{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D7","name":"Architectural Integrity","shortDescription":{"text":"Architectural Integrity"},"helpUri":"https://codehealth.canine.dev/dimensions/D7"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D11","name":"Test Reliability","shortDescription":{"text":"Test Reliability"},"helpUri":"https://codehealth.canine.dev/dimensions/D11"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D37","name":"Vulnerability-disclosure Policy","shortDescription":{"text":"Vulnerability-disclosure Policy"},"helpUri":"https://codehealth.canine.dev/dimensions/D37","relationships":[{"target":{"id":"CWE-1059","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1059"]}},{"id":"D40","name":"Network Egress Confinement","shortDescription":{"text":"Network Egress Confinement"},"helpUri":"https://codehealth.canine.dev/dimensions/D40"},{"id":"D41","name":"Kernel \u0026 Syscall Confinement","shortDescription":{"text":"Kernel \u0026 Syscall Confinement"},"helpUri":"https://codehealth.canine.dev/dimensions/D41"},{"id":"D42","name":"Runtime Threat Enforcement","shortDescription":{"text":"Runtime Threat Enforcement"},"helpUri":"https://codehealth.canine.dev/dimensions/D42"},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AX8","name":"Test isolation","shortDescription":{"text":"Test isolation"},"helpUri":"https://codehealth.canine.dev/dimensions/AX8"},{"id":"AX9","name":"CQS / query purity","shortDescription":{"text":"CQS / query purity"},"helpUri":"https://codehealth.canine.dev/dimensions/AX9"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P10","name":"Library API \u0026 versioning","shortDescription":{"text":"Library API \u0026 versioning"},"helpUri":"https://codehealth.canine.dev/dimensions/P10"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P2","name":"Observability","shortDescription":{"text":"Observability"},"helpUri":"https://codehealth.canine.dev/dimensions/P2"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"PF1","name":"Benchmark discipline","shortDescription":{"text":"Benchmark discipline"},"helpUri":"https://codehealth.canine.dev/dimensions/PF1"},{"id":"PF3","name":"Async \u0026 latency hygiene","shortDescription":{"text":"Async \u0026 latency hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/PF3"},{"id":"S1","name":"Web-Security Posture","shortDescription":{"text":"Web-Security Posture"},"helpUri":"https://codehealth.canine.dev/dimensions/S1"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X32","name":"Type resolved by simple name across every loaded assembly","shortDescription":{"text":"Type resolved by simple name across every loaded assembly"},"helpUri":"https://codehealth.canine.dev/dimensions/X32"},{"id":"X6","name":"Hand-rolled structured-format parsing","shortDescription":{"text":"Hand-rolled structured-format parsing"},"helpUri":"https://codehealth.canine.dev/dimensions/X6"},{"id":"X7","name":"Silent fallback defaults","shortDescription":{"text":"Silent fallback defaults"},"helpUri":"https://codehealth.canine.dev/dimensions/X7"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::exec_strategy::execute_supervised (cyclomatic 106): nono_cli::exec_strategy::execute_supervised has cyclomatic complexity 106 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":550}}}],"partialFingerprints":{"codehealthFindingId/v1":"3783ec00e10bcfaf696e77fbb81c9790b465788acd04a862585089ca79e2489d"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::profile_cmd::cmd_diff (cyclomatic 61): nono_cli::profile_cmd::cmd_diff has cyclomatic complexity 61 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":1422}}}],"partialFingerprints":{"codehealthFindingId/v1":"481cfd2dc3d72c9cc086eeda0fe54aa390ffc77449ee36d503c21da3b17c0414"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::profile_cmd::cmd_show (cyclomatic 54): nono_cli::profile_cmd::cmd_show has cyclomatic complexity 54 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":855}}}],"partialFingerprints":{"codehealthFindingId/v1":"739683faccc76f1f5e9eda3caf241510c9ec98da8a1d2ffd8bea63b6bb0a8b0a"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::execution_runtime::execute_sandboxed (cyclomatic 53): nono_cli::execution_runtime::execute_sandboxed has cyclomatic complexity 53 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/execution_runtime.rs"},"region":{"startLine":203}}}],"partialFingerprints":{"codehealthFindingId/v1":"f1d3616930e420387c84d3603e48d9263084ef5294d3f08ef7fe8294891f4c73"}},{"ruleId":"D1","level":"warning","message":{"text":"CapabilitySet::from_profile (cyclomatic 52): CapabilitySet::from_profile has cyclomatic complexity 52 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/capability_ext.rs"},"region":{"startLine":693}}}],"partialFingerprints":{"codehealthFindingId/v1":"eca4c9be9914210040a336d21f45983b1624d8ab7df22306249141cb327fb5ee"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::exec_strategy::supervisor_linux::handle_received_filesystem_notification (cyclomatic 44): nono_cli::exec_strategy::supervisor_linux::handle_received_filesystem_notification has cyclomatic complexity 44 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy/supervisor_linux.rs"},"region":{"startLine":195}}}],"partialFingerprints":{"codehealthFindingId/v1":"286fd6cd1ed5bcccb471df3b87023ffbfac81e5f5e517d1daf58be013a555aaf"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_proxy::server::handle_connection (cyclomatic 41): nono_proxy::server::handle_connection has cyclomatic complexity 41 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/server.rs"},"region":{"startLine":1477}}}],"partialFingerprints":{"codehealthFindingId/v1":"1da62a01fa07365133e8cc16cb80c23313c8921d6d826dc88e37e0fdb7a4b661"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::tool-sandbox::platform::linux::handle_shim_stream_inner (cyclomatic 39): nono_cli::tool-sandbox::platform::linux::handle_shim_stream_inner has cyclomatic complexity 39 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1265}}}],"partialFingerprints":{"codehealthFindingId/v1":"530539c419bc5dfa030246c55fe42f3a7fa0028cabbf8a18f7d353ae65d6b7f5"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::exec_strategy::clone_files::child_exec (cyclomatic 39): nono_cli::exec_strategy::clone_files::child_exec has cyclomatic complexity 39 (threshold 15). This file\u0027s own header attributes it to another copyright holder, so it is code this repository carries rather than code it wrote: restructuring the body in place forks it from upstream and turns every future re-sync into a manual merge. The performable moves are to leave the body as close to its upstream form as possible and keep it behind a narrow interface of your own, and to re-sync it when upstream changes \u2014 or, if it has already diverged far enough that you maintain it here, adopt it deliberately and then split the body into named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy/clone_files.rs"},"region":{"startLine":314}}}],"partialFingerprints":{"codehealthFindingId/v1":"09eafb607aab737a964373dcc7adb6ca872d195e030ec72fc0931fcbed4fd8d6"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::exec_strategy::run_supervisor_loop (cyclomatic 39): nono_cli::exec_strategy::run_supervisor_loop has cyclomatic complexity 39 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":2848}}}],"partialFingerprints":{"codehealthFindingId/v1":"283492e3e9b06e34d6943dceec5de996cdab50b85da29e5a7f7a80d81a92ce1f"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::tool-sandbox::platform::macos::handle_shim_stream_inner (cyclomatic 38): nono_cli::tool-sandbox::platform::macos::handle_shim_stream_inner has cyclomatic complexity 38 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":972}}}],"partialFingerprints":{"codehealthFindingId/v1":"e02c393efc8bed848ae864727afc816498ecb347105c51fa0a24e715fb6e18a3"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::sandbox_prepare::prepare_sandbox (cyclomatic 37): nono_cli::sandbox_prepare::prepare_sandbox has cyclomatic complexity 37 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/sandbox_prepare.rs"},"region":{"startLine":1427}}}],"partialFingerprints":{"codehealthFindingId/v1":"18b77e47cddbe9c875ca4014d5e0ac034082a9191759872c984a7093bde61524"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_proxy::reverse::handle_reverse_proxy (cyclomatic 37): nono_proxy::reverse::handle_reverse_proxy has cyclomatic complexity 37 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":128}}}],"partialFingerprints":{"codehealthFindingId/v1":"5a2782f128d59716dc9451320ee0a660c77ef863e4e5bb79c679e4c5bdb89fa9"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::profile_cmd::resolve_to_manifest (cyclomatic 36): nono_cli::profile_cmd::resolve_to_manifest has cyclomatic complexity 36 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":2942}}}],"partialFingerprints":{"codehealthFindingId/v1":"47d821c1c360a9bd951d277003ae8838607e9da32d3be89b0b95ccc0ae89546e"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::pty_proxy::run_attach_loop (cyclomatic 34): nono_cli::pty_proxy::run_attach_loop has cyclomatic complexity 34 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/pty_proxy.rs"},"region":{"startLine":2574}}}],"partialFingerprints":{"codehealthFindingId/v1":"710a2507b4f008c2a97d706890710b73e9b1af06b28a92177e15a3eec31c0c47"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::profile::validate_credential_capture_entries (cyclomatic 34): nono_cli::profile::validate_credential_capture_entries has cyclomatic complexity 34 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":1393}}}],"partialFingerprints":{"codehealthFindingId/v1":"104c9a416c67f03872886aa9b1c0ec784ae6d286bc4ee1cc54a616e7ed979fc8"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_proxy::tls_intercept::handle::handle_inner_request (cyclomatic 34): nono_proxy::tls_intercept::handle::handle_inner_request has cyclomatic complexity 34 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":1030}}}],"partialFingerprints":{"codehealthFindingId/v1":"991dcfe3cd0ac854152649b13b00be2e98f1271480caa0699b7ea3cc7244f5ed"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::audit_commands::cmd_show (cyclomatic 33): nono_cli::audit_commands::cmd_show has cyclomatic complexity 33 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":348}}}],"partialFingerprints":{"codehealthFindingId/v1":"d67d8746090080c10b83e143c2261752457b406d918c39dced2dd26d09e1cd11"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::profile::validate_custom_credential (cyclomatic 33): nono_cli::profile::validate_custom_credential has cyclomatic complexity 33 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":607}}}],"partialFingerprints":{"codehealthFindingId/v1":"027b9163e966cdd28b34207b98d2d5965536a33bd6be0a9cfedec02e4bea6c26"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::policy::apply_macos_keychain_db_exception (cyclomatic 32): nono_cli::policy::apply_macos_keychain_db_exception has cyclomatic complexity 32 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/policy.rs"},"region":{"startLine":1435}}}],"partialFingerprints":{"codehealthFindingId/v1":"fadc91d83c8ed9a5a048002b7792d3a177be93a9929bbe525df878fb43941045"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_proxy::tls_intercept::handle::select_intercept_route (cyclomatic 31): nono_proxy::tls_intercept::handle::select_intercept_route has cyclomatic complexity 31 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":397}}}],"partialFingerprints":{"codehealthFindingId/v1":"a177d2efc26328fff35f2239276dfa844bb089c4b8ce08879ae33ef08753fb68"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_proxy::tls_intercept::h2_forward::handle_h2_stream (cyclomatic 31): nono_proxy::tls_intercept::h2_forward::handle_h2_stream has cyclomatic complexity 31 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/h2_forward.rs"},"region":{"startLine":232}}}],"partialFingerprints":{"codehealthFindingId/v1":"9b342317041b64969d7539debb69e0e2dcbcbb4c1754c190ba8e2132dedbe4e8"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::command_policy::validate_credential (cyclomatic 28): nono_cli::command_policy::validate_credential has cyclomatic complexity 28 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_policy.rs"},"region":{"startLine":2551}}}],"partialFingerprints":{"codehealthFindingId/v1":"11b7b37c040bfb7b466b0f7a3da36d7ef91e93821f278385747179742ccdef14"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::profile_cmd::cmd_validate (cyclomatic 27): nono_cli::profile_cmd::cmd_validate has cyclomatic complexity 27 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":2402}}}],"partialFingerprints":{"codehealthFindingId/v1":"a33f97c38ffbd8d3dcf8ee1f132e5f125e1d3b619855e484e503ac238e15ca90"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::exec_strategy::supervisor_linux::handle_received_network_notification (cyclomatic 27): nono_cli::exec_strategy::supervisor_linux::handle_received_network_notification has cyclomatic complexity 27 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy/supervisor_linux.rs"},"region":{"startLine":1043}}}],"partialFingerprints":{"codehealthFindingId/v1":"cf0c686445f5ff41c836273c2cdf47323e135b18d05072692547e3e3241f3d37"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::trust_scan::run_pre_exec_scan (cyclomatic 27): nono_cli::trust_scan::run_pre_exec_scan has cyclomatic complexity 27 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_scan.rs"},"region":{"startLine":375}}}],"partialFingerprints":{"codehealthFindingId/v1":"e9821b9dfa50a0d5a67c875346a88e454ec72d115febaaa0d10d3a697ea7b066"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_proxy::server::start_with_nonce_resolver (cyclomatic 27): nono_proxy::server::start_with_nonce_resolver has cyclomatic complexity 27 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/server.rs"},"region":{"startLine":1054}}}],"partialFingerprints":{"codehealthFindingId/v1":"48188fd7ed5dd31888429104e74ae08a6d13d7cd868421cbe40f0d031df75f1b"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::exec_strategy::run_supervisor_loop (cyclomatic 26): nono_cli::exec_strategy::run_supervisor_loop has cyclomatic complexity 26 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":2603}}}],"partialFingerprints":{"codehealthFindingId/v1":"cc49b824a6cae9117764617aa873afc6eeb37cb691def52fdaab1ffff7dbcad3"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::output::print_capabilities (cyclomatic 26): nono_cli::output::print_capabilities has cyclomatic complexity 26 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/output.rs"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"3485418d0faa513d22cb881780e9954d03fccbdea4f437428beba2ac164a05bd"}},{"ruleId":"D1","level":"warning","message":{"text":"nono::capability::tokenize_sexp (cyclomatic 25): nono::capability::tokenize_sexp has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/capability.rs"},"region":{"startLine":681}}}],"partialFingerprints":{"codehealthFindingId/v1":"fa49254c75bd914371dd6b4ef8dddf105492a8d8dfe862e05c2c520173842c0b"}},{"ruleId":"D1","level":"warning","message":{"text":"nono::audit::verify_audit_attestation_bundle (cyclomatic 25): nono::audit::verify_audit_attestation_bundle has cyclomatic complexity 25 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/audit.rs"},"region":{"startLine":1123}}}],"partialFingerprints":{"codehealthFindingId/v1":"78eba2462f552ed4c29aad10ad27d7acb98eea3ecaf3807904a232a14fe54a2c"}},{"ruleId":"D1","level":"warning","message":{"text":"DiagnosticFormatter::format_supervised_footer_with_diagnostics (cyclomatic 25): DiagnosticFormatter::format_supervised_footer_with_diagnostics has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/diagnostic/formatter.rs"},"region":{"startLine":1250}}}],"partialFingerprints":{"codehealthFindingId/v1":"80f64f3e68f826cd5c4f3f0f5bc0b227f64298a6c9fe006fd5dd0ff31bfc53e3"}},{"ruleId":"D1","level":"warning","message":{"text":"DiagnosticFormatter::format_consolidated_denial_guidance (cyclomatic 25): DiagnosticFormatter::format_consolidated_denial_guidance has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/diagnostic/formatter.rs"},"region":{"startLine":1707}}}],"partialFingerprints":{"codehealthFindingId/v1":"2cfd3fe6bfa4c4602bfc29f67f00dfab9f25da4ca5086c944f7b15557c7df69b"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::proxy_runtime::prepare_proxy_launch_options (cyclomatic 25): nono_cli::proxy_runtime::prepare_proxy_launch_options has cyclomatic complexity 25 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":1430}}}],"partialFingerprints":{"codehealthFindingId/v1":"0ef06c89355fc1c777456df38975ad740bd01fd63911ee4d1ddb3ddbfa84eb7f"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::pty_proxy::match_enhanced_key_sequence (cyclomatic 25): nono_cli::pty_proxy::match_enhanced_key_sequence has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/pty_proxy.rs"},"region":{"startLine":1394}}}],"partialFingerprints":{"codehealthFindingId/v1":"ac256727457fc37c1bc012d6327b4cfdc597ca791c15e56144d5dbf9cb098855"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::policy::apply_deny_overrides (cyclomatic 24): nono_cli::policy::apply_deny_overrides has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/policy.rs"},"region":{"startLine":1687}}}],"partialFingerprints":{"codehealthFindingId/v1":"5ed1ab0058a3ff002733b47e39bb4f197abe2af643549b4565c2f98b6b73aa10"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::capability_ext::add_cli_unix_socket_caps (cyclomatic 24): nono_cli::capability_ext::add_cli_unix_socket_caps has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/capability_ext.rs"},"region":{"startLine":130}}}],"partialFingerprints":{"codehealthFindingId/v1":"eea2c22916df2ca4c7c53e4a2e0b264e49c9feda4db3e9346d00bfe491142580"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::output::render_diagnostic_line (cyclomatic 24): nono_cli::output::render_diagnostic_line has cyclomatic complexity 24 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/output.rs"},"region":{"startLine":1037}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee5d98d7fdd9e4e20a5be8e0098f5c6de534d85731c57bb098fc34bf55f2d7f4"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::profile_save_runtime::interactive_denial_selector (cyclomatic 23): nono_cli::profile_save_runtime::interactive_denial_selector has cyclomatic complexity 23 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_save_runtime.rs"},"region":{"startLine":1450}}}],"partialFingerprints":{"codehealthFindingId/v1":"64f4487b36082ed2103c0a19303622a5c1c4c5b7ab037008518df0a8c5d6afb0"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::profile_save_runtime::build_combined_patch_from_items (cyclomatic 23): nono_cli::profile_save_runtime::build_combined_patch_from_items has cyclomatic complexity 23 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_save_runtime.rs"},"region":{"startLine":1566}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7946d4de2a0a16f589cde46afec3fbcc3117967ac67e182743ef0832b3e5b1d"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::proxy_runtime::build_proxy_config_from_flags (cyclomatic 23): nono_cli::proxy_runtime::build_proxy_config_from_flags has cyclomatic complexity 23 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":2357}}}],"partialFingerprints":{"codehealthFindingId/v1":"2de7bf984be78267f43210041a6428ca81bcc745c29534c99af4b9ff4d4e36ee"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_proxy::reverse::classify_upgrade_attempt (cyclomatic 23): nono_proxy::reverse::classify_upgrade_attempt has cyclomatic complexity 23 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":2119}}}],"partialFingerprints":{"codehealthFindingId/v1":"74bb245cd662399b531df1b24b82e7eb695fac403499d60e6f6562334a88352a"}},{"ruleId":"D1","level":"warning","message":{"text":"DiagnosticFormatter::format_exit_explanation (cyclomatic 22): DiagnosticFormatter::format_exit_explanation has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/diagnostic/formatter.rs"},"region":{"startLine":991}}}],"partialFingerprints":{"codehealthFindingId/v1":"e00e532fb06096fe61e48fdbfa19718c73a8ff2ca44821a169cacc799065f2e9"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::connect_client::attach (cyclomatic 22): nono_cli::connect_client::attach has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/connect_client.rs"},"region":{"startLine":1575}}}],"partialFingerprints":{"codehealthFindingId/v1":"93904d38dac80b1d0324a5fa65c59f10677c25bb8f6a2542dd3c794f9c234cf5"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::profile_runtime::prepare_profile_with_options (cyclomatic 22): nono_cli::profile_runtime::prepare_profile_with_options has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_runtime.rs"},"region":{"startLine":658}}}],"partialFingerprints":{"codehealthFindingId/v1":"28f6b7246e1eda066e8f260ba8c0aa341796178d6aac8a5e82310db483501cf2"}},{"ruleId":"D1","level":"warning","message":{"text":"CapabilitySet::deduplicate_unix_sockets (cyclomatic 21): CapabilitySet::deduplicate_unix_sockets has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/capability.rs"},"region":{"startLine":1934}}}],"partialFingerprints":{"codehealthFindingId/v1":"420414feba3a77d046597aaeb55dc30fe83b853bb49f33bacd662ea755c8d795"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::exec_strategy::clone_files::spawn (cyclomatic 21): nono_cli::exec_strategy::clone_files::spawn has cyclomatic complexity 21 (threshold 15). This file\u0027s own header attributes it to another copyright holder, so it is code this repository carries rather than code it wrote: restructuring the body in place forks it from upstream and turns every future re-sync into a manual merge. The performable moves are to leave the body as close to its upstream form as possible and keep it behind a narrow interface of your own, and to re-sync it when upstream changes \u2014 or, if it has already diverged far enough that you maintain it here, adopt it deliberately and then split the body into named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy/clone_files.rs"},"region":{"startLine":145}}}],"partialFingerprints":{"codehealthFindingId/v1":"f2ad049bf5846b10e736508be55a4cdebfcb2ab78ac9c2aa94aaba5463df2c4f"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::query_ext::print_result (cyclomatic 21): nono_cli::query_ext::print_result has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/query_ext.rs"},"region":{"startLine":621}}}],"partialFingerprints":{"codehealthFindingId/v1":"62192b6a1fa519627ed044fa95534f4061150107e32bc3ce174dc414dbe7fc6e"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::why_runtime::run_why (cyclomatic 21): nono_cli::why_runtime::run_why has cyclomatic complexity 21 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/why_runtime.rs"},"region":{"startLine":117}}}],"partialFingerprints":{"codehealthFindingId/v1":"a75692bd5bf349bf00d86a2aaab14e0d3376284b3ee317ec69b7dd0fc6b13e54"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::why_runtime::query_profile_path_lexically (cyclomatic 21): nono_cli::why_runtime::query_profile_path_lexically has cyclomatic complexity 21 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/why_runtime.rs"},"region":{"startLine":338}}}],"partialFingerprints":{"codehealthFindingId/v1":"85f51dc716b16ed4870f0b95fec1c9683f88354ea836c87a8a255dc43201eea9"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::command_policy::validate_command (cyclomatic 21): nono_cli::command_policy::validate_command has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_policy.rs"},"region":{"startLine":1597}}}],"partialFingerprints":{"codehealthFindingId/v1":"6acb7ef13eb5841d96ea34d92eaf197fd2cd5fc914b1086011c81c3536eca6ad"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::command_policy::validate_approval_backend (cyclomatic 21): nono_cli::command_policy::validate_approval_backend has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_policy.rs"},"region":{"startLine":2162}}}],"partialFingerprints":{"codehealthFindingId/v1":"df0752db27b0722e7d2224171d70711795338feee8fe4a95ddb2140125aa1977"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::wiring::execute_one (cyclomatic 21): nono_cli::wiring::execute_one has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/wiring.rs"},"region":{"startLine":339}}}],"partialFingerprints":{"codehealthFindingId/v1":"16cb6bb4e7ae92e3ec74576d81372762c4cfdfcdba1d55baf9b991d5a6b05528"}},{"ruleId":"D1","level":"warning","message":{"text":"CapabilitySet::try_from (cyclomatic 20): CapabilitySet::try_from has cyclomatic complexity 20 (threshold 15). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/manifest_convert.rs"},"region":{"startLine":24}}}],"partialFingerprints":{"codehealthFindingId/v1":"5091dd8c2bff99eea90b064293b4e4b849efc5b951a57f3afa8a85d127cae207"}},{"ruleId":"D1","level":"warning","message":{"text":"Predicate::parse (cyclomatic 20): Predicate::parse has cyclomatic complexity 20 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/platform.rs"},"region":{"startLine":307}}}],"partialFingerprints":{"codehealthFindingId/v1":"655f0c6ab0513dbee65c7c0c30a991e6c46df4b322709f43d42b9657f9522dbb"}},{"ruleId":"D1","level":"warning","message":{"text":"ProxyCredentialCaptureBackend::run_capture_command (cyclomatic 20): ProxyCredentialCaptureBackend::run_capture_command has cyclomatic complexity 20 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":381}}}],"partialFingerprints":{"codehealthFindingId/v1":"3bae5632d362cea60b5f8c176ec78d07067114cb5c287b8ec109d66216d12a0b"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::profile_cmd::profile_to_json (cyclomatic 20): nono_cli::profile_cmd::profile_to_json has cyclomatic complexity 20 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":1257}}}],"partialFingerprints":{"codehealthFindingId/v1":"bb8af3a8b7f6e5d211c90996b2f86e9ef373289e455536443180a4c69b9a9053"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::exec_strategy::clone_files::transfer (cyclomatic 20): nono_cli::exec_strategy::clone_files::transfer has cyclomatic complexity 20 (threshold 15). This file\u0027s own header attributes it to another copyright holder, so it is code this repository carries rather than code it wrote: restructuring the body in place forks it from upstream and turns every future re-sync into a manual merge. The performable moves are to leave the body as close to its upstream form as possible and keep it behind a narrow interface of your own, and to re-sync it when upstream changes \u2014 or, if it has already diverged far enough that you maintain it here, adopt it deliberately and then split the body into named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy/clone_files.rs"},"region":{"startLine":713}}}],"partialFingerprints":{"codehealthFindingId/v1":"fce7acd0c5ac771cb5aa88815f4115ccd83e20c8626ba6f12f92f03965d21901"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::profile::credential_provider::validate_credential_provider_entries (cyclomatic 20): nono_cli::profile::credential_provider::validate_credential_provider_entries has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/credential_provider.rs"},"region":{"startLine":149}}}],"partialFingerprints":{"codehealthFindingId/v1":"8afdb464cee9076afc6fd2c240ba8a66ed173607478ad9f0cf904ebf279ab192"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::package_cmd::run_update (cyclomatic 20): nono_cli::package_cmd::run_update has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/package_cmd.rs"},"region":{"startLine":224}}}],"partialFingerprints":{"codehealthFindingId/v1":"0eec20cd5df2c8242576c76fecf0c0cb2b7e0090ff5efbf5548beeafad72d07c"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_proxy::config::validate_no_proxy_host_pattern (cyclomatic 20): nono_proxy::config::validate_no_proxy_host_pattern has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/config.rs"},"region":{"startLine":603}}}],"partialFingerprints":{"codehealthFindingId/v1":"ab42e4cf1de73ef38d22d511ba3b3b897cd9213dfcd21dcf953d99d849930368"}},{"ruleId":"D1","level":"warning","message":{"text":"CapabilitySet::deduplicate (cyclomatic 19): CapabilitySet::deduplicate has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/capability.rs"},"region":{"startLine":1777}}}],"partialFingerprints":{"codehealthFindingId/v1":"1dbb3b5d254fded7de8a81fc419e09891f3a3ad954ef862ab988e181666342a9"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::exec_strategy::handle_supervisor_message (cyclomatic 19): nono_cli::exec_strategy::handle_supervisor_message has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":3291}}}],"partialFingerprints":{"codehealthFindingId/v1":"3b1a8b4538aab0ddb996bea07eb5e02b617b8eec4a887a6cff00e24d1ba480e1"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::supervised_runtime::execute_supervised_runtime (cyclomatic 19): nono_cli::supervised_runtime::execute_supervised_runtime has cyclomatic complexity 19 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/supervised_runtime.rs"},"region":{"startLine":210}}}],"partialFingerprints":{"codehealthFindingId/v1":"3e4e595cb6ed0146557b06dbd70d6b55d5f216c98899e275ba716ba6bd7606b5"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::remote_run::run (cyclomatic 19): nono_cli::remote_run::run has cyclomatic complexity 19 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/remote_run.rs"},"region":{"startLine":89}}}],"partialFingerprints":{"codehealthFindingId/v1":"6f68ca0484bb7bf91b709c0aa8bb94f99d1a269c46d68cb9fa02af656f94813f"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::profile::validate_proxy_override (cyclomatic 19): nono_cli::profile::validate_proxy_override has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":763}}}],"partialFingerprints":{"codehealthFindingId/v1":"e4607e46ca213e4018ad14c8f7888d96b029486c1f1067d3aa5e8c781ab557b7"}},{"ruleId":"D1","level":"warning","message":{"text":"CredentialStore::load_with_diagnostics (cyclomatic 19): CredentialStore::load_with_diagnostics has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/credential.rs"},"region":{"startLine":222}}}],"partialFingerprints":{"codehealthFindingId/v1":"661d2e90121db51bb2058a09c35d7ec8d59661e8f0a539655055b70cd0580b86"}},{"ruleId":"D1","level":"warning","message":{"text":"CapabilitySet::from_args (cyclomatic 18): CapabilitySet::from_args has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top. This shape REPEATS in the file: one other method here (nono_cli::capability_ext::add_cli_overrides) has the same decision points, in the same order, at the same nesting depths \u2014 so this is one pattern written twice rather than two separate problems. Splitting this body alone leaves the other exactly as it is. Where these are variations on one operation, the change that clears both is the shared one: lift the common shape into a single routine the variants call, parameterised by whatever genuinely differs between them, and keep in each method only the part that is not shared."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/capability_ext.rs"},"region":{"startLine":586}}}],"partialFingerprints":{"codehealthFindingId/v1":"4b0d06b624bd9a38754fab498f9919b53c5a9185eb14462d0fed806bf53c67e7"}},{"ruleId":"D1","level":"warning","message":{"text":"nono::keystore::build_mappings_from_list (cyclomatic 18): nono::keystore::build_mappings_from_list has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/keystore.rs"},"region":{"startLine":1912}}}],"partialFingerprints":{"codehealthFindingId/v1":"4d68bf901949940c5f97ad634af5c14edb6b7bd240b802ca81a9bd366afb6017"}},{"ruleId":"D1","level":"warning","message":{"text":"PtyProxy::try_accept (cyclomatic 18): PtyProxy::try_accept has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/pty_proxy.rs"},"region":{"startLine":552}}}],"partialFingerprints":{"codehealthFindingId/v1":"8fe875d2ee5c39084c7ced2caef62809316e5fbc2b0d906c85e44af2e20f6664"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::tool-sandbox::platform::linux::build_child_launch_spec_for_binary (cyclomatic 18): nono_cli::tool-sandbox::platform::linux::build_child_launch_spec_for_binary has cyclomatic complexity 18 (threshold 15). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3570}}}],"partialFingerprints":{"codehealthFindingId/v1":"665b3bac9f81beb6a425c50e9381109cf358f3097c01394b66ac17b79245e62a"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::exec_strategy::clone_files::scrub_fds (cyclomatic 18): nono_cli::exec_strategy::clone_files::scrub_fds has cyclomatic complexity 18 (threshold 15). This file\u0027s own header attributes it to another copyright holder, so it is code this repository carries rather than code it wrote: restructuring the body in place forks it from upstream and turns every future re-sync into a manual merge. The performable moves are to leave the body as close to its upstream form as possible and keep it behind a narrow interface of your own, and to re-sync it when upstream changes \u2014 or, if it has already diverged far enough that you maintain it here, adopt it deliberately and then split the body into named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy/clone_files.rs"},"region":{"startLine":543}}}],"partialFingerprints":{"codehealthFindingId/v1":"4e419944eda848efb8e4d788a717daa03737159aaa63a216056d76d177cffbd4"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::rollback_commands::cmd_cleanup (cyclomatic 18): nono_cli::rollback_commands::cmd_cleanup has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/rollback_commands.rs"},"region":{"startLine":801}}}],"partialFingerprints":{"codehealthFindingId/v1":"9d56e2f2232ded29a7bb2c8cf6d1b688756893d828a9d035908c03bdfc77e3a1"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::capability_ext::add_cli_overrides (cyclomatic 18): nono_cli::capability_ext::add_cli_overrides has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top. This shape REPEATS in the file: one other method here (CapabilitySet::from_args) has the same decision points, in the same order, at the same nesting depths \u2014 so this is one pattern written twice rather than two separate problems. Splitting this body alone leaves the other exactly as it is. Where these are variations on one operation, the change that clears both is the shared one: lift the common shape into a single routine the variants call, parameterised by whatever genuinely differs between them, and keep in each method only the part that is not shared."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/capability_ext.rs"},"region":{"startLine":1229}}}],"partialFingerprints":{"codehealthFindingId/v1":"e8ad4e138008ca78159f61e009eb842351996c8aa5e7606889fa288835c2df10"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::query_ext::query_network (cyclomatic 18): nono_cli::query_ext::query_network has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/query_ext.rs"},"region":{"startLine":240}}}],"partialFingerprints":{"codehealthFindingId/v1":"e8c4e0f549a3d78c33e411649e7af85ff4d8941a70f95cb4cff07530420f28f4"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::trust_cmd::run_verify (cyclomatic 18): nono_cli::trust_cmd::run_verify has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_cmd.rs"},"region":{"startLine":759}}}],"partialFingerprints":{"codehealthFindingId/v1":"49fa06b5f7f8242558f603be890ccbc4b7ca2419f5ff206ad954d6c61f4b9284"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::profile::find_pack_store_profile (cyclomatic 18): nono_cli::profile::find_pack_store_profile has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":2987}}}],"partialFingerprints":{"codehealthFindingId/v1":"1f19cffec97b831ae9a2b241094c5eec16146de883923177bb98f51c8542e3a3"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::command_policy::validate_intercept_rules (cyclomatic 18): nono_cli::command_policy::validate_intercept_rules has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_policy.rs"},"region":{"startLine":1751}}}],"partialFingerprints":{"codehealthFindingId/v1":"7b7834894eba162d5cf5168dc5302ca99a60a2cd30c15310da1406b6ea3ffd47"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::sandbox_prepare::maybe_enable_gpu (cyclomatic 18): nono_cli::sandbox_prepare::maybe_enable_gpu has cyclomatic complexity 18 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/sandbox_prepare.rs"},"region":{"startLine":1227}}}],"partialFingerprints":{"codehealthFindingId/v1":"f0a624ac082f862545663780067b9d1e78ba52b8964bac6a99b239a10ca60473"}},{"ruleId":"D1","level":"warning","message":{"text":"SnapshotManager::restore_to (cyclomatic 17): SnapshotManager::restore_to has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/snapshot.rs"},"region":{"startLine":288}}}],"partialFingerprints":{"codehealthFindingId/v1":"160d64be392b9aa78f193acc160f46ae1043ce3e581b84bc1cc168d865cce8ab"}},{"ruleId":"D1","level":"warning","message":{"text":"SnapshotManager::walk_and_store (cyclomatic 17): SnapshotManager::walk_and_store has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/snapshot.rs"},"region":{"startLine":732}}}],"partialFingerprints":{"codehealthFindingId/v1":"40c0798cfdd11bc5cc967a9c13b87fbb1cbe118d7efa8154545c841b59b93fa4"}},{"ruleId":"D1","level":"warning","message":{"text":"PtyProxy::filter_client_input (cyclomatic 17): PtyProxy::filter_client_input has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/pty_proxy.rs"},"region":{"startLine":1214}}}],"partialFingerprints":{"codehealthFindingId/v1":"9bc48a4db1076679ff7d6d6977eb31cb854f6379c6797ba0cf8b5a65235fd018"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::tool-sandbox::env::env_shebang_target_interpreter (cyclomatic 17): nono_cli::tool-sandbox::env::env_shebang_target_interpreter has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/env.rs"},"region":{"startLine":223}}}],"partialFingerprints":{"codehealthFindingId/v1":"f1ef668af1e98f54c60c66dc97c2e4c9bfce3f005929adcfc20ecd4d6b6414f1"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::launch_runtime::prepare_run_launch_plan (cyclomatic 17): nono_cli::launch_runtime::prepare_run_launch_plan has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/launch_runtime.rs"},"region":{"startLine":333}}}],"partialFingerprints":{"codehealthFindingId/v1":"2bc7f515c81c13cff76cd678188fd0f98759575f2132153621cdc8d1fbe6b313"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::trust_cmd::run_init (cyclomatic 17): nono_cli::trust_cmd::run_init has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_cmd.rs"},"region":{"startLine":49}}}],"partialFingerprints":{"codehealthFindingId/v1":"6167c2c795de68547c99721c8ae5676f2afb798ef9584050cb33e57f0498e87c"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::rollback_runtime::finalize_supervised_exit (cyclomatic 17): nono_cli::rollback_runtime::finalize_supervised_exit has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/rollback_runtime.rs"},"region":{"startLine":505}}}],"partialFingerprints":{"codehealthFindingId/v1":"c57e059bccaeceacbe53b9726653c46ccf9685939503466910d787ab19c761dd"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_proxy::config::validate_no_proxy_entry (cyclomatic 17): nono_proxy::config::validate_no_proxy_entry has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/config.rs"},"region":{"startLine":391}}}],"partialFingerprints":{"codehealthFindingId/v1":"cd7a652868262d0c0591514bf223fb552f39a5398426cc1955e75ef3244a5a6e"}},{"ruleId":"D1","level":"warning","message":{"text":"nono::audit::verify_audit_log (cyclomatic 16): nono::audit::verify_audit_log has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/audit.rs"},"region":{"startLine":1434}}}],"partialFingerprints":{"codehealthFindingId/v1":"e5341c5f43820b4cfd176800282e5678a5465a865622975177599fa9cc16c308"}},{"ruleId":"D1","level":"warning","message":{"text":"EffectiveDenyPolicy::keychain_child_deny_rules (cyclomatic 16): EffectiveDenyPolicy::keychain_child_deny_rules has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/policy.rs"},"region":{"startLine":1224}}}],"partialFingerprints":{"codehealthFindingId/v1":"22ac520dc2d9f9eff941aad1ee9916d19df5463f3878665a10c04d3ee76e87b6"}},{"ruleId":"D1","level":"warning","message":{"text":"DaemonPidLineage::attribute_with_negative_ttl (cyclomatic 16): DaemonPidLineage::attribute_with_negative_ttl has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":2162}}}],"partialFingerprints":{"codehealthFindingId/v1":"361149c85e429652f2c04a550744605d04d939c8617b6e3b552abf58e97b17d5"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::tool-sandbox::platform::linux::filter_child_env (cyclomatic 16): nono_cli::tool-sandbox::platform::linux::filter_child_env has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4425}}}],"partialFingerprints":{"codehealthFindingId/v1":"f63cb01116b669180add94805578191feb441904ca7cae0bfd09a6a9fa64435f"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::tool-sandbox::platform::linux::relay_pty_and_wait (cyclomatic 16): nono_cli::tool-sandbox::platform::linux::relay_pty_and_wait has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":5065}}}],"partialFingerprints":{"codehealthFindingId/v1":"4eea323ee5df6aedeea788c03cad515183721adddc328d5d7c54b673ed3b9326"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::session_commands::run_ps (cyclomatic 16): nono_cli::session_commands::run_ps has cyclomatic complexity 16 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/session_commands.rs"},"region":{"startLine":38}}}],"partialFingerprints":{"codehealthFindingId/v1":"c424ed4249d66d714cbb1dab837bb1a8f97aaa881c4ad2d86cd4d38a28d32c8e"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::proxy_command::build_launch_options (cyclomatic 16): nono_cli::proxy_command::build_launch_options has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_command.rs"},"region":{"startLine":188}}}],"partialFingerprints":{"codehealthFindingId/v1":"29f216990218c98eaa3c517dff992d3e1f34934779e71384f15387c77ec9dc20"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::audit_commands::cmd_verify (cyclomatic 16): nono_cli::audit_commands::cmd_verify has cyclomatic complexity 16 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":557}}}],"partialFingerprints":{"codehealthFindingId/v1":"ed944f80963474454b1634cf400ecb6993dca652940edd7be0db644884b384cb"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::tool-sandbox::dynamic_providers::git::parse_paths_from_stdout (cyclomatic 16): nono_cli::tool-sandbox::dynamic_providers::git::parse_paths_from_stdout has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/dynamic_providers.rs"},"region":{"startLine":483}}}],"partialFingerprints":{"codehealthFindingId/v1":"1a509922aac4fca574c2d3fb062caed92dcdde12731ca703f85d15ddfbff35f2"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::tool-sandbox::platform::macos::filter_child_env (cyclomatic 16): nono_cli::tool-sandbox::platform::macos::filter_child_env has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":3869}}}],"partialFingerprints":{"codehealthFindingId/v1":"e4fd7e561a5fc1521d9c8a629c78ff980a467a143fc81f844ef7b4b1fb1e93a2"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::proxy_runtime::collect_tool_sandbox_proxy_grants (cyclomatic 16): nono_cli::proxy_runtime::collect_tool_sandbox_proxy_grants has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":1828}}}],"partialFingerprints":{"codehealthFindingId/v1":"9a91c99003b21f87f9b25fedd7baebdc8c9435ac2ae87a5f54976d6d401b10a5"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::session::load_session (cyclomatic 16): nono_cli::session::load_session has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/session.rs"},"region":{"startLine":378}}}],"partialFingerprints":{"codehealthFindingId/v1":"814a908ec3bb1f03ebf019cf1495ddd4cc213226fe4e64b487f8ce353edf9534"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::profile::list_pack_store_profiles (cyclomatic 16): nono_cli::profile::list_pack_store_profiles has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":4319}}}],"partialFingerprints":{"codehealthFindingId/v1":"45340f1f668bc14a43b7df498ae2408eb51e8415ac324d7aa93d02b599378637"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::diagnostic::formatter::analyze_error_output (cyclomatic 16): nono_cli::diagnostic::formatter::analyze_error_output has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/diagnostic/formatter.rs"},"region":{"startLine":150}}}],"partialFingerprints":{"codehealthFindingId/v1":"dedea35e5230633a49279e9e869cf8436eabd7ff39c10b04a81ce75c62173dec"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::sandbox_prepare::collect_missing_cli_requested_paths (cyclomatic 16): nono_cli::sandbox_prepare::collect_missing_cli_requested_paths has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/sandbox_prepare.rs"},"region":{"startLine":40}}}],"partialFingerprints":{"codehealthFindingId/v1":"604d7586fa4d08d08564cefcbdec95c490ebe612b735af42c36b73fda7f46279"}},{"ruleId":"D1","level":"warning","message":{"text":"nono_cli::rollback_runtime::enforce_rollback_limits (cyclomatic 16): nono_cli::rollback_runtime::enforce_rollback_limits has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/rollback_runtime.rs"},"region":{"startLine":115}}}],"partialFingerprints":{"codehealthFindingId/v1":"090546fae3d1b695b1e4621dd404221e21b35f6f94a8125b08d3114dbf769301"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::exec_strategy::execute_supervised (cognitive 199): nono_cli::exec_strategy::execute_supervised has cognitive complexity 199 (threshold 15). Drivers by points: if/else 83 (157 pts), boolean chains 23, match/switch 7 (17 pts), loops 2 (nesting depth added 84). