{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D10","name":"Test Quality","shortDescription":{"text":"Test Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D10"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AC2","name":"Forms \u0026 labels","shortDescription":{"text":"Forms \u0026 labels"},"helpUri":"https://codehealth.canine.dev/dimensions/AC2"},{"id":"AC3","name":"Page structure","shortDescription":{"text":"Page structure"},"helpUri":"https://codehealth.canine.dev/dimensions/AC3"},{"id":"AC5","name":"ARIA correctness","shortDescription":{"text":"ARIA correctness"},"helpUri":"https://codehealth.canine.dev/dimensions/AC5"},{"id":"AC6","name":"Visual \u0026 motion safety","shortDescription":{"text":"Visual \u0026 motion safety"},"helpUri":"https://codehealth.canine.dev/dimensions/AC6"},{"id":"AC7","name":"A11y enforcement","shortDescription":{"text":"A11y enforcement"},"helpUri":"https://codehealth.canine.dev/dimensions/AC7"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"ED5","name":"Idempotency","shortDescription":{"text":"Idempotency"},"helpUri":"https://codehealth.canine.dev/dimensions/ED5"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P10","name":"Library API \u0026 versioning","shortDescription":{"text":"Library API \u0026 versioning"},"helpUri":"https://codehealth.canine.dev/dimensions/P10"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P2","name":"Observability","shortDescription":{"text":"Observability"},"helpUri":"https://codehealth.canine.dev/dimensions/P2"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"PF3","name":"Async \u0026 latency hygiene","shortDescription":{"text":"Async \u0026 latency hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/PF3"},{"id":"R1","name":"Type Safety","shortDescription":{"text":"Type Safety"},"helpUri":"https://codehealth.canine.dev/dimensions/R1"},{"id":"R10","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/R10"},{"id":"R2","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/R2"},{"id":"R3","name":"Large Files","shortDescription":{"text":"Large Files"},"helpUri":"https://codehealth.canine.dev/dimensions/R3"},{"id":"R4","name":"Test Coverage","shortDescription":{"text":"Test Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/R4"},{"id":"R6","name":"Tooling","shortDescription":{"text":"Tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/R6"},{"id":"R7","name":"Dead Code","shortDescription":{"text":"Dead Code"},"helpUri":"https://codehealth.canine.dev/dimensions/R7"},{"id":"R8","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/R8"},{"id":"R9","name":"Circular Imports","shortDescription":{"text":"Circular Imports"},"helpUri":"https://codehealth.canine.dev/dimensions/R9"},{"id":"SC1","name":"Supply-chain hygiene","shortDescription":{"text":"Supply-chain hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/SC1"},{"id":"X1","name":"Async correctness","shortDescription":{"text":"Async correctness"},"helpUri":"https://codehealth.canine.dev/dimensions/X1"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X12","name":"Unreachable branch","shortDescription":{"text":"Unreachable branch"},"helpUri":"https://codehealth.canine.dev/dimensions/X12"},{"id":"X13","name":"Undrained process stream","shortDescription":{"text":"Undrained process stream"},"helpUri":"https://codehealth.canine.dev/dimensions/X13"},{"id":"X14","name":"Bypassable address classification","shortDescription":{"text":"Bypassable address classification"},"helpUri":"https://codehealth.canine.dev/dimensions/X14"},{"id":"X15","name":"Unvalidated length from an untrusted reader","shortDescription":{"text":"Unvalidated length from an untrusted reader"},"helpUri":"https://codehealth.canine.dev/dimensions/X15"},{"id":"X16","name":"Unfloored truncation loop","shortDescription":{"text":"Unfloored truncation loop"},"helpUri":"https://codehealth.canine.dev/dimensions/X16"},{"id":"X18","name":"Disposal-pattern correctness","shortDescription":{"text":"Disposal-pattern correctness"},"helpUri":"https://codehealth.canine.dev/dimensions/X18"},{"id":"X19","name":"Unrestored process-global state","shortDescription":{"text":"Unrestored process-global state"},"helpUri":"https://codehealth.canine.dev/dimensions/X19"},{"id":"X20","name":"Mistyped argument guard","shortDescription":{"text":"Mistyped argument guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X20"},{"id":"X21","name":"Side-effecting pattern guard","shortDescription":{"text":"Side-effecting pattern guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X21"},{"id":"X23","name":"Unguarded diagnostic materialisation","shortDescription":{"text":"Unguarded diagnostic materialisation"},"helpUri":"https://codehealth.canine.dev/dimensions/X23"},{"id":"X24","name":"Document value interpolated into markup unescaped","shortDescription":{"text":"Document value interpolated into markup unescaped"},"helpUri":"https://codehealth.canine.dev/dimensions/X24"},{"id":"X25","name":"Inert configuration knob","shortDescription":{"text":"Inert configuration knob"},"helpUri":"https://codehealth.canine.dev/dimensions/X25"},{"id":"X26","name":"Unsynchronised callback handoff","shortDescription":{"text":"Unsynchronised callback handoff"},"helpUri":"https://codehealth.canine.dev/dimensions/X26"},{"id":"X28","name":"Index access outside its own emptiness guard","shortDescription":{"text":"Index access outside its own emptiness guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X28"},{"id":"X29","name":"Per-element action decided by a fixed element","shortDescription":{"text":"Per-element action decided by a fixed element"},"helpUri":"https://codehealth.canine.dev/dimensions/X29"},{"id":"X30","name":"Support guard that admits what it rejects","shortDescription":{"text":"Support guard that admits what it rejects"},"helpUri":"https://codehealth.canine.dev/dimensions/X30"},{"id":"X32","name":"Type resolved by simple name across every loaded assembly","shortDescription":{"text":"Type resolved by simple name across every loaded assembly"},"helpUri":"https://codehealth.canine.dev/dimensions/X32"},{"id":"X5","name":"Nullable reference types","shortDescription":{"text":"Nullable reference types"},"helpUri":"https://codehealth.canine.dev/dimensions/X5"},{"id":"X6","name":"Hand-rolled structured-format parsing","shortDescription":{"text":"Hand-rolled structured-format parsing"},"helpUri":"https://codehealth.canine.dev/dimensions/X6"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: html/resource.ex: FileTooLong \u2014 938 significant lines (blank, comment-only and punctuation-only lines excluded), declaring 51 functions. The bar is 500 significant lines; this is 438 over it, 1.88\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/backpex/html/resource.ex"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d18ded31853ec2f20ca2dec57c8e64f0ccee0f8ddf558265b668ba7714e6a4c2"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: html/layout.ex: FileTooLong \u2014 649 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 149 over it, 1.30\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/backpex/html/layout.ex"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1abcfdee14b40b68487716907bde608cb7e784fddc8aae380367c865dec6ad8b"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: live_resource/index.ex: FileTooLong \u2014 646 significant lines (blank, comment-only and punctuation-only lines excluded), declaring 46 functions. The bar is 500 significant lines; this is 146 over it, 1.29\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/backpex/live_resource/index.ex"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"dd695d427839f280c8302b9032e8989e4effb33a9d8537970b307400aec7284e"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: backpex/live_resource.ex: FileTooLong \u2014 569 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 69 over it, 1.14\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/backpex/live_resource.ex"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"caa699c6b43486b33ff1b3ece3570baa5574e4533c6d1c119a40f63627b4d108"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFunctions: Ecto: TooManyFunctions \u2014 32 functions. The bar is 30 functions; this is 2 over it, 1.07\u00D7 the bar. The counted members are a module\u0027s functions \u2014 a module holds no instance state, so there is no shared data to group them by and no type to move them onto. To reduce it, extract each cohesive family of functions into a new module of its own and have this one delegate to it, so no single module carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/backpex/adapters/ecto.ex"},"region":{"startLine":2}}}],"partialFingerprints":{"codehealthFindingId/v1":"4715255fdaa3c16df554ba22c190886373535bb273137eddc37cd0b501e51118"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: html/form.ex: FileTooLong \u2014 510 significant lines (blank, comment-only and punctuation-only lines excluded). The bar is 500 significant lines; this is 10 over it, 1.02\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/backpex/html/form.ex"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ead61e229c87e50d69225dad3f24d424ed337ea63c2d3f80937b458c2cf4b6fc"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: fields/has_many.ex: FileTooLong \u2014 506 significant lines (blank, comment-only and punctuation-only lines excluded), declaring 35 functions. The bar is 500 significant lines; this is 6 over it, 1.01\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/backpex/fields/has_many.ex"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"126a71a1e3d7441d887252ab03cd862b61c80982fdc0d2e455d1747871206f7f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 3): lib/backpex/fields/date.ex:77-90 | lib/backpex/fields/date_time.ex:77-90 | lib/backpex/fields/time.ex:50-63 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from all 3 call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/backpex/fields/date.ex"},"region":{"startLine":77}}}],"partialFingerprints":{"codehealthFindingId/v1":"aa155678d75479bb85a028441e12519cb19c3ee8cfd31e00f62eb2bd36e8d7d8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13\u201314 lines \u00D7 2): lib/backpex/live_components/form_component.ex:246-259 | lib/backpex/live_components/form_component.ex:294-306 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/backpex/live_components/form_component.ex"},"region":{"startLine":246}}}],"partialFingerprints":{"codehealthFindingId/v1":"aec05c708e8c4a131dfdef7aae4a7bbd96869e94409545b4eaae697fa64d68f4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): lib/backpex/live_resource/form.ex:47-53 | lib/backpex/live_resource/index.ex:96-102 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/backpex/live_resource/form.ex"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"6a26e85d77febfdffcdf27a451e8855c40aa777b30e0c6e3ba3298797405f9ea"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (69 lines \u00D7 4): lib/backpex/fields/boolean.ex:27-95 | lib/backpex/fields/email.ex:31-99 | lib/backpex/fields/number.ex:32-107 | lib/backpex/fields/text.ex:31-99 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from all 4 call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/backpex/fields/boolean.ex"},"region":{"startLine":27}}}],"partialFingerprints":{"codehealthFindingId/v1":"9c3d9e6c2eb0fdf98ba9e24f9098da7a2072b80030cc52606da9c7af43bcd2f7"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): lib/backpex/fields/belongs_to.ex:292-299 | lib/backpex/fields/select.ex:167-174 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/backpex/fields/belongs_to.ex"},"region":{"startLine":292}}}],"partialFingerprints":{"codehealthFindingId/v1":"9f712966a8707a6a1ee37b65ca80b2d711312db4273b226f666974b0b57f55f1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): lib/backpex/fields/date_time.ex:122-129 | lib/backpex/fields/time.ex:95-102 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/backpex/fields/date_time.ex"},"region":{"startLine":122}}}],"partialFingerprints":{"codehealthFindingId/v1":"b7052a902f86200c83a39d1cf6839c95b9a0fa3919b4f726a6e69bfc962adb20"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): lib/backpex/fields/has_many.ex:648-652 | lib/backpex/fields/multi_select.ex:259-263 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/backpex/fields/has_many.ex"},"region":{"startLine":648}}}],"partialFingerprints":{"codehealthFindingId/v1":"95fb0a74e3a325afc0f43c070fbbfc29235d278afad06da8198206edc43f2adf"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (21 lines \u00D7 2): demo/lib/demo_web/live/user_live.ex:243-263 | demo/lib/demo_web/resource_actions/upload.ex:67-87 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"demo/lib/demo_web/live/user_live.ex"},"region":{"startLine":243}}}],"partialFingerprints":{"codehealthFindingId/v1":"fbfd91a6ba1dc96c4002144fa03769babab78d6eb56a5f4d91b93d34325bd190"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 3): demo/lib/demo/address.ex:24-38 | demo/lib/demo/film_review.ex:18-26 | demo/lib/demo/tag.ex:21-29 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from all 3 call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"demo/lib/demo/address.ex"},"region":{"startLine":24}}}],"partialFingerprints":{"codehealthFindingId/v1":"dc881918de6cb0aa7f253bfe1b489b098851e1e50237e60e6c6564c6821d9ba0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): demo/lib/demo_web/live/product_live.ex:196-201 | demo/lib/demo_web/live/user_live.ex:270-275 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"demo/lib/demo_web/live/product_live.ex"},"region":{"startLine":196}}}],"partialFingerprints":{"codehealthFindingId/v1":"edd41444f99f930fe6d2cd3034bfaac18066b1c6a71248773a80e4329b6b102b"}},{"ruleId":"D12","level":"warning","message":{"text":"Unbounded dependency requirement: postgrex: Runtime dependency \u0060:postgrex\u0060 is declared \u0060\u0022\u003E= 0.0.0\u0022\u0060 in demo/mix.exs, which has no upper bound \u2014 every future MAJOR release of \u0060:postgrex\u0060 satisfies it, so the next unlocked resolve can pull a breaking change. Use \u0060~\u003E\u0060 (e.g. \u0060\u0022~\u003E 1.0\u0022\u0060) to bound the requirement to a compatible range."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a74f0f4a0b8f96de01d4dc9f35711e922a8073c35f78fd42f717ef785c5354e6"}},{"ruleId":"D12","level":"warning","message":{"text":"Unbounded dependency requirement: jason: Runtime dependency \u0060:jason\u0060 is declared \u0060\u0022\u003E= 1.0.0\u0022\u0060 in demo/mix.exs, which has no upper bound \u2014 every future MAJOR release of \u0060:jason\u0060 satisfies it, so the next unlocked resolve can pull a breaking change. Use \u0060~\u003E\u0060 (e.g. \u0060\u0022~\u003E 1.0\u0022\u0060) to bound the requirement to a compatible range."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"10a643ddeb96936a6b2ca73b56622aabc4d97413f0a96618cc0d05143529d9dd"}},{"ruleId":"D12","level":"warning","message":{"text":"Unbounded dependency requirement: gettext: Runtime dependency \u0060:gettext\u0060 is declared \u0060\u0022\u003E= 0.26.0\u0022\u0060 in mix.exs, which has no upper bound \u2014 every future MAJOR release of \u0060:gettext\u0060 satisfies it, so the next unlocked resolve can pull a breaking change. Use \u0060~\u003E\u0060 (e.g. \u0060\u0022~\u003E 1.0\u0022\u0060) to bound the requirement to a compatible range."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"efef58737135afdd0a340f65edeff0c179d3c06c33e968975ea243659de2c198"}},{"ruleId":"D12","level":"warning","message":{"text":"Unbounded dependency requirement: postgrex: Runtime dependency \u0060:postgrex\u0060 is declared \u0060\u0022\u003E= 0.0.0\u0022\u0060 in mix.exs, which has no upper bound \u2014 every future MAJOR release of \u0060:postgrex\u0060 satisfies it, so the next unlocked resolve can pull a breaking change. Use \u0060~\u003E\u0060 (e.g. \u0060\u0022~\u003E 1.0\u0022\u0060) to bound the requirement to a compatible range."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f91ce2879884c71b198e6374aa2c5936866aae127676263298716d4100b0782f"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #1: If anonymized user #1 becomes unavailable, 17 significant file(s) lose their only recent owner: lib/backpex/preferences.ex, lib/backpex/preferences/adapters/ecto.ex, lib/backpex/preferences/live_view.ex, lib/backpex/preferences/router.ex, lib/backpex/preferences/adapter.ex, lib/backpex/preferences/key.ex, lib/backpex/preferences/keys.ex, lib/backpex/filters/boolean.ex (\u002B9 more). Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"085876e4b6de1ea2801d388fa6704fe4e38ad242e193ed755b0b1d454ab85f33"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: # TODO: find solution for this workaround \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060# REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/backpex/adapters/ecto.ex"},"region":{"startLine":337}}}],"partialFingerprints":{"codehealthFindingId/v1":"c0797694d379cd4599928b57db6a421c656d1faac3cbefcf9137a047d4519e71"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: # TODO: do not rely on specific adapter \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060# REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/backpex/fields/has_many.ex"},"region":{"startLine":390}}}],"partialFingerprints":{"codehealthFindingId/v1":"6925244e3123fdede79b21b000d5337e8f7c0c9dcfe972c2eb4b48de31212c63"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: # TODO: move to common module \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060# REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/backpex/live_resource/index.ex"},"region":{"startLine":752}}}],"partialFingerprints":{"codehealthFindingId/v1":"064cc7df899ab5224dc3821400d2c7740dc854073146cf4ac5eeaea469555674"}},{"ruleId":"D26","level":"note","message":{"text":"Projects may be oversized for their cohesion: 1 of 1 project(s) overshoot their size bounds, lowering Project Cohesion to 0.0/10. The most over is \u0060(repository root)\u0060 (24816 LoC, 68 module-visible types across 15 directories). Review these for cohesion \u2014 draw the boundary inside the module first (group each responsibility into its own package or directory and keep the cross-boundary members non-public), since splitting a published package moves types between packages and breaks consumers."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d5a94650dc74886a0f1f08eb9fb6775f1fc395279ef7e901c970c9d26f767a72"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fe9c2422135c7c87299217beac95f376d03757dcfd857fd33dd0732c453e1800"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ba47501e2bb70c3a5566d5b59f1dd1bc9cf90616ce9b7a2aa7f963df7ce10e94"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3c08773d5d0595b5e900fd7c92ecb3ca84370884c53dc9e51217461330ddf04a"},"properties":{"dependency":{"package":"usage_rules","version":"0.1.26","advisory":"EEF-[CVE redacted]","aliases":["[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2f48fadfe39f824745954ea654d7940527574ccd61e2f95cceb907202e48a55a"},"properties":{"dependency":{"package":"mint","version":"1.10.1","advisory":"EEF-[CVE redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","EEF-[CVE redacted]","EEF-[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"598b9b7343dffd061134186abb4393c45e322aea95d8d461bbf08f4fa793abd1"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"26301a556205ed2d488326824ca1af40d9336b39ff8724e3cd9f69e7ff31d2b7"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"be9c57e2fb625c43c271d051f76b97f27b6976f4ec358ef8fea1d9cb5205f460"},"taxa":[{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fa5157c759bcfa7e186f2f335f17fc0a7cb2fc8e0c9d2d4fa57162f3b302f33e"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"910198a389fb607e890ff895ec8df42f01cecdf922158a9181fd174c31d3a359"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c622bab8f3dace0cacee804422dc55592a6dcb7fd3b196d5086cd478627fe00f"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b8f2e363b9d053dd3c28d4375adc4ce6f18456ab7f87032ea1ae03bd7caa0b68"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1f51a163f26d94ce6b6f473117dde579d091c8cbf9e59810475c94d9fc921120"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling clique: form.ex, index.ex, show.ex: 3 files \u2014 \u0060lib/backpex/live_resource/form.ex\u0060, \u0060lib/backpex/live_resource/index.ex\u0060, \u0060lib/backpex/live_resource/show.ex\u0060 \u2014 all change together with no explicit dependency: a fully-connected co-change clique, not 3 separate couplings. They share one concern (thin parallel siblings over a common abstraction), so extract the shared part into ONE unit and the whole clique\u0027s coupling clears at once \u2014 you do not need to break each pair individually."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/backpex/live_resource/form.ex"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f8b09bd6665022e0462beb4df9ebca371e5c27d107fe6fd69532adfd281d8c8c"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1b213f6eedd4b140d0bc37bdf1496f72811a643f34064f12518b32e9e83bcfc7"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e17f71490e4d120a48b2b2881ab866c93b272bef2febb673a3e8e42b2c288ab"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eb00976a698a5d68999b7ee6d27206fd374e916853e7ff1ead5eed42386f043f"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d068c977b62d9a977df1bb6f53e8b00b586c3abee955f91d715f92b8e019d624"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c593d4dbd23724f337bfb8d2c1653812f143ae255bd9b59d4b3e9c37779fa6f4"}},{"ruleId":"AC7","level":"warning","message":{"text":"Accessibility enforcement below