{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D23","name":"Boundary Type-Coupling","shortDescription":{"text":"Boundary Type-Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D23"},{"id":"D24","name":"Comment Value","shortDescription":{"text":"Comment Value"},"helpUri":"https://codehealth.canine.dev/dimensions/D24"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"}]}},"results":[{"ruleId":"D2","level":"warning","message":{"text":"AuthorizationBehaviour.Handle (cognitive 44): AuthorizationBehaviour.Handle has cognitive complexity 44 (threshold 15). To reduce it, flatten the nesting: invert conditions into early returns or guard clauses so the happy path stays at one level, and lift the deepest nested block into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"CleanArchitecture.Application/Behaviors/AuthorizationBehaviour.cs"},"region":{"startLine":25}}}],"partialFingerprints":{"codehealthFindingId/v1":"490b8e7444543dc39eb6249775655862c57f1235e015f4d83d30b2d737aba428"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: BaseRepo: TooManyMethods \u2014 172 significant lines (blank, comment-only and punctuation-only lines excluded), 52 methods. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"CleanArchitecture.Persistence/Repo/BaseRepo.cs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a881b7965131bf510cc0f4a25f01aadab338f22ba6c24d403f48fcfa82accc47"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): CleanArchitecture.Application/Extenstions/QueryableExtensions.cs:12-21 | CleanArchitecture.Application/Extenstions/QueryableExtensions.cs:31-40 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060CleanArchitecture.Application/Extenstions/QueryableExtensions.cs:12\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"CleanArchitecture.Application/Extenstions/QueryableExtensions.cs"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"63abaeda199339317f7781bf06da28c37240dd47f69e1dafdff3dc47960d1657"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: CleanArchitecture.Domain: CleanArchitecture.Domain: abstractness 0.08, instability 0.00, distance 0.92 \u2014 zone of pain \u2014 concrete and depended on by 4 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"296ffabd671aa0e0e1992ab7ce43288cc8ef9ce2815892faada8861d152851a7"}},{"ruleId":"D8","level":"warning","message":{"text":"Coverage not measured \u2014 test suite did not build: Coverage NOT MEASURED: this repository did not build in our analyzer environment (a C#/MSBuild compiler error), so no coverage could be collected. It is excluded from the score rather than counted as a near-zero defect. We did not read WHERE the failing diagnostic is, so this does not claim the fault is in your test code \u2014 a repository written for an older SDK band can compile for you and not for us. Run \u0060dotnet build\u0060 on this commit; if it succeeds, the gap is ours. Committing the Cobertura/OpenCover/lcov report your CI already produces also lets us measure real coverage without building anything."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"62e63e619c28f057e129f2997c965d32a457366a9ce18ca019ffb6bdfba85c99"}},{"ruleId":"D9","level":"note","message":{"text":"No tests found: No test suite could be collected \u2014 nothing here references a test framework (xUnit, NUnit or MSTest), so there were no discoverable tests to count. Tests written as plain executables or shell/PowerShell harnesses are not collectible this way and are not scored here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c9bf64cbb5a4ae13d6bcd01fa3bc8d2879d860c73bc67f176ee3c2cecb8adce3"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: AutoMapper.Extensions.Microsoft.DependencyInjection: AutoMapper.Extensions.Microsoft.DependencyInjection 12.0.1 \u2014 Legacy \u2014 the publisher\u0027s replacement is \u0060AutoMapper\u0060 \u003E= 13.0.0; migrate the reference to it."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"52fbb14c6e02894d83d6297e82403018d3b31d7773fc40d3ebf0f0944199151f"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.AspNetCore.Http.Abstractions: Microsoft.AspNetCore.Http.Abstractions 2.2.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ab239d92a1ed0e780896b6b47df6648aa988d7c5c2e552fd20a0b8d4943c6f81"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.AspNetCore.Localization: Microsoft.AspNetCore.Localization 2.2.