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":550}}}],"partialFingerprints":{"codehealthFindingId/v1":"2ab1f25c51a5644d19260306c851ebf6f9d817ca8734e9939fe5a8d417c1e5c2"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_proxy::server::handle_connection (cognitive 131): nono_proxy::server::handle_connection has cognitive complexity 131 (threshold 15). Drivers by points: if/else 37 (94 pts), match/switch 3 (16 pts), loops 3 (13 pts), boolean chains 8 (nesting depth added 80). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/server.rs"},"region":{"startLine":1477}}}],"partialFingerprints":{"codehealthFindingId/v1":"50f5a92332f10d14e9eb03b614a3e07308d5c01b4c3442ea5bfaafbd6be0c641"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile_cmd::cmd_diff (cognitive 118): nono_cli::profile_cmd::cmd_diff has cognitive complexity 118 (threshold 15). Drivers by points: if/else 39 (74 pts), loops 18 (36 pts), boolean chains 8 (nesting depth added 53). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":1422}}}],"partialFingerprints":{"codehealthFindingId/v1":"6b6f6dc68bc188cda773e9523835ba3c1f32cf5ded394bc302afdd36d5583213"}},{"ruleId":"D2","level":"warning","message":{"text":"CapabilitySet::from_profile (cognitive 103): CapabilitySet::from_profile has cognitive complexity 103 (threshold 15). Drivers by points: if/else 31 (71 pts), loops 23 (30 pts), boolean chains 2 (nesting depth added 47). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/capability_ext.rs"},"region":{"startLine":693}}}],"partialFingerprints":{"codehealthFindingId/v1":"9901ef9b695070dcea5f70e17c65f8cdee20ce43ceac96feb8b97ab468472ec4"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::execution_runtime::execute_sandboxed (cognitive 85): nono_cli::execution_runtime::execute_sandboxed has cognitive complexity 85 (threshold 15). Drivers by points: if/else 41 (53 pts), match/switch 7 (13 pts), boolean chains 10, loops 5 (9 pts) (nesting depth added 22). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/execution_runtime.rs"},"region":{"startLine":203}}}],"partialFingerprints":{"codehealthFindingId/v1":"e00a40d940e9efe86404e75ea062a1d75382e68c15e967272f7c1fb3bacabb87"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile_cmd::cmd_show (cognitive 78): nono_cli::profile_cmd::cmd_show has cognitive complexity 78 (threshold 15). Drivers by points: if/else 36 (49 pts), loops 10 (20 pts), boolean chains 6, match/switch 1 (3 pts) (nesting depth added 25). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":855}}}],"partialFingerprints":{"codehealthFindingId/v1":"8a9b70718dccfa7af1a4edd0e483615ced52bb4075174ded2cad3cd6267d78a8"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::tool-sandbox::platform::linux::handle_shim_stream_inner (cognitive 72): nono_cli::tool-sandbox::platform::linux::handle_shim_stream_inner has cognitive complexity 72 (threshold 15). Drivers by points: if/else 28 (48 pts), match/switch 13 (24 pts) (nesting depth added 31). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1265}}}],"partialFingerprints":{"codehealthFindingId/v1":"acaec8e169c235066ed9f7c7d54620a442fd4c0acad2da77eecf02e0a465d53d"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::exec_strategy::supervisor_linux::handle_received_filesystem_notification (cognitive 71): nono_cli::exec_strategy::supervisor_linux::handle_received_filesystem_notification has cognitive complexity 71 (threshold 15). Drivers by points: if/else 29 (46 pts), match/switch 12 (19 pts), boolean chains 6 (nesting depth added 24). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy/supervisor_linux.rs"},"region":{"startLine":195}}}],"partialFingerprints":{"codehealthFindingId/v1":"d93f5928d7f5fe64d61fb5d73a8b9e2ea9e9e151683e36228107e379d1da9783"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::tool-sandbox::platform::macos::handle_shim_stream_inner (cognitive 69): nono_cli::tool-sandbox::platform::macos::handle_shim_stream_inner has cognitive complexity 69 (threshold 15). Drivers by points: if/else 28 (47 pts), match/switch 12 (22 pts) (nesting depth added 29). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":972}}}],"partialFingerprints":{"codehealthFindingId/v1":"7bc411a18ffaf7e4697bf5c896d53ed666fac6b880535ef243f1fc46cbd782e7"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::pty_proxy::run_attach_loop (cognitive 69): nono_cli::pty_proxy::run_attach_loop has cognitive complexity 69 (threshold 15). Drivers by points: if/else 19 (55 pts), match/switch 3 (10 pts), boolean chains 3, loops 1 (nesting depth added 43). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/pty_proxy.rs"},"region":{"startLine":2574}}}],"partialFingerprints":{"codehealthFindingId/v1":"63da30a6d04b516159a29c57fbb0b7b7b1f3faf707f4e88bce51979ac84f869f"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile::validate_credential_capture_entries (cognitive 64): nono_cli::profile::validate_credential_capture_entries has cognitive complexity 64 (threshold 15). Drivers by points: if/else 19 (44 pts), boolean chains 9, loops 4 (9 pts), match/switch 1 (2 pts) (nesting depth added 31). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":1393}}}],"partialFingerprints":{"codehealthFindingId/v1":"2e9803ffeebf45a76b940e73358445af75784b182b0bb1393c468457d2f65357"}},{"ruleId":"D2","level":"warning","message":{"text":"nono::capability::tokenize_sexp (cognitive 63): nono::capability::tokenize_sexp has cognitive complexity 63 (threshold 15). Drivers by points: if/else 12 (40 pts), loops 6 (18 pts), boolean chains 3, match/switch 1 (2 pts) (nesting depth added 41). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/capability.rs"},"region":{"startLine":681}}}],"partialFingerprints":{"codehealthFindingId/v1":"89583b5411e7f9bef1f3c2f78a96f3815132a0be144fed846f0f99d3e8594066"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::exec_strategy::run_supervisor_loop (cognitive 61): nono_cli::exec_strategy::run_supervisor_loop has cognitive complexity 61 (threshold 15). Drivers by points: if/else 17 (40 pts), boolean chains 12, match/switch 3 (8 pts), loops 1 (nesting depth added 28). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":2848}}}],"partialFingerprints":{"codehealthFindingId/v1":"592f24f50228d1e1b56c0c3f086819bb6d9dba8c8b4a5250dabe7a8421c055b2"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::sandbox_prepare::prepare_sandbox (cognitive 60): nono_cli::sandbox_prepare::prepare_sandbox has cognitive complexity 60 (threshold 15). Drivers by points: if/else 29 (41 pts), loops 4 (10 pts), boolean chains 9 (nesting depth added 18). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/sandbox_prepare.rs"},"region":{"startLine":1427}}}],"partialFingerprints":{"codehealthFindingId/v1":"0044eaf776ee4bca25fbc9c0fa9159ea3866f576dad8cd0c7048c91c56efe591"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_proxy::tls_intercept::handle::select_intercept_route (cognitive 57): nono_proxy::tls_intercept::handle::select_intercept_route has cognitive complexity 57 (threshold 15). Drivers by points: if/else 21 (42 pts), match/switch 5 (11 pts), boolean chains 3, loops 1 (nesting depth added 27). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":397}}}],"partialFingerprints":{"codehealthFindingId/v1":"12aadd568edef74cd9b90870bbb0429eeb4664c0c86ea64f807ab0c6089b27f3"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::policy::apply_deny_overrides (cognitive 56): nono_cli::policy::apply_deny_overrides has cognitive complexity 56 (threshold 15). Drivers by points: if/else 20 (43 pts), loops 3 (6 pts), match/switch 1 (4 pts), boolean chains 3 (nesting depth added 29). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/policy.rs"},"region":{"startLine":1687}}}],"partialFingerprints":{"codehealthFindingId/v1":"eb40d2cf2598ffd582ebe38359043fc9aa847a48b9ddee1c8a72d1868195a690"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_proxy::reverse::handle_reverse_proxy (cognitive 52): nono_proxy::reverse::handle_reverse_proxy has cognitive complexity 52 (threshold 15). Drivers by points: if/else 27 (37 pts), match/switch 6 (9 pts), boolean chains 5, loops 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":128}}}],"partialFingerprints":{"codehealthFindingId/v1":"be03a0451ec7358b35462286b8a2b829c21f2d68d334b5c829028fc0a01c9829"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::output::print_capabilities (cognitive 51): nono_cli::output::print_capabilities has cognitive complexity 51 (threshold 15). Drivers by points: if/else 25 (39 pts), loops 3 (6 pts), match/switch 2 (4 pts), boolean chains 2 (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/output.rs"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"0baf0cb366d49c7088a8a5e07ad019e71fb2c0fade1ba9b8d70598b164e3bb9b"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile_cmd::cmd_validate (cognitive 49): nono_cli::profile_cmd::cmd_validate has cognitive complexity 49 (threshold 15). Drivers by points: if/else 19 (33 pts), loops 7 (12 pts), boolean chains 3, match/switch 1 (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":2402}}}],"partialFingerprints":{"codehealthFindingId/v1":"2457ae234ebf117deef87f3e5ff015d47c1fc7804be3f2ecaad8370f45be625a"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::audit_commands::cmd_show (cognitive 48): nono_cli::audit_commands::cmd_show has cognitive complexity 48 (threshold 15). Drivers by points: if/else 20 (30 pts), loops 5 (10 pts), match/switch 3 (8 pts) (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":348}}}],"partialFingerprints":{"codehealthFindingId/v1":"6c18e3a28d617abce91a96621eb6d050195ec7c9fdeaf28bb80d2042d62f5408"}},{"ruleId":"D2","level":"warning","message":{"text":"nono::keystore::build_mappings_from_list (cognitive 47): nono::keystore::build_mappings_from_list has cognitive complexity 47 (threshold 15). Drivers by points: if/else 20 (42 pts), match/switch 1 (4 pts), loops 1 (nesting depth added 25). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/keystore.rs"},"region":{"startLine":1912}}}],"partialFingerprints":{"codehealthFindingId/v1":"e3f74569c7029140cebbfd4d596b76a8e8583fa5f9facb48024cd970a7d8609b"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::exec_strategy::handle_supervisor_message (cognitive 47): nono_cli::exec_strategy::handle_supervisor_message has cognitive complexity 47 (threshold 15). Drivers by points: if/else 14 (31 pts), match/switch 6 (16 pts) (nesting depth added 27). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":3291}}}],"partialFingerprints":{"codehealthFindingId/v1":"7c57a86eecf6db2c939755d2eb0c6f419ce323873d204bc2e8bb0ab314c461fe"}},{"ruleId":"D2","level":"warning","message":{"text":"DiagnosticFormatter::format_consolidated_denial_guidance (cognitive 46): DiagnosticFormatter::format_consolidated_denial_guidance has cognitive complexity 46 (threshold 15). Drivers by points: if/else 27 (42 pts), loops 3 (4 pts) (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/diagnostic/formatter.rs"},"region":{"startLine":1707}}}],"partialFingerprints":{"codehealthFindingId/v1":"6c8e4fcbc8bb7fb01710c2a79288f66bf0e4973cb976b2b7d438550245c06c43"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::capability_ext::add_cli_unix_socket_caps (cognitive 45): nono_cli::capability_ext::add_cli_unix_socket_caps has cognitive complexity 45 (threshold 15). Drivers by points: if/else 15 (37 pts), loops 6, boolean chains 2 (nesting depth added 22). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/capability_ext.rs"},"region":{"startLine":130}}}],"partialFingerprints":{"codehealthFindingId/v1":"bf01ea2963ede55a2664ea509151c33762b792c85c6f184a403c8c215fc09ea3"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile_runtime::prepare_profile_with_options (cognitive 45): nono_cli::profile_runtime::prepare_profile_with_options has cognitive complexity 45 (threshold 15). Drivers by points: if/else 19 (36 pts), loops 3 (7 pts), boolean chains 2 (nesting depth added 21). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_runtime.rs"},"region":{"startLine":658}}}],"partialFingerprints":{"codehealthFindingId/v1":"c8720b1399682e87f0a51caaed8a647e90974ac5c699337a5f8446aeba384d9b"}},{"ruleId":"D2","level":"warning","message":{"text":"CredentialStore::load_with_diagnostics (cognitive 45): CredentialStore::load_with_diagnostics has cognitive complexity 45 (threshold 15). Drivers by points: if/else 9 (23 pts), match/switch 6 (21 pts), loops 1 (nesting depth added 29). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/credential.rs"},"region":{"startLine":222}}}],"partialFingerprints":{"codehealthFindingId/v1":"0f8f455bf687f201b7d377cc803910571d4af940945368da8b5da0f6e5a9571d"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::exec_strategy::run_supervisor_loop (cognitive 44): nono_cli::exec_strategy::run_supervisor_loop has cognitive complexity 44 (threshold 15). Drivers by points: if/else 13 (32 pts), match/switch 2 (6 pts), boolean chains 5, loops 1 (nesting depth added 23). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":2603}}}],"partialFingerprints":{"codehealthFindingId/v1":"c0f550454169b55efbbf8ab01c8af1ec0378555489a34902c19b2d177ee738d2"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::trust_scan::run_pre_exec_scan (cognitive 44): nono_cli::trust_scan::run_pre_exec_scan has cognitive complexity 44 (threshold 15). Drivers by points: if/else 22 (35 pts), boolean chains 5, loops 3 (4 pts) (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_scan.rs"},"region":{"startLine":375}}}],"partialFingerprints":{"codehealthFindingId/v1":"645a6c064b5b218fc500b61d0ec8fa46fac3d3054ab5bf580d73c31ced167bfc"}},{"ruleId":"D2","level":"warning","message":{"text":"CapabilitySet::try_from (cognitive 43): CapabilitySet::try_from has cognitive complexity 43 (threshold 15). Drivers by points: loops 8 (21 pts), if/else 7 (13 pts), match/switch 3 (9 pts) (nesting depth added 25). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/manifest_convert.rs"},"region":{"startLine":24}}}],"partialFingerprints":{"codehealthFindingId/v1":"052aeea91da77f38d7d86fd638a3626e1ce845e9ca4144bf32af7a5e33dff323"}},{"ruleId":"D2","level":"warning","message":{"text":"SnapshotManager::walk_and_store (cognitive 43): SnapshotManager::walk_and_store has cognitive complexity 43 (threshold 15). Drivers by points: if/else 10 (31 pts), match/switch 2 (7 pts), loops 2 (3 pts), boolean chains 2 (nesting depth added 27). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/snapshot.rs"},"region":{"startLine":732}}}],"partialFingerprints":{"codehealthFindingId/v1":"7ecdaa695669a6da5e9528aa72675de231d13c62da1d9d4b7f621b7df5a988d7"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::exec_strategy::clone_files::child_exec (cognitive 43): nono_cli::exec_strategy::clone_files::child_exec has cognitive complexity 43 (threshold 15). Drivers by points: if/else 31 (35 pts), boolean chains 6, loops 1, match/switch 1 (nesting depth added 4). This file\u0027s own header attributes it to another copyright holder, so it is code this repository carries rather than code it wrote: restructuring the body in place forks it from upstream and turns every future re-sync into a manual merge. The performable moves are to leave the body as close to its upstream form as possible and keep it behind a narrow interface of your own, and to re-sync it when upstream changes \u2014 or, if it has already diverged far enough that you maintain it here, adopt it deliberately and then split the body into named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy/clone_files.rs"},"region":{"startLine":314}}}],"partialFingerprints":{"codehealthFindingId/v1":"4b10aaa922d0a4850d0b7e4e95d1b0c727a8f3897ec46a152e07748804d70178"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::proxy_runtime::build_proxy_config_from_flags (cognitive 43): nono_cli::proxy_runtime::build_proxy_config_from_flags has cognitive complexity 43 (threshold 15). Drivers by points: if/else 17 (33 pts), loops 5 (8 pts), boolean chains 2 (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":2357}}}],"partialFingerprints":{"codehealthFindingId/v1":"2dbbd39c6c6ae657953b39a936404dc418918bac4ef499130f4ddf1da90e6894"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::exec_strategy::supervisor_linux::handle_received_network_notification (cognitive 43): nono_cli::exec_strategy::supervisor_linux::handle_received_network_notification has cognitive complexity 43 (threshold 15). Drivers by points: if/else 12 (25 pts), match/switch 8 (15 pts), loops 2 (3 pts) (nesting depth added 21). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy/supervisor_linux.rs"},"region":{"startLine":1043}}}],"partialFingerprints":{"codehealthFindingId/v1":"3bd07201070d555937c5e9e7771d607e8ffc9ad162c82786a137de7ce3cf4512"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile::find_pack_store_profile (cognitive 43): nono_cli::profile::find_pack_store_profile has cognitive complexity 43 (threshold 15). Drivers by points: if/else 9 (24 pts), match/switch 4 (12 pts), loops 3 (6 pts), boolean chains 1 (nesting depth added 26). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":2987}}}],"partialFingerprints":{"codehealthFindingId/v1":"1ef37d001cb7d8baf6144c5094bafeab993fb892e32e086aa1fba546aff32a1d"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile::list_pack_store_profiles (cognitive 43): nono_cli::profile::list_pack_store_profiles has cognitive complexity 43 (threshold 15). Drivers by points: if/else 10 (30 pts), loops 4 (12 pts), match/switch 1 (nesting depth added 28). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":4319}}}],"partialFingerprints":{"codehealthFindingId/v1":"816f39ffdfcf6ce577cd2964237e2a8c3d8cb79b37b612f5872afb17baabd1e0"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_proxy::tls_intercept::handle::handle_inner_request (cognitive 43): nono_proxy::tls_intercept::handle::handle_inner_request has cognitive complexity 43 (threshold 15). Drivers by points: if/else 21 (23 pts), match/switch 9 (14 pts), boolean chains 5, loops 1 (nesting depth added 7). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":1030}}}],"partialFingerprints":{"codehealthFindingId/v1":"3decb49cee482caf29fd47fddb0d4250f8baa346a776b26fd43058640281541d"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_proxy::tls_intercept::h2_forward::handle_h2_stream (cognitive 43): nono_proxy::tls_intercept::h2_forward::handle_h2_stream has cognitive complexity 43 (threshold 15). Drivers by points: if/else 19 (26 pts), match/switch 6 (9 pts), boolean chains 5, loops 2 (3 pts) (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/h2_forward.rs"},"region":{"startLine":232}}}],"partialFingerprints":{"codehealthFindingId/v1":"84e7bd52d2bc1828299dc1c5dce8aba4a9f5af607c687f298cd28e8aa9510947"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_proxy::server::start_with_nonce_resolver (cognitive 43): nono_proxy::server::start_with_nonce_resolver has cognitive complexity 43 (threshold 15). Drivers by points: if/else 28 (35 pts), match/switch 3 (4 pts), boolean chains 3, loops 1 (nesting depth added 8). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/server.rs"},"region":{"startLine":1054}}}],"partialFingerprints":{"codehealthFindingId/v1":"4797fae8502a84b35a093675cc451e7946f047d03fae177b6095cbd0703bb692"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::policy::apply_macos_keychain_db_exception (cognitive 42): nono_cli::policy::apply_macos_keychain_db_exception has cognitive complexity 42 (threshold 15). Drivers by points: if/else 10 (17 pts), match/switch 7 (12 pts), loops 6 (8 pts), boolean chains 5 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/policy.rs"},"region":{"startLine":1435}}}],"partialFingerprints":{"codehealthFindingId/v1":"d39da6ef162950d2e26878c0e4851a8bf9e04af6790ee57e317a6b532fc110da"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::exec_strategy::clone_files::scrub_fds (cognitive 42): nono_cli::exec_strategy::clone_files::scrub_fds has cognitive complexity 42 (threshold 15). Drivers by points: if/else 11 (33 pts), loops 3 (6 pts), boolean chains 3 (nesting depth added 25). This file\u0027s own header attributes it to another copyright holder, so it is code this repository carries rather than code it wrote: restructuring the body in place forks it from upstream and turns every future re-sync into a manual merge. The performable moves are to leave the body as close to its upstream form as possible and keep it behind a narrow interface of your own, and to re-sync it when upstream changes \u2014 or, if it has already diverged far enough that you maintain it here, adopt it deliberately and then split the body into named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy/clone_files.rs"},"region":{"startLine":543}}}],"partialFingerprints":{"codehealthFindingId/v1":"c72bbc5f684d57f67ddc60479ea3d270aa3836eef292ba0c3194488a7f1e7822"}},{"ruleId":"D2","level":"warning","message":{"text":"CapabilitySet::deduplicate_unix_sockets (cognitive 41): CapabilitySet::deduplicate_unix_sockets has cognitive complexity 41 (threshold 15). Drivers by points: if/else 10 (27 pts), boolean chains 7, loops 4, match/switch 1 (3 pts) (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/capability.rs"},"region":{"startLine":1934}}}],"partialFingerprints":{"codehealthFindingId/v1":"402844650ab8803fff454a55a7dbb26a8e9e1fc482742902ed75ff05bce408dd"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile_save_runtime::interactive_denial_selector (cognitive 41): nono_cli::profile_save_runtime::interactive_denial_selector has cognitive complexity 41 (threshold 15). Drivers by points: if/else 6 (15 pts), match/switch 6 (15 pts), loops 4 (10 pts), boolean chains 1 (nesting depth added 24). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_save_runtime.rs"},"region":{"startLine":1450}}}],"partialFingerprints":{"codehealthFindingId/v1":"f53b8db6d3180d3cf353b0d55cf5fea923aa40224afa87d560c5c029f2fb7c35"}},{"ruleId":"D2","level":"warning","message":{"text":"CapabilitySet::deduplicate (cognitive 40): CapabilitySet::deduplicate has cognitive complexity 40 (threshold 15). Drivers by points: if/else 11 (28 pts), boolean chains 5, loops 4, match/switch 1 (3 pts) (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/capability.rs"},"region":{"startLine":1777}}}],"partialFingerprints":{"codehealthFindingId/v1":"e89d9dd1357e87fb0c2e3f04665d3e72927dc001a7257a64ae46660571c871ce"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::query_ext::query_network (cognitive 40): nono_cli::query_ext::query_network has cognitive complexity 40 (threshold 15). Drivers by points: if/else 12 (26 pts), match/switch 5 (13 pts), boolean chains 1 (nesting depth added 22). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/query_ext.rs"},"region":{"startLine":240}}}],"partialFingerprints":{"codehealthFindingId/v1":"c3a3026793f729a3fb64e8cbca861bcd02dac16e35bc43aee3ff361eea25ae0a"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile_cmd::resolve_to_manifest (cognitive 39): nono_cli::profile_cmd::resolve_to_manifest has cognitive complexity 39 (threshold 15). Drivers by points: if/else 15, match/switch 8 (11 pts), loops 6 (7 pts), boolean chains 6 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":2942}}}],"partialFingerprints":{"codehealthFindingId/v1":"f493da7e3f9d7eab8c3a8a29230a93850546a2c1112d20f77088c7fbf83af1cc"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::exec_strategy::clone_files::transfer (cognitive 39): nono_cli::exec_strategy::clone_files::transfer has cognitive complexity 39 (threshold 15). Drivers by points: if/else 17 (35 pts), boolean chains 3, loops 1 (nesting depth added 18). This file\u0027s own header attributes it to another copyright holder, so it is code this repository carries rather than code it wrote: restructuring the body in place forks it from upstream and turns every future re-sync into a manual merge. The performable moves are to leave the body as close to its upstream form as possible and keep it behind a narrow interface of your own, and to re-sync it when upstream changes \u2014 or, if it has already diverged far enough that you maintain it here, adopt it deliberately and then split the body into named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy/clone_files.rs"},"region":{"startLine":713}}}],"partialFingerprints":{"codehealthFindingId/v1":"c6f81496ac2ae073debaa0ee8410360fd6e9a538d44c78cda0f68d28c7c62f4e"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile::credential_provider::validate_credential_provider_entries (cognitive 39): nono_cli::profile::credential_provider::validate_credential_provider_entries has cognitive complexity 39 (threshold 15). Drivers by points: if/else 12 (24 pts), loops 6 (12 pts), match/switch 1 (2 pts), boolean chains 1 (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/credential_provider.rs"},"region":{"startLine":149}}}],"partialFingerprints":{"codehealthFindingId/v1":"d2438bbd59bb155a9dddde1d0dbc11ae394a1f9efe68b6fb442e712558f28603"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::terminal_approval::sanitize_for_terminal (cognitive 38): nono_cli::terminal_approval::sanitize_for_terminal has cognitive complexity 38 (threshold 15). Drivers by points: if/else 8 (25 pts), loops 3 (11 pts), boolean chains 2 (nesting depth added 25). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/terminal_approval.rs"},"region":{"startLine":139}}}],"partialFingerprints":{"codehealthFindingId/v1":"999096151360bee219c88953f76b60e3fa41c2da69769d094131f8facab6794d"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::audit_commands::sanitize_for_terminal (cognitive 38): nono_cli::audit_commands::sanitize_for_terminal has cognitive complexity 38 (threshold 15). Drivers by points: if/else 8 (25 pts), loops 3 (11 pts), boolean chains 2 (nesting depth added 25). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":1091}}}],"partialFingerprints":{"codehealthFindingId/v1":"b1e5cf50f59530d22b05bf5d39617903c267fd4f13e7078ac2ead69b7ca84044"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::pty_proxy::match_enhanced_key_sequence (cognitive 38): nono_cli::pty_proxy::match_enhanced_key_sequence has cognitive complexity 38 (threshold 15). Drivers by points: if/else 20 (32 pts), boolean chains 6 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/pty_proxy.rs"},"region":{"startLine":1394}}}],"partialFingerprints":{"codehealthFindingId/v1":"871393427d70c991d2392c657536b4b436169f905cb235d684f05e28cb84e985"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile_save_runtime::build_combined_patch_from_items (cognitive 37): nono_cli::profile_save_runtime::build_combined_patch_from_items has cognitive complexity 37 (threshold 15). Drivers by points: if/else 6 (18 pts), match/switch 5 (14 pts), boolean chains 4, loops 1 (nesting depth added 21). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_save_runtime.rs"},"region":{"startLine":1566}}}],"partialFingerprints":{"codehealthFindingId/v1":"2479ff4f876d095caaab1cbf7077c5e49b00485c65006e5e980ff699644af84a"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::proxy_runtime::prepare_proxy_launch_options (cognitive 37): nono_cli::proxy_runtime::prepare_proxy_launch_options has cognitive complexity 37 (threshold 15). Drivers by points: if/else 23 (28 pts), boolean chains 9 (nesting depth added 5). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":1430}}}],"partialFingerprints":{"codehealthFindingId/v1":"3707c455b932d2af948419ad56ddd260f04760e3b6b7c22826a729bb2a44100f"}},{"ruleId":"D2","level":"warning","message":{"text":"DiagnosticFormatter::format_supervised_footer_with_diagnostics (cognitive 36): DiagnosticFormatter::format_supervised_footer_with_diagnostics has cognitive complexity 36 (threshold 15). Drivers by points: if/else 17 (27 pts), boolean chains 9 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/diagnostic/formatter.rs"},"region":{"startLine":1250}}}],"partialFingerprints":{"codehealthFindingId/v1":"c8a9ea058badf1a336d598f45499b054ef46edd772b496d8d4c95264850af523"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::session::load_session (cognitive 36): nono_cli::session::load_session has cognitive complexity 36 (threshold 15). Drivers by points: if/else 9 (20 pts), match/switch 4 (12 pts), loops 2 (3 pts), boolean chains 1 (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/session.rs"},"region":{"startLine":378}}}],"partialFingerprints":{"codehealthFindingId/v1":"2edb70ceea76c746380a80fcbe6351e20e45b859d90950236309c9346379042b"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::package_cmd::run_update (cognitive 36): nono_cli::package_cmd::run_update has cognitive complexity 36 (threshold 15). Drivers by points: if/else 14 (23 pts), match/switch 4 (10 pts), boolean chains 2, loops 1 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/package_cmd.rs"},"region":{"startLine":224}}}],"partialFingerprints":{"codehealthFindingId/v1":"5616e20f548b4a264384074bcc9e0663835c580f008fba79573f81b96f107f3d"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile::validate_custom_credential (cognitive 35): nono_cli::profile::validate_custom_credential has cognitive complexity 35 (threshold 15). Drivers by points: if/else 15 (19 pts), boolean chains 13, match/switch 1 (2 pts), loops 1 (nesting depth added 5). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":607}}}],"partialFingerprints":{"codehealthFindingId/v1":"f0768ae3b45305fb02c1ebee8503bb34a84ba5b452088a73c7af1534cea63a0e"}},{"ruleId":"D2","level":"warning","message":{"text":"SnapshotManager::restore_to (cognitive 34): SnapshotManager::restore_to has cognitive complexity 34 (threshold 15). Drivers by points: if/else 13 (27 pts), loops 4, match/switch 2 (3 pts) (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/snapshot.rs"},"region":{"startLine":288}}}],"partialFingerprints":{"codehealthFindingId/v1":"8b46e4019301beb925878153fc883a828654abe6a563c35a6b8512d9907490cc"}},{"ruleId":"D2","level":"warning","message":{"text":"PtyProxy::try_accept (cognitive 34): PtyProxy::try_accept has cognitive complexity 34 (threshold 15). Drivers by points: if/else 10 (23 pts), match/switch 5 (10 pts), boolean chains 1 (nesting depth added 18). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/pty_proxy.rs"},"region":{"startLine":552}}}],"partialFingerprints":{"codehealthFindingId/v1":"d9c23141ae10dbc1932c9a1126fa13b9c0d17bed6ed9bbf60b0623412a8e194a"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile_save_runtime::render_denial_selector (cognitive 34): nono_cli::profile_save_runtime::render_denial_selector has cognitive complexity 34 (threshold 15). Drivers by points: if/else 13 (21 pts), match/switch 4 (11 pts), boolean chains 1, loops 1 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_save_runtime.rs"},"region":{"startLine":1266}}}],"partialFingerprints":{"codehealthFindingId/v1":"38d65b5255f5bf17dca40c473fbe0b55d53a810e945e6f5814ec5872524dfa70"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::proxy_runtime::collect_tool_sandbox_proxy_grants (cognitive 34): nono_cli::proxy_runtime::collect_tool_sandbox_proxy_grants has cognitive complexity 34 (threshold 15). Drivers by points: if/else 15 (32 pts), loops 2 (nesting depth added 17). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":1828}}}],"partialFingerprints":{"codehealthFindingId/v1":"4943c9d08a22558a640377374db8c3852704cb784aa2942446919398a3d52386"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::rollback_commands::cmd_cleanup (cognitive 33): nono_cli::rollback_commands::cmd_cleanup has cognitive complexity 33 (threshold 15). Drivers by points: if/else 12 (21 pts), loops 5 (10 pts), boolean chains 2 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/rollback_commands.rs"},"region":{"startLine":801}}}],"partialFingerprints":{"codehealthFindingId/v1":"685c77708814cc6ce873b144134dd46c82df12ad99a743fa3d87a11147825454"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::connect_client::attach (cognitive 33): nono_cli::connect_client::attach has cognitive complexity 33 (threshold 15). Drivers by points: if/else 6 (20 pts), match/switch 4 (11 pts), loops 2 (nesting depth added 21). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/connect_client.rs"},"region":{"startLine":1575}}}],"partialFingerprints":{"codehealthFindingId/v1":"7fe865488918b03274c303339cbec5fe864e18a9eb0d27dd404878e000f83fb8"}},{"ruleId":"D2","level":"warning","message":{"text":"DetachMatcher::push (cognitive 32): DetachMatcher::push has cognitive complexity 32 (threshold 15). Drivers by points: if/else 10 (27 pts), match/switch 1 (3 pts), boolean chains 1, loops 1 (nesting depth added 19). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/connect_client.rs"},"region":{"startLine":1826}}}],"partialFingerprints":{"codehealthFindingId/v1":"332a31382f7b5809b7bf8b016055e3760c3295e3034092aaf00351e6f7158151"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::why_runtime::run_why (cognitive 32): nono_cli::why_runtime::run_why has cognitive complexity 32 (threshold 15). Drivers by points: if/else 19 (24 pts), match/switch 4 (8 pts) (nesting depth added 9). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/why_runtime.rs"},"region":{"startLine":117}}}],"partialFingerprints":{"codehealthFindingId/v1":"6af4c2530aad29c06001376ce22e43048a0e66526deb14af5d0e3f15555541ab"}},{"ruleId":"D2","level":"warning","message":{"text":"PtyProxy::filter_client_input (cognitive 31): PtyProxy::filter_client_input has cognitive complexity 31 (threshold 15). Drivers by points: if/else 12 (27 pts), boolean chains 3, loops 1 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/pty_proxy.rs"},"region":{"startLine":1214}}}],"partialFingerprints":{"codehealthFindingId/v1":"6fa42eaca7662f68bdbf7201e59ed2c9ca9db18c6ea34ae011e0a243ad998e2a"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::tool-sandbox::platform::linux::relay_pty_and_wait (cognitive 31): nono_cli::tool-sandbox::platform::linux::relay_pty_and_wait has cognitive complexity 31 (threshold 15). Drivers by points: if/else 10 (20 pts), match/switch 2 (8 pts), boolean chains 2, loops 1 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":5065}}}],"partialFingerprints":{"codehealthFindingId/v1":"aebbac0511e1248ec58ec19e8304a9e1939a7967094130a447d4106560009e0a"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile::validate_proxy_override (cognitive 31): nono_cli::profile::validate_proxy_override has cognitive complexity 31 (threshold 15). Drivers by points: if/else 12 (26 pts), boolean chains 4, match/switch 1 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":763}}}],"partialFingerprints":{"codehealthFindingId/v1":"f708a84e32b1b621d7a22dc8fa5623d27f319ff4245bf2510dfa55d4c07a73de"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::command_policy::validate_credential (cognitive 31): nono_cli::command_policy::validate_credential has cognitive complexity 31 (threshold 15). Drivers by points: if/else 18 (24 pts), boolean chains 6, match/switch 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_policy.rs"},"region":{"startLine":2551}}}],"partialFingerprints":{"codehealthFindingId/v1":"8dee6e848ed312a9f91f68098ef83b1bdadb2b8b1c93b7f426b6353febe739a8"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::query_ext::print_result (cognitive 30): nono_cli::query_ext::print_result has cognitive complexity 30 (threshold 15). Drivers by points: if/else 14 (23 pts), loops 2 (6 pts), match/switch 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/query_ext.rs"},"region":{"startLine":621}}}],"partialFingerprints":{"codehealthFindingId/v1":"51e2b01b244bb7651ca8bb0d9d65d938c7b8c63b826b82ee02f1dab2ef83f6e4"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::command_policy::validate_intercept_rules (cognitive 30): nono_cli::command_policy::validate_intercept_rules has cognitive complexity 30 (threshold 15). Drivers by points: if/else 9 (22 pts), match/switch 2 (5 pts), boolean chains 2, loops 1 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_policy.rs"},"region":{"startLine":1751}}}],"partialFingerprints":{"codehealthFindingId/v1":"c00c8e20ab99989c07218b138da1e0e5c99e0122e5d9a82422d5a2f5a46d54aa"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::rollback_runtime::finalize_supervised_exit (cognitive 30): nono_cli::rollback_runtime::finalize_supervised_exit has cognitive complexity 30 (threshold 15). Drivers by points: if/else 14 (24 pts), boolean chains 2, loops 1 (2 pts), match/switch 1 (2 pts) (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/rollback_runtime.rs"},"region":{"startLine":505}}}],"partialFingerprints":{"codehealthFindingId/v1":"9be050453fa1802475dedd5113901c62dc649cd5caf459861747397b7eef6e51"}},{"ruleId":"D2","level":"warning","message":{"text":"nono::trust::policy::merge_policies (cognitive 29): nono::trust::policy::merge_policies has cognitive complexity 29 (threshold 15). Drivers by points: if/else 7 (17 pts), loops 7 (12 pts) (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/trust/policy.rs"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"cd36395d886feedb9de50e837280d06d0df69055b18b153e92875e4c4fee4971"}},{"ruleId":"D2","level":"warning","message":{"text":"EffectiveDenyPolicy::keychain_child_deny_rules (cognitive 29): EffectiveDenyPolicy::keychain_child_deny_rules has cognitive complexity 29 (threshold 15). Drivers by points: if/else 8 (16 pts), loops 6 (10 pts), boolean chains 3 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/policy.rs"},"region":{"startLine":1224}}}],"partialFingerprints":{"codehealthFindingId/v1":"1093b2848f2e8fba148f2a5c2f14f341efcb6136d61be08b281e68d580eeeebf"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::trust_cmd::run_verify (cognitive 29): nono_cli::trust_cmd::run_verify has cognitive complexity 29 (threshold 15). Drivers by points: if/else 11 (17 pts), loops 4 (6 pts), match/switch 2 (4 pts), boolean chains 2 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_cmd.rs"},"region":{"startLine":759}}}],"partialFingerprints":{"codehealthFindingId/v1":"6a20c83fa2515bc744e9ca816a7365b8cecb4fb744719c07044433bcda5740f0"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::rollback_preflight::detect_heavy_dirs (cognitive 28): nono_cli::rollback_preflight::detect_heavy_dirs has cognitive complexity 28 (threshold 15). Drivers by points: if/else 9 (20 pts), loops 3 (4 pts), boolean chains 2, match/switch 1 (2 pts) (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/rollback_preflight.rs"},"region":{"startLine":142}}}],"partialFingerprints":{"codehealthFindingId/v1":"783867014f7cd84d42f5ed5c62b67da16cd2106dd6d9de485592774d40d5621b"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::tool-sandbox::platform::linux::build_child_launch_spec_for_binary (cognitive 28): nono_cli::tool-sandbox::platform::linux::build_child_launch_spec_for_binary has cognitive complexity 28 (threshold 15). Drivers by points: loops 6 (13 pts), if/else 7 (11 pts), boolean chains 4 (nesting depth added 11). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3570}}}],"partialFingerprints":{"codehealthFindingId/v1":"b60546af5af22d22c3a64c168bfd203b12494a500abc30a14b12e5c301b373bd"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::session_commands::run_prune (cognitive 28): nono_cli::session_commands::run_prune has cognitive complexity 28 (threshold 15). Drivers by points: if/else 14 (25 pts), loops 2, boolean chains 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/session_commands.rs"},"region":{"startLine":603}}}],"partialFingerprints":{"codehealthFindingId/v1":"7c022ccc9dca129b5e75b06f9e37efb689c23701246184f32aa6bee123602209"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile_save_runtime::prompt_profile_name (cognitive 28): nono_cli::profile_save_runtime::prompt_profile_name has cognitive complexity 28 (threshold 15). Drivers by points: if/else 11 (24 pts), match/switch 1 (3 pts), loops 1 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_save_runtime.rs"},"region":{"startLine":470}}}],"partialFingerprints":{"codehealthFindingId/v1":"3e9a4254779fe99e0151004372aa9e8ad955f530ebeb0bba4672011f2936f1b1"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::why_runtime::query_profile_path_lexically (cognitive 28): nono_cli::why_runtime::query_profile_path_lexically has cognitive complexity 28 (threshold 15). Drivers by points: if/else 6 (10 pts), match/switch 5 (9 pts), boolean chains 5, loops 2 (4 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/why_runtime.rs"},"region":{"startLine":338}}}],"partialFingerprints":{"codehealthFindingId/v1":"365b7849aa89b4cbb7423e9c7236ef33ec05fcfc9c19389f96b56201ffcb5bb5"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::diagnostic::formatter::analyze_error_output (cognitive 28): nono_cli::diagnostic::formatter::analyze_error_output has cognitive complexity 28 (threshold 15). Drivers by points: if/else 14 (26 pts), boolean chains 1, loops 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/diagnostic/formatter.rs"},"region":{"startLine":150}}}],"partialFingerprints":{"codehealthFindingId/v1":"6407588396e11c307a3c472aa703302b11c07bb1c078ea0e65cf4628ff20c14c"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::command_policy::validate_command (cognitive 28): nono_cli::command_policy::validate_command has cognitive complexity 28 (threshold 15). Drivers by points: if/else 13 (21 pts), match/switch 2 (4 pts), boolean chains 2, loops 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_policy.rs"},"region":{"startLine":1597}}}],"partialFingerprints":{"codehealthFindingId/v1":"ad8d7cdb883b5b1b3ee0b51d485bd77d3489a532565e81b908ccec6f31123dd9"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::output::render_diagnostic_line (cognitive 27): nono_cli::output::render_diagnostic_line has cognitive complexity 27 (threshold 15). Drivers by points: if/else 19 (21 pts), boolean chains 4, match/switch 1 (2 pts) (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/output.rs"},"region":{"startLine":1037}}}],"partialFingerprints":{"codehealthFindingId/v1":"70f993391a03e014f28f497609bfb1ec76a84a28c55985228547f4795009d81e"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_proxy::config::validate_no_proxy_host_pattern (cognitive 27): nono_proxy::config::validate_no_proxy_host_pattern has cognitive complexity 27 (threshold 15). Drivers by points: if/else 17 (24 pts), boolean chains 3 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/config.rs"},"region":{"startLine":603}}}],"partialFingerprints":{"codehealthFindingId/v1":"970aa368d3d81c4199cf85e018be278cbf8f61f1e0c7f9d2ce7a5d77ba074edb"}},{"ruleId":"D2","level":"warning","message":{"text":"DiagnosticFormatter::format_exit_explanation (cognitive 26): DiagnosticFormatter::format_exit_explanation has cognitive complexity 26 (threshold 15). Drivers by points: if/else 14 (23 pts), match/switch 2 (3 pts) (nesting depth added 10). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/diagnostic/formatter.rs"},"region":{"startLine":991}}}],"partialFingerprints":{"codehealthFindingId/v1":"8f33aa4bf6faa7d1d5f646d26c4d57e5938acd1f3c3f3ab34193be9ef4a90509"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::tool-sandbox::env::env_shebang_target_interpreter (cognitive 26): nono_cli::tool-sandbox::env::env_shebang_target_interpreter has cognitive complexity 26 (threshold 15). Drivers by points: if/else 13 (22 pts), loops 3 (4 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/env.rs"},"region":{"startLine":223}}}],"partialFingerprints":{"codehealthFindingId/v1":"5a805aa02ba569dd39dbed6b5ad00a672e7632da13640fa6550a8b1ccaa21eca"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::command_policy::validate_approval_backend (cognitive 26): nono_cli::command_policy::validate_approval_backend has cognitive complexity 26 (threshold 15). Drivers by points: if/else 12 (18 pts), boolean chains 5, loops 1 (2 pts), match/switch 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_policy.rs"},"region":{"startLine":2162}}}],"partialFingerprints":{"codehealthFindingId/v1":"0ed44e883e0d38fad913bbdbe26c2a0aa1bf04c78fc0295a5a034a95eb4b731f"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::wiring::execute_one (cognitive 26): nono_cli::wiring::execute_one has cognitive complexity 26 (threshold 15). Drivers by points: if/else 7 (15 pts), match/switch 4 (9 pts), boolean chains 2 (nesting depth added 13). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/wiring.rs"},"region":{"startLine":339}}}],"partialFingerprints":{"codehealthFindingId/v1":"9338e1934d2a3b5150319739b71a8ba507d95d4b04c5b2bcddfd6d7a070b2944"}},{"ruleId":"D2","level":"warning","message":{"text":"nono::audit::verify_audit_log (cognitive 25): nono::audit::verify_audit_log has cognitive complexity 25 (threshold 15). Drivers by points: if/else 13 (21 pts), boolean chains 3, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/audit.rs"},"region":{"startLine":1434}}}],"partialFingerprints":{"codehealthFindingId/v1":"4c483d63341ce38ded5d7303e81c988f4aaf6e517fe202ccbba33939245bcb9c"}},{"ruleId":"D2","level":"warning","message":{"text":"PtyProxy::drain_master_output (cognitive 25): PtyProxy::drain_master_output has cognitive complexity 25 (threshold 15). Drivers by points: if/else 8 (20 pts), match/switch 1 (4 pts), loops 1 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/pty_proxy.rs"},"region":{"startLine":810}}}],"partialFingerprints":{"codehealthFindingId/v1":"c30a845c2aa1dab078e7fb3f2e3aa8befd065b78b32514cb88febdc5c9d3250c"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::rollback_runtime::enforce_rollback_limits (cognitive 25): nono_cli::rollback_runtime::enforce_rollback_limits has cognitive complexity 25 (threshold 15). Drivers by points: if/else 9 (15 pts), match/switch 4 (5 pts), loops 2 (4 pts), boolean chains 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/rollback_runtime.rs"},"region":{"startLine":115}}}],"partialFingerprints":{"codehealthFindingId/v1":"dc2cbc9f0709c09757165f8c4cfea2129584d718574460f7d305e53e38008c85"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_proxy::reverse::classify_upgrade_attempt (cognitive 25): nono_proxy::reverse::classify_upgrade_attempt has cognitive complexity 25 (threshold 15). Drivers by points: if/else 16 (19 pts), boolean chains 4, match/switch 2 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":2119}}}],"partialFingerprints":{"codehealthFindingId/v1":"48603b0918cda5e95c564daeea106c770d84421da14ff54106f3a4632dee3dd2"}},{"ruleId":"D2","level":"warning","message":{"text":"nono::audit::verify_audit_attestation_bundle (cognitive 24): nono::audit::verify_audit_attestation_bundle has cognitive complexity 24 (threshold 15). Drivers by points: if/else 16, match/switch 6, boolean chains 2. To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/audit.rs"},"region":{"startLine":1123}}}],"partialFingerprints":{"codehealthFindingId/v1":"bab1ff0ad08bdd1030a25589c2ffd45dc7e8267a7f01011d795239e4a31c3ce4"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::tool-sandbox::platform::linux::add_interpreted_script_read_inner (cognitive 24): nono_cli::tool-sandbox::platform::linux::add_interpreted_script_read_inner has cognitive complexity 24 (threshold 15). Drivers by points: if/else 10 (17 pts), loops 3 (5 pts), boolean chains 2 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3912}}}],"partialFingerprints":{"codehealthFindingId/v1":"3fa10db4bf96205a4a2f47eb67ed08577d63ae80f301ec3dce1b2545681211a2"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::policy::apply_unlink_overrides (cognitive 24): nono_cli::policy::apply_unlink_overrides has cognitive complexity 24 (threshold 15). Drivers by points: if/else 5 (10 pts), match/switch 3 (10 pts), loops 3 (4 pts) (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/policy.rs"},"region":{"startLine":1850}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7191056e301bf56746722accd771cbab668d3efc980a6aefff1bd41b5048cd3"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::exec_strategy::clone_files::spawn (cognitive 24): nono_cli::exec_strategy::clone_files::spawn has cognitive complexity 24 (threshold 15). Drivers by points: if/else 21 (22 pts), boolean chains 1, match/switch 1 (nesting depth added 1). This file\u0027s own header attributes it to another copyright holder, so it is code this repository carries rather than code it wrote: restructuring the body in place forks it from upstream and turns every future re-sync into a manual merge. The performable moves are to leave the body as close to its upstream form as possible and keep it behind a narrow interface of your own, and to re-sync it when upstream changes \u2014 or, if it has already diverged far enough that you maintain it here, adopt it deliberately and then split the body into named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy/clone_files.rs"},"region":{"startLine":145}}}],"partialFingerprints":{"codehealthFindingId/v1":"139240cdb2b819dd2bacd5ea60dc9aca3292bb66b1c8aa80758fadceee5f81b8"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::tool-sandbox::dynamic_providers::git::parse_paths_from_stdout (cognitive 24): nono_cli::tool-sandbox::dynamic_providers::git::parse_paths_from_stdout has cognitive complexity 24 (threshold 15). Drivers by points: if/else 10 (19 pts), boolean chains 4, loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/dynamic_providers.rs"},"region":{"startLine":483}}}],"partialFingerprints":{"codehealthFindingId/v1":"ded84e2ea1777a732ba3182e71e885844aaf2587662212f947ffe7b9ded0a6af"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::proxy_runtime::synthesize_credential_provider_proxy_config (cognitive 24): nono_cli::proxy_runtime::synthesize_credential_provider_proxy_config has cognitive complexity 24 (threshold 15). Drivers by points: if/else 5 (11 pts), loops 4 (6 pts), match/switch 2 (6 pts), boolean chains 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":2560}}}],"partialFingerprints":{"codehealthFindingId/v1":"8196653155ec26e670b1410c91aa96cd769cc5796444da5aaebe8dc40cd16260"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::proxy_runtime::command_proxy_scopes (cognitive 24): nono_cli::proxy_runtime::command_proxy_scopes has cognitive complexity 24 (threshold 15). Drivers by points: if/else 4 (13 pts), loops 4 (8 pts), match/switch 1 (2 pts), boolean chains 1 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":3367}}}],"partialFingerprints":{"codehealthFindingId/v1":"543fe72c9a0d2ce6cfdbea2a7938a92f36267c22bf25b9a0e7201fe8037ba4ff"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_proxy::server::normalize_authority (cognitive 24): nono_proxy::server::normalize_authority has cognitive complexity 24 (threshold 15). Drivers by points: if/else 11 (22 pts), boolean chains 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/server.rs"},"region":{"startLine":1438}}}],"partialFingerprints":{"codehealthFindingId/v1":"b859ffda338af1c2033a4b3f66aa592e7c7230958e77bb5c7b7f5cc6ee5dfc0f"}},{"ruleId":"D2","level":"warning","message":{"text":"CapabilitySet::from_args (cognitive 23): CapabilitySet::from_args has cognitive complexity 23 (threshold 15). Drivers by points: if/else 7 (13 pts), loops 10 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body. This shape REPEATS in the file: one other method here (nono_cli::capability_ext::add_cli_overrides) has the same decision points, in the same order, at the same nesting depths \u2014 so this is one pattern written twice rather than two separate problems. Splitting this body alone leaves the other exactly as it is. Where these are variations on one operation, the change that clears both is the shared one: lift the common shape into a single routine the variants call, parameterised by whatever genuinely differs between them, and keep in each method only the part that is not shared."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/capability_ext.rs"},"region":{"startLine":586}}}],"partialFingerprints":{"codehealthFindingId/v1":"a656f4ace6315758f77f0d3d1de8064e9d51ea0e793c022c1d51eb647784c232"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::tool-sandbox::platform::linux::build_outer_exec_files (cognitive 23): nono_cli::tool-sandbox::platform::linux::build_outer_exec_files has cognitive complexity 23 (threshold 15). Drivers by points: if/else 7 (17 pts), loops 4 (5 pts), boolean chains 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3055}}}],"partialFingerprints":{"codehealthFindingId/v1":"3be7b4ee482921cea6a62f5005cf7dfd544ec84aceec3583b5e6d482aad576ba"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile_save_runtime::print_patch_preview (cognitive 23): nono_cli::profile_save_runtime::print_patch_preview has cognitive complexity 23 (threshold 15). Drivers by points: if/else 8 (12 pts), loops 4 (9 pts), boolean chains 2 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_save_runtime.rs"},"region":{"startLine":872}}}],"partialFingerprints":{"codehealthFindingId/v1":"7efd7de120f414e7387d71ef07863dcd70dced127db27931d5ae1482e9f06557"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::audit_commands::cmd_verify (cognitive 23): nono_cli::audit_commands::cmd_verify has cognitive complexity 23 (threshold 15). Drivers by points: if/else 14 (18 pts), boolean chains 5 (nesting depth added 4). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":557}}}],"partialFingerprints":{"codehealthFindingId/v1":"a8633fb8a3eb20dcb41e51bdd977ca548c47739ce232fbb34f291d9516f55017"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::capability_ext::add_cli_overrides (cognitive 23): nono_cli::capability_ext::add_cli_overrides has cognitive complexity 23 (threshold 15). Drivers by points: if/else 7 (13 pts), loops 10 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body. This shape REPEATS in the file: one other method here (CapabilitySet::from_args) has the same decision points, in the same order, at the same nesting depths \u2014 so this is one pattern written twice rather than two separate problems. Splitting this body alone leaves the other exactly as it is. Where these are variations on one operation, the change that clears both is the shared one: lift the common shape into a single routine the variants call, parameterised by whatever genuinely differs between them, and keep in each method only the part that is not shared."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/capability_ext.rs"},"region":{"startLine":1229}}}],"partialFingerprints":{"codehealthFindingId/v1":"ce2aeff294e4489e55583efa024039a51a0ede1c916de671287b16c4f0442d29"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::trust_cmd::run_init (cognitive 23): nono_cli::trust_cmd::run_init has cognitive complexity 23 (threshold 15). Drivers by points: if/else 11 (13 pts), match/switch 4 (5 pts), boolean chains 3, loops 1 (2 pts) (nesting depth added 4). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_cmd.rs"},"region":{"startLine":49}}}],"partialFingerprints":{"codehealthFindingId/v1":"8e4c2cc4f1396dfea051be41d5ae734e93d99aa2b79093952846baa8c4b5134c"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::trust_cmd::run_list (cognitive 23): nono_cli::trust_cmd::run_list has cognitive complexity 23 (threshold 15). Drivers by points: if/else 7 (13 pts), match/switch 2 (6 pts), loops 2 (4 pts) (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_cmd.rs"},"region":{"startLine":1075}}}],"partialFingerprints":{"codehealthFindingId/v1":"63c6a6175d64c41590b35c8750445aac8354b4c3001c3cb23a4d6acc5b85ece4"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile::load_base_profile_raw (cognitive 23): nono_cli::profile::load_base_profile_raw has cognitive complexity 23 (threshold 15). Drivers by points: if/else 11 (20 pts), match/switch 1 (2 pts), boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":3559}}}],"partialFingerprints":{"codehealthFindingId/v1":"43b46315ac7775ba803eef19b74abd159c7d2ddd30c597055ddc9f350c517f6e"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::sandbox_prepare::maybe_enable_gpu (cognitive 23): nono_cli::sandbox_prepare::maybe_enable_gpu has cognitive complexity 23 (threshold 15). Drivers by points: if/else 13 (16 pts), loops 4 (7 pts) (nesting depth added 6). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/sandbox_prepare.rs"},"region":{"startLine":1227}}}],"partialFingerprints":{"codehealthFindingId/v1":"bb63c282f065cf95711e964b0bda3c6e9a8e178d9f3e86b7b8f377246031adce"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_proxy::tls_intercept::h2_forward::forward_h2_connection (cognitive 23): nono_proxy::tls_intercept::h2_forward::forward_h2_connection has cognitive complexity 23 (threshold 15). Drivers by points: if/else 6 (13 pts), match/switch 3 (8 pts), loops 2 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/h2_forward.rs"},"region":{"startLine":56}}}],"partialFingerprints":{"codehealthFindingId/v1":"9ac0eec4746da7bbc87b2db7d21a50b64790c8deb74289715e929d91db006d1d"}},{"ruleId":"D2","level":"warning","message":{"text":"SnapshotManager::walk_current (cognitive 22): SnapshotManager::walk_current has cognitive complexity 22 (threshold 15). Drivers by points: if/else 7 (18 pts), loops 2 (3 pts), boolean chains 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/snapshot.rs"},"region":{"startLine":839}}}],"partialFingerprints":{"codehealthFindingId/v1":"abe629f45074dc1bfaf77817eaf1808dddbcf868da3f10a04cc84341166f3aba"}},{"ruleId":"D2","level":"warning","message":{"text":"nono::path::resolve_hops (cognitive 22): nono::path::resolve_hops has cognitive complexity 22 (threshold 15). Drivers by points: if/else 7 (19 pts), match/switch 1 (2 pts), loops 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/path.rs"},"region":{"startLine":69}}}],"partialFingerprints":{"codehealthFindingId/v1":"6264cfe7995cdbcd5fdf9d8da2edcc5d412d2125ce502da288bc4776b9898ba8"}},{"ruleId":"D2","level":"warning","message":{"text":"nono::audit::verify_inclusion_proof (cognitive 22): nono::audit::verify_inclusion_proof has cognitive complexity 22 (threshold 15). Drivers by points: if/else 9 (17 pts), match/switch 1 (3 pts), boolean chains 1, loops 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/audit.rs"},"region":{"startLine":775}}}],"partialFingerprints":{"codehealthFindingId/v1":"4e65da013fc5c609e6652d65cfd8be364eaa72b4ca19241e1304e8008d9471aa"}},{"ruleId":"D2","level":"warning","message":{"text":"ProxyCredentialCaptureBackend::run_capture_command (cognitive 22): ProxyCredentialCaptureBackend::run_capture_command has cognitive complexity 22 (threshold 15). Drivers by points: if/else 13 (14 pts), match/switch 2 (4 pts), loops 3, boolean chains 1 (nesting depth added 3). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":381}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a8af48b112b8ccd2b08cb2f8a4123870f2b7bacc79cfae83c8e07e3460a768f"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::pack_update_hint::show_pack_update_hints (cognitive 22): nono_cli::pack_update_hint::show_pack_update_hints has cognitive complexity 22 (threshold 15). Drivers by points: if/else 7 (13 pts), loops 2 (4 pts), boolean chains 3, match/switch 1 (2 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/pack_update_hint.rs"},"region":{"startLine":49}}}],"partialFingerprints":{"codehealthFindingId/v1":"f158799e99d835a86ef0c053e14cd59ea6a1aa04d138a6e865fc05b68717b1ca"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::tool-sandbox::platform::macos::filter_child_env (cognitive 22): nono_cli::tool-sandbox::platform::macos::filter_child_env has cognitive complexity 22 (threshold 15). Drivers by points: if/else 9 (18 pts), loops 2, match/switch 1 (2 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":3869}}}],"partialFingerprints":{"codehealthFindingId/v1":"108e9f3f1cc505a2d4d1554ef3686dce3224a379d647df49856500028f345ae8"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile_runtime::verify_profile_packs (cognitive 22): nono_cli::profile_runtime::verify_profile_packs has cognitive complexity 22 (threshold 15). Drivers by points: if/else 8 (17 pts), loops 3 (5 pts) (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_runtime.rs"},"region":{"startLine":102}}}],"partialFingerprints":{"codehealthFindingId/v1":"d9079ff68236261962c668b90fa540832ef63e4bc228ce99e6071735ad89fc4f"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_proxy::server::accept_loop (cognitive 22): nono_proxy::server::accept_loop has cognitive complexity 22 (threshold 15). Drivers by points: if/else 4 (16 pts), match/switch 2 (5 pts), loops 1 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/server.rs"},"region":{"startLine":1388}}}],"partialFingerprints":{"codehealthFindingId/v1":"7163d81f3f0fceb99fcd24c5131f81783bfd43a1e96670a8ab1075a4b86b6380"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_proxy::reverse::read_chunked_request_body (cognitive 22): nono_proxy::reverse::read_chunked_request_body has cognitive complexity 22 (threshold 15). Drivers by points: if/else 7 (18 pts), loops 2 (3 pts), boolean chains 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":1704}}}],"partialFingerprints":{"codehealthFindingId/v1":"8dd80b81746e45cd9f8fc705cdc58ead3ed104634debe1b3cc2f60281f903c6b"}},{"ruleId":"D2","level":"warning","message":{"text":"nono::trust::policy::find_files_recursive (cognitive 21): nono::trust::policy::find_files_recursive has cognitive complexity 21 (threshold 15). Drivers by points: if/else 7 (16 pts), boolean chains 2, match/switch 1 (2 pts), loops 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/trust/policy.rs"},"region":{"startLine":321}}}],"partialFingerprints":{"codehealthFindingId/v1":"bb835978d9678df6c6b0635d4c37d94cbee9cff4f55b5de5c8fc2aec6288ae8d"}},{"ruleId":"D2","level":"warning","message":{"text":"DaemonPidLineage::attribute_with_negative_ttl (cognitive 21): DaemonPidLineage::attribute_with_negative_ttl has cognitive complexity 21 (threshold 15). Drivers by points: if/else 9 (15 pts), boolean chains 5, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":2162}}}],"partialFingerprints":{"codehealthFindingId/v1":"a026910d31ffc34d915aa80ef36ede6ff8ea1611b95a6609b4c49d93af961b59"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::policy::resolve_single_group (cognitive 21): nono_cli::policy::resolve_single_group has cognitive complexity 21 (threshold 15). Drivers by points: loops 6 (12 pts), if/else 5 (7 pts), boolean chains 2 (nesting depth added 8). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/policy.rs"},"region":{"startLine":795}}}],"partialFingerprints":{"codehealthFindingId/v1":"4f83d70e8bc80349d25eca8749f1d83d53e6ecc32c62a4f1865ff28a09e2044d"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::policy::find_deny_group_for_path (cognitive 21): nono_cli::policy::find_deny_group_for_path has cognitive complexity 21 (threshold 15). Drivers by points: if/else 4 (16 pts), loops 2 (4 pts), boolean chains 1 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/policy.rs"},"region":{"startLine":2036}}}],"partialFingerprints":{"codehealthFindingId/v1":"6513d2c80052e579c77be24d793b59cc1db76a51c8db3dd64dfa25ab47213cee"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::proxy_command::build_launch_options (cognitive 21): nono_cli::proxy_command::build_launch_options has cognitive complexity 21 (threshold 15). Drivers by points: if/else 12 (13 pts), boolean chains 6, loops 1, match/switch 1 (nesting depth added 1). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_command.rs"},"region":{"startLine":188}}}],"partialFingerprints":{"codehealthFindingId/v1":"4aee58d479d1cb659ec618190576d778268db5cafd55fcf8f1e15faab095988c"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::audit_session::discover_sessions (cognitive 21): nono_cli::audit_session::discover_sessions has cognitive complexity 21 (threshold 15). Drivers by points: if/else 4 (11 pts), match/switch 2 (6 pts), loops 2 (3 pts), boolean chains 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_session.rs"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"0b4f2af7c180b3fd4bf5e2bd3c49cc932f728185c1b69076fcc4dff42386e54d"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::supervised_runtime::execute_supervised_runtime (cognitive 21): nono_cli::supervised_runtime::execute_supervised_runtime has cognitive complexity 21 (threshold 15). Drivers by points: if/else 11 (12 pts), match/switch 5 (6 pts), boolean chains 3 (nesting depth added 2). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/supervised_runtime.rs"},"region":{"startLine":210}}}],"partialFingerprints":{"codehealthFindingId/v1":"3b713fe69d67d3f89e78382393fe0fac139aeeac1a01a019b8c4ee4547f3f698"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::sandbox_prepare::collect_missing_cli_requested_paths (cognitive 21): nono_cli::sandbox_prepare::collect_missing_cli_requested_paths has cognitive complexity 21 (threshold 15). Drivers by points: if/else 6 (12 pts), loops 6, boolean chains 3 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/sandbox_prepare.rs"},"region":{"startLine":40}}}],"partialFingerprints":{"codehealthFindingId/v1":"f6c598c0ece4cf6c131736f459b4990d3a0b707e0f4b14915474b44e3c20370d"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::trust_scan::verify_multi_subject_bundle (cognitive 21): nono_cli::trust_scan::verify_multi_subject_bundle has cognitive complexity 21 (threshold 15). Drivers by points: match/switch 8 (11 pts), if/else 6 (9 pts), loops 1 (nesting depth added 6). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_scan.rs"},"region":{"startLine":899}}}],"partialFingerprints":{"codehealthFindingId/v1":"e118bd8ea78cf4cead3ec646e592a381dbb120e74135c7167919cb518b73a27e"}},{"ruleId":"D2","level":"warning","message":{"text":"SnapshotManager::collect_atomic_temp_files (cognitive 20): SnapshotManager::collect_atomic_temp_files has cognitive complexity 20 (threshold 15). Drivers by points: if/else 6 (16 pts), loops 2 (3 pts), boolean chains 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/snapshot.rs"},"region":{"startLine":401}}}],"partialFingerprints":{"codehealthFindingId/v1":"0049f357d327e25f6d4960fa33c7f045eedf10ce5a25946716c04cac0c1c084d"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile_save_runtime::profile_name_from_command (cognitive 20): nono_cli::profile_save_runtime::profile_name_from_command has cognitive complexity 20 (threshold 15). Drivers by points: if/else 9 (16 pts), boolean chains 2, loops 2 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_save_runtime.rs"},"region":{"startLine":673}}}],"partialFingerprints":{"codehealthFindingId/v1":"24c0a3cab375e0e7d76fd7f2471fccaadd8e89c2691dd356b2c87925f06cad14"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::tool-sandbox::platform::macos::resolve_caller_with (cognitive 20): nono_cli::tool-sandbox::platform::macos::resolve_caller_with has cognitive complexity 20 (threshold 15). Drivers by points: if/else 8 (14 pts), boolean chains 3, match/switch 1 (2 pts), loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":1898}}}],"partialFingerprints":{"codehealthFindingId/v1":"3d18776a61f8c500500cfcc4f0b28eed7c3a5ff16bf4bfacb4408469030664d8"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::remote_run::run (cognitive 20): nono_cli::remote_run::run has cognitive complexity 20 (threshold 15). Drivers by points: if/else 7 (10 pts), boolean chains 5, match/switch 4, loops 1 (nesting depth added 3). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/remote_run.rs"},"region":{"startLine":89}}}],"partialFingerprints":{"codehealthFindingId/v1":"5622addc86d14f4c4c65a4203c1cb76340464e8c7bc7eb76de822f1649857863"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile_runtime::collect_derived_redaction_env_vars (cognitive 20): nono_cli::profile_runtime::collect_derived_redaction_env_vars has cognitive complexity 20 (threshold 15). Drivers by points: if/else 8 (15 pts), loops 3 (4 pts), boolean chains 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_runtime.rs"},"region":{"startLine":1153}}}],"partialFingerprints":{"codehealthFindingId/v1":"514c1ec98e5bf27a8da84f58b48e3496094a6d3349d8f0036c537cf1abfcad5e"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile_cmd::profile_to_json (cognitive 19): nono_cli::profile_cmd::profile_to_json has cognitive complexity 19 (threshold 15). Drivers by points: if/else 15, boolean chains 4. To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":1257}}}],"partialFingerprints":{"codehealthFindingId/v1":"62770abec4994acb7c07c3cda78fbc033e6a91cab076d0a824487000175c6438"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::exec_strategy::wait_for_child_with_pty (cognitive 19): nono_cli::exec_strategy::wait_for_child_with_pty has cognitive complexity 19 (threshold 15). Drivers by points: if/else 6 (14 pts), match/switch 2 (3 pts), boolean chains 1, loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":2016}}}],"partialFingerprints":{"codehealthFindingId/v1":"e19c222a0e55646829ec9df02e9eaae2ee8aef59baf06cb4a24bd7c3a27eb0bf"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::exec_strategy::forward_signal (cognitive 19): nono_cli::exec_strategy::forward_signal has cognitive complexity 19 (threshold 15). Drivers by points: if/else 9 (19 pts) (nesting depth added 10). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":2274}}}],"partialFingerprints":{"codehealthFindingId/v1":"514aca4a5c28f5df762ea263d0e67af172c5fa1f7639bb4b74c122332db645ad"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::audit_commands::cmd_cleanup (cognitive 19): nono_cli::audit_commands::cmd_cleanup has cognitive complexity 19 (threshold 15). Drivers by points: if/else 13 (15 pts), loops 2 (3 pts), boolean chains 1 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":720}}}],"partialFingerprints":{"codehealthFindingId/v1":"f2a532274a0fe012d2f10efd3eed1822291952f96ca857ac3459a7805d5fdb6e"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::output::sanitize_terminal_output (cognitive 19): nono_cli::output::sanitize_terminal_output has cognitive complexity 19 (threshold 15). Drivers by points: if/else 5 (12 pts), loops 2 (5 pts), boolean chains 2 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/output.rs"},"region":{"startLine":1270}}}],"partialFingerprints":{"codehealthFindingId/v1":"ce960269ca473bc668f475376409e9d26120b15bd7f51f4e62d8cf721d3b9d71"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::sandbox_prepare::validate_block_net_conflicts (cognitive 19): nono_cli::sandbox_prepare::validate_block_net_conflicts has cognitive complexity 19 (threshold 15). Drivers by points: if/else 8 (13 pts), boolean chains 6 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/sandbox_prepare.rs"},"region":{"startLine":922}}}],"partialFingerprints":{"codehealthFindingId/v1":"d6faeb3cfb47adad87aa628a1a9725ba5aea3399de8d8ef1431299ba71ccb850"}},{"ruleId":"D2","level":"warning","message":{"text":"ProxyHandle::route_diagnostics (cognitive 19): ProxyHandle::route_diagnostics has cognitive complexity 19 (threshold 15). Drivers by points: if/else 7 (11 pts), boolean chains 5, loops 2, match/switch 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/server.rs"},"region":{"startLine":402}}}],"partialFingerprints":{"codehealthFindingId/v1":"2d9c5f6b1f985187a89e4747bce5233f1b970810026865601f17c59ee70bb266"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_proxy::config::validate_no_proxy_entry (cognitive 19): nono_proxy::config::validate_no_proxy_entry has cognitive complexity 19 (threshold 15). Drivers by points: if/else 12 (15 pts), boolean chains 4 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/config.rs"},"region":{"startLine":391}}}],"partialFingerprints":{"codehealthFindingId/v1":"b2d862de368e0f41c0323a27e7aa4ec00eb4b93a7ca562ee2698748b4585696e"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_proxy::tls_intercept::http1::relay_chunked (cognitive 19): nono_proxy::tls_intercept::http1::relay_chunked has cognitive complexity 19 (threshold 15). Drivers by points: if/else 6 (15 pts), loops 2 (3 pts), boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/http1.rs"},"region":{"startLine":184}}}],"partialFingerprints":{"codehealthFindingId/v1":"a7b94b2cf797bb5c20ee5b60febc112dc868a960990e76aef623a1c7583addc9"}},{"ruleId":"D2","level":"warning","message":{"text":"CapabilitySet::scan_covering (cognitive 18): CapabilitySet::scan_covering has cognitive complexity 18 (threshold 15). Drivers by points: if/else 6 (14 pts), boolean chains 3, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/capability.rs"},"region":{"startLine":1525}}}],"partialFingerprints":{"codehealthFindingId/v1":"a4a361c7c6904f94193d1c55ada8c39fb3df6500a2d19c5d498a3f76425d3db8"}},{"ruleId":"D2","level":"warning","message":{"text":"SandboxState::to_caps (cognitive 18): SandboxState::to_caps has cognitive complexity 18 (threshold 15). Drivers by points: if/else 7 (10 pts), match/switch 3 (6 pts), loops 2 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/state.rs"},"region":{"startLine":103}}}],"partialFingerprints":{"codehealthFindingId/v1":"2d8d51b4f0ffaced51f5360a31071b1c560b9d7dc2861a3725b29eefd4520c63"}},{"ruleId":"D2","level":"warning","message":{"text":"nono::trust::types::wildcard_match (cognitive 18): nono::trust::types::wildcard_match has cognitive complexity 18 (threshold 15). Drivers by points: if/else 8 (14 pts), match/switch 1 (3 pts), loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/trust/types.rs"},"region":{"startLine":264}}}],"partialFingerprints":{"codehealthFindingId/v1":"c3a1f521554fdb42ea0b68174e108ae306f5ae79322e79bc339243703e3d7ada"}},{"ruleId":"D2","level":"warning","message":{"text":"nono::net_filter::host_pattern_matches (cognitive 18): nono::net_filter::host_pattern_matches has cognitive complexity 18 (threshold 15). Drivers by points: if/else 7 (14 pts), match/switch 1 (2 pts), boolean chains 1, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/net_filter.rs"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"8640da4a29bf28ae0fdab7f4b4296d7cde54c61972eb5c70c8c717289585e8da"}},{"ruleId":"D2","level":"warning","message":{"text":"nono::capability::validate_platform_rule (cognitive 18): nono::capability::validate_platform_rule has cognitive complexity 18 (threshold 15). Drivers by points: if/else 6 (11 pts), boolean chains 3, loops 2, match/switch 1 (2 pts) (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/capability.rs"},"region":{"startLine":615}}}],"partialFingerprints":{"codehealthFindingId/v1":"37c282320aa12e51e24ce010cbf0c7fafa5c1dee34771d0adea3f1a110bad22d"}},{"ruleId":"D2","level":"warning","message":{"text":"DiagnosticFormatter::format_network_denial_guidance (cognitive 18): DiagnosticFormatter::format_network_denial_guidance has cognitive complexity 18 (threshold 15). Drivers by points: if/else 6 (11 pts), loops 3 (4 pts), match/switch 1 (2 pts), boolean chains 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/diagnostic/formatter.rs"},"region":{"startLine":2109}}}],"partialFingerprints":{"codehealthFindingId/v1":"59e3a4def49c3dcfba1920e3abdb5073ef05a00711a7b3bedebfbd5d97e0908c"}},{"ruleId":"D2","level":"warning","message":{"text":"TokenBroker::scan_and_reissue (cognitive 18): TokenBroker::scan_and_reissue has cognitive complexity 18 (threshold 15). Drivers by points: if/else 7 (16 pts), boolean chains 1, loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/token_broker.rs"},"region":{"startLine":273}}}],"partialFingerprints":{"codehealthFindingId/v1":"705793b1efab6e4dc15de75d06bd677cc50279b56294fb916d94fde9f303a772"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::tool-sandbox::platform::linux::filter_child_env (cognitive 18): nono_cli::tool-sandbox::platform::linux::filter_child_env has cognitive complexity 18 (threshold 15). Drivers by points: if/else 9 (14 pts), loops 2, match/switch 1 (2 pts) (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4425}}}],"partialFingerprints":{"codehealthFindingId/v1":"5d4f90e8af45da86c66371003dfaeab5bbbbd7e90c20ebb0405144e6d883a79e"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::launch_runtime::prepare_run_launch_plan (cognitive 18): nono_cli::launch_runtime::prepare_run_launch_plan has cognitive complexity 18 (threshold 15). Drivers by points: if/else 11 (12 pts), boolean chains 6 (nesting depth added 1). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/launch_runtime.rs"},"region":{"startLine":333}}}],"partialFingerprints":{"codehealthFindingId/v1":"0ab669e4a385c6a15c1be5ebe60a8c0b9dc0fe98136d582bfdd309a1ca14f678"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile_cmd::cmd_list (cognitive 18): nono_cli::profile_cmd::cmd_list has cognitive complexity 18 (threshold 15). Drivers by points: if/else 8 (9 pts), loops 4 (7 pts), match/switch 1 (2 pts) (nesting depth added 5). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":701}}}],"partialFingerprints":{"codehealthFindingId/v1":"df0713f5481b9aa3e037457bd90708a175133136c9cd1b07b1d539bf24d1b925"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::network_policy::resolve_credentials (cognitive 18): nono_cli::network_policy::resolve_credentials has cognitive complexity 18 (threshold 15). Drivers by points: if/else 7 (14 pts), loops 3, boolean chains 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/network_policy.rs"},"region":{"startLine":182}}}],"partialFingerprints":{"codehealthFindingId/v1":"994dbcc2003ea4b49bea8fad7a9f283fcbe235160e921b67fad8f4771e808779"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::session::list_sessions (cognitive 18): nono_cli::session::list_sessions has cognitive complexity 18 (threshold 15). Drivers by points: if/else 4 (12 pts), loops 2 (3 pts), match/switch 1 (3 pts) (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/session.rs"},"region":{"startLine":326}}}],"partialFingerprints":{"codehealthFindingId/v1":"85f71178aefa8089ffcaccadda1eb3223628e2b189aac8b3451e2f72d297f07e"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::diagnostic::formatter::sanitize_for_diagnostic (cognitive 18): nono_cli::diagnostic::formatter::sanitize_for_diagnostic has cognitive complexity 18 (threshold 15). Drivers by points: if/else 5 (12 pts), loops 2 (5 pts), boolean chains 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/diagnostic/formatter.rs"},"region":{"startLine":124}}}],"partialFingerprints":{"codehealthFindingId/v1":"5dfbd0e96f232b34f846e632e97c7922296b5d88ee69e9ecd711534c4dfad551"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_proxy::forward::rewrite_http1_response (cognitive 18): nono_proxy::forward::rewrite_http1_response has cognitive complexity 18 (threshold 15). Drivers by points: if/else 8 (13 pts), boolean chains 3, loops 2 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/forward.rs"},"region":{"startLine":367}}}],"partialFingerprints":{"codehealthFindingId/v1":"c5c1c960a922294c063eb0900535a19a2c027b9a3a6659950d4a2c9b25965dde"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_proxy::reverse::strip_proxy_path_token (cognitive 18): nono_proxy::reverse::strip_proxy_path_token has cognitive complexity 18 (threshold 15). Drivers by points: if/else 9 (11 pts), match/switch 2 (5 pts), boolean chains 2 (nesting depth added 5). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":2687}}}],"partialFingerprints":{"codehealthFindingId/v1":"ce5967cf642ec251bf57d29a4af45f603fcb218e228faceb668e5f837a9ec9e6"}},{"ruleId":"D2","level":"warning","message":{"text":"SnapshotManager::validate_restore_target (cognitive 17): SnapshotManager::validate_restore_target has cognitive complexity 17 (threshold 15). Drivers by points: if/else 5 (11 pts), match/switch 3 (5 pts), loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/snapshot.rs"},"region":{"startLine":621}}}],"partialFingerprints":{"codehealthFindingId/v1":"3abff37b11c94d1380b64d2870ad2bb60807ab908a3b7f4922fe68e12a7d44db"}},{"ruleId":"D2","level":"warning","message":{"text":"nono::scrub::scrub_argv_with_policy (cognitive 17): nono::scrub::scrub_argv_with_policy has cognitive complexity 17 (threshold 15). Drivers by points: if/else 7 (16 pts), loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/scrub.rs"},"region":{"startLine":313}}}],"partialFingerprints":{"codehealthFindingId/v1":"8498100defe25d00655df85d1ab095256637eee24019af96140f84493cc75f4b"}},{"ruleId":"D2","level":"warning","message":{"text":"nono::audit::build_inclusion_proof (cognitive 17): nono::audit::build_inclusion_proof has cognitive complexity 17 (threshold 15). Drivers by points: if/else 8 (14 pts), loops 2 (3 pts) (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/audit.rs"},"region":{"startLine":714}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a8d5c066c366932c53e5fe5424edd40098794f216573bf4fbb73f474b28f449"}},{"ruleId":"D2","level":"warning","message":{"text":"Predicate::matches_linux (cognitive 17): Predicate::matches_linux has cognitive complexity 17 (threshold 15). Drivers by points: if/else 10 (15 pts), boolean chains 2 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/platform.rs"},"region":{"startLine":417}}}],"partialFingerprints":{"codehealthFindingId/v1":"e65dc1e8555867687501b1ef14ee1c2d4c6e4289a4072ca33b2da94500732a21"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::rollback_preflight::run_preflight (cognitive 17): nono_cli::rollback_preflight::run_preflight has cognitive complexity 17 (threshold 15). Drivers by points: if/else 5 (12 pts), loops 2 (3 pts), boolean chains 2 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/rollback_preflight.rs"},"region":{"startLine":85}}}],"partialFingerprints":{"codehealthFindingId/v1":"01fb91c8520f7294ce423b7d109b857cfb369bb2a1d118112f72a7502ddc4c7a"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::session_commands::run_attach (cognitive 17): nono_cli::session_commands::run_attach has cognitive complexity 17 (threshold 15). Drivers by points: if/else 10 (14 pts), match/switch 2 (3 pts) (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/session_commands.rs"},"region":{"startLine":323}}}],"partialFingerprints":{"codehealthFindingId/v1":"ebe188bd74e866fe0c6428732c8a45a3211a8325b84c3676891864ee0dd43b77"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::policy::add_deny_access_rules (cognitive 17): nono_cli::policy::add_deny_access_rules has cognitive complexity 17 (threshold 15). Drivers by points: if/else 9 (12 pts), boolean chains 3, match/switch 1 (2 pts) (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/policy.rs"},"region":{"startLine":1070}}}],"partialFingerprints":{"codehealthFindingId/v1":"cd54417f798607ffaac074621dc4ca300177ccee7119f8a737497e1e61f91662"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::rollback_session::discover_sessions (cognitive 17): nono_cli::rollback_session::discover_sessions has cognitive complexity 17 (threshold 15). Drivers by points: if/else 3 (8 pts), match/switch 2 (6 pts), loops 2 (3 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/rollback_session.rs"},"region":{"startLine":40}}}],"partialFingerprints":{"codehealthFindingId/v1":"5ca351825dbff0c800dabcbfd99cb6534e9c4b9a2843266dbb8d0a970d9bfbb3"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile::validate_oauth2_auth (cognitive 17): nono_cli::profile::validate_oauth2_auth has cognitive complexity 17 (threshold 15). Drivers by points: if/else 7 (14 pts), match/switch 1 (2 pts), boolean chains 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":892}}}],"partialFingerprints":{"codehealthFindingId/v1":"7b58e7a05bc0b764f7d007d17d09b409bf950a6bbf92dbb81e2dbb00e0d371c0"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::diagnostic::formatter::extract_structured_string_property (cognitive 17): nono_cli::diagnostic::formatter::extract_structured_string_property has cognitive complexity 17 (threshold 15). Drivers by points: if/else 8 (13 pts), boolean chains 3, loops 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/diagnostic/formatter.rs"},"region":{"startLine":454}}}],"partialFingerprints":{"codehealthFindingId/v1":"8d0d368d63345856c36d45236a59756a5c76c8e5cbfb662c92f396f67eaad541"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::package_cmd::run_outdated (cognitive 17): nono_cli::package_cmd::run_outdated has cognitive complexity 17 (threshold 15). Drivers by points: if/else 8 (11 pts), boolean chains 2, loops 2, match/switch 1 (2 pts) (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/package_cmd.rs"},"region":{"startLine":488}}}],"partialFingerprints":{"codehealthFindingId/v1":"7800d0fede2db687c04ef020fea8b15906973ba9be5e28ef12caf25391553098"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::wiring::walk_and_merge (cognitive 17): nono_cli::wiring::walk_and_merge has cognitive complexity 17 (threshold 15). Drivers by points: if/else 6 (15 pts), loops 1 (2 pts) (nesting depth added 10). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/wiring.rs"},"region":{"startLine":961}}}],"partialFingerprints":{"codehealthFindingId/v1":"d22f702b4d27e38e6bb31008d5f21798595652eca09cb6fd957eec06bc298c36"}},{"ruleId":"D2","level":"warning","message":{"text":"OAuthCaptureStore::rewrite_response_body (cognitive 17): OAuthCaptureStore::rewrite_response_body has cognitive complexity 17 (threshold 15). Drivers by points: if/else 6 (11 pts), match/switch 2 (5 pts), loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/oauth_capture/rewrite.rs"},"region":{"startLine":127}}}],"partialFingerprints":{"codehealthFindingId/v1":"fad7070f51e417cfffb945f1e97fec3156b94ae0b7cc61e4b63c7184b48ebbd9"}},{"ruleId":"D2","level":"warning","message":{"text":"Predicate::parse (cognitive 16): Predicate::parse has cognitive complexity 16 (threshold 15). Drivers by points: match/switch 5 (8 pts), if/else 4 (5 pts), loops 1 (3 pts) (nesting depth added 6). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/platform.rs"},"region":{"startLine":307}}}],"partialFingerprints":{"codehealthFindingId/v1":"f1c562b961bfcc36edab11d6b81b9b0e85aff386de273a18a0a80e658dca9cc4"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::session_commands::run_ps (cognitive 16): nono_cli::session_commands::run_ps has cognitive complexity 16 (threshold 15). Drivers by points: match/switch 5 (8 pts), if/else 4 (5 pts), loops 2, boolean chains 1 (nesting depth added 4). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/session_commands.rs"},"region":{"startLine":38}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c68d5858bfaf0fe67539f79eda70b5488883ee6254fec6d5cb30c02247276d3"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::policy::push_glob_as_seatbelt_regex (cognitive 16): nono_cli::policy::push_glob_as_seatbelt_regex has cognitive complexity 16 (threshold 15). Drivers by points: if/else 5 (11 pts), boolean chains 2, match/switch 1 (2 pts), loops 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/policy.rs"},"region":{"startLine":657}}}],"partialFingerprints":{"codehealthFindingId/v1":"31b7b6fdc97f3906edb2b91ba6d339f7b0791fedb7c91afbb1e4e77a771aeca2"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::network_policy::partition_allow_domain (cognitive 16): nono_cli::network_policy::partition_allow_domain has cognitive complexity 16 (threshold 15). Drivers by points: if/else 5 (13 pts), match/switch 1 (2 pts), loops 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/network_policy.rs"},"region":{"startLine":424}}}],"partialFingerprints":{"codehealthFindingId/v1":"ec509e1a8ba30ecf9568a9ac7a6a3b0b7646eb3760328534e2fbb8f273b52d47"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::query_ext::suggested_flag_parts (cognitive 16): nono_cli::query_ext::suggested_flag_parts has cognitive complexity 16 (threshold 15). Drivers by points: if/else 9 (10 pts), match/switch 3 (4 pts), boolean chains 2 (nesting depth added 2). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/query_ext.rs"},"region":{"startLine":787}}}],"partialFingerprints":{"codehealthFindingId/v1":"e208c6458fde6df971bd0c23c21ab58c26f3f267535318269ead380eb146917d"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::tool-sandbox::platform::macos::command_search_dirs (cognitive 16): nono_cli::tool-sandbox::platform::macos::command_search_dirs has cognitive complexity 16 (threshold 15). Drivers by points: if/else 5 (11 pts), loops 2 (3 pts), boolean chains 2 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":4983}}}],"partialFingerprints":{"codehealthFindingId/v1":"9ac4d9749b6abf9a78cc129175918406f940d66a899f2f6b45e4c713feaab448"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::profile::list_profiles (cognitive 16): nono_cli::profile::list_profiles has cognitive complexity 16 (threshold 15). Drivers by points: if/else 4 (10 pts), boolean chains 3, loops 2 (3 pts) (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":4278}}}],"partialFingerprints":{"codehealthFindingId/v1":"f7d7c02582b0b5daa8db9435b53c93111c4fef58c27db0c9b4a00e10d68854c3"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::sandbox_state::cleanup_stale_state_files (cognitive 16): nono_cli::sandbox_state::cleanup_stale_state_files has cognitive complexity 16 (threshold 15). Drivers by points: if/else 4 (7 pts), match/switch 4 (7 pts), boolean chains 1, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/sandbox_state.rs"},"region":{"startLine":606}}}],"partialFingerprints":{"codehealthFindingId/v1":"e79bc694b5f4ca4ba120ab9c27c7f06c7d7fa027a8d16bf6144f217e85d9d8bd"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::command_policy::validate_sandbox (cognitive 16): nono_cli::command_policy::validate_sandbox has cognitive complexity 16 (threshold 15). Drivers by points: if/else 10 (13 pts), boolean chains 2, loops 1 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_policy.rs"},"region":{"startLine":1942}}}],"partialFingerprints":{"codehealthFindingId/v1":"dec20b67963056ece4da321c0aefeaad1cb9d22d73c5c3792c75cdad116df5ce"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::trust_scan::check_missing_literal_patterns (cognitive 16): nono_cli::trust_scan::check_missing_literal_patterns has cognitive complexity 16 (threshold 15). Drivers by points: if/else 6 (9 pts), loops 2 (4 pts), boolean chains 2, match/switch 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_scan.rs"},"region":{"startLine":552}}}],"partialFingerprints":{"codehealthFindingId/v1":"5b114790ace6d7cb06a00e81fe3ab89da993975f43ea318199050d9ab77e5471"}},{"ruleId":"D2","level":"warning","message":{"text":"nono_cli::command_runtime::run_sandbox (cognitive 16): nono_cli::command_runtime::run_sandbox has cognitive complexity 16 (threshold 15). Drivers by points: if/else 6 (9 pts), boolean chains 3, loops 1 (3 pts), match/switch 1 (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_runtime.rs"},"region":{"startLine":155}}}],"partialFingerprints":{"codehealthFindingId/v1":"9f7bd53be9416e28fd49fba69a6ba63a04610758fd2be3bb44493ed811542939"}},{"ruleId":"D2","level":"warning","message":{"text":"RouteStore::load (cognitive 16): RouteStore::load has cognitive complexity 16 (threshold 15). Drivers by points: if/else 6 (10 pts), boolean chains 5, loops 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/route.rs"},"region":{"startLine":206}}}],"partialFingerprints":{"codehealthFindingId/v1":"97d3ce2e37176b2ddde94d5543d917f6eaf893c1424be545b608f1b7fbb426eb"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/exec_strategy.rs: FileTooLong \u2014 2615 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), declaring 61 free functions. The bar is 500 significant lines; this is 2115 over it, 5.23\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"785c8c4273f4e5dcbfe7965219c680adf05ea428f7c2c8d8622dedcb04dbb802"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/proxy_runtime.rs: FileTooLong \u2014 2553 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), declaring 72 free functions. The bar is 500 significant lines; this is 2053 over it, 5.11\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ec6789a1c7ef577a03acd2bf42512b0710f94d7195eef07554b89dfb0979c63e"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: profile/mod.rs: FileTooLong \u2014 2413 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), declaring 84 free functions. The bar is 500 significant lines; this is 1913 over it, 4.83\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f67a28f4fcd68f1cd50404204af572d4725e8bd1398f9185cffd63b70b3ebfcc"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::execution_runtime::execute_sandboxed: FunctionTooLong \u2014 nono_cli::execution_runtime::execute_sandboxed runs 477 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 377 over it, 4.77\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/execution_runtime.rs"},"region":{"startLine":203}}}],"partialFingerprints":{"codehealthFindingId/v1":"43289b48a72ec1a29c9ab9ac17545a67628676b8c47002177aa7212dfc2bdc74"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/command_policy.rs: FileTooLong \u2014 2286 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), declaring 55 free functions. The bar is 500 significant lines; this is 1786 over it, 4.57\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_policy.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0ee161c648e1c4fa68d55a20570fdc2bc9c930f4846b1cb35a072d36a6196b73"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/profile_cmd.rs: FileTooLong \u2014 2238 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), declaring 52 free functions. The bar is 500 significant lines; this is 1738 over it, 4.48\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"9ebe2ecf8fdfdc57ed66ee35257a4ded825740302d9423453391f359bc34a9f2"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::profile_cmd::cmd_diff: FunctionTooLong \u2014 nono_cli::profile_cmd::cmd_diff runs 413 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 313 over it, 4.13\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":1422}}}],"partialFingerprints":{"codehealthFindingId/v1":"4cb169ecffa26d35891c3b435e16be44529220a56887c493dc66ab4e780ed216"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::sandbox_prepare::prepare_sandbox: FunctionTooLong \u2014 nono_cli::sandbox_prepare::prepare_sandbox runs 409 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 309 over it, 4.09\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/sandbox_prepare.rs"},"region":{"startLine":1427}}}],"partialFingerprints":{"codehealthFindingId/v1":"0f970bb67e5a8339128e1f4bde0499d20437340b1f37bd93ee87b50045f953de"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/reverse.rs: FileTooLong \u2014 1978 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), declaring 50 free functions. The bar is 500 significant lines; this is 1478 over it, 3.96\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c0a4ecc6158c707db02317b612e98e8bdd846ebead6b80820a5bf29b698ae0da"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_proxy::reverse::handle_reverse_proxy: FunctionTooLong \u2014 nono_proxy::reverse::handle_reverse_proxy runs 394 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 294 over it, 3.94\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":128}}}],"partialFingerprints":{"codehealthFindingId/v1":"0396d8a7732e261140fee71aea7c27538f3e9e9b5b058e5ee22f97b20bec51fb"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_proxy::tls_intercept::handle::select_intercept_route: FunctionTooLong \u2014 nono_proxy::tls_intercept::handle::select_intercept_route runs 365 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 265 over it, 3.65\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":397}}}],"partialFingerprints":{"codehealthFindingId/v1":"e87cd00743b2747317a20b7131998a0d0855119b60c2bc6bcbd2d4fce46f75d6"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/cli.rs: FileTooLong \u2014 1777 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 1277 over it, 3.55\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/cli.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"cc476f8836cd5c49ffa286cb02427011be65b51f51465a519d54befc284c5bdc"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: diagnostic/formatter.rs: FileTooLong \u2014 1756 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), about 62% of them inside a single declaration: DiagnosticFormatter (2 blocks, 634-2330), declaring 39 free functions. The bar is 500 significant lines; this is 1256 over it, 3.51\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/diagnostic/formatter.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"736d1011fcc06303fb0f2acd48405c7c5631fd323a7e4375cb8e75f7b9ae14db"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/pty_proxy.rs: FileTooLong \u2014 1632 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), declaring 59 free functions. The bar is 500 significant lines; this is 1132 over it, 3.26\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/pty_proxy.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"103dda6b7367604a6a0432f459971c845825d141f1d764a4d4b6f1011f7cc2a7"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_proxy::server::handle_connection: FunctionTooLong \u2014 nono_proxy::server::handle_connection runs 318 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 218 over it, 3.18\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/server.rs"},"region":{"startLine":1477}}}],"partialFingerprints":{"codehealthFindingId/v1":"da779099fac24d47d7689c5df502b2b9077342a4120432e59fc73e974c1bc79a"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: CapabilitySet.from_profile: MethodTooLong \u2014 from_profile runs 313 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 213 over it, 3.13\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/capability_ext.rs"},"region":{"startLine":693}}}],"partialFingerprints":{"codehealthFindingId/v1":"85280da3ceacbe0325462c7e2b611e885ad46b320b5aa8d3c6fb5c40c0d9d9cb"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: tls_intercept/handle.rs: FileTooLong \u2014 1520 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 1020 over it, 3.04\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"83af9140d63b899976371d7c8f864069769907a422917bfa8e4e84da11fd3608"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::exec_strategy::supervisor_linux::handle_received_filesystem_notification: FunctionTooLong \u2014 nono_cli::exec_strategy::supervisor_linux::handle_received_filesystem_notification runs 304 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 204 over it, 3.04\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy/supervisor_linux.rs"},"region":{"startLine":195}}}],"partialFingerprints":{"codehealthFindingId/v1":"862a49581c91f5f22ae94413b4670d4d223fa2cbe22f56adde2cd811145b1989"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: CredentialStore.load_with_diagnostics: MethodTooLong \u2014 load_with_diagnostics runs 279 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 179 over it, 2.79\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/credential.rs"},"region":{"startLine":222}}}],"partialFingerprints":{"codehealthFindingId/v1":"6f9925b9d4f48dab2142f1fa70e69a1d2a6ea129edf6a87644c0dd6ffeba0acf"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/connect_client.rs: FileTooLong \u2014 1374 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), declaring 61 free functions. The bar is 500 significant lines; this is 874 over it, 2.75\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/connect_client.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"975895e58a9be23673008ab3a8d9bb05525512022b7a046e6f6ec921e1db1153"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: DiagnosticFormatter: ClassTooLong \u2014 1096 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 70 methods, 2 blocks, lines 634-2330. The bar is 400 significant lines; this is 696 over it, 2.74\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/diagnostic/formatter.rs"},"region":{"startLine":634}}}],"partialFingerprints":{"codehealthFindingId/v1":"39c6d049df7e79d613aee947c94aabf66c466446db7b5648f4598a8dba839e4e"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/profile_save_runtime.rs: FileTooLong \u2014 1340 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), declaring 62 free functions. The bar is 500 significant lines; this is 840 over it, 2.68\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_save_runtime.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"77e6e8a852cd44f47d5ec0c6c5e5ab3b9ba78a37a439096ca46a88ea666b8d1d"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::profile_cmd::resolve_to_manifest: FunctionTooLong \u2014 nono_cli::profile_cmd::resolve_to_manifest runs 266 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 166 over it, 2.66\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":2942}}}],"partialFingerprints":{"codehealthFindingId/v1":"aa90fd6241a5bfe823b95e67393a78a1ceae6d5fd983d1c6aa92bc72a160256e"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/server.rs: FileTooLong \u2014 1315 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 815 over it, 2.63\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/server.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"881bd9b97b86560dec5c3ad93d5aea46a21ce420123c49725578dcb93c05f9ca"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_proxy::reverse::enforce_endpoint_policy: FunctionTooLong \u2014 nono_proxy::reverse::enforce_endpoint_policy runs 259 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 159 over it, 2.59\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":1058}}}],"partialFingerprints":{"codehealthFindingId/v1":"7ebdee38dcfa9181f05dc0edd3f3fba3d2c34225847a257cdc96bc77027fe1dc"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_proxy::tls_intercept::handle::handle_inner_request: FunctionTooLong \u2014 nono_proxy::tls_intercept::handle::handle_inner_request runs 258 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 158 over it, 2.58\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":1030}}}],"partialFingerprints":{"codehealthFindingId/v1":"ad14225b47f0cc532ef7bd2f28cee19b9154d67ae3440569e5602a6c0c58de12"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/sandbox_prepare.rs: FileTooLong \u2014 1267 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), declaring 46 free functions. The bar is 500 significant lines; this is 767 over it, 2.53\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/sandbox_prepare.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"7c9f0c9696d1dfc28dd9219bb035cdb46be1df778aa7885fcc248085ede287fd"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::profile_cmd::cmd_show: FunctionTooLong \u2014 nono_cli::profile_cmd::cmd_show runs 253 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 153 over it, 2.53\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":855}}}],"partialFingerprints":{"codehealthFindingId/v1":"e11ac2d882954d600c3d1498cbe162b6b018db8c727683765030490d686f96e6"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: CapabilitySet: TooManyMethods \u2014 73 methods. The bar is 30 methods; this is 43 over it, 2.43\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/capability.rs"},"region":{"startLine":951}}}],"partialFingerprints":{"codehealthFindingId/v1":"8669286f55b6e14b088e64bf846578964a11fc2ab639fb0c4b1b5a8f0cc3c143"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::profile_runtime::prepare_profile_with_options: FunctionTooLong \u2014 nono_cli::profile_runtime::prepare_profile_with_options runs 242 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 142 over it, 2.42\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_runtime.rs"},"region":{"startLine":658}}}],"partialFingerprints":{"codehealthFindingId/v1":"7b83db9c5b51f66d63621d1bda67794bda0848c359bb3c91d126f84862ef5d3e"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/policy.rs: FileTooLong \u2014 1182 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), declaring 41 free functions. The bar is 500 significant lines; this is 682 over it, 2.36\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/policy.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"98a73150106b4e9621c038cefdadfe48a110bdcf22ea5099c540c088cb906bb9"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: DiagnosticFormatter: TooManyMethods \u2014 70 methods. The bar is 30 methods; this is 40 over it, 2.33\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/diagnostic/formatter.rs"},"region":{"startLine":634}}}],"partialFingerprints":{"codehealthFindingId/v1":"838558374749bbb6139a41fa42acf8ae18f3862cae48e6f94a14e7bda1999bf1"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_proxy::server::start_with_nonce_resolver: FunctionTooLong \u2014 nono_proxy::server::start_with_nonce_resolver runs 230 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 130 over it, 2.30\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/server.rs"},"region":{"startLine":1054}}}],"partialFingerprints":{"codehealthFindingId/v1":"a902897870070499881c61615880aef6ad0c0a14f961858eb6437630c6413b99"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_proxy::tls_intercept::h2_forward::handle_h2_stream: FunctionTooLong \u2014 nono_proxy::tls_intercept::h2_forward::handle_h2_stream runs 228 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 128 over it, 2.28\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/h2_forward.rs"},"region":{"startLine":232}}}],"partialFingerprints":{"codehealthFindingId/v1":"330c431e7d2991c7a2f671da233838c51af87b634f0e822efffb7dd97dc5ddc2"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/keystore.rs: FileTooLong \u2014 1100 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), declaring 49 free functions. The bar is 500 significant lines; this is 600 over it, 2.20\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/keystore.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"931ca32840bde0c5b09a48b0ec482e4ddb6492877797823f7b3e11c3dadc489c"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/audit.rs: FileTooLong \u2014 1038 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 538 over it, 2.08\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/audit.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a9a0c83a983d53d7a79c3ea5ff8989af9130c24bdd7756c1059d1eb798049719"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::supervised_runtime::execute_supervised_runtime: FunctionTooLong \u2014 nono_cli::supervised_runtime::execute_supervised_runtime runs 207 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 107 over it, 2.07\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/supervised_runtime.rs"},"region":{"startLine":210}}}],"partialFingerprints":{"codehealthFindingId/v1":"c12f94e67dee57a357e0ddf5f0d36907ca48fba075a719bd7cef8ca5a9f3cbee"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/trust_cmd.rs: FileTooLong \u2014 975 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), declaring 39 free functions. The bar is 500 significant lines; this is 475 over it, 1.95\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_cmd.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c14d055e4d02a9f505265be90f3c7d3b6d72449360073c36e8015fb9dcd84abd"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/capability.rs: FileTooLong \u2014 964 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 464 over it, 1.93\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/capability.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"9576f77242b32042594e3f8a0762a07ab520c13102929380c5d2a752aa3d24d4"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::profile::merge_profiles: FunctionTooLong \u2014 nono_cli::profile::merge_profiles runs 190 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 90 over it, 1.90\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":3719}}}],"partialFingerprints":{"codehealthFindingId/v1":"26d210122093cea601d17dfc7740d1056284f14d602787b84d64c257e1f2885f"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::query_ext::query_network: FunctionTooLong \u2014 nono_cli::query_ext::query_network runs 189 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 89 over it, 1.89\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/query_ext.rs"},"region":{"startLine":240}}}],"partialFingerprints":{"codehealthFindingId/v1":"1f49d982bbccb102e894de01dda6adc534d47c2804444fa4daa9f663c8847ed1"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: exec_strategy/supervisor_linux.rs: FileTooLong \u2014 944 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 444 over it, 1.89\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy/supervisor_linux.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"01bd4671c6178dc908c02f47e732ab46a4336971d1ed65df575ab42bb0666fc7"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: ProxyCredentialCaptureBackend.run_capture_command: MethodTooLong \u2014 run_capture_command runs 187 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 87 over it, 1.87\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":381}}}],"partialFingerprints":{"codehealthFindingId/v1":"ca37ea060b52b4ec9df83a6b7e76e9fc46db60f7f1e4d73e52db7f454158ca4f"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/wiring.rs: FileTooLong \u2014 931 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), declaring 41 free functions. The bar is 500 significant lines; this is 431 over it, 1.86\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/wiring.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"86ee99f7983ec666f853b45b4fccf437c89c45ffff95fac84c69ff67bd10bfe2"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_proxy::reverse::handle_spiffe_route: FunctionTooLong \u2014 nono_proxy::reverse::handle_spiffe_route runs 183 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 83 over it, 1.83\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":696}}}],"partialFingerprints":{"codehealthFindingId/v1":"9158dbaca9721b202e59c0c824c783c77ce0d2b9bcbddf354200faf4fa0b65e9"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono::audit::verify_audit_attestation_bundle: FunctionTooLong \u2014 nono::audit::verify_audit_attestation_bundle runs 177 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 77 over it, 1.77\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/audit.rs"},"region":{"startLine":1123}}}],"partialFingerprints":{"codehealthFindingId/v1":"0d0f18e9b6bafa6d978cb9bf3374ca1aebc12bbff087e5363c382e5aea79a13d"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/output.rs: FileTooLong \u2014 860 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), declaring 40 free functions. The bar is 500 significant lines; this is 360 over it, 1.72\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/output.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"40b37a01fbb0f8d74e370893097638bae70c76d685270a2cc008712199cdd8c6"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/package_cmd.rs: FileTooLong \u2014 847 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), declaring 36 free functions. The bar is 500 significant lines; this is 347 over it, 1.69\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/package_cmd.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a2120b8e30fdaceba16dd109bcd4e4c86e6ee06e718f1fa8ed4230edc4224c95"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::why_runtime::run_why: FunctionTooLong \u2014 nono_cli::why_runtime::run_why runs 166 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 66 over it, 1.66\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/why_runtime.rs"},"region":{"startLine":117}}}],"partialFingerprints":{"codehealthFindingId/v1":"95558d440802b31ec6d589808d9771432c963ed80743c0d96714b584ed6e1293"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/profile_runtime.rs: FileTooLong \u2014 818 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 318 over it, 1.64\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_runtime.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c3b1efc9bacd24012cbdc48c63b92b76507544cf648fa0c34450787cd1e5478"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::proxy_runtime::prepare_proxy_launch_options: FunctionTooLong \u2014 nono_cli::proxy_runtime::prepare_proxy_launch_options runs 163 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 63 over it, 1.63\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":1430}}}],"partialFingerprints":{"codehealthFindingId/v1":"5ae9168922ff9f96f2ea46b4be1a29b819c317be42c1ff0dcfd50c98c2d58b90"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: PtyProxy: ClassTooLong \u2014 646 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 38 methods, 3 blocks, lines 263-1722. The bar is 400 significant lines; this is 246 over it, 1.62\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/pty_proxy.rs"},"region":{"startLine":263}}}],"partialFingerprints":{"codehealthFindingId/v1":"cafd8ecd02a7420b02f0414ef678a94918265392b3fe2e190c207dd56b16f5d4"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/capability_ext.rs: FileTooLong \u2014 805 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 305 over it, 1.61\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/capability_ext.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"baf92a632f2bca2b4299306fe8b6f6f021481afa4ae13a0e0b1f189065f0b412"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_proxy::server::handle_forward_http: FunctionTooLong \u2014 nono_proxy::server::handle_forward_http runs 161 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 61 over it, 1.61\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/server.rs"},"region":{"startLine":1987}}}],"partialFingerprints":{"codehealthFindingId/v1":"6b999a577f7849dae2ac063f35bf1def8834ab04669fa68908ce2b47d7d7c95d"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/config.rs: FileTooLong \u2014 776 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), declaring 31 free functions. The bar is 500 significant lines; this is 276 over it, 1.55\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/config.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"8b233db7c707667815f932015400c69dcbf0c61d3393a61640c4163bd90e9d3e"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_proxy::tls_intercept::handle::handle_spiffe_intercept_request: FunctionTooLong \u2014 nono_proxy::tls_intercept::handle::handle_spiffe_intercept_request runs 150 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 50 over it, 1.50\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":1407}}}],"partialFingerprints":{"codehealthFindingId/v1":"e47102e6be6e1ffce32642dda0a1d1f21f706191896c9b2f948b7951de9c1224"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFields: PreparedSandbox: TooManyFields \u2014 45 stored fields. The bar is 30 stored fields; this is 15 over it, 1.50\u00D7 the bar. This is width in DATA, not behaviour: every reader that takes the whole type couples to all of its fields, so a change to any one of them is a change every reader has to be checked against. To reduce it, group the fields that are read together by the same callers into a smaller type of their own, and have this one hold that type as a single member \u2014 each reader then names only the group it uses."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/sandbox_prepare.rs"},"region":{"startLine":506}}}],"partialFingerprints":{"codehealthFindingId/v1":"643decacf27a0bb1acadbaa2f9fba2349dfa9a0c5568021f4191c6eba37c3424"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::output::print_capabilities: FunctionTooLong \u2014 nono_cli::output::print_capabilities runs 149 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 49 over it, 1.49\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/output.rs"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"cea9cd2301b59a2f227ad9f559f80224931b0c1a3722d71fb5c32274627fa3d2"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::policy::apply_macos_keychain_db_exception: FunctionTooLong \u2014 nono_cli::policy::apply_macos_keychain_db_exception runs 142 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 42 over it, 1.42\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/policy.rs"},"region":{"startLine":1435}}}],"partialFingerprints":{"codehealthFindingId/v1":"d6b86555f2e5ac42e4994055dc1ab2ebb3451ae091053debf750dfc4ec692fb8"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::proxy_runtime::start_proxy_runtime: FunctionTooLong \u2014 nono_cli::proxy_runtime::start_proxy_runtime runs 141 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 41 over it, 1.41\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":2973}}}],"partialFingerprints":{"codehealthFindingId/v1":"a49e754de3147711b0d3f1fd7611aba9981c45839315520e7b8c96ebf9249173"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/rollback_commands.rs: FileTooLong \u2014 704 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 204 over it, 1.41\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/rollback_commands.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0e9ceccb067c1493247510e4706a649ca43cc6c08d8354f2a40dbb0f0d1d0423"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/audit_commands.rs: FileTooLong \u2014 685 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 185 over it, 1.37\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"cb667db97dd8528f1bdaae56061101f204d59f613add163117648c54a3a60ab6"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: undo/snapshot.rs: FileTooLong \u2014 665 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), about 78% of them inside a single declaration: SnapshotManager (2 blocks, 62-951). The bar is 500 significant lines; this is 165 over it, 1.33\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/snapshot.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"61ad8109f93efa3d789378509c5867766f43b2752e9117deaa1c818ec6613886"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/execution_runtime.rs: FileTooLong \u2014 664 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 164 over it, 1.33\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/execution_runtime.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d9d80340f1048ee4aab46d1c47b7db439e8cca16e75769f20c6836a95924438c"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::audit_commands::cmd_show: FunctionTooLong \u2014 nono_cli::audit_commands::cmd_show runs 132 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 32 over it, 1.32\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":348}}}],"partialFingerprints":{"codehealthFindingId/v1":"58863e12a4d3329499582c1e0fefee512f2f09e88535dfda4540c5e522e6bb9b"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: SnapshotManager: ClassTooLong \u2014 518 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 26 methods, 2 blocks, lines 62-951. The bar is 400 significant lines; this is 118 over it, 1.30\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/snapshot.rs"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"fb96c24081df294ca18cb3a128ec6b3fdc01847197278bf0a9a10266f1a319d1"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/why_runtime.rs: FileTooLong \u2014 646 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 146 over it, 1.29\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/why_runtime.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"78ca99fb7429e7383bff002b76fa679d5b599020222a306dea5fca37b1491c40"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/trust_scan.rs: FileTooLong \u2014 642 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 142 over it, 1.28\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_scan.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"fb93eee99326738f3026f08f3d2519073a4af2311c74c8d4b5f41053b9cf963c"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: PtyProxy: TooManyMethods \u2014 38 methods. The bar is 30 methods; this is 8 over it, 1.27\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/pty_proxy.rs"},"region":{"startLine":263}}}],"partialFingerprints":{"codehealthFindingId/v1":"5bf75cfe690ba39d3788997cce970367def6935bfdff2373bb2484c903e52a17"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFields: PreparedProfile: TooManyFields \u2014 38 stored fields. The bar is 30 stored fields; this is 8 over it, 1.27\u00D7 the bar. This is width in DATA, not behaviour: every reader that takes the whole type couples to all of its fields, so a change to any one of them is a change every reader has to be checked against. To reduce it, group the fields that are read together by the same callers into a smaller type of their own, and have this one hold that type as a single member \u2014 each reader then names only the group it uses."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_runtime.rs"},"region":{"startLine":8}}}],"partialFingerprints":{"codehealthFindingId/v1":"05e707137adbca69f4cff28db9aed414d23aac73e0cd2b853f28198d8d74866b"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: DiagnosticFormatter.format_exit_explanation: MethodTooLong \u2014 format_exit_explanation runs 126 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 26 over it, 1.26\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/diagnostic/formatter.rs"},"region":{"startLine":991}}}],"partialFingerprints":{"codehealthFindingId/v1":"ba545785c284c3488c3829cef907370b695a2ac082113182b0046b14787e00bd"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::proxy_command::build_launch_options: FunctionTooLong \u2014 nono_cli::proxy_command::build_launch_options runs 126 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 26 over it, 1.26\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_command.rs"},"region":{"startLine":188}}}],"partialFingerprints":{"codehealthFindingId/v1":"e81dad564ec9375435a097f0a9f1161b739582250ffe5363a6304221c16484ea"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/query_ext.rs: FileTooLong \u2014 628 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 128 over it, 1.26\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/query_ext.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1f7b59459cf245adb5aad2d3fce8e092632cd8baef78658ff713831ef2772b87"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::proxy_runtime::build_proxy_config_from_flags: FunctionTooLong \u2014 nono_cli::proxy_runtime::build_proxy_config_from_flags runs 124 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 24 over it, 1.24\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":2357}}}],"partialFingerprints":{"codehealthFindingId/v1":"3594833a670e331f5f9952d1bfde4ff531427ff8c81e06cbef2611d4a90d74bb"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::rollback_runtime::finalize_supervised_exit: FunctionTooLong \u2014 nono_cli::rollback_runtime::finalize_supervised_exit runs 124 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 24 over it, 1.24\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/rollback_runtime.rs"},"region":{"startLine":505}}}],"partialFingerprints":{"codehealthFindingId/v1":"61472bfb0928ecaa8a352d0efb006fd7285ca31343993d12d885237826b3199c"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::pty_proxy::run_attach_loop: FunctionTooLong \u2014 nono_cli::pty_proxy::run_attach_loop runs 123 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 23 over it, 1.23\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/pty_proxy.rs"},"region":{"startLine":2574}}}],"partialFingerprints":{"codehealthFindingId/v1":"a22dad9fdb76171b338092682157323ed3ca21f5a6f7f27202bcac65c1ab4721"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::session_commands::run_ps: FunctionTooLong \u2014 nono_cli::session_commands::run_ps runs 123 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 23 over it, 1.23\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/session_commands.rs"},"region":{"startLine":38}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b0e2d94d3d326c5c19a14322f1992cfb0d96d5578827b2726fc2ecc7c0b104d"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_proxy::tls_intercept::handle::handle_inner_request_aws: FunctionTooLong \u2014 nono_proxy::tls_intercept::handle::handle_inner_request_aws runs 123 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 23 over it, 1.23\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":1671}}}],"partialFingerprints":{"codehealthFindingId/v1":"75984cc69473d0254c846a2856a2c82965df9eab656b95c8d55fe68038c63b84"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::proxy_runtime::collect_tool_sandbox_proxy_grants: FunctionTooLong \u2014 nono_cli::proxy_runtime::collect_tool_sandbox_proxy_grants runs 121 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 21 over it, 1.21\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":1828}}}],"partialFingerprints":{"codehealthFindingId/v1":"4127278f8ad76f7ada028dc3f0cb3203d615b2dfe50cad1e92e0122a4e07261d"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: CapabilitySet: ClassTooLong \u2014 480 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 73 methods, 2 blocks, lines 951-2086. The bar is 400 significant lines; this is 80 over it, 1.20\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/capability.rs"},"region":{"startLine":951}}}],"partialFingerprints":{"codehealthFindingId/v1":"67b4fbc3445c2b3927c9a72dbfad37599d826476261a0d2031957c1b623ba8d0"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_proxy::reverse::handle_oauth2_like: FunctionTooLong \u2014 nono_proxy::reverse::handle_oauth2_like runs 119 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 19 over it, 1.19\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":1416}}}],"partialFingerprints":{"codehealthFindingId/v1":"b6af737c2a5042cc5cb2f5f93deddf65ccbffb12f9fe81ce54938b6ac4900a76"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::exec_strategy::supervisor_linux::handle_received_network_notification: FunctionTooLong \u2014 nono_cli::exec_strategy::supervisor_linux::handle_received_network_notification runs 118 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 18 over it, 1.18\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy/supervisor_linux.rs"},"region":{"startLine":1043}}}],"partialFingerprints":{"codehealthFindingId/v1":"fce1612f99b160692e78b779982c6190b38f7340c632015ed3b73a1a29197c95"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_proxy::tls_intercept::handle::run_websocket_tunnel: FunctionTooLong \u2014 nono_proxy::tls_intercept::handle::run_websocket_tunnel runs 118 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 18 over it, 1.18\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":1987}}}],"partialFingerprints":{"codehealthFindingId/v1":"a525a42813829e06829f00d7445c020ffd9edcae1113eff5f746fde39461b899"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/session.rs: FileTooLong \u2014 589 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), declaring 33 free functions. The bar is 500 significant lines; this is 89 over it, 1.18\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/session.