{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"}]}},"results":[{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: Reddnet.Domain: Reddnet.Domain: abstractness 0.29, instability 0.00, distance 0.71 \u2014 zone of pain \u2014 concrete and depended on by 3 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4027f98ab106e44e0f76ba71da94d4d39fa05160508c522cfd2d10c3bd7a8c2e"}},{"ruleId":"D8","level":"error","message":{"text":"No automated tests: No automated tests \u2014 no test code was found in this repository. Untested code is the largest single risk to changing it safely."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3132564c6310e5d01a231f252a02d5d2f5a542c0a8fa29a14c89693f1e3df871"}},{"ruleId":"D9","level":"note","message":{"text":"No tests found: No test suite could be collected \u2014 nothing here references a test framework (xUnit, NUnit or MSTest), so there were no discoverable tests to count. Tests written as plain executables or shell/PowerShell harnesses are not collectible this way and are not scored here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c9bf64cbb5a4ae13d6bcd01fa3bc8d2879d860c73bc67f176ee3c2cecb8adce3"}},{"ruleId":"D17","level":"warning","message":{"text":"BarePragmaDisable: #pragma warning disable CS8632 \u2014 the disable has no matching restore, so it does not end with the construct that needed it: it runs to the end of the file and silences the rule for everything written below, including code added years later. Close it with the matching restore directive immediately after the construct it covers, or fix the cause and drop the directive entirely."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Source/Reddnet.Application/Community/Commands/UpdateCommunityCommand.cs"},"region":{"startLine":11}}}],"partialFingerprints":{"codehealthFindingId/v1":"7dd508d9ff1b0b13ef7911c2cca08767e17b228d08e0fc984b0526d73c1ad5d6"}},{"ruleId":"D17","level":"warning","message":{"text":"BarePragmaDisable: #pragma warning disable CS8632 \u2014 the disable has no matching restore, so it does not end with the construct that needed it: it runs to the end of the file and silences the rule for everything written below, including code added years later. Close it with the matching restore directive immediately after the construct it covers, or fix the cause and drop the directive entirely."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Source/Reddnet.Application/Post/Commands/UpdatePostCommand.cs"},"region":{"startLine":11}}}],"partialFingerprints":{"codehealthFindingId/v1":"a6ada84bd40a5df55571acf7da03bdeac04e7bdf9794cb92771cf5934f01a9a1"}},{"ruleId":"D17","level":"warning","message":{"text":"BarePragmaDisable: #pragma warning disable CS8632 \u2014 the disable has no matching restore, so it does not end with the construct that needed it: it runs to the end of the file and silences the rule for everything written below, including code added years later. Close it with the matching restore directive immediately after the construct it covers, or fix the cause and drop the directive entirely."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Source/Reddnet.Application/Validation/Result.cs"},"region":{"startLine":28}}}],"partialFingerprints":{"codehealthFindingId/v1":"53ec110e737c3d94ed0e624e8cdc263362ca09ffb495af97a670590d2d5d268d"}},{"ruleId":"D17","level":"warning","message":{"text":"BarePragmaDisable: #pragma warning disable RCS1155 \u2014 the disable has no matching restore, so it does not end with the construct that needed it: it runs to the end of the file and silences the rule for everything written below, including code added years later. Close it with the matching restore directive immediately after the construct it covers, or fix the cause and drop the directive entirely."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Source/Reddnet.Application/Post/Queries/GetPostsByFilter.cs"},"region":{"startLine":26}}}],"partialFingerprints":{"codehealthFindingId/v1":"114583d1cab80a3a0f102485db5ca4695225588bd5c8e3c99cbbd2dde3c5642f"}},{"ruleId":"D19","level":"note","message":{"text":"The \u0027Getting Started\u0027 section is a bare template with only prerequisites and an empty setup; no actual steps or environment variables are shown.: Add the exact commands for each step (dotnet restore, dotnet build, dotnet run) and any required environment variables."