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"26531cc0a8f6a9bf50680c007aee5f26e32a7194bccd89ac26f3ae131ebbbf2c"}},{"ruleId":"D16","level":"warning","message":{"text":"single-maintainer \u2014 knowledge-concentration (bus factor) risk: single-maintainer \u2014 knowledge-concentration (bus factor) risk (1 author(s) across 27 commit(s) sampled)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b4b49d961df742f0e507f4cc5c8094fb077ba0391a27fd015d18320865187719"}},{"ruleId":"D17","level":"warning","message":{"text":"CommentedOutCode: 5 consecutive commented-code lines"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"CleanArchitecture.Application/Behaviors/AuthorizationBehaviour.cs"},"region":{"startLine":33}}}],"partialFingerprints":{"codehealthFindingId/v1":"8d4a735041f4a1addfb2f9c8e1431fad8a9190e99001f6921a8ac3b789f2f872"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: //TODO:: cover all validation errors \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"CleanArchitecture.Application/Middleware/ErrorHandlerMiddleware.cs"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"4795b33cce5c933fa7a191162a5009271e4a6a435e30c765e2a8705b63bba58f"}},{"ruleId":"D17","level":"warning","message":{"text":"CommentedOutCode: 19 consecutive commented-code lines"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"CleanArchitecture.Identity/IdentityDependencies.cs"},"region":{"startLine":77}}}],"partialFingerprints":{"codehealthFindingId/v1":"8cfd98ed17fe8e8c5c03755b6aa28e750c04ea69e1e11859d5c1c72c00fb597f"}},{"ruleId":"D18","level":"note","message":{"text":"Shell project: Application.MSTest: \u0060Application.MSTest\u0060 contributes only 0 significant line(s) \u2014 an empty/placeholder project is structural noise. Remove it or fold its contents into a real project."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Application.MSTest/Application.MSTest.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"250e67eb2bd8e2bfe90865a9e5aeb2f5c7bdbf52eed6dac625c276326a0582cc"}},{"ruleId":"D18","level":"note","message":{"text":"Thin analysable surface across projects: 2 project(s) carry only a thin slice of real code (e.g. \u0060CleanArchitecture.Infrustructure\u0060 with 12 significant line(s)). The mean analysable-surface weight is 86 %, lowering Solution Shape by about 1.11 point(s). Consolidate thin projects or grow them into substantial, well-scoped assemblies."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"dd0b92fd965c2065080f16843920964ee00f7696ea03d87cdf61aed4cd2c746a"}},{"ruleId":"D19","level":"note","message":{"text":"The .NET Core project has open-source third-party libraries (jQuery, jQuery Validation) under the OpenJS Foundation license but no LICENSE file for any of them in the wwwroot/lib/ directory.: Add a LICENSE entry for each third-party library placed in wwwroot/lib/* so contributors and users know where to find its license."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"CleanArchitecture.Mvc/wwwroot/lib/jquery/LICENSE.txt"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3e1e9bc98ca21627e8ec6be533e99e659b314be3f2d58c562261b17513865f76"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found at common paths; consider documenting architectural decisions in Docs/ADL/ or similar."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D21","level":"note","message":{"text":"The command for assigning a role to a user is named \u0027AssignRoleToUserCommand\u0027, but the corresponding service method is named \u0027AddRoleToUser\u0027. The verb \u0027Assign\u0027 is used in the request model but \u0027Add\u0027 is used in the service implementation.: Align the service method name to \u0027AssignRoleToUser\u0027 or rename the command to \u0027AddRoleToUserCommand\u0027 for consistency. (symbols: CleanArchitecture.Application.Features.Roles.Requests.Commands.AssignRoleToUserCommand, CleanArchitecture.Identity.Services.RoleService.AddRoleToUser)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1aa1431cec5d4c0b79b659b6c7c62dc1f79299fc25a2f8622e4fac56d86d5d05"}},{"ruleId":"D21","level":"note","message":{"text":"The command for adding a claim to a role is named \u0027AddClaimToRoleCommand\u0027, and the service method is \u0027AddClaimToRole\u0027. While consistent with each other, the verb \u0027Add\u0027 is used here, whereas \u0027Assign\u0027 is used for the similar \u0027Role\u0027 assignment operation.: Consider using \u0027AssignClaimToRole\u0027 