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"bd104add73dc7f49113745d3012c325aef78943d7f835100f1278bc2d1bf1aee"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: exec_strategy/clone_files.rs: FileTooLong \u2014 585 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 85 over it, 1.17\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy/clone_files.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"781839192e13ec6c56d3843f1fd2eaf9a7b892c4c96a0d8fc119b96c41a24fb6"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::wiring::execute_one: FunctionTooLong \u2014 nono_cli::wiring::execute_one runs 116 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 16 over it, 1.16\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/wiring.rs"},"region":{"startLine":339}}}],"partialFingerprints":{"codehealthFindingId/v1":"3ea4b87618d91dc88f926c22635b478e0a8c922c5a929b7660021aaee3aeb8a1"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: RouteStore.load: MethodTooLong \u2014 load runs 116 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 16 over it, 1.16\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/route.rs"},"region":{"startLine":206}}}],"partialFingerprints":{"codehealthFindingId/v1":"d1bd7f94aa7f9514cac23f0a5cd1c6d12d90149eeca43717fd351834f68fdea7"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::launch_runtime::prepare_run_launch_plan: FunctionTooLong \u2014 nono_cli::launch_runtime::prepare_run_launch_plan runs 113 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 13 over it, 1.13\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/launch_runtime.rs"},"region":{"startLine":333}}}],"partialFingerprints":{"codehealthFindingId/v1":"21c408d0f76accb51ca71acf32e8937a05ff964cd755aa9b93b6d2ead76c2b5f"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::profile_cmd::cmd_validate: FunctionTooLong \u2014 nono_cli::profile_cmd::cmd_validate runs 113 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 13 over it, 1.13\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":2402}}}],"partialFingerprints":{"codehealthFindingId/v1":"dff690c8ce14efcff1c9c72811aaa0445f0887c69da7d27e57efe96936b740ef"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: ProxyCredentialCaptureBackend: ClassTooLong \u2014 445 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 7 methods, 3 blocks, lines 144-773. The bar is 400 significant lines; this is 45 over it, 1.11\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":144}}}],"partialFingerprints":{"codehealthFindingId/v1":"244a92e7dbc21994b2f6b330ab5a9a5b49d9108752ceb003606c1c21f38fdf35"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::profile_save_runtime::render_denial_selector: FunctionTooLong \u2014 nono_cli::profile_save_runtime::render_denial_selector runs 110 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 10 over it, 1.10\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_save_runtime.rs"},"region":{"startLine":1266}}}],"partialFingerprints":{"codehealthFindingId/v1":"78bb9390889b839d9e83bfb88f5f549a2dbf1bca68036ed61c9545dc8f65148e"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFields: NetworkAuditEvent: TooManyFields \u2014 33 stored fields. The bar is 30 stored fields; this is 3 over it, 1.10\u00D7 the bar. This is width in DATA, not behaviour: every reader that takes the whole type couples to all of its fields, so a change to any one of them is a change every reader has to be checked against. To reduce it, group the fields that are read together by the same callers into a smaller type of their own, and have this one hold that type as a single member \u2014 each reader then names only the group it uses."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/types.rs"},"region":{"startLine":303}}}],"partialFingerprints":{"codehealthFindingId/v1":"f3f418a7c972c9d998193a39525ccdfb3a6fc38bd88b06eb61b288e3410eb3ec"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/credential.rs: FileTooLong \u2014 547 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), about 61% of them inside a single declaration: CredentialStore (2 blocks, 188-667). The bar is 500 significant lines; this is 47 over it, 1.09\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/credential.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"51b3f67bce51267875faae564c4b4baf119959925803b94e71132d42abab82d7"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::audit_commands::cmd_verify: FunctionTooLong \u2014 nono_cli::audit_commands::cmd_verify runs 109 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 9 over it, 1.09\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":557}}}],"partialFingerprints":{"codehealthFindingId/v1":"12d5d7cdf1839a5d2873291a723ced4dbeaac2e74a84b8814102498484a29c04"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::profile_runtime::verify_stored_bundles: FunctionTooLong \u2014 nono_cli::profile_runtime::verify_stored_bundles runs 109 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 9 over it, 1.09\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_runtime.rs"},"region":{"startLine":251}}}],"partialFingerprints":{"codehealthFindingId/v1":"29361dd9e1bc7349a6cc4c36af0eed68f9637a7a358337afb7fc234dc6b7ad49"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono::audit::verify_audit_log: FunctionTooLong \u2014 nono::audit::verify_audit_log runs 109 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 9 over it, 1.09\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/audit.rs"},"region":{"startLine":1434}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7a29a453c589393a7498b45f390c684471cc6aebc7b6a72c91dc5d99a517ef0"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::profile_cmd::diff_to_json: FunctionTooLong \u2014 nono_cli::profile_cmd::diff_to_json runs 108 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 8 over it, 1.08\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":2042}}}],"partialFingerprints":{"codehealthFindingId/v1":"ff4138e7e7783aee398e2dc7e7f2ca693cd1b54f0115a4e7c4cd32dbda5a1fdf"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_proxy::reverse::capture_cmd_credential: FunctionTooLong \u2014 nono_proxy::reverse::capture_cmd_credential runs 108 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 8 over it, 1.08\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":934}}}],"partialFingerprints":{"codehealthFindingId/v1":"50cc98a71a6f6ccc386c27d13d82c2c0341b57d0a862d2f9e9daebe407728664"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: PtyProxy.try_accept: MethodTooLong \u2014 try_accept runs 107 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 7 over it, 1.07\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/pty_proxy.rs"},"region":{"startLine":552}}}],"partialFingerprints":{"codehealthFindingId/v1":"70c9c4704b7d50c98fbcdcf51e143794a057dbc9ae861d22884dfb44c583159f"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_proxy::oauth2::exchange_token: FunctionTooLong \u2014 nono_proxy::oauth2::exchange_token runs 107 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 7 over it, 1.07\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/oauth2.rs"},"region":{"startLine":208}}}],"partialFingerprints":{"codehealthFindingId/v1":"a5bcd54265a0f578f28cd6ecfe5c4bb1c0bcd94b6ba32bdc3cc37ee60b22b2d8"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: Commands: ClassTooLong \u2014 427 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 0 methods. The bar is 400 significant lines; this is 27 over it, 1.07\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/cli.rs"},"region":{"startLine":107}}}],"partialFingerprints":{"codehealthFindingId/v1":"01bc037620585fb78db7f4346e6f31e5d9d9ef7defec1b10c8a1a06b84d8696e"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::command_policy::validate_credential: FunctionTooLong \u2014 nono_cli::command_policy::validate_credential runs 106 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 6 over it, 1.06\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_policy.rs"},"region":{"startLine":2551}}}],"partialFingerprints":{"codehealthFindingId/v1":"12ee1d222bc399745e3e4da83cd9df3a8f95ccacbd300c65aa01d8ddd795d8aa"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::connect_client::attach: FunctionTooLong \u2014 nono_cli::connect_client::attach runs 104 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 4 over it, 1.04\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/connect_client.rs"},"region":{"startLine":1575}}}],"partialFingerprints":{"codehealthFindingId/v1":"b1e80abe435e6bcd1f4dbdbb9b54f9637f071b05a81fa2f2dc9be8e1807fa141"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::remote_run::run: FunctionTooLong \u2014 nono_cli::remote_run::run runs 104 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 4 over it, 1.04\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/remote_run.rs"},"region":{"startLine":89}}}],"partialFingerprints":{"codehealthFindingId/v1":"c810a2121af6880f389d4295bf83dd8bd89f380b5b4033342558d9d3ea4b64e1"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::why_runtime::query_command_policy: FunctionTooLong \u2014 nono_cli::why_runtime::query_command_policy runs 104 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 4 over it, 1.04\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/why_runtime.rs"},"region":{"startLine":684}}}],"partialFingerprints":{"codehealthFindingId/v1":"63d1499d87d097df41124ce41ba3e18256708b0e1824eed866f220b06480d1ff"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_proxy::oauth2::exchange_jwt_assertion: FunctionTooLong \u2014 nono_proxy::oauth2::exchange_jwt_assertion runs 104 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 4 over it, 1.04\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/oauth2.rs"},"region":{"startLine":538}}}],"partialFingerprints":{"codehealthFindingId/v1":"63ab4a5bc98bd3720e9dc6b91e11c7ad2c2beaa9452d23b1c7f2262580edff87"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFields: WrapSandboxArgs: TooManyFields \u2014 31 stored fields. The bar is 30 stored fields; this is 1 over it, 1.03\u00D7 the bar. This is width in DATA, not behaviour: every reader that takes the whole type couples to all of its fields, so a change to any one of them is a change every reader has to be checked against. To reduce it, group the fields that are read together by the same callers into a smaller type of their own, and have this one hold that type as a single member \u2014 each reader then names only the group it uses."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/cli.rs"},"region":{"startLine":1636}}}],"partialFingerprints":{"codehealthFindingId/v1":"47fa28c80077b308ca48834ddab9caeabdfc9d1ae3544f7b8b6c805e6e2e4bb4"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/session_commands.rs: FileTooLong \u2014 510 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 10 over it, 1.02\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/session_commands.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e501581c5d2b8dd90036101f42fb5f719be1f7ea8049c84f894719362a7ddb19"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::proxy_runtime::synthesize_credential_provider_proxy_config: FunctionTooLong \u2014 nono_cli::proxy_runtime::synthesize_credential_provider_proxy_config runs 102 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 2 over it, 1.02\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":2560}}}],"partialFingerprints":{"codehealthFindingId/v1":"beca1eae77a76992860e194e485aded276b0738cfc1ab7068d6b161a641d19ef"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: nono_cli::profile_runtime::verify_profile_packs: FunctionTooLong \u2014 nono_cli::profile_runtime::verify_profile_packs runs 101 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 1 over it, 1.01\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_runtime.rs"},"region":{"startLine":102}}}],"partialFingerprints":{"codehealthFindingId/v1":"d0f7a8e1faa87bcd78789fb3e8345dfbbcf9618916a6235d835dfc08f70e3cb2"}},{"ruleId":"D4","level":"warning","message":{"text":"Near-duplicate member pair (298 shared lines): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1271-2051 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:978-1785 \u2014 These two members are variants of one another: 298 of their lines are already reported as duplicated blocks below, spread through both bodies rather than gathered into one. Read them as a single construct written twice. The repair is at the members\u0027 grain \u2014 factor the shared pipeline into one implementation the two call with their differences as parameters or as an injected step, or, where the difference is systematic (sync against async, one transport against another), generate one from the other. Extracting the individual blocks below is not the same fix: it leaves the two bodies in place and the next edit still has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1271}}}],"partialFingerprints":{"codehealthFindingId/v1":"1f9289182683785fcc733d186e81f198b0086068d9ef8a997c8a79f4980c6d48"}},{"ruleId":"D4","level":"warning","message":{"text":"Near-duplicate member pair (54 shared lines): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4639-4706 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4082-4154 \u2014 These two members are variants of one another: 54 of their lines are already reported as duplicated blocks below, spread through both bodies rather than gathered into one. Read them as a single construct written twice. The repair is at the members\u0027 grain \u2014 factor the shared pipeline into one implementation the two call with their differences as parameters or as an injected step, or, where the difference is systematic (sync against async, one transport against another), generate one from the other. Extracting the individual blocks below is not the same fix: it leaves the two bodies in place and the next edit still has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4639}}}],"partialFingerprints":{"codehealthFindingId/v1":"59dfde8930af6a7453291f56b3946a34e630b6389b5eeddf4dd1bfabb77295b8"}},{"ruleId":"D4","level":"warning","message":{"text":"Near-duplicate member pair (45 shared lines): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4431-4537 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:3875-3978 \u2014 These two members are variants of one another: 45 of their lines are already reported as duplicated blocks below, spread through both bodies rather than gathered into one. Read them as a single construct written twice. The repair is at the members\u0027 grain \u2014 factor the shared pipeline into one implementation the two call with their differences as parameters or as an injected step, or, where the difference is systematic (sync against async, one transport against another), generate one from the other. Extracting the individual blocks below is not the same fix: it leaves the two bodies in place and the next edit still has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4431}}}],"partialFingerprints":{"codehealthFindingId/v1":"549505c8a3654c76db88fec43ed3c9deebc959e3a9262d155981201eacbab2b8"}},{"ruleId":"D4","level":"warning","message":{"text":"Near-duplicate member pair (39 shared lines): crates/nono-cli/src/tool-sandbox/platform/linux.rs:266-431 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:276-392 \u2014 These two members are variants of one another: 39 of their lines are already reported as duplicated blocks below, spread through both bodies rather than gathered into one. Read them as a single construct written twice. The repair is at the members\u0027 grain \u2014 factor the shared pipeline into one implementation the two call with their differences as parameters or as an injected step, or, where the difference is systematic (sync against async, one transport against another), generate one from the other. Extracting the individual blocks below is not the same fix: it leaves the two bodies in place and the next edit still has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":266}}}],"partialFingerprints":{"codehealthFindingId/v1":"ea73a92d9ba9efe190ce79dee983fd0600bb69786ff189d13580d72e10c1721c"}},{"ruleId":"D4","level":"warning","message":{"text":"Near-duplicate member pair (37 shared lines): crates/nono-proxy/src/tls_intercept/handle.rs:1418-1596 | crates/nono-proxy/src/tls_intercept/handle.rs:1681-1838 \u2014 These two members are variants of one another: 37 of their lines are already reported as duplicated blocks below, spread through both bodies rather than gathered into one. Read them as a single construct written twice. The repair is at the members\u0027 grain \u2014 factor the shared pipeline into one implementation the two call with their differences as parameters or as an injected step, or, where the difference is systematic (sync against async, one transport against another), generate one from the other. Extracting the individual blocks below is not the same fix: it leaves the two bodies in place and the next edit still has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":1418}}}],"partialFingerprints":{"codehealthFindingId/v1":"a8e14282189b381946cc50bb797a68a20db0f08773feeb9e193b9a5ae96ec90c"}},{"ruleId":"D4","level":"warning","message":{"text":"Near-duplicate member pair (33 shared lines): crates/nono/src/sandbox/linux.rs:1414-1487 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:3337-3418 \u2014 These two members are variants of one another: 33 of their lines are already reported as duplicated blocks below, spread through both bodies rather than gathered into one. Read them as a single construct written twice. The repair is at the members\u0027 grain \u2014 factor the shared pipeline into one implementation the two call with their differences as parameters or as an injected step, or, where the difference is systematic (sync against async, one transport against another), generate one from the other. Extracting the individual blocks below is not the same fix: it leaves the two bodies in place and the next edit still has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/sandbox/linux.rs"},"region":{"startLine":1414}}}],"partialFingerprints":{"codehealthFindingId/v1":"253ddadb5c791cc3893c1935d272c6739f3bed623f0bdfa84a7f344df9803515"}},{"ruleId":"D4","level":"warning","message":{"text":"Near-duplicate member pair (27 shared lines): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2254-2306 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4667-4711 \u2014 These two members are variants of one another: 27 of their lines are already reported as duplicated blocks below, spread through both bodies rather than gathered into one. Read them as a single construct written twice. The repair is at the members\u0027 grain \u2014 factor the shared pipeline into one implementation the two call with their differences as parameters or as an injected step, or, where the difference is systematic (sync against async, one transport against another), generate one from the other. Extracting the individual blocks below is not the same fix: it leaves the two bodies in place and the next edit still has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2254}}}],"partialFingerprints":{"codehealthFindingId/v1":"f654c79894ae73bf08592ac5862285ffedf3bacfbd43c269b3dbb58dc5e639e1"}},{"ruleId":"D4","level":"warning","message":{"text":"Edited copy of a member (28 corresponding lines): crates/nono-cli/src/sandbox_state.rs:247-281 | crates/nono-cli/src/session.rs:803-835 \u2014 These two members are one piece of code written twice and then edited apart: 28 consecutive lines correspond almost exactly, broken only by small local edits. Most of that correspondence is NOT reported as duplicated blocks below \u2014 the edits cut it into fragments and only the largest of them clear the block floor, so the rows below understate it. The repair is at the members\u0027 grain \u2014 factor the shared implementation into one the two call with their differences as parameters or as an injected step, or, where the difference is systematic (an extra return value, one transport against another), generate one from the other. Left alone, the next edit has to be made twice and the two will drift further apart."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/sandbox_state.rs"},"region":{"startLine":247}}}],"partialFingerprints":{"codehealthFindingId/v1":"a91a42f4368d377324df7034afcddfe38b713d01c3bf40ae49fe91f6d3bf277a"}},{"ruleId":"D4","level":"warning","message":{"text":"Edited copy of a member (7 corresponding lines): crates/nono-cli/src/profile_cmd.rs:2042-2180 | crates/nono-cli/src/profile_cmd.rs:2185-2206 \u2014 These two members are one piece of code written twice and then edited apart: 7 consecutive lines correspond almost exactly, broken only by small local edits. Most of that correspondence is NOT reported as duplicated blocks below \u2014 the edits cut it into fragments and only the largest of them clear the block floor, so the rows below understate it. The repair is at the members\u0027 grain \u2014 factor the shared implementation into one the two call with their differences as parameters or as an injected step, or, where the difference is systematic (an extra return value, one transport against another), generate one from the other. Left alone, the next edit has to be made twice and the two will drift further apart."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":2042}}}],"partialFingerprints":{"codehealthFindingId/v1":"8ca00b9e9decd2caaa14f830755711a3589ffa88a63e84e33db8d44e0c2b87b2"}},{"ruleId":"D4","level":"warning","message":{"text":"Members sharing a duplicated core (6 members, 50\u002B identical tokens): crates/nono-cli/src/command_policy.rs:1126-1142 | crates/nono-cli/src/command_policy.rs:3451-3458 | crates/nono-cli/src/command_policy.rs:3463-3470 | crates/nono-cli/src/command_policy.rs:3475-3482 | crates/nono-cli/src/profile/mod.rs:3719-3977 | crates/nono-cli/src/profile/mod.rs:3982-3989 \u2014 These 6 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below \u2014 it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 6 times. The repair is at the members\u0027 grain \u2014 factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 6 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_policy.rs"},"region":{"startLine":1126}}}],"partialFingerprints":{"codehealthFindingId/v1":"6481b8fa93ab1db064473c4b1536775438952ed3fe45b480e8a8bf4358f67030"}},{"ruleId":"D4","level":"warning","message":{"text":"Members sharing a duplicated core (4 members, 50\u002B identical tokens): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2817-2837 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:2844-2901 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5245-5265 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5272-5329 \u2014 These 4 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below \u2014 it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 4 times. The repair is at the members\u0027 grain \u2014 factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 4 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2817}}}],"partialFingerprints":{"codehealthFindingId/v1":"5d5ec83eb0846706d437dd97ea6b4d74c0ff872008da67a33389dd25335d24ba"}},{"ruleId":"D4","level":"warning","message":{"text":"Members sharing a duplicated core (4 members, 50\u002B identical tokens): crates/nono-cli/src/trust_keystore.rs:198-227 | crates/nono-cli/src/trust_keystore.rs:229-282 | crates/nono-cli/src/trust_keystore.rs:286-331 | crates/nono-cli/src/trust_keystore.rs:333-372 \u2014 These 4 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below \u2014 it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 4 times. The repair is at the members\u0027 grain \u2014 factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 4 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_keystore.rs"},"region":{"startLine":198}}}],"partialFingerprints":{"codehealthFindingId/v1":"30e746a03107cf7fdda1815a333727f927e76435b068ef78b9a39292625b5688"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (64\u201365 lines \u00D7 2): crates/nono-cli/src/query_ext.rs:263-327 | crates/nono-cli/src/query_ext.rs:374-437 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/query_ext.rs"},"region":{"startLine":263}}}],"partialFingerprints":{"codehealthFindingId/v1":"a406145ab2239662f6b32ff42f4ec9c9b6f22ee859c21fcf5688f19328dd0266"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (61 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1144-1204 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:835-895 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1144}}}],"partialFingerprints":{"codehealthFindingId/v1":"7a0b1aa9d8b9208eb5ed1a456842aa6f1085f5ed3a5d78055a35333425131e53"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (56 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2846-2901 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5274-5329 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2846}}}],"partialFingerprints":{"codehealthFindingId/v1":"9e9808b813c5b0eddf9dd23d84e5c8f3f1247658fe5e6fe98bc3ee8b9833e0cf"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (47 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4758-4804 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4204-4250 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4758}}}],"partialFingerprints":{"codehealthFindingId/v1":"7967ad77140befb7cf489bf05e532ed295ab45a3f258b9439b7e36caad538eb5"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (44 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:3997-4040 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:3595-3638 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3997}}}],"partialFingerprints":{"codehealthFindingId/v1":"569d2aae3858ba4bf05692385744f480e848ddf624e1b60730107da2a004a762"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (39\u201340 lines \u00D7 2): crates/nono-cli/src/exec_strategy.rs:3390-3429 | crates/nono-cli/src/exec_strategy.rs:3456-3494 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":3390}}}],"partialFingerprints":{"codehealthFindingId/v1":"e2646b57bd8a9f7bfc08586ef936fcf032473e0609ab44390fb2a3ec954d1dcb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (38\u201340 lines \u00D7 2): crates/nono-cli/src/audit_commands.rs:1092-1129 | crates/nono-cli/src/terminal_approval.rs:140-179 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":1092}}}],"partialFingerprints":{"codehealthFindingId/v1":"73e8a69179e0b9fc2bcb078c1f6c6f222ade5aae7b41cd5e9a03d5c11c7657a3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (38 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4256-4293 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:3819-3856 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4256}}}],"partialFingerprints":{"codehealthFindingId/v1":"f9a9a3f2a31aebfed5b1297e36a18aacbcf57f400ea95472c0d50dca35248c2d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (33\u201336 lines \u00D7 2): crates/nono-cli/src/audit_commands.rs:246-278 | crates/nono-cli/src/rollback_commands.rs:1000-1035 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/audit_commands.rs\u0060 and \u0060crates/nono-cli/src/rollback_commands.rs\u0060 as WHOLE FILES: this scan already matched 9 separate duplicated blocks between them, totalling at least 136 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":246}}}],"partialFingerprints":{"codehealthFindingId/v1":"ffa15d63f18533b65d2fa1ab02906d680b666e515d3f35fc33a7a08c1b54a0bd"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (30\u201334 lines \u00D7 2): crates/nono-cli/src/profile_save_runtime.rs:1080-1113 | crates/nono-cli/src/terminal_prompt.rs:61-90 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_save_runtime.rs"},"region":{"startLine":1080}}}],"partialFingerprints":{"codehealthFindingId/v1":"8f976305ea4dbbf7434166906027c078aac3352a7688d579590f85e4bf09f123"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (34 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:5412-5445 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4571-4604 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":5412}}}],"partialFingerprints":{"codehealthFindingId/v1":"63d405d19f1c3114be56661233f0ae2cc4e0227ed49e4707288d948e71461170"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (31\u201334 lines \u00D7 2): crates/nono-proxy/src/server.rs:1481-1514 | crates/nono-proxy/src/server.rs:1633-1663 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/server.rs"},"region":{"startLine":1481}}}],"partialFingerprints":{"codehealthFindingId/v1":"f7c1f4de805baa30f92b5c63c4c4451d1984765c92111ebf93d5c9e7d438e96e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (32 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1748-1779 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1462-1493 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1748}}}],"partialFingerprints":{"codehealthFindingId/v1":"eea49c8f51f8bc3b45b66d244058cf1584eb2384b91793f83ae6b68c7ff15b95"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (32 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:5448-5479 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4607-4638 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":5448}}}],"partialFingerprints":{"codehealthFindingId/v1":"5243136097debea174b964cc13203d77e9939bb0b66aa55f1da2f29bf7a1b002"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (30 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4677-4706 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4125-4154 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4677}}}],"partialFingerprints":{"codehealthFindingId/v1":"2b6451823d56be0354fa36af1a3ffac675b50c900ff3b6a1a9d57a5c08a2cfb0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (3\u201330 lines \u00D7 4): crates/nono-cli/src/profile_cmd.rs:1455-1484 | crates/nono-cli/src/profile_cmd.rs:1698-1718 | crates/nono-cli/src/profile_cmd.rs:1833-1835 | crates/nono-cli/src/profile_cmd.rs:1862-1864 \u2014 all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":1455}}}],"partialFingerprints":{"codehealthFindingId/v1":"b8b2c20f4b02a0aca46e1c9a7b660a5ae5adbffb2cc639d680e146aecdf98372"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (30 lines \u00D7 2): crates/nono-cli/src/audit_commands.rs:792-821 | crates/nono-cli/src/rollback_commands.rs:879-908 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/audit_commands.rs\u0060 and \u0060crates/nono-cli/src/rollback_commands.rs\u0060 as WHOLE FILES: this scan already matched 9 separate duplicated blocks between them, totalling at least 136 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":792}}}],"partialFingerprints":{"codehealthFindingId/v1":"9624ff1c53f9b3c162dcb4cfc1304b03c57a805f456bd5c851e8503c8880ba60"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (28\u201329 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1921-1948 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:1999-2027 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1921}}}],"partialFingerprints":{"codehealthFindingId/v1":"0ebaf4b5b9ebc23d0b162c6df2e939b254a038e24ba7c69818f81a3d2253d8c6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (29 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:5381-5409 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4540-4568 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":5381}}}],"partialFingerprints":{"codehealthFindingId/v1":"0775127e3c9acfcc5ca8c5704348089602b14ee82db180bb338c8b1d2a4cfe22"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (28\u201329 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/macos.rs:1648-1675 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1733-1761 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":1648}}}],"partialFingerprints":{"codehealthFindingId/v1":"ae44cd862ad9c3e4af51471980eac95a3d0c0945ba728b55a12c043a545b014e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (27\u201328 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:333-360 | crates/nono-proxy/src/reverse.rs:362-388 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":333}}}],"partialFingerprints":{"codehealthFindingId/v1":"70c5c5a64a68dd7541ac15a9165d4fb51447557a9482cc1cc5871097fa159ed4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (26 lines \u00D7 2): crates/nono-cli/src/capability_ext.rs:654-679 | crates/nono-cli/src/capability_ext.rs:1290-1315 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/capability_ext.rs"},"region":{"startLine":654}}}],"partialFingerprints":{"codehealthFindingId/v1":"b310a65f8b261eef0607a69bac709b115f1798ad701b319916e5b54f9aa0822f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (26 lines \u00D7 2): crates/nono-cli/src/sandbox_state.rs:253-278 | crates/nono-cli/src/session.rs:807-832 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/sandbox_state.rs"},"region":{"startLine":253}}}],"partialFingerprints":{"codehealthFindingId/v1":"be1d8e6bd7ca33bbedfd034ef9f57fa098c01084f2bd01d495c878ade3feeb01"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (26 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:711-736 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:607-632 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":711}}}],"partialFingerprints":{"codehealthFindingId/v1":"1717be585a7ae0bb130644bd0a46be0fe3999af3a4e67fa69fbc1b9b558f2ce8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (26 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4050-4075 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:3648-3673 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4050}}}],"partialFingerprints":{"codehealthFindingId/v1":"c9c26d89ce90c74c093f3b06985cf9a9b7fe076af58a20bacbe8f268217d0f8a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (26 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4200-4225 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:3765-3790 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4200}}}],"partialFingerprints":{"codehealthFindingId/v1":"507a0f34d012072dbdc748f1efcb06ccc26aa5500e6d54a58fd8a07abbb06c26"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (25 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4084-4108 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:3682-3706 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4084}}}],"partialFingerprints":{"codehealthFindingId/v1":"2b38acff0ef170c8d9598634cd5982406e6b648b8290e43491193f1d09d532b4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (25 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:5302-5326 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5369-5393 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":5302}}}],"partialFingerprints":{"codehealthFindingId/v1":"444631debd52290200b448d7d9f2d35efc1b25239804960f46d9798b5d095ec1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (24 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1434-1457 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1148-1171 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1434}}}],"partialFingerprints":{"codehealthFindingId/v1":"d77ee0888769e2015843c8891a2684b22b23a87f5f85c9f188cccf842ea1bda4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (21\u201324 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:5507-5530 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5453-5473 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":5507}}}],"partialFingerprints":{"codehealthFindingId/v1":"6649c556de4a17393130366508bbdb0e766bcbcfeda466c48b6cac515f28dfae"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (19\u201324 lines \u00D7 2): crates/nono-cli/src/wiring.rs:1156-1179 | crates/nono-cli/src/wiring.rs:1474-1492 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/wiring.rs"},"region":{"startLine":1156}}}],"partialFingerprints":{"codehealthFindingId/v1":"a35a7f959638f76beb5112c5f39c72b5d8d7598427cd428baf21159da6982815"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (24 lines \u00D7 2): crates/nono-proxy/src/tls_intercept/handle.rs:1425-1448 | crates/nono-proxy/src/tls_intercept/handle.rs:1450-1473 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":1425}}}],"partialFingerprints":{"codehealthFindingId/v1":"2f81839eed932e3b2b624854f2d0f582190ed0f94ba249b78e79f9fb26dde1db"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (22\u201323 lines \u00D7 2): bindings/c/src/capability_set.rs:68-90 | bindings/c/src/capability_set.rs:115-136 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"bindings/c/src/capability_set.rs"},"region":{"startLine":68}}}],"partialFingerprints":{"codehealthFindingId/v1":"d60446a1fe9c0732153b2a7b218837a29d0129fd731b95c33f707be165f49755"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (23 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2673-2695 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5095-5117 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2673}}}],"partialFingerprints":{"codehealthFindingId/v1":"9cdf021766b2b39293ec9c0ffea2cd0be4eef4f8852f0daea30adc03f2c66ec8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (23 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/macos.rs:1432-1454 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1536-1558 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":1432}}}],"partialFingerprints":{"codehealthFindingId/v1":"52c9875c7edb3f4401a60b7b90fb8c889bcd8dc6af6347865dc54378a09698d0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (22 lines \u00D7 2): crates/nono-cli/src/pty_proxy.rs:2163-2184 | crates/nono-cli/src/pty_proxy.rs:2191-2212 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/pty_proxy.rs"},"region":{"startLine":2163}}}],"partialFingerprints":{"codehealthFindingId/v1":"dec670c340c5df82ce3606f25f1e6f7973e827815f8b7c32bc4188650874a08f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (22 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1526-1547 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:1662-1683 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1526}}}],"partialFingerprints":{"codehealthFindingId/v1":"fa2a288e2072670113adc5fe7f49aa039014328a883c3144d50ee27c02c43612"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (22 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2644-2665 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5066-5087 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2644}}}],"partialFingerprints":{"codehealthFindingId/v1":"a84459bc125f31753f4d1d1c18129230d9130bda99ffef9870ab1d365d0a684e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (22 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/macos.rs:1240-1261 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1368-1389 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":1240}}}],"partialFingerprints":{"codehealthFindingId/v1":"f5aedaa94e70473037cea29f5a3ecd94486926d7e4ec8665781861f63ebdf009"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (22 lines \u00D7 2): crates/nono-cli/src/rollback_commands.rs:901-922 | crates/nono-cli/src/rollback_commands.rs:962-983 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/rollback_commands.rs"},"region":{"startLine":901}}}],"partialFingerprints":{"codehealthFindingId/v1":"65b7466a0cc69b3bea9b3e2455592e2b41616a3dbad0b9d340471fc754a8b9fc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (20\u201322 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:1135-1154 | crates/nono-proxy/src/reverse.rs:1164-1185 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":1135}}}],"partialFingerprints":{"codehealthFindingId/v1":"08bb3cb511a7ee83510f5ef6c6b72d35718f631acd0267697d160c86582ce1ae"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (20\u201321 lines \u00D7 4): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1714-1733 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:1813-1832 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:1886-1905 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:1974-1994 \u2014 all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1714}}}],"partialFingerprints":{"codehealthFindingId/v1":"44426eccba2c97768ee0001d08cebbfddb289316c69551c1f2f0a4c5330914e0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (21 lines \u00D7 2): crates/nono/src/undo/snapshot.rs:733-753 | crates/nono/src/undo/snapshot.rs:840-860 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/snapshot.rs"},"region":{"startLine":733}}}],"partialFingerprints":{"codehealthFindingId/v1":"4f28077f80cf938a68714f29d99e64d34a89229e7685ea5c8482c6e13901c6d2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (21 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1318-1338 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1032-1052 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1318}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c93d53f0abeeffa5fd5f6c2b16e7521fe000c0fe926a41b40acac9192013b3a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (18\u201321 lines \u00D7 2): crates/nono-cli/src/trust_cmd.rs:910-930 | crates/nono-cli/src/trust_cmd.rs:1036-1053 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_cmd.rs"},"region":{"startLine":910}}}],"partialFingerprints":{"codehealthFindingId/v1":"3a1d2a5389c5b69d2ca2b6d2cc4868ce01f187cbc79886d9b891062a92e15aa0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12\u201321 