the top rung: No accessibility enforcement found \u2014 no a11y linter (an a11y linter that can read your UI \u2014 no component framework was detected, so the JSX/Vue ESLint plugins would have nothing to lint; use an HTML-template a11y linter (html-eslint, htmlhint) or run axe/pa11y over the rendered pages) and no axe/pa11y/Lighthouse in tests or CI. Start with the linter to catch issues at author time. What was searched, so you can tell an absence from a miss: the 6 markup file(s) this pass actually assessed, the linter configuration checked in beside them, and this repository\u0027s test and CI files \u2014 matched by name against the accessibility checkers this dimension carries. An audit run outside the repository, a hosted scanner, or a check whose name is not one of those, is not seen here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d46019b86eff5ddad9db289e6802ac158899e980df54c34f67722442787ead62"}},{"ruleId":"M1","level":"warning","message":{"text":"README may be stale: 71 code files changed in the last 6 months but the README was not touched \u2014 it may no longer reflect the system."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e973e7a8d5d866995cbf78b120250fe7f132bf928812d48ca62e69aba11b9910"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"P4","level":"note","message":{"text":"No release approval gate: Deployment is automated and no gate that pauses it for a human is DECLARED IN THIS REPOSITORY\u0027S PIPELINE FILES. What was read: every file under \u0060.github/workflows/\u0060, \u0060.forgejo/workflows/\u0060, \u0060.gitea/workflows/\u0060, \u0060.azuredevops/\u0060 and \u0060.azure-pipelines/\u0060, plus \u0060.gitlab-ci*\u0060 and \u0060azure-pipelines*\u0060 \u2014 with comment text stripped, so documenting a gate is not declaring one. What would have counted: GitLab\u0027s \u0060when: manual\u0060, CircleCI\u0027s \u0060type: approval\u0060, an Azure \u0060ManualValidation@\u0060 task or an \u0060approvals:\u0060 block, a Jenkins \u0060input\u0060 step, a \u0060uses:\u0060 step naming an approval action, an \u0060environment:\u0060 paired with \u0060reviewers\u0060 / \u0060required_reviewers\u0060 / \u0060protection\u0060 / \u0060wait-timer\u0060 / \u0060deployment_branch_policy\u0060, a draft-release step, a \u0060workflow_dispatch\u0060 promotion, or a release-event gate. \u2605 What this cannot see, because none of it is a file: a GitHub environment whose required reviewers are configured in repo SETTINGS, a branch protection rule, or an organisation deployment policy \u2014 all of them real, enforced gates that live outside the repository. If yours is one of those, this row is wrong and nothing in the tree could have told us. Otherwise: whatever reaches the release trigger goes to production unreviewed, so a mistaken merge or tag is live before anyone can stop it."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6c11e2dbd483b4b423b95ac61bfcc7af1d55351b28a20d2b1105b31cfe38cc60"}},{"ruleId":"P6","level":"note","message":{"text":"No changelog: No CHANGELOG/HISTORY/RELEASES file \u2014 what shipped when isn\u0027t easy to reconstruct for support or audit. (Versioning/tagging makes releases traceable, but a changelog records the what.)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"dda5aa5aed8cbb292c3ef2b733bc138f614293ae6426c85e98bf31ef330d9415"}},{"ruleId":"R1","level":"warning","message":{"text":"Type Safety: 0 typed \u00B7 13 plain JS \u2014 the untyped files are assets/js/backpex.js, assets/js/hooks/_cancel_entry.js, assets/js/hooks/_currency_input.js, assets/js/hooks/_drag_hover.js, assets/js/hooks/_dropdown.js, assets/js/hooks/_preferences.js (\u002B7 more)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d00ee7953f55325a823d27e5db9657c80ca9b9861c0c0abf8fe487cd3fa586d3"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block with local edits (8 matched lines \u00D7 2 locations): assets/js/hooks/_preferences.js:157 \u00B7 assets/js/hooks/_preferences.js:385 \u2014 the two spans are one implementation copied and then locally edited \u2014 55 tokens are still identical, in the same order in both spans, with only local edits between them. The copies have already begun to drift, which is this row\u0027s finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters \u2014 