for both the command and service method to align with the \u0027Assign\u0027 verb used for role assignments. (symbols: CleanArchitecture.Application.Features.Roles.Requests.Commands.AddClaimToRoleCommand, CleanArchitecture.Identity.Services.RoleService.AddClaimToRole)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6ee093d96d8364508597e1efd15931cbc36a1fc66299c72ff5df7a4fead20ea8"}},{"ruleId":"D21","level":"note","message":{"text":"The command for assigning a claim to a user is named \u0027AssignClaimToUserCommand\u0027, but the service method is named \u0027AddClaimToUser\u0027.: Align the service method name to \u0027AssignClaimToUser\u0027 or rename the command to \u0027AddClaimToUserCommand\u0027 for consistency. (symbols: CleanArchitecture.Application.Features.Roles.Requests.Commands.AssignClaimToUserCommand, CleanArchitecture.Identity.Services.RoleService.AddClaimToUser)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ec8354cc773708c33a01c91b38ccc978d80b8db6563939eba1d8c02ea61f5bd2"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent use of \u0027Add\u0027 vs \u0027Assign\u0027 for similar operations. \u0027AddClaimToRoleCommand\u0027 uses \u0027Add\u0027, while \u0027AssignClaimToUserCommand\u0027 uses \u0027Assign\u0027.: Standardize on one verb (e.g., \u0027Assign\u0027 for both) to reflect that these are assignments of relationships rather than simple additions. (symbols: CleanArchitecture.Application.Features.Roles.Requests.Commands.AddClaimToRoleCommand, CleanArchitecture.Application.Features.Roles.Requests.Commands.AssignClaimToUserCommand)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"71fc8e20559eb47c1cfab27bba1336f1ca66f3cab4efc33659f28f1fc42e0743"}},{"ruleId":"D21","level":"note","message":{"text":"The command for assigning a role to a user uses \u0027Assign\u0027, while the command for assigning a claim to a user also uses \u0027Assign\u0027. However, the service methods differ (\u0027Add\u0027 vs \u0027Assign\u0027).: Ensure the service methods match the command verbs. If \u0027Assign\u0027 is the preferred term for these relationships, rename the service methods accordingly. (symbols: CleanArchitecture.Application.Features.Roles.Requests.Commands.AssignRoleToUserCommand, CleanArchitecture.Application.Features.Roles.Requests.Commands.AssignClaimToUserCommand)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"24bcc7f5ba80bcd09e1c0983d8a45a6d133add6477080100987a9950a430716d"}},{"ruleId":"D23","level":"note","message":{"text":"Bounded contexts not declared: At 2917 LoC across 8 projects the codebase is large and multi-module, so explicit bounded contexts are needed. Name this codebase\u0027s bounded contexts (\u22652 module groups, e.g. per subsystem) so cross-boundary type coupling can be assessed. Declare them in \u0060.codehealth/config.yaml\u0060 at the repository root (create it if absent), mapping each context name to the module-path or namespace prefixes that belong to it \u2014 e.g. \u0060architecture:\u0060 \u2192 \u0060contexts:\u0060 \u2192 \u0060Billing: [\u0022src/billing\u0022, \u0022Acme.Billing\u0022]\u0060, \u0060Catalog: [\u0022src/catalog\u0022, \u0022Acme.Catalog\u0022]\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1c7e276c9c682731f01819ed5378b90ca320cde1b583c90920172911598362b3"}},{"ruleId":"D24","level":"note","message":{"text":"misleading comment: \u0022Add services to the container.\u0022 \u2014 Delete - AddMediatR and AddAuthentication are registrations; this restates Add(IServiceCollection) rather than explaining WHY add them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"CleanArchitecture.Api/Program.cs"},"region":{"startLine":11}}}],"partialFingerprints":{"codehealthFindingId/v1":"5377e574be1c052ae414f64109f3e7b4778da79530f7293c98b8bf2821d3e3f0"}},{"ruleId":"D24","level":"note","message":{"text":"misleading comment: \u0022Configure TokenValidationParameters\u0022 \u2014 Fix - the comment is a stub, not the actual code being documented. The real comment should explain what validation parameters are set here and why they matter."