lines \u00D7 2): crates/nono-proxy/src/oauth2.rs:259-279 | crates/nono-proxy/src/oauth2.rs:596-607 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/oauth2.rs"},"region":{"startLine":259}}}],"partialFingerprints":{"codehealthFindingId/v1":"f8ac5bd51b17ec176338755b08fa94ee8b58232b436d80c5024f1130f2229e13"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (21 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:735-755 | crates/nono-proxy/src/reverse.rs:757-777 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":735}}}],"partialFingerprints":{"codehealthFindingId/v1":"24316f8cfba36e9e0591aae12c7795f6b637da3e2ef0304375aeafd9fbaf021c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (20 lines \u00D7 4): crates/nono-cli/src/tool-sandbox/platform/macos.rs:1421-1440 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1525-1544 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1606-1625 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1702-1721 \u2014 all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":1421}}}],"partialFingerprints":{"codehealthFindingId/v1":"f85c2251fa0e2ba784a738aa1045e87c6d583f65f8f1b77b522cfcc5b0710aa0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (20 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2736-2755 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5192-5211 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2736}}}],"partialFingerprints":{"codehealthFindingId/v1":"4ff66631a4eb3879724ac3285d44c7b216f863cb92244f2086dd426324567d90"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (20 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2818-2837 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5246-5265 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2818}}}],"partialFingerprints":{"codehealthFindingId/v1":"b1b15c3ddc3140e1de8cf7cd12b92575b9f2a6fa65baf352908be73b26f729e1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (20 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:5359-5378 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4518-4537 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":5359}}}],"partialFingerprints":{"codehealthFindingId/v1":"543698fd14ec93699d9ae9838cb2a116d5bb54a3cd07d16221749595c0bbe3fb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (20 lines \u00D7 2): crates/nono-cli/src/trust_cmd.rs:289-308 | crates/nono-cli/src/trust_cmd.rs:410-429 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_cmd.rs"},"region":{"startLine":289}}}],"partialFingerprints":{"codehealthFindingId/v1":"d82ebae4a6a2ea1402970c94090887bfd08e8b41411b3acf1f9ce611c813346c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (19\u201320 lines \u00D7 2): crates/nono-proxy/src/tls_intercept/handle.rs:1381-1400 | crates/nono-proxy/src/tls_intercept/handle.rs:1816-1834 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":1381}}}],"partialFingerprints":{"codehealthFindingId/v1":"302e4168e6158f645ae7b5b3aa7849e14912640475150b114d483b4a45c8e1f7"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17\u201319 lines \u00D7 2): crates/nono/src/undo/exclusion.rs:144-162 | crates/nono/src/undo/exclusion.rs:181-197 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/exclusion.rs"},"region":{"startLine":144}}}],"partialFingerprints":{"codehealthFindingId/v1":"57fa384a023ec100e15a672ffba2d6e27068eef058359eca8cf3d9dbc45327a7"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (19 lines \u00D7 2): crates/nono-cli/src/diagnostic/formatter.rs:2717-2735 | crates/nono-cli/src/exec_strategy.rs:4013-4031 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/diagnostic/formatter.rs"},"region":{"startLine":2717}}}],"partialFingerprints":{"codehealthFindingId/v1":"3dec5091da501867c4561c1f49460029af5090da640b71c7dcc37d5890dfdd65"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (18\u201319 lines \u00D7 2): crates/nono-cli/src/session.rs:329-347 | crates/nono-cli/src/session.rs:381-398 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/session.rs"},"region":{"startLine":329}}}],"partialFingerprints":{"codehealthFindingId/v1":"227e1d6308100a4f89c2119eaad11e17cfeb9378c732532128d453610aab133e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (19 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1452-1470 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:1476-1494 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1452}}}],"partialFingerprints":{"codehealthFindingId/v1":"fc5bcb88046d27e32b321334eb87fc72b6d9cec751af3b166e4c322cc524c53a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17\u201319 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1900-1916 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1620-1638 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1900}}}],"partialFingerprints":{"codehealthFindingId/v1":"9540e3f4fd9a8778186a5d8a92147bb10ee5e20e2672a94103c9add325c0faef"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (19 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1950-1968 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:2029-2047 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1950}}}],"partialFingerprints":{"codehealthFindingId/v1":"553774df37212129a453fbe25c1f3e71dd618850c7aa2eae8bc6529e132c98a2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (19 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2430-2448 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4848-4866 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2430}}}],"partialFingerprints":{"codehealthFindingId/v1":"42a8d7b9858d1c33195767bb54a6d5ea63514a769c4b29dad85d921a9f802127"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (19 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2618-2636 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5040-5058 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2618}}}],"partialFingerprints":{"codehealthFindingId/v1":"495bdb805dbdb939ffc4e560428219b91e7f513146c3d770d3cdf8b034119b8f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (19 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:5257-5275 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4416-4434 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":5257}}}],"partialFingerprints":{"codehealthFindingId/v1":"81973e07c1725bf6f9ae46ead1399c479a2a05d1b7f6a00799f69b7f354f4a97"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (19 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/macos.rs:1166-1184 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1190-1208 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":1166}}}],"partialFingerprints":{"codehealthFindingId/v1":"7a5cca865c802ba9d207c20a9343c6959ec9a2957b2c472abcc45be136f98bb8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (19 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/macos.rs:1677-1695 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1763-1781 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":1677}}}],"partialFingerprints":{"codehealthFindingId/v1":"9957728a098768eaf1e451a05c007a0139b8029e7d3b0da472fc711aae1b3448"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (19 lines \u00D7 2): crates/nono-proxy/src/connect.rs:157-175 | crates/nono-proxy/src/forward.rs:232-250 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/connect.rs"},"region":{"startLine":157}}}],"partialFingerprints":{"codehealthFindingId/v1":"52b7b53832d43043e033bc893d45029d12dfdd147c8fb265acb0510f3f70423b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (18\u201319 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:527-544 | crates/nono-proxy/src/reverse.rs:818-836 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":527}}}],"partialFingerprints":{"codehealthFindingId/v1":"8fa1eda11150ad959cbfef3d444994b85a798a0c44fecb058dca8a8fe73b2859"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (18 lines \u00D7 2): crates/nono/src/capability.rs:1237-1254 | crates/nono/src/capability.rs:1434-1451 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/capability.rs"},"region":{"startLine":1237}}}],"partialFingerprints":{"codehealthFindingId/v1":"95ff9ee397dcd9eb65b3e8e8d955fc0c1396bd789a9874a2256b2f31511648fa"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17\u201318 lines \u00D7 2): crates/nono/src/undo/snapshot.rs:785-802 | crates/nono/src/undo/snapshot.rs:871-887 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/snapshot.rs"},"region":{"startLine":785}}}],"partialFingerprints":{"codehealthFindingId/v1":"aedcb2eec222c1743efa817e781d34ceb56552d41d4e126387ca56c785271cc6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (18 lines \u00D7 2): crates/nono-cli/src/registry_client.rs:236-253 | crates/nono-cli/src/registry_client.rs:371-388 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/registry_client.rs"},"region":{"startLine":236}}}],"partialFingerprints":{"codehealthFindingId/v1":"87ef31662049aadad16baadeb8dbd831b6afb0bfa231c5cfb9510a304b4f2b84"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17\u201318 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:546-562 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:476-493 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":546}}}],"partialFingerprints":{"codehealthFindingId/v1":"bed63f2594febbd77358a0547b690c7870e9936be39524e3431e514c8e93e254"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (18 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1464-1481 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1178-1195 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1464}}}],"partialFingerprints":{"codehealthFindingId/v1":"696e2cb81eee282d649e8d1ad6598e367c151513ef9d8090075f3f0395e9c699"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (18 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1686-1703 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1393-1410 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1686}}}],"partialFingerprints":{"codehealthFindingId/v1":"e6cdb77a974bdd06a2e55941cad61e0cee57983cf0d1b5afe8430e3554410e59"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17\u201318 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:3586-3603 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:3068-3084 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3586}}}],"partialFingerprints":{"codehealthFindingId/v1":"048815097e5833546ba29ecdac136169ef287e660167350d166138fb7b4fe947"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17\u201318 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4484-4500 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:3920-3937 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4484}}}],"partialFingerprints":{"codehealthFindingId/v1":"70625d05fee1ce123eaad8d287433aaa1d0c44160389b51103cc5263779d7321"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (18 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4833-4850 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4279-4296 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4833}}}],"partialFingerprints":{"codehealthFindingId/v1":"9b4b42d95ce7f748fee391bab63f32a4be79f407c83f08337b6d870b874145fc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (18 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:232-249 | crates/nono-proxy/src/reverse.rs:455-472 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":232}}}],"partialFingerprints":{"codehealthFindingId/v1":"f6bb5c40d9fa7f6c0727afa8067dd0befc9cb0e8e2d6e4eb0a5f9fe3ca1b8847"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 3): crates/nono-cli/src/audit_commands.rs:810-826 | crates/nono-cli/src/rollback_commands.rs:897-913 | crates/nono-cli/src/rollback_commands.rs:958-974 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/audit_commands.rs\u0060 and \u0060crates/nono-cli/src/rollback_commands.rs\u0060 as WHOLE FILES: this scan already matched 9 separate duplicated blocks between them, totalling at least 136 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":810}}}],"partialFingerprints":{"codehealthFindingId/v1":"ddfadd1807e475209bd78d4130267d46f3bc2107fad326ecd0495e175658dec3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15\u201317 lines \u00D7 3): crates/nono-proxy/src/server.rs:1495-1509 | crates/nono-proxy/src/server.rs:1644-1658 | crates/nono-proxy/src/tls_intercept/handle.rs:320-336 \u2014 there are 3 copies across 2 file(s) \u2014 more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 3 sites; resolving a subset leaves the remainder to drift apart."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/server.rs"},"region":{"startLine":1495}}}],"partialFingerprints":{"codehealthFindingId/v1":"ffc0c256c026e1aac4d542ee97eec94f6cdc855f8c55d63b9500069d9292baaa"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 3): crates/nono-proxy/src/tls_intercept/handle.rs:1388-1404 | crates/nono-proxy/src/tls_intercept/handle.rs:1580-1596 | crates/nono-proxy/src/tls_intercept/handle.rs:1822-1838 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":1388}}}],"partialFingerprints":{"codehealthFindingId/v1":"8e4249d05e968667735ff0a059218eed20e08d046f116f865382d34dde4c1eb1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16\u201317 lines \u00D7 2): crates/nono/src/undo/snapshot.rs:756-771 | crates/nono/src/undo/snapshot.rs:805-821 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/snapshot.rs"},"region":{"startLine":756}}}],"partialFingerprints":{"codehealthFindingId/v1":"f24b64bd76a24b6909886587e315983a178ccf47f2d4a3c86bae7306cd5722d6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): crates/nono-cli/src/audit_session.rs:60-76 | crates/nono-cli/src/rollback_session.rs:55-71 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/audit_session.rs\u0060 and \u0060crates/nono-cli/src/rollback_session.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 58 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_session.rs"},"region":{"startLine":60}}}],"partialFingerprints":{"codehealthFindingId/v1":"b6990734b73dcb0c1c43cdef584250a3c1bab87f294434de5595070c47b61aed"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15\u201317 lines \u00D7 2): crates/nono-cli/src/exec_strategy.rs:422-438 | crates/nono-cli/src/exec_strategy.rs:629-643 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":422}}}],"partialFingerprints":{"codehealthFindingId/v1":"1559cca587a740f4f99875761d9ef06cc9857b2ec2f7a8d22f4220e66f4ce4d8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): crates/nono-cli/src/policy.rs:1590-1606 | crates/nono-cli/src/policy.rs:1642-1658 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/policy.rs"},"region":{"startLine":1590}}}],"partialFingerprints":{"codehealthFindingId/v1":"736813d5ce657ae8e68117e3cc178f2e30855d5ae5d6ea7b69e7032f5d57816e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1371-1387 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:1390-1406 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1371}}}],"partialFingerprints":{"codehealthFindingId/v1":"4cf486054617e91a6eeac6e571cfe5e1388665367112fd9840f795bdb895a8cb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16\u201317 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4168-4183 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:3731-3747 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4168}}}],"partialFingerprints":{"codehealthFindingId/v1":"77034d6b1d76ee5b2679622ee38a5c0a2b17631e60a11ce0c6d4eaba60181950"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4856-4872 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4302-4318 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4856}}}],"partialFingerprints":{"codehealthFindingId/v1":"3696ae14d104d253ad713fab1c8b2cf8486ad4707aeed98c3671aef349a2bd4c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/macos.rs:1085-1101 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1104-1120 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":1085}}}],"partialFingerprints":{"codehealthFindingId/v1":"6133ba62db003697e9dd8f17e5fc5c3f44889d867d1838caf0d5365ca1870181"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): crates/nono-cli/src/trust_cmd.rs:310-326 | crates/nono-cli/src/trust_cmd.rs:431-447 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_cmd.rs"},"region":{"startLine":310}}}],"partialFingerprints":{"codehealthFindingId/v1":"3da6453348278abb7fdfb9d8c12f38c04f2367088966869fccb8c7eb0bcb1d40"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16\u201317 lines \u00D7 2): crates/nono-proxy/src/connect.rs:183-199 | crates/nono-proxy/src/external.rs:314-329 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/connect.rs"},"region":{"startLine":183}}}],"partialFingerprints":{"codehealthFindingId/v1":"1fcb1e8418ad69bc4bf5c924dc911d6b6cba60bd62634f2868a23887af2be6cb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:1298-1314 | crates/nono-proxy/src/reverse.rs:1317-1333 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":1298}}}],"partialFingerprints":{"codehealthFindingId/v1":"6cdd4fe0ab57a81dee35e99777ab7e599f06cd6a900a040f3205c8a2a8c6a677"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15\u201317 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:2435-2449 | crates/nono-proxy/src/reverse.rs:2556-2572 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":2435}}}],"partialFingerprints":{"codehealthFindingId/v1":"6ba2460dcd010052948656d59f2334086cbb1c95b3fd2909f3490cea1bb88c9b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15\u201316 lines \u00D7 4): crates/nono-cli/src/tool-sandbox/platform/macos.rs:1505-1519 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1586-1600 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1683-1697 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1769-1784 \u2014 all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":1505}}}],"partialFingerprints":{"codehealthFindingId/v1":"d0ad4128d94b379f980fc090faaaf58d1b487e3d5e0d1438e02b1793eaa3dacc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 3): crates/nono-cli/src/registry_client.rs:178-193 | crates/nono-cli/src/registry_client.rs:234-249 | crates/nono-cli/src/registry_client.rs:369-384 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/registry_client.rs"},"region":{"startLine":178}}}],"partialFingerprints":{"codehealthFindingId/v1":"357ff548b25e4238fce0be82461d5212fca0ae6d72ad64c572a36e1404867794"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15\u201316 lines \u00D7 3): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1791-1805 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:1956-1970 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:2035-2050 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1791}}}],"partialFingerprints":{"codehealthFindingId/v1":"bcb0d1aac904e7b883ebfcc130995f84a188403cf2a544e522b678f29c50fa4a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): crates/nono-cli/src/exec_strategy.rs:2682-2697 | crates/nono-cli/src/exec_strategy.rs:3004-3019 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":2682}}}],"partialFingerprints":{"codehealthFindingId/v1":"552d261703f48b42eba64c056856f584f411a8d7af7e3e98bf56a27a2731031c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1578-1593 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1293-1308 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1578}}}],"partialFingerprints":{"codehealthFindingId/v1":"4a1941a61330a6d6bfa3679a1e5cb68b600fde887e18d16457fa591931e37034"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15\u201316 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2581-2596 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4988-5002 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2581}}}],"partialFingerprints":{"codehealthFindingId/v1":"d6006ca1fc0d9a448caca83258ae8125cde7cdc61661e544b3c02e1d709ab485"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2916-2931 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5344-5359 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2916}}}],"partialFingerprints":{"codehealthFindingId/v1":"0c6abacace604ad969f73169387287557b3a1558280008482cedf3f28a79f81c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:3367-3382 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:3385-3400 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3367}}}],"partialFingerprints":{"codehealthFindingId/v1":"0d8f5322e7f67d63cf9c94793ac8a3ba6cfd93d51ec4518c226f437097ce397d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:3764-3779 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:3160-3175 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3764}}}],"partialFingerprints":{"codehealthFindingId/v1":"8f8b156d315ec6afecb7467e8c7ce83704f20b38923812427735a8da93e98d14"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14\u201316 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4662-4675 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4108-4123 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4662}}}],"partialFingerprints":{"codehealthFindingId/v1":"18a6bb02fb20363e41601b5dbaddb8bb62adc5f5534bd1acd0bd4e033a5d4e1b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14\u201316 lines \u00D7 2): crates/nono-cli/src/wiring.rs:1190-1203 | crates/nono-cli/src/wiring.rs:1224-1239 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/wiring.rs"},"region":{"startLine":1190}}}],"partialFingerprints":{"codehealthFindingId/v1":"1af8be6ec6a49a2ee0130b1f2d11bd78f228498872ffc43c34a60967ba640a72"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): crates/nono-cli/src/profile_cmd.rs:809-824 | crates/nono-cli/src/profile_cmd.rs:833-848 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":809}}}],"partialFingerprints":{"codehealthFindingId/v1":"f07e88a3cb9fc4b8bce52a9935bc8e9acc6150549f5821d797dd39211d3383d6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): crates/nono-proxy/src/tls_intercept/handle.rs:645-660 | crates/nono-proxy/src/tls_intercept/handle.rs:663-678 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":645}}}],"partialFingerprints":{"codehealthFindingId/v1":"f2159616074fefb50126518c2dbbc5ef2fe9a6ed9b9be4958f002b08bd40de50"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15\u201316 lines \u00D7 2): crates/nono-proxy/src/tls_intercept/handle.rs:754-768 | crates/nono-proxy/src/tls_intercept/handle.rs:785-800 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":754}}}],"partialFingerprints":{"codehealthFindingId/v1":"f4e4d310aa13a2b9d2553b7a0ac3aee0d4890edf3b5628a46b8f9c9e90670fc1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): crates/nono/src/undo/snapshot.rs:229-243 | crates/nono/src/undo/snapshot.rs:335-349 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/snapshot.rs"},"region":{"startLine":229}}}],"partialFingerprints":{"codehealthFindingId/v1":"497b1e48d601747c79186bf348db96d7921f6f8d3c48b351d17850fd34b9742a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14\u201315 lines \u00D7 2): crates/nono-cli/src/diagnostic/formatter.rs:125-138 | crates/nono-cli/src/output.rs:1271-1285 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/diagnostic/formatter.rs"},"region":{"startLine":125}}}],"partialFingerprints":{"codehealthFindingId/v1":"2e399574bf807015f0d776d831c476906a74c3d8b34bb0b942105645c883ff20"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): crates/nono-cli/src/exec_strategy.rs:1095-1109 | crates/nono-cli/src/exec_strategy.rs:1301-1315 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":1095}}}],"partialFingerprints":{"codehealthFindingId/v1":"f2996eae8e855a9db6820968bd4dd2082599d7f5a15cd36bcd6f99dd8f11fa21"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14\u201315 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:306-319 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:309-323 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":306}}}],"partialFingerprints":{"codehealthFindingId/v1":"84caeb8a9ae581de6578f8ce7b6ab0aefd30346b0b6ca2a128974106c21b0850"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:394-408 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:354-368 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":394}}}],"partialFingerprints":{"codehealthFindingId/v1":"978ec831fa759970e07272b75ffd2e7cf8c71c328da166abe79ff45c5843e968"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:477-491 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:437-451 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":477}}}],"partialFingerprints":{"codehealthFindingId/v1":"792e9bf03b56038d39f9bcb16f9e614cc3fa4c61b9a4b06bcf05f3959e38eb56"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9\u201315 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1541-1549 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1255-1269 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1541}}}],"partialFingerprints":{"codehealthFindingId/v1":"33290c90c355e72e5486786e657d1911e22e66fc793a70b150f13f5831150a6e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14\u201315 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2263-2277 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4675-4688 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2263}}}],"partialFingerprints":{"codehealthFindingId/v1":"eae40378dbae72fb3e48d2f0ddd7410b79aa4122c679fbdc1b45caac3e1c600f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): crates/nono-cli/src/trust_intercept.rs:137-151 | crates/nono-cli/src/trust_intercept.rs:285-299 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_intercept.rs"},"region":{"startLine":137}}}],"partialFingerprints":{"codehealthFindingId/v1":"dc62b18e552c19a01222b6907973c76a40746b07ae847f249f4e7dae6591d865"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13\u201315 lines \u00D7 2): crates/nono-cli/src/rollback_commands.rs:416-428 | crates/nono-cli/src/rollback_commands.rs:473-487 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/rollback_commands.rs"},"region":{"startLine":416}}}],"partialFingerprints":{"codehealthFindingId/v1":"810df70085ad02376b089c8eb8560208bd586c5dfb54a9887c8d2a4f5226a075"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:511-525 | crates/nono-proxy/src/reverse.rs:803-817 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":511}}}],"partialFingerprints":{"codehealthFindingId/v1":"64ca103fff89eba97d7d0b1c817fc4eeb860887f8a8c2c53940a5d361946d2b2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14\u201315 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:572-585 | crates/nono-proxy/src/reverse.rs:1485-1499 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":572}}}],"partialFingerprints":{"codehealthFindingId/v1":"b5450be36ca261b865df52033ac7eb303cba3d1804559be27fbda1309ed1942f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13\u201314 lines \u00D7 2): crates/nono/src/capability.rs:163-176 | crates/nono/src/capability.rs:534-546 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/capability.rs"},"region":{"startLine":163}}}],"partialFingerprints":{"codehealthFindingId/v1":"9ab698688beb4d054b80d67e897a5caa9b9bafbc4d4e83c5e24f2d25e3464070"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): crates/nono/src/undo/snapshot.rs:903-916 | crates/nono/src/undo/snapshot.rs:1024-1037 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/snapshot.rs"},"region":{"startLine":903}}}],"partialFingerprints":{"codehealthFindingId/v1":"bc05cb5a26d16366045130a10891317e7c478f814cdb2626abb23bc0f2fdc960"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): crates/nono-cli/src/audit_session.rs:217-230 | crates/nono-cli/src/rollback_session.rs:196-209 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/audit_session.rs\u0060 and \u0060crates/nono-cli/src/rollback_session.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 58 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_session.rs"},"region":{"startLine":217}}}],"partialFingerprints":{"codehealthFindingId/v1":"7035e37ab9ba74a738fface52d0ed883131a28822d682e423ffe69dfaaf88c9b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): crates/nono-cli/src/audit_session.rs:248-261 | crates/nono-cli/src/rollback_session.rs:166-179 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/audit_session.rs\u0060 and \u0060crates/nono-cli/src/rollback_session.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 58 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_session.rs"},"region":{"startLine":248}}}],"partialFingerprints":{"codehealthFindingId/v1":"28048bf3db8ae2dc48359029d30836714d724df96dd7f875bb46e1daa1751f8f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): crates/nono-cli/src/exec_strategy.rs:2731-2744 | crates/nono-cli/src/exec_strategy.rs:3128-3141 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":2731}}}],"partialFingerprints":{"codehealthFindingId/v1":"54fb65add57a23d6cf63dbbd3220480b4da4b1d941dd28189b72f10dbab0dd5d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11\u201314 lines \u00D7 2): crates/nono-cli/src/exec_strategy.rs:3909-3919 | crates/nono-cli/src/exec_strategy.rs:3952-3965 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":3909}}}],"partialFingerprints":{"codehealthFindingId/v1":"8caaecd92423bb6b50e6297c71035e0501e51c67f83829decc73d492204c0b4c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): crates/nono-cli/src/exec_strategy.rs:3928-3941 | crates/nono-cli/src/exec_strategy.rs:3993-4006 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":3928}}}],"partialFingerprints":{"codehealthFindingId/v1":"a99171ecf108d305481fad760852ce4095e0e72d84f16e889dfa2561b886fb24"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:786-799 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:656-669 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":786}}}],"partialFingerprints":{"codehealthFindingId/v1":"b899ec5f269893ccf61ecb8ec743e5f73b5e2925c26eb5f39acecac3a3769765"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1096-1109 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4469-4482 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1096}}}],"partialFingerprints":{"codehealthFindingId/v1":"36583a70ac4536eaf5f2de09cc1b62246932ab7b7e86e985890d683e9255e8bd"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): crates/nono-cli/src/output.rs:109-122 | crates/nono-cli/src/output.rs:162-175 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/output.rs"},"region":{"startLine":109}}}],"partialFingerprints":{"codehealthFindingId/v1":"bb30344252e78ad8a84603dcf10b1d320de5046b5cdc50be3e8d06bc65ee941d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): crates/nono-cli/src/trust_cmd.rs:347-360 | crates/nono-cli/src/trust_cmd.rs:497-510 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_cmd.rs"},"region":{"startLine":347}}}],"partialFingerprints":{"codehealthFindingId/v1":"4593461df01383c5f692eed6a7955d74e020b71c35b6e1f096cd4ac527e58f77"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11\u201314 lines \u00D7 2): crates/nono-proxy/src/oauth2.rs:216-229 | crates/nono-proxy/src/oauth2.rs:564-574 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/oauth2.rs"},"region":{"startLine":216}}}],"partialFingerprints":{"codehealthFindingId/v1":"eeb294c36b7db138ba002eff146f3e3c8b49580fd586492442fba9cdd4c8ccf2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12\u201314 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:487-498 | crates/nono-proxy/src/reverse.rs:2810-2823 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":487}}}],"partialFingerprints":{"codehealthFindingId/v1":"e300a003a726696d466e36bace73f46598143e5dc5cad808d8a9fecd30340b69"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:1219-1232 | crates/nono-proxy/src/tls_intercept/handle.rs:561-574 \u2014 before extracting anything, compare \u0060crates/nono-proxy/src/reverse.rs\u0060 and \u0060crates/nono-proxy/src/tls_intercept/handle.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 44 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":1219}}}],"partialFingerprints":{"codehealthFindingId/v1":"657f73c1dc10d00b5264a0d72b6612299fa704bde22cd536236ace511c4431fc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:1431-1444 | crates/nono-proxy/src/reverse.rs:1521-1534 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":1431}}}],"partialFingerprints":{"codehealthFindingId/v1":"d6c610ec9e8f785e1a38c4c13b3b7b3fad9adcc53e2e8f7477b17402c0d138cf"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): crates/nono-proxy/src/tls_intercept/handle.rs:1280-1293 | crates/nono-proxy/src/tls_intercept/handle.rs:1777-1790 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":1280}}}],"partialFingerprints":{"codehealthFindingId/v1":"d863261b6c8b08ca194fa8efe012eeb80f13121cb3bddfbeb2a19b525c27897d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 3): crates/nono-cli/src/trust_keystore.rs:199-211 | crates/nono-cli/src/trust_keystore.rs:230-242 | crates/nono-cli/src/trust_keystore.rs:287-299 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_keystore.rs"},"region":{"startLine":199}}}],"partialFingerprints":{"codehealthFindingId/v1":"daae3fcffbc3be69611e35ec13c0007853a236a53ec8256bd4e8e4db2061eb3a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): bindings/c/src/capability_set.rs:314-326 | bindings/c/src/capability_set.rs:343-355 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"bindings/c/src/capability_set.rs"},"region":{"startLine":314}}}],"partialFingerprints":{"codehealthFindingId/v1":"67314fe08c07613728c856a97a6572090d6e7aaaf269266d320f9e7286a0ff84"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/nono/src/undo/object_store.rs:185-197 | crates/nono/src/undo/object_store.rs:247-259 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/object_store.rs"},"region":{"startLine":185}}}],"partialFingerprints":{"codehealthFindingId/v1":"68de41148a6b61fa7e580f7de0fb8c3f4f19245aed8a4ab69e47166b95aa1e3b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/nono-cli/src/audit_session.rs:233-245 | crates/nono-cli/src/rollback_session.rs:147-159 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/audit_session.rs\u0060 and \u0060crates/nono-cli/src/rollback_session.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 58 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_session.rs"},"region":{"startLine":233}}}],"partialFingerprints":{"codehealthFindingId/v1":"85949166c653c919f5318ef827b1a38f42200b6d8755a6b15b2f5c1544716f5b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/nono-cli/src/exec_strategy.rs:1158-1170 | crates/nono-cli/src/exec_strategy.rs:1176-1188 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":1158}}}],"partialFingerprints":{"codehealthFindingId/v1":"51d9707df170cafb86c833e97247a1bc00b5e89bccab327730db0d7f3afa215c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/nono-cli/src/exec_strategy.rs:2918-2930 | crates/nono-cli/src/exec_strategy.rs:2945-2957 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":2918}}}],"partialFingerprints":{"codehealthFindingId/v1":"fce83c949d119d303f78c9f670d16f44a664ac7a67b43e14860f8490d507b514"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/nono-cli/src/network_policy.rs:359-371 | crates/nono-cli/src/network_policy.rs:382-394 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/network_policy.rs"},"region":{"startLine":359}}}],"partialFingerprints":{"codehealthFindingId/v1":"16ac76e795f4c6d674b220bf9f8ab1b79465bd12705f869ac3fd30407f5bf302"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:457-469 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:414-426 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":457}}}],"partialFingerprints":{"codehealthFindingId/v1":"035b50f608538bd8caf7cfbde2960c0d6ea494dc26da1eab8532176d1a79e4fa"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1384-1396 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1098-1110 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1384}}}],"partialFingerprints":{"codehealthFindingId/v1":"ac7c8cae9cd77ad8fabe1a6546ba749ca9ca51c14e78156448ced17dc3fb29ee"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1501-1513 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1215-1227 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1501}}}],"partialFingerprints":{"codehealthFindingId/v1":"b97cabe6f7b076c711c3bc28ed98d4a788231a1956ff9e86e895223392a7a788"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1969-1981 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1696-1709 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1969}}}],"partialFingerprints":{"codehealthFindingId/v1":"3c3b61a86001579fa34cd1038f46c6034aa9ee73b2a2a3aa1b685f4fd0167ade"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2520-2532 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4938-4950 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2520}}}],"partialFingerprints":{"codehealthFindingId/v1":"69ca35635fc24f0959083d3b3274d9d63594f76f7b2d3c271b54488dce1a87af"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:3798-3810 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:3249-3261 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3798}}}],"partialFingerprints":{"codehealthFindingId/v1":"dfe2c544686547d5e95cdfd6fa5ea62cbdfa152a58347f6e776b99e1a2d10d35"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11\u201313 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4737-4749 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4185-4195 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4737}}}],"partialFingerprints":{"codehealthFindingId/v1":"903a419235d85d2a5c87869fa08afd91fb6bcc1921ff5ce300220ead18f4e2ff"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:5744-5756 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:5771-5783 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":5744}}}],"partialFingerprints":{"codehealthFindingId/v1":"bc6c0372ddf57ae53327f7873f61209f1001ae865c00142633769f43974a215b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/nono-cli/src/trust_cmd.rs:938-950 | crates/nono-cli/src/trust_intercept.rs:365-377 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_cmd.rs"},"region":{"startLine":938}}}],"partialFingerprints":{"codehealthFindingId/v1":"eaf07ce63292e115a6a3e9042afddc8a0c486ddf774ced45ee4d9ff441c4f11b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11\u201313 lines \u00D7 2): crates/nono-cli/src/why_runtime.rs:205-217 | crates/nono-cli/src/why_runtime.rs:241-251 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/why_runtime.rs"},"region":{"startLine":205}}}],"partialFingerprints":{"codehealthFindingId/v1":"04566341920d0433336083aa4093c61364c80a780eda87486603cc00b900156f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/nono-cli/src/wiring.rs:935-947 | crates/nono-cli/src/wiring.rs:1442-1454 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/wiring.rs"},"region":{"startLine":935}}}],"partialFingerprints":{"codehealthFindingId/v1":"d83d0d4bea7e5884b2e7b1a330c08197b45a3ca51f2c4cf136c28470fd2ef771"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/nono-cli/src/command_runtime.rs:212-224 | crates/nono-cli/src/command_runtime.rs:352-364 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_runtime.rs"},"region":{"startLine":212}}}],"partialFingerprints":{"codehealthFindingId/v1":"de12deea2842f8d7d88ca09b1a76bd60a0733c5fad9deca40ad39a1004dd965e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/nono-proxy/src/server.rs:1915-1927 | crates/nono-proxy/src/server.rs:2051-2063 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/server.rs"},"region":{"startLine":1915}}}],"partialFingerprints":{"codehealthFindingId/v1":"b7e28bef75dd26fd29bfe76b70d2ff890364d77830e10b6265e556c1c7d5f0d3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 3): crates/nono-cli/src/tool-sandbox/launch.rs:80-91 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:2951-2962 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5494-5505 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/launch.rs"},"region":{"startLine":80}}}],"partialFingerprints":{"codehealthFindingId/v1":"351d7ad78fe5f18f6e176f8929d23ea873b343eae38b9b8d863355995da96e0d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8\u201312 lines \u00D7 3): crates/nono-proxy/src/reverse.rs:2439-2448 | crates/nono-proxy/src/reverse.rs:2560-2571 | crates/nono-proxy/src/reverse.rs:2704-2711 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":2439}}}],"partialFingerprints":{"codehealthFindingId/v1":"6bdcc67102d56d0d7de3a36bff95a7f77912625b64918f787d9b6458e077f4e0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/nono/src/undo/snapshot.rs:217-228 | crates/nono/src/undo/snapshot.rs:289-300 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/snapshot.rs"},"region":{"startLine":217}}}],"partialFingerprints":{"codehealthFindingId/v1":"198d6136aee9f656ef63f22979fc4c13e0b580b898c00eed0206ec3ce5733c32"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/nono/src/trust/signing.rs:102-113 | crates/nono/src/trust/signing.rs:190-201 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/trust/signing.rs"},"region":{"startLine":102}}}],"partialFingerprints":{"codehealthFindingId/v1":"b50011257d6503f62360110c59288670e685e668bb4ebad9c986f0631fa38d45"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/nono-cli/src/exec_strategy.rs:2747-2758 | crates/nono-cli/src/exec_strategy.rs:3150-3161 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":2747}}}],"partialFingerprints":{"codehealthFindingId/v1":"a8866335a8edd127360331772ee7529e58b1a6c83fbb4c7ad804c803b33f89c2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1366-1377 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1080-1091 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1366}}}],"partialFingerprints":{"codehealthFindingId/v1":"a1fbd1e4b9bbbcd99f36496a00ba489c0709fcf10b607b5e4de19b89a3bda22d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1488-1499 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1202-1213 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1488}}}],"partialFingerprints":{"codehealthFindingId/v1":"ab481b1b38211b715474a62cb74cf185abfc9cb7b1a56712ece6249381aa1e62"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1627-1638 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1335-1346 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1627}}}],"partialFingerprints":{"codehealthFindingId/v1":"cddac46c905d646d4442112f3696fa0089cac65b16db0f37cd1d26e336ab2c83"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11\u201312 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1646-1657 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1353-1363 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1646}}}],"partialFingerprints":{"codehealthFindingId/v1":"f404be76e6e230ad2377773b8ee0f765f25d126b78e857da9674437f001c888d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2416-2427 