or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"assets/js/hooks/_preferences.js"},"region":{"startLine":157}}}],"partialFingerprints":{"codehealthFindingId/v1":"8fb2a161a48ee182e12f9ff354bef4ede26d070d893cf9368d504f7caeb31aa3"}},{"ruleId":"R3","level":"warning","message":{"text":"Large Files: 1 file(s) over 400 lines (counted as significant lines \u2014 blank lines excluded \u2014 over production source only, tests excluded), largest first: assets/js/hooks/_preferences.js (528)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"cecee31b569df4f07e06db732f1ca037af27b5afef9023da51f9673d931a142f"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"assets/js/hooks/_sidebar.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d82273c9c7f3daa7ea2d2e732e0159202dde22013513aa44f99affe2c0ff8b92"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"assets/js/hooks/_sidebar_sections.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"4ee18f1ef3cd3a35b4bbc0bac9580385f114e013ac20971edd5722ce50a87ff9"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"assets/js/hooks/_dropdown.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"4733e9ce4341fa6f6890d8e17dcd1a57a4b6055aa08c8f9c456c1b2732b16b47"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"assets/js/hooks/_theme_selector.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e2e314ba22553cc766a7e9988b29ef879990ac99c447097a8459f723a1b3fd23"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"assets/js/hooks/_tooltip.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"5c1355732205ae773949bfa0f9b1bc8ce63a9a17699d56aa4ce629e2a7608bf1"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"assets/js/hooks/_currency_input.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"dbd4a3902186a249e77742096d917a3ba5c6a1cd05df2965b909936601786eb0"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"assets/js/hooks/_sticky_actions.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f95de5d5112303e285533a7bbef6f6d129540146850a640e95cd4928b39b90d7"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"assets/js/hooks/_drag_hover.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"23d3e54676d474734eeb3c89a19ebccc65e91e918c460fa72e601837c6ba1992"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"assets/js/hooks/_cancel_entry.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"4344b2d87efb3f750cb91a74adf883d9db247159c47ee97a4e855b59f0acd710"}},{"ruleId":"R4","level":"warning","message":{"text":"No test reaches this file: No test imports this module directly or transitively. Import reachability cannot see a test that executes a file by path instead of importing it, nor one that drives it through a running browser by navigating to a URL \u2014 if neither does, no test reaches this one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"assets/js/backpex.js"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a93e0eac57c9f77bcdd61b9417bcb4c41010162b4dbe6cbae761a78ff6a1657f"}},{"ruleId":"R6","level":"warning","message":{"text":"No typecheck script: test \u2713 \u00B7 lint \u2713 \u00B7 typecheck \u2717 \u2014 read from this repository\u0027s package.json scripts and corroborated against its CI workflows. A script counts when its name or command matches the step: \u0060test\u0060 for the suite, \u0060lint\u0060 or \u0060prettier\u0060 for linting, \u0060typecheck\u0060/\u0060type-check\u0060/\u0060tsc\u0060 for type checking. \u2717 therefore means no script or CI step under those names was found, NOT that the step is absent from your pipeline \u2014 a task invoked by a runner this check does not read, or named something else entirely, is not seen and is worth confirming before acting on a cross. A \u2713 means the wiring is DECLARED \u2014 a script or CI step under those names exists. It is not a statement that the step passes, or that it runs at all: nothing here installs a dependency or executes a suite."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"912edc7f1fd20bf80ef68c3293e3048565115e48707dc5f9d492201598794658"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-829","guid":"13c33925-97fb-5a5e-b40c-56d328b8a4d7","name":"CWE-829","shortDescription":{"text":"CWE-829"},"helpUri":"https://cwe.mitre.org/data/definitions/829.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":17,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}