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"CleanArchitecture.Identity/Services/IdentityService.cs"},"region":{"startLine":83}}}],"partialFingerprints":{"codehealthFindingId/v1":"d83525f9623bbe30bfe6c86de0d3cba6db48fd4f1815c137ccdbbd909ed4a31b"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6444bebef6a2b7c1a780c2519451844e5574c89e6734193baad0ebdf3621631e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cd909376dbe64d39e1d7487d86a4cd7c7a2e3b39bcf2db77b8411cac8ea2c104"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a9b844b6c8c1cd10c637ec0a93e254d503dd4fd0ae1081566e79ce9e5ec0ef8e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d68f7101d68f81a416c587fc75c184582e6f28ddb6e0d8e7a2fea42efc952904"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"21c0dea1e87823862eae16667d0d5ffd89a73c74f47f1875df3fb0db30fb4d9c"},"taxa":[{"id":"CWE-613","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"aac3766f62c092d438e2d962a2badeb1cd12f8160b4b6435280558f7ee5a3de5"},"taxa":[{"id":"CWE-862","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4e4448b31e8b4dd1a6489e264df38146de5afb770ee8e6556d999f07ae5800a8"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d3458738a9b505811049a751f4012492d190bd65163306d4a068a5ebbf0982b5"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"232013a63d845603c2a626f52ada8d8ad59691f3c568e940aad78d11f17c4f7b"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b74ed2402a32a3483f0222438e364162079e47e69d6fc647f12c48e4e51634de"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9b1edc6c5709bced9c1610ceea5038d37f22592f9e1b77be60513c55be5f6020"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"03b31df8570933308505a1624e4fd5ee0390537c65b94f5898a4ad85f2c0b177"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a9fd6c4f13eca413e6ee281165116f5d3103d0f420a58f7e31ac0f01002a05c3"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9b95c7f70b5ad8865f097e370868df43e0f61bc9dc4fee12b1725c6895e596c0"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"92ecbbe6239883511716fc87fc2172ba7b6bbe16bddb5b2893bae19b65877837"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0ec952ada219fe5a028e3a8aa8d56d26ded08861b1152c70e1e8a6609e9450b6"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f0283fefd69ded207beb5469b27e465d9c8060dc2c965c70204f65b73a4446e9"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"864002a5a4fc44333de574ab02e4076c626972c76f4d49734f161b89e756b2a0"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8c5befb86e53034ab72e241f96f9bcdd1112c97a565b97a680e23a0ef98049c9"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9edcd1fe22279a6cdb47df108e8a3cf0b833bb878bb5bc4a9e1a92f2ae090c4d"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"875991af1d30c7d9ab802abc53d9c685d0ca9934ffd5ad7d5f5d2eb32e4a8df7"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"286328dc012f755dbc5499c710be3e1e805ec38fbacc8654c10fa0cd0c05d824"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9958b7e6670990c30eeec58379cd7231ce9dfd166e88c4414fae46d2018a6e0b"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"09384a97da30bf1dac29184a6c4772b49d46ad8b9b39eda15d25643c72fddb71"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"500c56d1154b6703a85e24b9c841b4a406a5c2b2ac901404d6ed39d2508de2d0"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c132b998930b71f3c6379d2ef6b07948e343d47391f37b543876716d0ef2b020"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7273280dcd8f4031d8edecebe4f87a896668de0e5e0cc93987067e5bfc3fc659"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8824e55d1da1085aee1af5ee1a8437b587443a677a751bd2fe2f8ea598d95eef"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6a25d88a5017215a5581dbd818019705bf9c568acca819c6b7233f6b702f1926"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"69ddfcdd1e7bb99f6a1c265f8192516c6f61bf2b98a50a656a0aa07e0e3ab8ff"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b67c0aca0aaaa61146d54cea151b0f662e4d48c414e78f8e85ad1406a0e09cb6"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3257bcafd27dcaedc602292873b591c905bc91653c19544886d5893388dc7015"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c005f9c2df48e726dc4c6cba5c7a18d0f179aec90bb7e849f0280754002a7831"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-613","guid":"b3754f88-69aa-ee5f-9be5-dea9f3c46b9e","name":"CWE-613","shortDescription":{"text":"CWE-613"},"helpUri":"https://cwe.mitre.org/data/definitions/613.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-862","guid":"2d96ecd7-f7f1-7f55-9f3a-43bb5bafdf33","name":"CWE-862","shortDescription":{"text":"CWE-862"},"helpUri":"https://cwe.mitre.org/data/definitions/862.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":33,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}