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4834-4845 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2416}}}],"partialFingerprints":{"codehealthFindingId/v1":"f7ed836a7b948ae7652b5341de6dab9fbe0b3b830dc1fbba309f9d9769b18102"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11\u201312 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4900-4911 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4344-4354 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4900}}}],"partialFingerprints":{"codehealthFindingId/v1":"c161ccb46aaba44613eb1a42cc3cf975de4121bb7a4564d8c834208a9a1a40c7"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4932-4943 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4372-4383 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4932}}}],"partialFingerprints":{"codehealthFindingId/v1":"ececc4153a30fbf2875ec38ea1c8832ea2ec5229afef239464d7a34c0fdbac4d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/macos.rs:2588-2599 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:2661-2672 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":2588}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7df2e9554517484bf5b4a34b2b1e7f40aeba3347a0422001a91bf6cffb4a3dc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/nono-cli/src/trust_scan.rs:965-976 | crates/nono-cli/src/trust_scan.rs:996-1007 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_scan.rs"},"region":{"startLine":965}}}],"partialFingerprints":{"codehealthFindingId/v1":"050d5fdb868f695500991fd9aafeebf38e0c433ca8d41d3d70b896c678ca8cf9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11\u201312 lines \u00D7 2): crates/nono-cli/src/profile_cmd.rs:1521-1532 | crates/nono-cli/src/profile_cmd.rs:1653-1663 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":1521}}}],"partialFingerprints":{"codehealthFindingId/v1":"1ce5b206272ffca11f5a82d8893731c3f4c633a6e8256ae332a06b199f7f519e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/nono-cli/src/profile_cmd.rs:1588-1599 | crates/nono-cli/src/profile_cmd.rs:2057-2068 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":1588}}}],"partialFingerprints":{"codehealthFindingId/v1":"bc094b42a9e15226d261113c0c8c92e625df2f8c89d820d63edf22ee8cfdf65e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:1790-1801 | crates/nono-proxy/src/reverse.rs:2304-2315 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":1790}}}],"partialFingerprints":{"codehealthFindingId/v1":"ddd640e7c7cfb0b5184f94407e71c7c934b9e01368ab3aab709e7aed7821daf8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/nono-proxy/src/tls_intercept/handle.rs:1949-1960 | crates/nono-proxy/src/tls_intercept/handle.rs:2056-2067 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":1949}}}],"partialFingerprints":{"codehealthFindingId/v1":"27dfb1dc0bae048a49da71078e74a1bb2e160d3b0fa59f87171571b993d46a25"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 4): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2820-2830 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:2858-2868 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5248-5258 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5286-5296 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2820}}}],"partialFingerprints":{"codehealthFindingId/v1":"f0ba80c4663f049de453920a2db80db6e2d87364a606142488b8a9e9fc981628"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 4): crates/nono-proxy/src/tls_intercept/handle.rs:1949-1959 | crates/nono-proxy/src/tls_intercept/handle.rs:2009-2019 | crates/nono-proxy/src/tls_intercept/handle.rs:2030-2042 | crates/nono-proxy/src/tls_intercept/handle.rs:2056-2066 \u2014 all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":1949}}}],"partialFingerprints":{"codehealthFindingId/v1":"886e1df5e585a3c6511ed5e00e4bf68d1639baed3ab5cc3c296c1ad63e0ff130"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 3): crates/nono-proxy/src/tls_intercept/handle.rs:1287-1297 | crates/nono-proxy/src/tls_intercept/handle.rs:1784-1794 | crates/nono-proxy/src/tls_intercept/handle.rs:1928-1938 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":1287}}}],"partialFingerprints":{"codehealthFindingId/v1":"8fbe874e01b571b21dbfcf55ca4c6602290fb68d436f2d85edf6c815cd2b3745"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono/src/audit.rs:916-926 | crates/nono/src/audit.rs:994-1004 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/audit.rs"},"region":{"startLine":916}}}],"partialFingerprints":{"codehealthFindingId/v1":"5921366a4b934b266ab397d2b42767dec71faee7663db2c5800b8841dd010869"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono/src/capability.rs:158-168 | crates/nono/src/capability.rs:196-206 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/capability.rs"},"region":{"startLine":158}}}],"partialFingerprints":{"codehealthFindingId/v1":"705a2d36e3a0bec74b4df645f8c47d11b65e086588e1251842d3ca86eec0f94a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono/src/keystore.rs:1136-1146 | crates/nono/src/keystore.rs:1609-1619 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/keystore.rs"},"region":{"startLine":1136}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee303a6a9841af08710c1f22cda8a72e0b113ead2ad65b5a5c95815f453ff99a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10\u201311 lines \u00D7 2): crates/nono-cli/src/command_policy.rs:309-319 | crates/nono-cli/src/command_policy.rs:664-673 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_policy.rs"},"region":{"startLine":309}}}],"partialFingerprints":{"codehealthFindingId/v1":"0e3d77c080e22d01fdea60f17395440d75f0fa15513110e14bd17bd8231e0005"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10\u201311 lines \u00D7 2): crates/nono-cli/src/package_cmd.rs:429-439 | crates/nono-cli/src/package_cmd.rs:458-467 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/package_cmd.rs"},"region":{"startLine":429}}}],"partialFingerprints":{"codehealthFindingId/v1":"cf3d98c7741cdb3ddd3af9c42d47572e03801296b87076c8ae7855f67fddbb61"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9\u201311 lines \u00D7 2): crates/nono-cli/src/profile/mod.rs:3251-3259 | crates/nono-cli/src/profile/mod.rs:3385-3395 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":3251}}}],"partialFingerprints":{"codehealthFindingId/v1":"9580d729786ad52f83455d45d27ece0fa0c965425f646244f15ec45b1b4c8640"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono-cli/src/proxy_command.rs:333-343 | crates/nono-cli/src/proxy_runtime.rs:1563-1573 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_command.rs"},"region":{"startLine":333}}}],"partialFingerprints":{"codehealthFindingId/v1":"f0e21d5e88a267027f736a187d8744baf6e9ba0aa37eb5b0a35062d2af44b4ef"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono-cli/src/sandbox_log.rs:312-322 | crates/nono-cli/src/sandbox_log.rs:328-340 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/sandbox_log.rs"},"region":{"startLine":312}}}],"partialFingerprints":{"codehealthFindingId/v1":"a9199532cb5c6fd06aa05d82f98bb083dc78f63a40567f1bb2a00a98307fba6e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1709-1719 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1416-1426 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1709}}}],"partialFingerprints":{"codehealthFindingId/v1":"72fcc49d39f4b915d5adbf5977f3197c718bf57f2eb06d1cbf6eef429a3107ee"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10\u201311 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1918-1927 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1644-1654 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1918}}}],"partialFingerprints":{"codehealthFindingId/v1":"2fdb988eca60286de0f01154410a0995f875f2554a860d0786c1cba520040fcf"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10\u201311 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1997-2006 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1730-1740 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1997}}}],"partialFingerprints":{"codehealthFindingId/v1":"9ac17e0faf97633872fc0394e0632dc8d63f00f6e494bb72d4197052511b33fa"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2496-2506 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4914-4924 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2496}}}],"partialFingerprints":{"codehealthFindingId/v1":"38eb06e187f3fc6e603bd1a92fd97a790704a17cc66d84af9c489dbdc18e43df"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:3433-3443 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:3466-3476 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3433}}}],"partialFingerprints":{"codehealthFindingId/v1":"7255e3160605e0ed0726ada08210868de1c338e4f16e0db321f71bc6748d4131"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:5348-5358 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4507-4517 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":5348}}}],"partialFingerprints":{"codehealthFindingId/v1":"277ffcee4ddee51d4ff922cfdb925e84291f77e76041b41f1eedce36f85685c4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono-cli/src/trust_keystore.rs:235-245 | crates/nono-cli/src/trust_keystore.rs:339-349 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_keystore.rs"},"region":{"startLine":235}}}],"partialFingerprints":{"codehealthFindingId/v1":"29b60e3e794d389d9f45d4afe349d2be5554a3f855d325057b040612cd385f4e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono-cli/src/audit_commands.rs:838-848 | crates/nono-cli/src/rollback_commands.rs:569-579 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/audit_commands.rs\u0060 and \u0060crates/nono-cli/src/rollback_commands.rs\u0060 as WHOLE FILES: this scan already matched 9 separate duplicated blocks between them, totalling at least 136 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":838}}}],"partialFingerprints":{"codehealthFindingId/v1":"371dd563247efc3bfa95cfec0a4f550a54492cad157d0d4cdbc1171fadd29b11"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono-cli/src/audit_commands.rs:861-871 | crates/nono-cli/src/rollback_commands.rs:591-601 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/audit_commands.rs\u0060 and \u0060crates/nono-cli/src/rollback_commands.rs\u0060 as WHOLE FILES: this scan already matched 9 separate duplicated blocks between them, totalling at least 136 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":861}}}],"partialFingerprints":{"codehealthFindingId/v1":"75a667cfe85f4e821e1f59708f7add5437c9ea283f0b01bae9fc6b2722a979ee"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono-proxy/src/audit.rs:170-180 | crates/nono-proxy/src/audit.rs:289-299 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/audit.rs"},"region":{"startLine":170}}}],"partialFingerprints":{"codehealthFindingId/v1":"09a839bea3509f841397162aba8ebb48f87d4ca83c9408c53cbd55a75a1ab9f4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10\u201311 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:2013-2022 | crates/nono-proxy/src/reverse.rs:2042-2052 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":2013}}}],"partialFingerprints":{"codehealthFindingId/v1":"6d86ca9b132cd389f42b915e0c711350c1fad2ff1ef069aee360cce868a91dbf"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono-proxy/src/server.rs:1938-1948 | crates/nono-proxy/src/server.rs:2074-2084 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/server.rs"},"region":{"startLine":1938}}}],"partialFingerprints":{"codehealthFindingId/v1":"7c08ba1912c4669a2fc2fb56cbef280d8176176dd45e257f9fc84c19dc4fce73"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 4): crates/nono-cli/src/trust_keystore.rs:204-213 | crates/nono-cli/src/trust_keystore.rs:235-244 | crates/nono-cli/src/trust_keystore.rs:292-301 | crates/nono-cli/src/trust_keystore.rs:339-348 \u2014 all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_keystore.rs"},"region":{"startLine":204}}}],"partialFingerprints":{"codehealthFindingId/v1":"9aa17fede19f1d80e8ce6588cc5e40ef9fce405dd008317a6e75d5f8f87ac962"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 3): crates/nono/src/capability.rs:162-171 | crates/nono/src/capability.rs:200-209 | crates/nono/src/capability.rs:533-542 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/capability.rs"},"region":{"startLine":162}}}],"partialFingerprints":{"codehealthFindingId/v1":"252ea8fecfc9fb3863ca4dd125ddbfff8d140955a5550c0fb126c987d0911ade"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 3): crates/nono/src/undo/snapshot.rs:416-425 | crates/nono/src/undo/snapshot.rs:782-791 | crates/nono/src/undo/snapshot.rs:868-877 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/snapshot.rs"},"region":{"startLine":416}}}],"partialFingerprints":{"codehealthFindingId/v1":"716c1fa84ea7aaabe8043352a6588ead59dabcda87c13ef439a090738a19982d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 3): crates/nono-cli/src/command_policy.rs:2584-2593 | crates/nono-cli/src/command_policy.rs:2618-2627 | crates/nono-cli/src/command_policy.rs:2684-2693 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_policy.rs"},"region":{"startLine":2584}}}],"partialFingerprints":{"codehealthFindingId/v1":"fc45e9546e7cecd7ada29e2a7d961ca654a9ae7da41ec2dc6d5dbc2bcc7f300d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 3): crates/nono-cli/src/tool-sandbox/dynamic_providers.rs:255-264 | crates/nono-cli/src/tool-sandbox/dynamic_providers.rs:306-315 | crates/nono-cli/src/tool-sandbox/dynamic_providers.rs:351-360 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/dynamic_providers.rs"},"region":{"startLine":255}}}],"partialFingerprints":{"codehealthFindingId/v1":"4631b2aea5209bee7c6bced5bbe8132b77680e8b2e2194d7e52ad3d919948b73"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono/src/capability.rs:712-721 | crates/nono/src/capability.rs:765-774 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/capability.rs"},"region":{"startLine":712}}}],"partialFingerprints":{"codehealthFindingId/v1":"a1e1b572256667aff7bf23301347b8c2aed2d5f4f6439cfc14dfc09692e7bd3b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6\u201310 lines \u00D7 2): crates/nono/src/keystore.rs:1067-1076 | crates/nono/src/keystore.rs:1096-1101 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/keystore.rs"},"region":{"startLine":1067}}}],"partialFingerprints":{"codehealthFindingId/v1":"d9944f56282c393735811da65441bf7fe8b8799d540e34e7322dca9553c86e44"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-cli/src/capability_ext.rs:922-931 | crates/nono-cli/src/capability_ext.rs:976-985 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/capability_ext.rs"},"region":{"startLine":922}}}],"partialFingerprints":{"codehealthFindingId/v1":"689eebfe52d665c1da02dca3d18b7c15790f8678c93c71143e990e33c7bcbe1a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-cli/src/capability_ext.rs:949-958 | crates/nono-cli/src/capability_ext.rs:1003-1012 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/capability_ext.rs"},"region":{"startLine":949}}}],"partialFingerprints":{"codehealthFindingId/v1":"97f2aed7d6eedb8dadaac25852a7099bd7f5c1f7e25df0ecc7d75249472ebd87"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-cli/src/exec_strategy.rs:729-738 | crates/nono-cli/src/exec_strategy.rs:755-764 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":729}}}],"partialFingerprints":{"codehealthFindingId/v1":"69dd75dd357731dc806390186d318a8b02d8fad1205c77d9149fa507ea8be5ad"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-cli/src/exec_strategy.rs:2761-2770 | crates/nono-cli/src/exec_strategy.rs:3164-3173 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":2761}}}],"partialFingerprints":{"codehealthFindingId/v1":"857d00de06981aca35256be6bdd0a2816834af36df0c30a5a0e01c612b4105b0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-cli/src/profile/mod.rs:103-112 | crates/nono-cli/src/profile/mod.rs:1930-1939 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":103}}}],"partialFingerprints":{"codehealthFindingId/v1":"4a1524387f769256baf655a9b71b57b82c279bcd6530d42bc35f3398a25d6422"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9\u201310 lines \u00D7 2): crates/nono-cli/src/query_ext.rs:360-369 | crates/nono-cli/src/query_ext.rs:458-466 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/query_ext.rs"},"region":{"startLine":360}}}],"partialFingerprints":{"codehealthFindingId/v1":"9bfffa8f875c85850e84bb080992b27df5d8b61b1d630a45fac85647f7976a0a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:418-427 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:379-388 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":418}}}],"partialFingerprints":{"codehealthFindingId/v1":"b964bf6c041ac7f501b64b4914d0eee1e9ce984a96cb805cbd5b9e741cca1047"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:952-961 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:765-774 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":952}}}],"partialFingerprints":{"codehealthFindingId/v1":"db4757fd0b633a77ed450a497b42e1f53a53ba22a34096e8931bee686fdd5494"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8\u201310 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1011-1020 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:791-798 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1011}}}],"partialFingerprints":{"codehealthFindingId/v1":"9f43e12ed694cc8517d15a405405a516265fb23744d2220cacb0791898c14a13"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9\u201310 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1556-1565 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1275-1283 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1556}}}],"partialFingerprints":{"codehealthFindingId/v1":"28339461f5ec03836f2c258738cdc5df83aa6f0c2ac6018b143943638ead08d4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2484-2493 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4902-4911 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2484}}}],"partialFingerprints":{"codehealthFindingId/v1":"82375c26215007acc87387177854e968c21559c8429ffcc61a545ac46a3618dd"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2904-2913 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5332-5341 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2904}}}],"partialFingerprints":{"codehealthFindingId/v1":"192818e2d55c090ad56addadf66391df32f78252fd092a586afa71fd4d6f4f6f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:3550-3559 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:3039-3048 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3550}}}],"partialFingerprints":{"codehealthFindingId/v1":"8a1a5c4536143b7a46e44ace7f2336990c26ad9ddf1346695b9ca3ae22e30601"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4640-4649 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4083-4092 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4640}}}],"partialFingerprints":{"codehealthFindingId/v1":"8be342b0bd75ca03f38beaf729fbe44da4d0732543aef57344ad7f845a5ac56c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-cli/src/trust_cmd.rs:999-1008 | crates/nono-cli/src/trust_intercept.rs:327-336 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_cmd.rs"},"region":{"startLine":999}}}],"partialFingerprints":{"codehealthFindingId/v1":"373d8331524a9e4dfe35446beeac131498863aad38cdbf0e9d20fff425aed51f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-cli/src/trust_scan.rs:466-475 | crates/nono-cli/src/trust_scan.rs:497-506 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_scan.rs"},"region":{"startLine":466}}}],"partialFingerprints":{"codehealthFindingId/v1":"ccb3f4f428e5f9dc96b5dc0c7fb874a2db6a618eaa63993f0e05a2d2a8fbbf8d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-proxy/src/connect.rs:89-98 | crates/nono-proxy/src/external.rs:213-222 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/connect.rs"},"region":{"startLine":89}}}],"partialFingerprints":{"codehealthFindingId/v1":"be7b30a5bbc2ae278d92b965f5226ad5cdb4e98ab2ed902ea3f455610397886e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8\u201310 lines \u00D7 2): crates/nono-proxy/src/credential.rs:90-97 | crates/nono-proxy/src/credential.rs:325-334 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/credential.rs"},"region":{"startLine":90}}}],"partialFingerprints":{"codehealthFindingId/v1":"213d561b9d3b4f3e83a7ea3f51a79fe79d49dd3584e4aa797c647be0528904a6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-proxy/src/credential.rs:266-275 | crates/nono-proxy/src/credential.rs:361-370 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/credential.rs"},"region":{"startLine":266}}}],"partialFingerprints":{"codehealthFindingId/v1":"4282103c77be8b18ef35cb0f1244963d1ca90318200e35c8137ff8f27a0f213c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:790-799 | crates/nono-proxy/src/tls_intercept/handle.rs:1476-1485 \u2014 before extracting anything, compare \u0060crates/nono-proxy/src/reverse.rs\u0060 and \u0060crates/nono-proxy/src/tls_intercept/handle.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 44 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":790}}}],"partialFingerprints":{"codehealthFindingId/v1":"90687423f7088e687df61b5148bc2b3c9c5335737311edf59fb6ec53478c6bd6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:845-854 | crates/nono-proxy/src/reverse.rs:1482-1491 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":845}}}],"partialFingerprints":{"codehealthFindingId/v1":"11a79515679f4fcdc5675d1ddcde6de5aa45c2a58a3ce9e66042db1d32d23af0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9\u201310 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:2003-2011 | crates/nono-proxy/src/reverse.rs:2031-2040 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":2003}}}],"partialFingerprints":{"codehealthFindingId/v1":"087e31faab31661c9b9ad6dbaefd6006d89d7ac47ae268d9ecb53d8c717a4d88"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-proxy/src/tls_intercept/h2_forward.rs:626-635 | crates/nono-proxy/src/tls_intercept/h2_forward.rs:663-672 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/h2_forward.rs"},"region":{"startLine":626}}}],"partialFingerprints":{"codehealthFindingId/v1":"ae7af58b2f6dc0566c244059a4878798b02fc50fecbd93d81cb9085f6e1fd865"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-proxy/src/tls_intercept/handle.rs:1203-1212 | crates/nono-proxy/src/tls_intercept/handle.rs:1867-1876 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":1203}}}],"partialFingerprints":{"codehealthFindingId/v1":"d384c3dede44fd6302d087f1e8056c037d31abb1a450f101a00fda52e159da48"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 4): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1503-1511 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:1629-1637 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1217-1225 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1337-1345 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1503}}}],"partialFingerprints":{"codehealthFindingId/v1":"8a9a4de668f1c933dedcaeb24f4f6196e2548ae9e34ec6161e89a7d0bdc1898a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 4): crates/nono-cli/src/profile_cmd.rs:1486-1494 | crates/nono-cli/src/profile_cmd.rs:1520-1528 | crates/nono-cli/src/profile_cmd.rs:1720-1728 | crates/nono-cli/src/profile_cmd.rs:1750-1758 \u2014 all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":1486}}}],"partialFingerprints":{"codehealthFindingId/v1":"ebf35cb8ace233517d07bcbba7cc77eb6312709650db20f732dbeaa12065f924"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/session.rs:581-589 | crates/nono/src/audit.rs:885-893 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/session.rs"},"region":{"startLine":581}}}],"partialFingerprints":{"codehealthFindingId/v1":"636dfd7b215c72d658c4a4e3d6dcf83cddd866bb57a60456fa93e9e1f3e91581"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono/src/undo/snapshot.rs:472-480 | crates/nono/src/undo/snapshot.rs:549-557 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/snapshot.rs"},"region":{"startLine":472}}}],"partialFingerprints":{"codehealthFindingId/v1":"2671804fea03210c882562e766ebe1074b3fe45c8c7cf8042bbdd973c60d3a3d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/capability_ext.rs:720-728 | crates/nono-cli/src/capability_ext.rs:1112-1120 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/capability_ext.rs"},"region":{"startLine":720}}}],"partialFingerprints":{"codehealthFindingId/v1":"71e57583870fc2e392917ce4b856771b6d06e3471acae67b6dbb721ea15be1d3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/profile_save_runtime.rs:366-374 | crates/nono-cli/src/profile_save_runtime.rs:426-434 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_save_runtime.rs"},"region":{"startLine":366}}}],"partialFingerprints":{"codehealthFindingId/v1":"6af98e54d5639620c1e77fd17b0351bf40040df26789e64da0b6f97315985aa9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/proxy_runtime.rs:674-682 | crates/nono-cli/src/proxy_runtime.rs:752-760 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":674}}}],"partialFingerprints":{"codehealthFindingId/v1":"d649074ebf938c7cb54621c7cddc4fcac0fa066d157240f254a47bcc02dea714"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/pty_proxy.rs:2224-2232 | crates/nono-cli/src/pty_proxy.rs:2266-2274 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/pty_proxy.rs"},"region":{"startLine":2224}}}],"partialFingerprints":{"codehealthFindingId/v1":"2c6d11ec9932c2bd350c3f2085e141a1a0dfef45683e4a318d4c3a381697f5a1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/pty_proxy.rs:2632-2640 | crates/nono-cli/src/pty_proxy.rs:2704-2712 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/pty_proxy.rs"},"region":{"startLine":2632}}}],"partialFingerprints":{"codehealthFindingId/v1":"641c2b8c2ea6418528d3b5605b50919c91e21d1fb2365726ade0f3eac8b0dc72"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/dynamic_providers.rs:232-240 | crates/nono-cli/src/tool-sandbox/dynamic_providers.rs:328-336 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/dynamic_providers.rs"},"region":{"startLine":232}}}],"partialFingerprints":{"codehealthFindingId/v1":"7a8bfd7d4ecd9c356fcfb94624d6f25aa2e376d68165a31367a73459d86f0922"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:3005-3013 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:3020-3028 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3005}}}],"partialFingerprints":{"codehealthFindingId/v1":"32d295333f3aff0764723cfd12fd8fb5a845453ebc9fa1858c840e5446066e84"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4122-4130 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:3720-3728 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4122}}}],"partialFingerprints":{"codehealthFindingId/v1":"2abdc315a654956ad50673880030600f96e4a87d51e02ef54a2a7c12193e83ce"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/policy.rs:141-149 | crates/nono-cli/src/tool-sandbox/policy.rs:151-159 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/policy.rs"},"region":{"startLine":141}}}],"partialFingerprints":{"codehealthFindingId/v1":"078f9a1618ffc76cffc63c4ebcd6db86af99cd606f5eaae67762e3abfcb68b3e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/audit_commands.rs:313-321 | crates/nono-cli/src/rollback_commands.rs:266-274 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/audit_commands.rs\u0060 and \u0060crates/nono-cli/src/rollback_commands.rs\u0060 as WHOLE FILES: this scan already matched 9 separate duplicated blocks between them, totalling at least 136 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":313}}}],"partialFingerprints":{"codehealthFindingId/v1":"1aa4145ec1aac2721cc02034a0853f8e248b4e714e8da7f57264ae6f71ff62cf"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7\u20139 lines \u00D7 2): crates/nono-cli/src/trust_cmd.rs:1180-1186 | crates/nono-cli/src/trust_cmd.rs:1241-1249 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_cmd.rs"},"region":{"startLine":1180}}}],"partialFingerprints":{"codehealthFindingId/v1":"fc649553343f88499ecba3f94d2f665faab3f2982e6a5dcb556b7d3fe678aea4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-proxy/src/tls_intercept/ca.rs:310-318 | crates/nono-proxy/src/tls_intercept/cert_cache.rs:216-224 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/ca.rs"},"region":{"startLine":310}}}],"partialFingerprints":{"codehealthFindingId/v1":"74be5bcb460ac24303f4e5201b1153cfdd17562ea68d3a81d48e291793daad24"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/exec_strategy.rs:4092-4099 | crates/nono/src/capability.rs:2146-2153 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":4092}}}],"partialFingerprints":{"codehealthFindingId/v1":"6f5d431fde5e46435dfb91e55b596af4843325a13be23e7434ca77cce4c9d287"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono/src/supervisor/socket.rs:271-278 | crates/nono/src/supervisor/socket.rs:328-335 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/supervisor/socket.rs"},"region":{"startLine":271}}}],"partialFingerprints":{"codehealthFindingId/v1":"a7e1ca8ec90076f0133e7025cff6dba37120743ac112c051e3186e77e1b0ed13"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/audit_client.rs:350-357 | crates/nono-cli/src/platform_client.rs:241-248 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_client.rs"},"region":{"startLine":350}}}],"partialFingerprints":{"codehealthFindingId/v1":"a1429181ba730d5e08e68d13ba33711e7971b0689cff77319d0373423b5b9b0d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/capability_ext.rs:53-60 | crates/nono-cli/src/capability_ext.rs:88-95 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/capability_ext.rs"},"region":{"startLine":53}}}],"partialFingerprints":{"codehealthFindingId/v1":"511a4d53e812d5ae22ff6cf6ffead4064392687c4ce14c81fc45515f3d4a1279"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/command_policy.rs:3486-3493 | crates/nono-cli/src/profile/mod.rs:3994-4001 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_policy.rs"},"region":{"startLine":3486}}}],"partialFingerprints":{"codehealthFindingId/v1":"ed8b5c9b380ea11d6f87b23c0ad9f5df0a41288fec55bd57d42b127e8aaa942f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/connect_client.rs:307-314 | crates/nono-cli/src/connect_client.rs:565-572 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/connect_client.rs"},"region":{"startLine":307}}}],"partialFingerprints":{"codehealthFindingId/v1":"c6ae1dc2a4cbfd50a295dc6fe174a9e1c3fd51a09ca44e64b599f0b43158e624"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/exec_strategy.rs:2237-2244 | crates/nono-cli/src/pty_proxy.rs:2305-2312 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":2237}}}],"partialFingerprints":{"codehealthFindingId/v1":"772925fb9d291af1ccafcd66616014f2f3404429f8fd231c9b61160fe0326143"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/proxy_command.rs:273-280 | crates/nono-cli/src/proxy_runtime.rs:1516-1523 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_command.rs"},"region":{"startLine":273}}}],"partialFingerprints":{"codehealthFindingId/v1":"e5e1dca04934720956f925f7cb843a6e797d1cf6efe2656bb5d125c601e215e1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:218-225 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:228-235 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":218}}}],"partialFingerprints":{"codehealthFindingId/v1":"650194e6216fb2f76fb8dfcfa95ad331766652810c8f3e73f9dd292723dde57d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:230-237 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:245-252 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":230}}}],"partialFingerprints":{"codehealthFindingId/v1":"d23fff2566cadc27771124e0b6d79cc31f88ff3ae35c30d5bf36b2cd32bb739c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1886-1893 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1606-1613 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1886}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee2d0d5dc6e0b3bc496572d022680617702abb1915f921e3368ece763b8e9582"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2119-2126 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1907-1914 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2119}}}],"partialFingerprints":{"codehealthFindingId/v1":"5f506752c1f2b35b3a6665eda11f5b5a1140f86c847453f88ad17323668aed0f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:3632-3639 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:3650-3657 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3632}}}],"partialFingerprints":{"codehealthFindingId/v1":"937f1db856afea5b576d70fe45754bf61313faa796f99e308ad0723f3c22e0a1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:5733-5740 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:5760-5767 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":5733}}}],"partialFingerprints":{"codehealthFindingId/v1":"786df658165e3048f6b74006c30110db4883af256bbcbb3a179f74c3d037ca18"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/audit_commands.rs:938-945 | crates/nono-cli/src/rollback_commands.rs:192-199 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/audit_commands.rs\u0060 and \u0060crates/nono-cli/src/rollback_commands.rs\u0060 as WHOLE FILES: this scan already matched 9 separate duplicated blocks between them, totalling at least 136 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":938}}}],"partialFingerprints":{"codehealthFindingId/v1":"c8c5d13b4fc884db12308b400737d73515b267cb85a4c9de381c6d5f69dadadd"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-proxy/src/forward.rs:167-174 | crates/nono-proxy/src/tls_intercept/h2_forward.rs:214-221 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/forward.rs"},"region":{"startLine":167}}}],"partialFingerprints":{"codehealthFindingId/v1":"e913aaa3f6e0a03d204bd228bba97bfd6102ca1df4c14faf975a5e3a83f9eaa0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:412-419 | crates/nono-proxy/src/tls_intercept/handle.rs:840-847 \u2014 before extracting anything, compare \u0060crates/nono-proxy/src/reverse.rs\u0060 and \u0060crates/nono-proxy/src/tls_intercept/handle.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 44 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":412}}}],"partialFingerprints":{"codehealthFindingId/v1":"05e74bfc3f7f01b4aa02e023dc43ea61ad1d309cf90b9aa3663ad37612d4278e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:2428-2435 | crates/nono-proxy/src/reverse.rs:2539-2546 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":2428}}}],"partialFingerprints":{"codehealthFindingId/v1":"5bb7452a87168bd79892ad3621bc52dcc501d789a300b8bc369a2a18b06eac7c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 4): crates/nono-cli/src/tool-sandbox/platform/linux.rs:955-961 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:967-973 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:768-774 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:780-786 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":955}}}],"partialFingerprints":{"codehealthFindingId/v1":"e8273065fae87a3905510570289261b37d0293c709d1189dc098ed53978af050"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 3): crates/nono-cli/src/capability_ext.rs:769-775 | crates/nono-cli/src/capability_ext.rs:792-798 | crates/nono-cli/src/capability_ext.rs:812-818 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/capability_ext.rs"},"region":{"startLine":769}}}],"partialFingerprints":{"codehealthFindingId/v1":"91855c9645dcbebe88c3efd51c4ba4b93a1e732ac8c52c8fb1a9c29b8844b146"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 3): crates/nono-proxy/src/tls_intercept/handle.rs:1278-1284 | crates/nono-proxy/src/tls_intercept/handle.rs:1535-1541 | crates/nono-proxy/src/tls_intercept/handle.rs:1775-1781 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":1278}}}],"partialFingerprints":{"codehealthFindingId/v1":"d1c2e6c808604922c481369231f916c326bf1d4fefdf0b00d5f1a7566a75aeb9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/nono/src/supervisor/socket.rs:259-265 | crates/nono/src/supervisor/socket.rs:316-322 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/supervisor/socket.rs"},"region":{"startLine":259}}}],"partialFingerprints":{"codehealthFindingId/v1":"94e64c9bb81e63cfe64135296d26ee64b2161c8a7722c795e04ee15947296c10"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/nono-cli/src/exec_strategy.rs:540-546 | crates/nono-cli/src/exec_strategy.rs:687-693 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":540}}}],"partialFingerprints":{"codehealthFindingId/v1":"179e144e00b715682ebba063116f63e793ee7c697fdb7d87cf5828233f7626c8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/nono-cli/src/proxy_runtime.rs:716-722 | crates/nono-cli/src/proxy_runtime.rs:734-740 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":716}}}],"partialFingerprints":{"codehealthFindingId/v1":"067bc41c186491c212d5ad137cb5df166874fd69bb998d67b7486829fdb9ada7"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:903-909 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:742-748 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":903}}}],"partialFingerprints":{"codehealthFindingId/v1":"a9c93025f0b7d4b050aa98adf1b77793129a4a29fac015e3c569ee38605217c2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1495-1501 | crates/nono-cli/src/tool-sandbox/platform/linux.rs:1621-1627 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1495}}}],"partialFingerprints":{"codehealthFindingId/v1":"c65cfbf9da071b963bf32fbc5d3299ceb5285160a275cffe0f03319608558773"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1515-1521 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:1229-1235 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1515}}}],"partialFingerprints":{"codehealthFindingId/v1":"5dc36a92d78e71d453fc48c90521d9ce95894e899fa9d29a8fbdff634ac13c69"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2512-2518 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4930-4936 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2512}}}],"partialFingerprints":{"codehealthFindingId/v1":"c28a772cc028b1fc72da9f87b6840c5e0a61083e6fa8ac3d9bad06816c1031aa"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:5341-5347 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4500-4506 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":5341}}}],"partialFingerprints":{"codehealthFindingId/v1":"a3f2eb3c308ecdfb6ff9051a68906712d45110a5face218e5e6ac51b6ac8b61e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:1907-1913 | crates/nono-proxy/src/reverse.rs:1954-1960 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":1907}}}],"partialFingerprints":{"codehealthFindingId/v1":"762b7971810b1e6151f95be740bbed7905f4c1055230077b962b49497f5c04a4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): crates/nono-proxy/src/config.rs:710-715 | crates/nono/src/net_filter.rs:224-229 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/config.rs"},"region":{"startLine":710}}}],"partialFingerprints":{"codehealthFindingId/v1":"4d6fa58eb706b9c39936a3592d27e3f6ee1236c77922142ea841575cc4d2983a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): crates/nono-cli/src/config/version.rs:46-51 | crates/nono-cli/src/package.rs:365-370 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/config/version.rs"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"2f26b74915eed365c7fba94adfe181fb6f5d3aa26afbb3542d3d949cd07ff98a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): crates/nono-cli/src/profile/mod.rs:961-966 | crates/nono-cli/src/profile/mod.rs:973-978 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":961}}}],"partialFingerprints":{"codehealthFindingId/v1":"a3aef9d7532631ac5e7a7e356e5d9ec17bb8c6fcbde9d52eabbaf2cdb73a8f9e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:1219-1224 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:910-915 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1219}}}],"partialFingerprints":{"codehealthFindingId/v1":"3674fe9a6384d0def07afde59942737345e6ffc708224bd4798800212e1d19fe"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2935-2940 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5403-5408 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2935}}}],"partialFingerprints":{"codehealthFindingId/v1":"eca074d211c0e6d7442d940a3d6979734efecfdd6d5db080bbd05580cafe6e27"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): crates/nono-cli/src/url_open.rs:103-108 | crates/nono-cli/src/url_open.rs:112-117 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/url_open.rs"},"region":{"startLine":103}}}],"partialFingerprints":{"codehealthFindingId/v1":"383cf8d3228a889ae22ce903e75c214a3e212023c8e5e5d7419b6eadbd97265f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): crates/nono-proxy/src/config.rs:1188-1193 | crates/nono-proxy/src/config.rs:1348-1353 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/config.rs"},"region":{"startLine":1188}}}],"partialFingerprints":{"codehealthFindingId/v1":"ae82597a95f6e3ade0c7ae514ff22a29563b4b8468632cf92711752f0d4d6c53"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (3\u20135 lines \u00D7 6): crates/nono-cli/src/command_policy.rs:1135-1137 | crates/nono-cli/src/command_policy.rs:3454-3458 | crates/nono-cli/src/command_policy.rs:3466-3470 | crates/nono-cli/src/command_policy.rs:3478-3482 | crates/nono-cli/src/profile/mod.rs:3892-3894 | crates/nono-cli/src/profile/mod.rs:3985-3989 \u2014 there are 6 copies across 2 file(s) \u2014 more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 6 sites; resolving a subset leaves the remainder to drift apart."