db0ad2c954f1bd2f5299efec2c18d6c8d9efabb6"}},{"ruleId":"X31","level":"note","message":{"text":"Test-only surface in a production module: \u0060r3lfe_prv_compile:info/1\u0060 is exported unconditionally, and the comment directly above the \u0060-export\u0060 on this line says the exports below it are for testing. Erlang has no visibility below \u0060-export\u0060, so this is part of the module\u0027s public contract: it cannot be changed without a compatibility argument. This arm read the comment, not the call graph: if the comment is right and only tests call it, wrapping the attribute in \u0060-ifdef(TEST). \u2026 -endif.\u0060 keeps the test\u0027s access and removes it from the shipped module. If production code calls it, the comment is stale and wrapping the export would break the build \u2014 delete the comment and document the function as part of the module\u0027s API."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_prv_compile.erl"},"region":{"startLine":11}}}],"partialFingerprints":{"codehealthFindingId/v1":"6a3672205ddde599463f94ba9125c78472ad877466d9db758d5c4d887352a301"}},{"ruleId":"X31","level":"note","message":{"text":"Test-only surface in a production module: \u0060r3lfe_prv_compile:get_dep_include_dirs/1\u0060 is exported unconditionally, and the comment directly above the \u0060-export\u0060 on this line says the exports below it are for testing. Erlang has no visibility below \u0060-export\u0060, so this is part of the module\u0027s public contract: it cannot be changed without a compatibility argument. This arm read the comment, not the call graph: if the comment is right and only tests call it, wrapping the attribute in \u0060-ifdef(TEST). \u2026 -endif.\u0060 keeps the test\u0027s access and removes it from the shipped module. If production code calls it, the comment is stale and wrapping the export would break the build \u2014 delete the comment and document the function as part of the module\u0027s API."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_prv_compile.erl"},"region":{"startLine":11}}}],"partialFingerprints":{"codehealthFindingId/v1":"52bc076b89724303ab053d5d4ca527e2e731f63adf5c84b9941b6546925f3c13"}},{"ruleId":"X31","level":"note","message":{"text":"Test-only surface in a production module: \u0060r3lfe_prv_confabulate:info/1\u0060 is exported unconditionally, and the comment directly above the \u0060-export\u0060 on this line says the exports below it are for testing. Erlang has no visibility below \u0060-export\u0060, so this is part of the module\u0027s public contract: it cannot be changed without a compatibility argument. This arm read the comment, not the call graph: if the comment is right and only tests call it, wrapping the attribute in \u0060-ifdef(TEST). \u2026 -endif.\u0060 keeps the test\u0027s access and removes it from the shipped module. If production code calls it, the comment is stale and wrapping the export would break the build \u2014 delete the comment and document the function as part of the module\u0027s API."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_prv_confabulate.erl"},"region":{"startLine":11}}}],"partialFingerprints":{"codehealthFindingId/v1":"fc5468e429dee304e01d720b9d37c6b28dac0ff401d0a7a94234995412af65d6"}},{"ruleId":"X31","level":"note","message":{"text":"Test-only surface in a production module: \u0060r3lfe_prv_defabulate:info/1\u0060 is exported unconditionally, and the comment directly above the \u0060-export\u0060 on this line says the exports below it are for testing. Erlang has no visibility below \u0060-export\u0060, so this is part of the module\u0027s public contract: it cannot be changed without a compatibility argument. This arm read the comment, not the call graph: if the comment is right and only tests call it, wrapping the attribute in \u0060-ifdef(TEST). \u2026 -endif.\u0060 keeps the test\u0027s access and removes it from the shipped module. If production code calls it, the comment is stale and wrapping the export would break the build \u2014 delete the comment and document the function as part of the module\u0027s API."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_prv_defabulate.erl"},"region":{"startLine":11}}}],"partialFingerprints":{"codehealthFindingId/v1":"e0b455afa1021b30d3939a3c6e8d30b55aa67eb2a0b9c583a2eaf30bc4fbf647"}},{"ruleId":"X31","level":"note","message":{"text":"Test-only surface in a production module: \u0060r3lfe_prv_repl:read_vm_args/1\u0060 is exported unconditionally, and the comment directly above the \u0060-export\u0060 on this line says the exports below it are for testing. Erlang has no visibility below \u0060-export\u0060, so this is part of the module\u0027s public contract: it cannot be changed without a compatibility argument. This arm read the comment, not the call graph: if the comment is right and only tests call it, wrapping the attribute in \u0060-ifdef(TEST). \u2026 -endif.\u0060 keeps the test\u0027s access and removes it from the shipped module. If production code calls it, the comment is stale and wrapping the export would break the build \u2014 delete the comment and document the function as part of the module\u0027s API."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_prv_repl.erl"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"e05a3991e6fe138397e171f6a3480fc2ceb96987c6f308c067ce8d76e3bc1488"}},{"ruleId":"X31","level":"note","message":{"text":"Test-only surface in a production module: \u0060r3lfe_prv_repl:build_shell_args/1\u0060 is exported unconditionally, and the comment directly above the \u0060-export\u0060 on this line says the exports below it are for testing. Erlang has no visibility below \u0060-export\u0060, so this is part of the module\u0027s public contract: it cannot be changed without a compatibility argument. This arm read the comment, not the call graph: if the comment is right and only tests call it, wrapping the attribute in \u0060-ifdef(TEST). \u2026 -endif.\u0060 keeps the test\u0027s access and removes it from the shipped module. If production code calls it, the comment is stale and wrapping the export would break the build \u2014 delete the comment and document the function as part of the module\u0027s API."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_prv_repl.erl"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"dbb52d21d4833a001bc7bcdd499f65951c21156805b7659d9fdbf217bb62427d"}},{"ruleId":"X31","level":"note","message":{"text":"Test-only surface in a production module: \u0060r3lfe_prv_repl:merge_repl_opts/2\u0060 is exported unconditionally, and the comment directly above the \u0060-export\u0060 on this line says the exports below it are for testing. Erlang has no visibility below \u0060-export\u0060, so this is part of the module\u0027s public contract: it cannot be changed without a compatibility argument. This arm read the comment, not the call graph: if the comment is right and only tests call it, wrapping the attribute in \u0060-ifdef(TEST). \u2026 -endif.\u0060 keeps the test\u0027s access and removes it from the shipped module. If production code calls it, the comment is stale and wrapping the export would break the build \u2014 delete the comment and document the function as part of the module\u0027s API."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/r3lfe_prv_repl.erl"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"da3fe308e78d535b666f76e8f726736b9a287971c12abc0612f699befc5073a9"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":17,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}