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"fac6e3e88eca12d26ee0a9730b7c77e2c6002c2b51a51e5ec08e1353d5706c49"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found at common paths; consider documenting architectural decisions in Docs/ADL/ or similar."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent terminology for \u0027Community\u0027 entities. Some handlers/queries use \u0027Subreddit\u0027 in their name, while others (e.g., CreateCommunityCommand, GetAllCommunitiesQuery) use \u0027Community\u0027.: Standardize on \u0027Community\u0027 to match the domain entities (CommunityEntity) and most commands/queries. (symbols: Reddnet.Application.Community.Queries.GetSubredditByNameHandler, Reddnet.Application.Community.Queries.GetAllSubredditsHandler, Reddnet.Application.Community.Commands.CreateSubredditHandler, Reddnet.Application.Community.Commands.DeleteSubredditHandler, Reddnet.Application.Community.Commands.UpdateSubredditHandler)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d3be5ce08877ee4ff459b1f487152a5954d3b5ce16aa814cb695da60c2283b70"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent naming for the current user context. \u0027User\u0027 is used in the Authorization namespace, but \u0027UserEntity\u0027 is used for the domain model. Additionally, \u0027User\u0027 is used for the current user context, while \u0027IUser\u0027 and \u0027IUserEntity\u0027 are used for interfaces and domain models respectively.: Clarify the distinction between the current user context (e.g., CurrentUser or AuthUser) and the domain entity (UserEntity). Ensure interfaces and models have distinct names to avoid confusion. (symbols: Reddnet.Web.Authorization.User, Reddnet.Web.Authorization.User.UserName, Reddnet.Web.Authorization.User.Id)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f410f53db7935e3d85d1f1c084697888a362b6dd333529cf6aaf210c8b5802ee"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent naming for Post queries. Some use \u0027GetPosts\u0027 (plural) while others use \u0027GetPost\u0027 (singular) or \u0027GetPostById\u0027. Also, \u0027GetPostsByFilter\u0027 vs \u0027GetPostsByUserName\u0027 vs \u0027GetPostById\u0027 shows a mix of query types.: Standardize query naming to \u0027GetPostBy...\u0027 or \u0027GetPostsBy...\u0027 consistently based on the return type (single vs collection). (symbols: Reddnet.Application.Post.Queries.GetPostsByFilter, Reddnet.Application.Post.Queries.GetPostsByFilterHandler, Reddnet.Application.Post.Queries.GetPostsByUserName, Reddnet.Application.Post.Queries.GetPostsByUserNameHandler, Reddnet.Application.Post.Queries.GetPostByIdQuery, Reddnet.Application.Post.Queries.GetPostByIdHandler)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c8bce6deb53738e91be7ba16c07db5cebf62f49cbaf03ee1192f24e9f0cd9438"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent naming for Community commands. Some use \u0027Community\u0027 while others use \u0027Subreddit\u0027 (see above). Also, the command names are consistent within the Community namespace, but inconsistent with the Query/Handler names in the same namespace.: Align Community commands with the \u0027Community\u0027 terminology used in most other parts of the codebase. (symbols: Reddnet.Application.Community.Commands.CreateCommunityCommand, Reddnet.Application.Community.Commands.UpdateCommunityCommand, Reddnet.Application.Community.Commands.DeleteCommunityCommand, Reddnet.Application.Community.Commands.CreateCommunityCommand, Reddnet.Application.Community.Commands.UpdateCommunityCommand, Reddnet.Application.Community.Commands.DeleteCommunityCommand)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"666426a7408cad34c4d4a36de161c41862cfc85c408213630e7c99c549df1c88"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent naming for Post commands and handlers. \u0027Post\u0027 is used consistently here, which is good. However, compare with Community/Reply naming.: Ensure all Post-related commands and handlers use \u0027Post\u0027 consistently. (symbols: Reddnet.Application.Post.Commands.CreatePostCommand, Reddnet.Application.Post.Commands.UpdatePostCommand, Reddnet.Application.Post.Commands.DeletePostCommand, Reddnet.Application.Post.Commands.CreatePostHandler, Reddnet.Application.Post.Commands.UpdatePostHandler, Reddnet.Application.Post.Commands.DeletePostHandler)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d78d625fd9b2389c988e97dee2c567061296160a6c7a8e4aaac137d33a7a3b4e"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent naming for page models. \u0027EditModel\u0027, \u0027CreateModel\u0027, \u0027DeleteModel\u0027 are used. This is consistent within each entity\u0027s namespace.: No inconsistency, but ensure all page models follow the same naming convention. (symbols: Reddnet.Web.Pages.Community.EditModel, Reddnet.Web.Pages.Community.CreateModel, Reddnet.Web.Pages.Community.DeleteModel, Reddnet.Web.Pages.Post.EditModel, Reddnet.Web.Pages.Post.CreateModel, Reddnet.Web.Pages.Post.DeleteModel, Reddnet.Web.Pages.Post.EditModel, Reddnet.Web.Pages.Post.CreateModel, Reddnet.Web.Pages.Post.DeleteModel, Reddnet.Web.Pages.Reply.DeleteModel)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"fd3001c3043068919c3d13a08b9af751d86ee885c83983c5626aba916657dbac"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c3e6c10c115b57ff13e2c6ecffdcfba0f101bfd55dda1c77353120af7b930b5e"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1f79a595d62add568feda19f54d04fdad0273f072ae213a4e4ad714127a8a2fe"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f731ad12a73ffc98e36af5ede2fa695a0c9b4540e95dea58f51d97f6da68570b"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"75683b379cef509edf9d64481e25766e752c53804df7591967e67e7d9b68e8f3"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"aa3bbb3371f0884e02bd084b9c67af8190d8ac63ced4118bb48e9bd7f7ce927d"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9470d7d3a2af61c0fbee35450930b4f2eb2ad2baab5a0ef4a90f26bfb30cda50"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0912468502895fef4191cf23b29c5d522839d785a26e658050b8cfe283b341f2"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e951121f453b4896c50a66b0d8b0eae9a46b14a5f577bf0d665634737b99a841"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"14d8fa5b374706f2a23b008484ae491b6498dedf4e25e13a0f4f0850a7c57e1f"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"76fcbc4b336aee9ba2226e1cccce9f9ff607a7c674dce255b4aec71c1a56ca49"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a032a72549b25fa4b110e49c0f8600b47f75a4b99d48bdca2b066d4b34e0c034"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"03b31df8570933308505a1624e4fd5ee0390537c65b94f5898a4ad85f2c0b177"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7cf85abffe732f2645ef95a624d6badc26f0263616284d6a4cc46ca8e983031d"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b96b7173c4377d5bea4d6fd7b52323631c631c44172b743bec6f266c10a4e538"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d0d58bee8a1f84a88e57c1b51f58995d8a12fbcde8de290222bddbe5d55c45be"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"58106056685967c09bcfc6d8c9b4b4481cf0b2853763e609447eae2b66e5c321"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e50124f15b14c54e2fe2b23106e34393c49b65d3a3d6323c15f8756c0bf9229e"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9cec1f5663228ba23d32e17d6db71e311c6fd868ef96d60d0998ed8f060b767a"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"44ce2d8b93d43078ef26152644bdd0169c325f698c1c93c0f6080cade22dd30d"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"468c774f848f9e826068575818af846e86f4df2e9b24474b2686c992eed7aa36"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"65b1d0b7217bcf35dff4a58430c6a66ebe6040cf4433d8ab69bd8b52902829a1"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eed4294f9e1eae21e5d60eedc4e4758881e81814e4f18d62e0c956c4a0671f12"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e5292a00ee09746542cf06089863ccdcb8fe3b8987e1fe5363e069c89ef1a54"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"59b6b49e35b44acf37dcd783be5e03d7633342f6cc76f6d0601a074150801b4c"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0d9eec6fa3579d9bfbc2acea0c4ea50af890d1da3d401368bce67e90fc79514a"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6263a56fe3a70af87a269967837af0dd5b722c97091869d8433487b538f5d47f"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"de0152212ca8b0d3aa7654014e44d070de785c3d7870950658b1a178eece01d2"}},{"ruleId":"D30","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"626d0f9bc2a4dc54e69bf1646c0e82ca21e35de834996dce34f8cfc90e4588b8"}},{"ruleId":"D30","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"655d03e4bab03415a7a1cd63e9bfa256517be2ba114e00dbbed29519dd5b5252"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":29,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}