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_policy.rs"},"region":{"startLine":1135}}}],"partialFingerprints":{"codehealthFindingId/v1":"1f7b7cc9720e857fbd06a3ea041162004274e5f3b08758a038550fe481d4d620"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): crates/nono-cli/src/profile_cmd.rs:1446-1450 | crates/nono-cli/src/profile_cmd.rs:1689-1693 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":1446}}}],"partialFingerprints":{"codehealthFindingId/v1":"a7cb7669662b7f8a9df72db621eba6b4e4a34cb7e1c962ce0c0238eb74ab4953"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono/src/diagnostic/observation.rs:157-165 | crates/nono/src/diagnostic/report.rs:252-260 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/diagnostic/observation.rs"},"region":{"startLine":157}}}],"partialFingerprints":{"codehealthFindingId/v1":"3b852de25e62b3c708f3b8d54684dce094ce0f66083b9607e86622c961313529"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 3): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2800-2809 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5228-5237 | crates/nono/src/broker_path.rs:183-192 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2800}}}],"partialFingerprints":{"codehealthFindingId/v1":"3f4413679836fc4891e02d0d435d5c6194cb827b6c8d5279fe0eb3f6ef2f31be"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (20 lines \u00D7 3): crates/nono-cli/src/profile/mod.rs:491-510 | crates/nono-cli/src/proxy_runtime.rs:1268-1287 | crates/nono-proxy/src/tls_intercept/http1.rs:51-70 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 3 call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made 3 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":491}}}],"partialFingerprints":{"codehealthFindingId/v1":"df671fe3d663714ab78e1a4020d00e87ba1aebfd0f0ba7bc548497b7ff36d5fe"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (18 lines \u00D7 2): crates/nono-cli/src/profile/mod.rs:1515-1532 | crates/nono-cli/src/proxy_runtime.rs:1289-1306 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":1515}}}],"partialFingerprints":{"codehealthFindingId/v1":"389600102e2ffa6359cefe671e51ed704b84c1c8130d23f3151488062d9e2cd5"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/audit_commands.rs:905-913 | crates/nono-cli/src/session_commands.rs:27-35 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":905}}}],"partialFingerprints":{"codehealthFindingId/v1":"de58cf41f2498ff23539c80cb9f9249ab4a00f30682a2e6535f677eed61f3c6e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:519-527 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:460-468 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":519}}}],"partialFingerprints":{"codehealthFindingId/v1":"6bf4f8498aa4b6d1298dc7ce70092d527354f15f775db7d991d4ffd3b3d6adfa"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4717-4725 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4165-4173 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4717}}}],"partialFingerprints":{"codehealthFindingId/v1":"93f955699d4693b5e7fc65ba92d3b156e36627db7462994fb9b9bfbbecf872c1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2450-2457 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4868-4875 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2450}}}],"partialFingerprints":{"codehealthFindingId/v1":"031137686c6bbb8858658c557c48efe5d693b55e6a138565b32bb2af23322675"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2459-2467 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4877-4885 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2459}}}],"partialFingerprints":{"codehealthFindingId/v1":"9847f76730d772d11af2247e8c47f09795d61d0036bbf9cc0584621f0296d7ea"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2534-2538 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4952-4956 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2534}}}],"partialFingerprints":{"codehealthFindingId/v1":"2029dca12b3b84d1610d8931acf627d262ee0ccb71d078f3618a08977098a027"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2545-2552 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4963-4970 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2545}}}],"partialFingerprints":{"codehealthFindingId/v1":"2ae534af4aa3225b5d4228fa57945a2219f24161de5de29c4c6cec65ccf77dd0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2567-2574 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4974-4981 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2567}}}],"partialFingerprints":{"codehealthFindingId/v1":"e1d88754d7a6603cf47f460a4d730393e64ee8fa8cdb45d0477469e2492ac96b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2610-2615 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5032-5037 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2610}}}],"partialFingerprints":{"codehealthFindingId/v1":"ca695826910cb90764dc5697fa47687425c26cdc59ae05ea33619c2aca24ba55"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2703-2718 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5129-5144 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2703}}}],"partialFingerprints":{"codehealthFindingId/v1":"836a60a0f83873f6f1578f18a3fb7b8e92ab4e384ec2299250902f96dc57a9ae"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2722-2728 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5178-5184 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2722}}}],"partialFingerprints":{"codehealthFindingId/v1":"db334c35046aca8aca4e1724722d7ea49165773e01d86d7ec57fbb339cbac0ab"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2811-2815 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5239-5243 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2811}}}],"partialFingerprints":{"codehealthFindingId/v1":"69b70218203217bb70b850d14b131cc808e61ad1a7a9bf4f81ea393407da770f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:3722-3728 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:3118-3124 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3722}}}],"partialFingerprints":{"codehealthFindingId/v1":"3f2e09106518ef550298f19a22fe2879517a0d0e3e609fea37019d045e07a35a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:3732-3745 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:3128-3141 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3732}}}],"partialFingerprints":{"codehealthFindingId/v1":"ac29ae538bf197aff76a543ef419943f715db36ca87388dbd8e363bbbe6116e7"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4110-4119 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:3708-3717 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4110}}}],"partialFingerprints":{"codehealthFindingId/v1":"878783cf8588aa886c87a6ad55ef447d81397370b10ce0dd496b9789d79653ad"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4241-4249 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:3804-3812 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4241}}}],"partialFingerprints":{"codehealthFindingId/v1":"9d1f21ffd6ac60210cfa2b955c5640ad693e903ae6e27d97b2a8266d7a3b73e3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4874-4882 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4320-4328 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4874}}}],"partialFingerprints":{"codehealthFindingId/v1":"00ad704f777ab56622e82f5e15b354fe7ce9e309939fecdca16b13482042e9ab"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:5038-5044 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:2725-2731 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":5038}}}],"partialFingerprints":{"codehealthFindingId/v1":"b04160545addd3ac9dd5fb5c20177259bce89584165ffc1ce411d996f07fecf4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:5277-5281 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4489-4493 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":5277}}}],"partialFingerprints":{"codehealthFindingId/v1":"1215e67fd8963c0ed4acec3d958c337abef61b51e589f582c0134b5959f8840a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:5481-5490 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4640-4649 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":5481}}}],"partialFingerprints":{"codehealthFindingId/v1":"9a5ae9a0b6ba3b615139a44cfa36d82190b8d8b971031809c78bd3ff3c8001f0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:5492-5500 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4651-4659 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":5492}}}],"partialFingerprints":{"codehealthFindingId/v1":"f5339d6172545fa53362fc1d45620d11638a81321b474b979340363410b00211"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/nono-cli/src/audit_commands.rs:237-243 | crates/nono-cli/src/rollback_commands.rs:990-996 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/audit_commands.rs\u0060 and \u0060crates/nono-cli/src/rollback_commands.rs\u0060 as WHOLE FILES: this scan already matched 9 separate duplicated blocks between them, totalling at least 136 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":237}}}],"partialFingerprints":{"codehealthFindingId/v1":"d1ecbfa873a97ffe48ef87e81b0ace65505fdd166cc440614c5981b47235e420"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/nono-cli/src/audit_commands.rs:283-289 | crates/nono-cli/src/rollback_commands.rs:1041-1047 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/audit_commands.rs\u0060 and \u0060crates/nono-cli/src/rollback_commands.rs\u0060 as WHOLE FILES: this scan already matched 9 separate duplicated blocks between them, totalling at least 136 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":283}}}],"partialFingerprints":{"codehealthFindingId/v1":"7e5fb34c8b3dd418162b1f957d2a33df083604d6d2d6beb6866b152030e19a53"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/connect_client.rs:1907-1914 | crates/nono-cli/src/pty_proxy.rs:1374-1381 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/connect_client.rs"},"region":{"startLine":1907}}}],"partialFingerprints":{"codehealthFindingId/v1":"c07266625289bcd29deff1f1d460fe5774bcd93f83e222357d7009c4121e8791"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 3): crates/nono-cli/src/profile_cmd.rs:1461-1485 | crates/nono-cli/src/profile_cmd.rs:1500-1519 | crates/nono-cli/src/profile_cmd.rs:1704-1719 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":1461}}}],"partialFingerprints":{"codehealthFindingId/v1":"61ed110e8c2ec71b60045c51f914f951efbb9a7c017d7203e564db60201b987d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (18 lines \u00D7 2): crates/nono-proxy/src/credential.rs:437-454 | crates/nono-proxy/src/credential.rs:501-519 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/credential.rs"},"region":{"startLine":437}}}],"partialFingerprints":{"codehealthFindingId/v1":"3dde243f033fb6fcd9ad115b30357f42cc1261e07ae9119f6bdf8da87c5f8eee"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4519-4533 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:3958-3973 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4519}}}],"partialFingerprints":{"codehealthFindingId/v1":"1fe5210f6fac77764766bd37c77f3030124c08e827ec8d1668622d2976389463"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): crates/nono-proxy/src/tls_intercept/handle.rs:625-639 | crates/nono-proxy/src/tls_intercept/handle.rs:683-696 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":625}}}],"partialFingerprints":{"codehealthFindingId/v1":"e80b7e6507add4bce495758b14934765f99d31165a3c89f360d06c0b6c7e8c43"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/nono-cli/src/exec_strategy.rs:1160-1171 | crates/nono-cli/src/exec_strategy.rs:1271-1285 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":1160}}}],"partialFingerprints":{"codehealthFindingId/v1":"c4e0b4c0ed1cf9959434c47ddb3618d8ab84999df8f9679cb5b22ec4f5b6e2c0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 3): crates/nono-cli/src/exec_strategy.rs:1160-1171 | crates/nono-cli/src/exec_strategy.rs:1240-1250 | crates/nono-cli/src/exec_strategy.rs:1271-1285 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":1160}}}],"partialFingerprints":{"codehealthFindingId/v1":"848670507eba0bc9d613f72445dddb37ddab45c77185b13582a87dd2391f225a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 3): crates/nono-proxy/src/reverse.rs:714-726 | crates/nono-proxy/src/reverse.rs:742-755 | crates/nono-proxy/src/reverse.rs:764-777 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":714}}}],"partialFingerprints":{"codehealthFindingId/v1":"5e11d9ebb303e8807e8bf0674da46da0f23dd9b70fb5401c73ea9d46b24a0910"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:1713-1726 | crates/nono-proxy/src/reverse.rs:1756-1769 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":1713}}}],"partialFingerprints":{"codehealthFindingId/v1":"ea7ead058d0b2c350a61629b08f8e67975aeb020fea1cb750eb418f6fbf06497"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): crates/nono/src/keystore.rs:811-824 | crates/nono/src/keystore.rs:901-914 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/keystore.rs"},"region":{"startLine":811}}}],"partialFingerprints":{"codehealthFindingId/v1":"3e8220458c01a3c11771e79ac5581b525c72774b4fc6b7fefaa7fdf5b24e502d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 3): crates/nono-proxy/src/reverse.rs:1100-1112 | crates/nono-proxy/src/reverse.rs:1135-1147 | crates/nono-proxy/src/reverse.rs:1164-1177 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":1100}}}],"partialFingerprints":{"codehealthFindingId/v1":"db139febf46869ea289d9fc5b41a9acb9a96730f02ebab0cc31a92876fd7d8cd"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 5): crates/nono-cli/src/exec_strategy.rs:1160-1170 | crates/nono-cli/src/exec_strategy.rs:1178-1188 | crates/nono-cli/src/exec_strategy.rs:1223-1236 | crates/nono-cli/src/exec_strategy.rs:1240-1250 | crates/nono-cli/src/exec_strategy.rs:1271-1284 \u2014 all 5 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":1160}}}],"partialFingerprints":{"codehealthFindingId/v1":"ff857e21b102bc6ae44b15c2539316f326b8da2d0e5f10f80d335e1c1a91d084"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/nono-cli/src/proxy_runtime.rs:224-236 | crates/nono-cli/src/proxy_runtime.rs:249-261 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":224}}}],"partialFingerprints":{"codehealthFindingId/v1":"fbc938eecb6683bc0d07727568f1531e24b6aca5a81c5e72836fe732c6dc361c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono/src/keystore.rs:333-345 | crates/nono/src/keystore.rs:486-496 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/keystore.rs"},"region":{"startLine":333}}}],"partialFingerprints":{"codehealthFindingId/v1":"af5c6480e91478e3054f05aa69e233b610b172e0890a34e26a1dbd8fe4a15a62"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 4): crates/nono-proxy/src/reverse.rs:1070-1082 | crates/nono-proxy/src/reverse.rs:1100-1112 | crates/nono-proxy/src/reverse.rs:1135-1147 | crates/nono-proxy/src/reverse.rs:1165-1177 \u2014 all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":1070}}}],"partialFingerprints":{"codehealthFindingId/v1":"b4fe3f54d6d065d5026f1d1e158ff20c199b66ecae8cddb668cfb94a8d85cc7f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/nono-cli/src/exec_strategy.rs:2065-2076 | crates/nono-cli/src/exec_strategy.rs:2719-2731 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":2065}}}],"partialFingerprints":{"codehealthFindingId/v1":"b8a3583734ccdf5d7d16f3c67a54f52eeae567f54622c07d47a3aef95ecf30ba"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4504-4516 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:3943-3955 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4504}}}],"partialFingerprints":{"codehealthFindingId/v1":"d8b60fd3a8c9ecf0323a018216c4492108bfde1096ff6d3b6df9883df38f707f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 3): crates/nono-proxy/src/tls_intercept/handle.rs:1437-1448 | crates/nono-proxy/src/tls_intercept/handle.rs:1462-1473 | crates/nono-proxy/src/tls_intercept/handle.rs:1760-1772 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":1437}}}],"partialFingerprints":{"codehealthFindingId/v1":"4467ff0bcffd70b93a43092fb78b5b88ca0dcaef1688dd08a1f2822f3e6fe258"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:3341-3353 | crates/nono/src/sandbox/linux.rs:1419-1431 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono/src/sandbox/linux.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 33 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3341}}}],"partialFingerprints":{"codehealthFindingId/v1":"01a21953562d5bc448e158ab9a67321c8110a77f4734c364caa8cee0ee22bdc2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 7): crates/nono-cli/src/exec_strategy.rs:1039-1051 | crates/nono-cli/src/exec_strategy.rs:1121-1133 | crates/nono-cli/src/exec_strategy.rs:1159-1169 | crates/nono-cli/src/exec_strategy.rs:1177-1187 | crates/nono-cli/src/exec_strategy.rs:1223-1235 | crates/nono-cli/src/exec_strategy.rs:1239-1249 | crates/nono-cli/src/exec_strategy.rs:1271-1283 \u2014 all 7 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":1039}}}],"partialFingerprints":{"codehealthFindingId/v1":"273098cc2b15e36bf21395e48dc61142cb437daa0b96a43a8b5c6e17091613a3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono/src/trust/bundle.rs:551-562 | crates/nono/src/trust/bundle.rs:568-578 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/trust/bundle.rs"},"region":{"startLine":551}}}],"partialFingerprints":{"codehealthFindingId/v1":"a3a714b20c470dd65cc8f84d0ad72efda7eba52c44a58d6f11ccfd49463977e0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/output.rs:707-718 | crates/nono-cli/src/output.rs:740-748 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/output.rs"},"region":{"startLine":707}}}],"partialFingerprints":{"codehealthFindingId/v1":"2f8f2e4e0f6fd8c922270d35a12b2ec89f5a7dd6f283a9d5499363ad28dcc9e6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:3389-3400 | crates/nono/src/sandbox/linux.rs:1450-1461 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono/src/sandbox/linux.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 33 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3389}}}],"partialFingerprints":{"codehealthFindingId/v1":"33678775c8338331f945fa8703fd602fbb2d2302c730fbac9fc2bb93ccee0fae"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/nono-cli/src/exec_strategy/supervisor_linux.rs:371-382 | crates/nono-cli/src/exec_strategy/supervisor_linux.rs:428-439 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy/supervisor_linux.rs"},"region":{"startLine":371}}}],"partialFingerprints":{"codehealthFindingId/v1":"a09d43a51179ba8e4611129f44d282718996b8e94d628c26c976d072a3f095e5"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:4944-4953 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4383-4394 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":4944}}}],"partialFingerprints":{"codehealthFindingId/v1":"f26df9cbb5b7365e277ce3d5f7051045f595db2eeb92986514053cef41705f4a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 3): bindings/c/src/capability_set.rs:315-326 | bindings/c/src/capability_set.rs:344-355 | bindings/c/src/capability_set.rs:377-388 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"bindings/c/src/capability_set.rs"},"region":{"startLine":315}}}],"partialFingerprints":{"codehealthFindingId/v1":"0984aa0fd97aa35f5f42b55d8057b56ecccb23e5d47eb5c2c61319e74b041ff9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/nono-proxy/src/reverse.rs:1866-1877 | crates/nono-proxy/src/tls_intercept/handle.rs:2196-2207 \u2014 before extracting anything, compare \u0060crates/nono-proxy/src/reverse.rs\u0060 and \u0060crates/nono-proxy/src/tls_intercept/handle.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 44 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":1866}}}],"partialFingerprints":{"codehealthFindingId/v1":"af3c8272dfad438db79861f6009cda1e62902fe4728eee087ba29504bd83e018"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2966-2976 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5422-5432 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2966}}}],"partialFingerprints":{"codehealthFindingId/v1":"b629b13f279d0af305903aafdc817ef6a89a0fd2e3d400b71ab3bb4800af356b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono-cli/src/output.rs:870-880 | crates/nono-cli/src/output.rs:936-946 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/output.rs"},"region":{"startLine":870}}}],"partialFingerprints":{"codehealthFindingId/v1":"cd261fd074cc43f426e4e9b612ab8321bdd32a357bd9e77d1868c953092ff4a1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono/src/keystore.rs:492-502 | crates/nono/src/keystore.rs:625-634 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/keystore.rs"},"region":{"startLine":492}}}],"partialFingerprints":{"codehealthFindingId/v1":"bc4766899b5457ad673466e439a66840d1138d3830f44d0651dbb1cbf72d8892"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono-cli/src/audit_ledger.rs:38-48 | crates/nono-cli/src/audit_ledger.rs:99-109 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_ledger.rs"},"region":{"startLine":38}}}],"partialFingerprints":{"codehealthFindingId/v1":"9a7b3ab41b253e123bab403f40f6c5869b4a544fa717c411ad14fede635c0b18"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 5): crates/nono-cli/src/trust_scan.rs:905-915 | crates/nono-cli/src/trust_scan.rs:919-929 | crates/nono-cli/src/trust_scan.rs:944-954 | crates/nono-cli/src/trust_scan.rs:966-976 | crates/nono-cli/src/trust_scan.rs:997-1007 \u2014 all 5 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_scan.rs"},"region":{"startLine":905}}}],"partialFingerprints":{"codehealthFindingId/v1":"f9b4cb1821e4dcc388b4f32d1ea2eeaeb2075d0fe734741ac4b55d92711051f8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2283-2293 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4692-4698 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2283}}}],"partialFingerprints":{"codehealthFindingId/v1":"494928accdafccddd92c08fe5e61a7dc2e0d2fe88f6554d26642276522741dec"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 3): crates/nono-proxy/src/reverse.rs:1791-1801 | crates/nono-proxy/src/reverse.rs:2305-2315 | crates/nono-proxy/src/reverse.rs:2323-2333 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":1791}}}],"partialFingerprints":{"codehealthFindingId/v1":"dd5e79c9f59570a1c70b2e00954e5f11bf6c2320f3e1c0c90a1eae20837e05cc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono-cli/src/exec_strategy.rs:3560-3570 | crates/nono-cli/src/exec_strategy.rs:3629-3639 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":3560}}}],"partialFingerprints":{"codehealthFindingId/v1":"4b3b6e2cc4d1b51e3c5fb660754d05518c63756207007cf080291395a42eec92"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/nono-cli/src/exec_strategy/supervisor_linux.rs:460-470 | crates/nono-cli/src/exec_strategy/supervisor_linux.rs:486-496 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy/supervisor_linux.rs"},"region":{"startLine":460}}}],"partialFingerprints":{"codehealthFindingId/v1":"bdf297c2292cdc85679eef4424c496a1b0fcdaf7110f1968765f887314f772d0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-proxy/src/route.rs:799-808 | crates/nono-proxy/src/route.rs:862-871 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/route.rs"},"region":{"startLine":799}}}],"partialFingerprints":{"codehealthFindingId/v1":"6cf662c8d5490dc15170981b46d57bfb680c8d2c6859e877ee3399b3b41b7b70"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 3): crates/nono-cli/src/output.rs:638-644 | crates/nono-cli/src/output.rs:706-715 | crates/nono-cli/src/output.rs:739-745 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/output.rs"},"region":{"startLine":638}}}],"partialFingerprints":{"codehealthFindingId/v1":"a11a07b6827654991eac75462077d43dbd1204ac62a317f4dd0e23379cf43d6e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono/src/keystore.rs:1923-1931 | crates/nono/src/keystore.rs:1953-1962 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/keystore.rs"},"region":{"startLine":1923}}}],"partialFingerprints":{"codehealthFindingId/v1":"e8dca91fca08450d5b85dd3705ab0c4a2ad0506f7d677fe4642dc918264656cc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono/src/undo/snapshot.rs:654-663 | crates/nono/src/undo/snapshot.rs:699-708 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/snapshot.rs"},"region":{"startLine":654}}}],"partialFingerprints":{"codehealthFindingId/v1":"8d0aa38f37931565e9707e2c2c514ac39a635a27fb6d4b5df064f168a4dbf8dc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/macos.rs:545-554 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:591-600 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":545}}}],"partialFingerprints":{"codehealthFindingId/v1":"785afb70b1718706f7ad163e872f293b3d00231627fff6eecabecb975879caa8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/connect_client.rs:609-617 | crates/nono-cli/src/connect_client.rs:707-715 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/connect_client.rs"},"region":{"startLine":609}}}],"partialFingerprints":{"codehealthFindingId/v1":"3727a029c3e83f48f96abb09395d1da9b459349c8ffca6812231c9e01cc0a117"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono/src/keystore.rs:1121-1129 | crates/nono/src/keystore.rs:1589-1597 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/keystore.rs"},"region":{"startLine":1121}}}],"partialFingerprints":{"codehealthFindingId/v1":"ae9401cecd698c4f6354b61b4d8372001693ae9e7ec6eb2a1a882c74abe44499"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/diagnostic/formatter.rs:1719-1727 | crates/nono-cli/src/diagnostic/formatter.rs:1840-1848 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/diagnostic/formatter.rs"},"region":{"startLine":1719}}}],"partialFingerprints":{"codehealthFindingId/v1":"d0c54c151c851a347a9c720a853b00fe6e36f307d43ce42821706bc5d2df3231"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono/src/undo/snapshot.rs:643-651 | crates/nono/src/undo/snapshot.rs:688-696 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/snapshot.rs"},"region":{"startLine":643}}}],"partialFingerprints":{"codehealthFindingId/v1":"65264f7d78c78895eb5c43f0b050a6fcc03156f9ed2ee1e19c49f46a3c8bc249"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/nono-cli/src/execution_runtime.rs:433-441 | crates/nono-cli/src/execution_runtime.rs:465-473 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/execution_runtime.rs"},"region":{"startLine":433}}}],"partialFingerprints":{"codehealthFindingId/v1":"3ab7331780413da4101f2f01769cb6e8e30290ec385d1e436dfdfba1d15896d2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:3402-3409 | crates/nono/src/sandbox/linux.rs:1463-1470 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono/src/sandbox/linux.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 33 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3402}}}],"partialFingerprints":{"codehealthFindingId/v1":"53bf272c2fe9929623229096768109f18dea73e385eb05168232a982db9394dd"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:3478-3485 | crates/nono/src/supervisor/socket.rs:340-347 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3478}}}],"partialFingerprints":{"codehealthFindingId/v1":"74cccd581f97995c89404f00fa9a71bbf27202d1d75f1594205aeff6219e019d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/macos.rs:517-524 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:570-577 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":517}}}],"partialFingerprints":{"codehealthFindingId/v1":"f8f84210b8f99b57a5351c2aa19febb5c14b4cd67d4d31cda3351018f028c92e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): crates/nono/src/keystore.rs:523-530 | crates/nono/src/keystore.rs:706-710 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/keystore.rs"},"region":{"startLine":523}}}],"partialFingerprints":{"codehealthFindingId/v1":"0e5fa791092f869728ce5b6dc410a2da14e415cd98ed46423607a411216066a3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): crates/nono-cli/src/pty_proxy.rs:2237-2242 | crates/nono-cli/src/pty_proxy.rs:2279-2285 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/pty_proxy.rs"},"region":{"startLine":2237}}}],"partialFingerprints":{"codehealthFindingId/v1":"2ee629389b94f65792467463a1664ac391c7b32d3e42ba63cee61081ab6346e9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): crates/nono-cli/src/connect_client.rs:585-590 | crates/nono-cli/src/url_open.rs:121-127 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/connect_client.rs"},"region":{"startLine":585}}}],"partialFingerprints":{"codehealthFindingId/v1":"3937dfdf0537d85ee50c917eb2f4a9ff67b236f68b70267fa70327841c8a837d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/nono/src/undo/snapshot.rs:354-360 | crates/nono/src/undo/snapshot.rs:379-385 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/undo/snapshot.rs"},"region":{"startLine":354}}}],"partialFingerprints":{"codehealthFindingId/v1":"51ace985987470c632e970d17aed6e200faa6546c622d1703bf60f87cc2bb895"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/nono-proxy/src/tls_intercept/h2_forward.rs:615-621 | crates/nono-proxy/src/tls_intercept/h2_forward.rs:652-658 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/h2_forward.rs"},"region":{"startLine":615}}}],"partialFingerprints":{"codehealthFindingId/v1":"5020a0d23c8af288bbc9ea1399b9a02d158def76dc30c223d24f7bb753684d75"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 3): crates/nono-proxy/src/reverse.rs:2428-2434 | crates/nono-proxy/src/reverse.rs:2539-2545 | crates/nono-proxy/src/reverse.rs:2549-2555 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":2428}}}],"partialFingerprints":{"codehealthFindingId/v1":"e39fdffc9f7c469477bcf2488c8ec8dd236881011ee07a466681fbd420b2b6fd"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/nono-cli/src/profile/mod.rs:3219-3225 | crates/nono-cli/src/profile/mod.rs:3232-3238 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":3219}}}],"partialFingerprints":{"codehealthFindingId/v1":"14bf341a21689e5f8302ccbcf8e6c4a232eabf151db57119b365bc1a347e6bae"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): crates/nono-cli/src/trust_keystore.rs:315-320 | crates/nono-cli/src/trust_keystore.rs:324-328 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_keystore.rs"},"region":{"startLine":315}}}],"partialFingerprints":{"codehealthFindingId/v1":"67cff1ed1b3176a806bc83c9e80f62be0b93f1f432f30d778a78d3f196816e23"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:2295-2300 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:4700-4705 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":2295}}}],"partialFingerprints":{"codehealthFindingId/v1":"dd5866a9d15eba5367880928d909981a54197a059178758495d9330604afe0f4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): crates/nono-proxy/src/tls_intercept/h2_forward.rs:609-614 | crates/nono-proxy/src/tls_intercept/h2_forward.rs:646-651 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/h2_forward.rs"},"region":{"startLine":609}}}],"partialFingerprints":{"codehealthFindingId/v1":"6ceedac4cc96c921fcd00c94557bba7c5460ab95d04519fb01c37fabe82267c4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): crates/nono-cli/src/sandbox_prepare.rs:1321-1326 | crates/nono-cli/src/sandbox_prepare.rs:1332-1337 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/sandbox_prepare.rs"},"region":{"startLine":1321}}}],"partialFingerprints":{"codehealthFindingId/v1":"88ad0842b040cd280fcfeb6e04ac7e9192eded65336135e8faaada90f95a1b4b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): crates/nono-cli/src/profile_cmd.rs:1828-1832 | crates/nono-cli/src/profile_cmd.rs:1857-1861 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":1828}}}],"partialFingerprints":{"codehealthFindingId/v1":"2f3a4f95dec11143b48a1830739597283c609c60611b7592d4c91aa69937965f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:3001-3005 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:5533-5537 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3001}}}],"partialFingerprints":{"codehealthFindingId/v1":"74b4a38ba30428c519b90d2d99314ac375456916790d01cf5bb20f9377b8a173"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): crates/nono/src/supervisor/socket.rs:266-270 | crates/nono/src/supervisor/socket.rs:323-327 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/supervisor/socket.rs"},"region":{"startLine":266}}}],"partialFingerprints":{"codehealthFindingId/v1":"e98cc13e0cd2838acc6f7f19b8dbe1c1f7d71b2188b1519b68233cf87a6172c4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): crates/nono-cli/src/tool-sandbox/platform/linux.rs:3780-3784 | crates/nono-cli/src/tool-sandbox/platform/macos.rs:3183-3187 \u2014 before extracting anything, compare \u0060crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060 and \u0060crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060 as WHOLE FILES: this scan already matched 118 separate duplicated blocks between them, totalling at least 1796 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":3780}}}],"partialFingerprints":{"codehealthFindingId/v1":"20479dec1f3e68a1fe969b7ca20d6e874df2d1100f26d6b39cb027b8a7bac155"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): crates/nono-cli/src/profile_cmd.rs:2051-2055 | crates/nono-cli/src/profile_cmd.rs:2188-2192 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":2051}}}],"partialFingerprints":{"codehealthFindingId/v1":"6da0d61d8b01ba81abba591d02ea77ad0335deed79cb475c2cd1878c6475a4e8"}},{"ruleId":"D4","level":"warning","message":{"text":"Edited copy of a member (88 corresponding lines): tool-sandbox-examples/kubernetes-with-approval/make-proxy-kubeconfig.py:46-133 | tool-sandbox-examples/kubernetes/make-proxy-kubeconfig.py:46-133 \u2014 These two members are one piece of code written twice and then edited apart: 88 consecutive lines correspond almost exactly, broken only by small local edits. Most of that correspondence is NOT reported as duplicated blocks below \u2014 the edits cut it into fragments and only the largest of them clear the block floor, so the rows below understate it. The repair is at the members\u0027 grain \u2014 factor the shared implementation into one the two call with their differences as parameters or as an injected step, or, where the difference is systematic (an extra return value, one transport against another), generate one from the other. Left alone, the next edit has to be made twice and the two will drift further apart."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tool-sandbox-examples/kubernetes-with-approval/make-proxy-kubeconfig.py"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"ac31fb9fd862340cd04e7f37e1718bef8fccd0ae3ef58fb7aa4af5ea969e09c1"}},{"ruleId":"D4","level":"warning","message":{"text":"Members sharing a duplicated core (4 members, 50\u002B identical tokens): crates/nono/src/sandbox/linux.rs:2431-2461 | crates/nono/src/sandbox/linux.rs:2542-2565 | crates/nono/src/sandbox/linux.rs:3569-3702 | crates/nono/src/sandbox/linux.rs:3721-3757 \u2014 These 4 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below \u2014 it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 4 times. The repair is at the members\u0027 grain \u2014 factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 4 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/sandbox/linux.rs"},"region":{"startLine":2431}}}],"partialFingerprints":{"codehealthFindingId/v1":"7c1025af000d1fd811de98776501affe54db04e263552897dea117e0a6fb8c6a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (21\u201324 lines \u00D7 2): crates/nono/src/sandbox/macos.rs:743-766 | crates/nono/src/sandbox/macos.rs:779-799 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/sandbox/macos.rs"},"region":{"startLine":743}}}],"partialFingerprints":{"codehealthFindingId/v1":"2cdc989a90941f5d391ac8bf04cdbce120946641bcc5901b59498de9e1a9b1e6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13\u201314 lines \u00D7 2): crates/nono/src/sandbox/linux.rs:886-898 | crates/nono/src/sandbox/linux.rs:1044-1057 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/sandbox/linux.rs"},"region":{"startLine":886}}}],"partialFingerprints":{"codehealthFindingId/v1":"9be8294d141fe548adeff32b6bb5912154ddbe8b8abe41720757f69af617e75b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/nono/src/sandbox/macos.rs:221-232 | crates/nono/src/sandbox/macos.rs:235-246 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/sandbox/macos.rs"},"region":{"startLine":221}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7fff0948ecaa7c9d298d995dc4ceec0041351843bdc990ed8a7e71aa823ad1b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): crates/nono/src/sandbox/linux.rs:899-904 | crates/nono/src/sandbox/linux.rs:1072-1077 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/sandbox/linux.rs"},"region":{"startLine":899}}}],"partialFingerprints":{"codehealthFindingId/v1":"4e90cf7789741a04e9a6c75def79a5c07958562b8f8903b857ac6b63650ca9c3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (3\u20135 lines \u00D7 4): crates/nono/src/sandbox/linux.rs:2432-2436 | crates/nono/src/sandbox/linux.rs:2543-2547 | crates/nono/src/sandbox/linux.rs:3580-3582 | crates/nono/src/sandbox/linux.rs:3731-3733 \u2014 all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/sandbox/linux.rs"},"region":{"startLine":2432}}}],"partialFingerprints":{"codehealthFindingId/v1":"ab6c1fa7ee3258181181221538b1a52400ac4cf185ee2df2a74255e8c5db24af"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): crates/nono/src/sandbox/linux.rs:2661-2678 | crates/nono/src/sandbox/linux.rs:2694-2709 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/sandbox/linux.rs"},"region":{"startLine":2661}}}],"partialFingerprints":{"codehealthFindingId/v1":"058ecd580da1a5aadbe8654e0f39251ef24af17c71091bc982b5a93fbdff0b70"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): crates/nono/src/sandbox/macos.rs:422-426 | crates/nono/src/sandbox/macos.rs:444-448 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/sandbox/macos.rs"},"region":{"startLine":422}}}],"partialFingerprints":{"codehealthFindingId/v1":"8b82ac0f9100b1a81bf0304c59a672b155828204d1c0e2670af2eff4634d8f44"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (40 lines \u00D7 2): tool-sandbox-examples/kubernetes-with-approval/make-proxy-kubeconfig.py:94-133 | tool-sandbox-examples/kubernetes/make-proxy-kubeconfig.py:94-133 \u2014 \u0060tool-sandbox-examples/kubernetes-with-approval/make-proxy-kubeconfig.py\u0060 and \u0060tool-sandbox-examples/kubernetes/make-proxy-kubeconfig.py\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 3 separate duplicated blocks between them, totalling at least 73 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at \u0060tool-sandbox-examples/kubernetes-with-approval/make-proxy-kubeconfig.py:94\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tool-sandbox-examples/kubernetes-with-approval/make-proxy-kubeconfig.py"},"region":{"startLine":94}}}],"partialFingerprints":{"codehealthFindingId/v1":"f4c9c7c9860ae14ab7f19ec48730320c6a9df0632a275509d7cc93c2978b8de9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (26 lines \u00D7 2): tool-sandbox-examples/kubernetes-with-approval/https-front-proxy.py:34-59 | tool-sandbox-examples/kubernetes/https-front-proxy.py:34-59 \u2014 \u0060tool-sandbox-examples/kubernetes-with-approval/https-front-proxy.py\u0060 and \u0060tool-sandbox-examples/kubernetes/https-front-proxy.py\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 4 separate duplicated blocks between them, totalling at least 101 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tool-sandbox-examples/kubernetes-with-approval/https-front-proxy.py"},"region":{"startLine":34}}}],"partialFingerprints":{"codehealthFindingId/v1":"78cb10da582387c793784c0d120502eb792cd28ac2ef14238d9f01f7e01eb186"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (26 lines \u00D7 2): tool-sandbox-examples/kubernetes-with-approval/https-front-proxy.py:120-145 | tool-sandbox-examples/kubernetes/https-front-proxy.py:120-145 \u2014 \u0060tool-sandbox-examples/kubernetes-with-approval/https-front-proxy.py\u0060 and \u0060tool-sandbox-examples/kubernetes/https-front-proxy.py\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 4 separate duplicated blocks between them, totalling at least 101 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tool-sandbox-examples/kubernetes-with-approval/https-front-proxy.py"},"region":{"startLine":120}}}],"partialFingerprints":{"codehealthFindingId/v1":"cdc3908f6a0b6b9bf777f3b6bb2a5cc16cda23c5530efbfea1e87b361cea3761"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (23 lines \u00D7 2): tool-sandbox-examples/kubernetes-with-approval/make-proxy-kubeconfig.py:46-68 | tool-sandbox-examples/kubernetes/make-proxy-kubeconfig.py:46-68 \u2014 \u0060tool-sandbox-examples/kubernetes-with-approval/make-proxy-kubeconfig.py\u0060 and \u0060tool-sandbox-examples/kubernetes/make-proxy-kubeconfig.py\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 3 separate duplicated blocks between them, totalling at least 73 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. Read the line range as the matched WINDOW rather than a finished unit: at \u0060tool-sandbox-examples/kubernetes-with-approval/make-proxy-kubeconfig.py:46\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tool-sandbox-examples/kubernetes-with-approval/make-proxy-kubeconfig.py"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"41672906607bcd78c0ed279b37e5808c41b93c90ff6bbd58a3778eb70a9f1e60"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (22 lines \u00D7 2): tool-sandbox-examples/kubernetes-with-approval/https-front-proxy.py:62-83 | tool-sandbox-examples/kubernetes/https-front-proxy.py:62-83 \u2014 \u0060tool-sandbox-examples/kubernetes-with-approval/https-front-proxy.py\u0060 and \u0060tool-sandbox-examples/kubernetes/https-front-proxy.py\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 4 separate duplicated blocks between them, totalling at least 101 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tool-sandbox-examples/kubernetes-with-approval/https-front-proxy.py"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"4fe230e7175e52e4fdb5f3c6fffd7478ae6cea3ccf24e46a79eed40ad7bad002"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): tool-sandbox-examples/kubernetes-with-approval/make-proxy-kubeconfig.py:14-23 | tool-sandbox-examples/kubernetes/make-proxy-kubeconfig.py:14-23 \u2014 \u0060tool-sandbox-examples/kubernetes-with-approval/make-proxy-kubeconfig.py\u0060 and \u0060tool-sandbox-examples/kubernetes/make-proxy-kubeconfig.py\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 3 separate duplicated blocks between them, totalling at least 73 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. The \u0060return\u0060 at the foot of the matched lines is the enclosing body\u0027s own terminal exit, not an early one: it moves with them unchanged, and each site calls the extracted unit from the position that \u0060return\u0060 occupied \u2014 no decision has to be handed back and re-acted on."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tool-sandbox-examples/kubernetes-with-approval/make-proxy-kubeconfig.py"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c033bbb27c23f4231a45129d6c1df6d32ccd3411c7f4d7a1656581666b77dfe"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (27 lines \u00D7 2): tool-sandbox-examples/kubernetes-with-approval/https-front-proxy.py:90-116 | tool-sandbox-examples/kubernetes/https-front-proxy.py:90-116 \u2014 \u0060tool-sandbox-examples/kubernetes-with-approval/https-front-proxy.py\u0060 and \u0060tool-sandbox-examples/kubernetes/https-front-proxy.py\u0060 are one unit implemented once per sibling directory, so they are most likely parallel implementations of one contract rather than a copy of each other \u2014 this scan matched 4 separate duplicated blocks between them, totalling at least 101 lines. If both are selected at run time, neither can be retired in favour of the other, and the lines that DIFFER between them are the reason both exist. The move that pays here is to hoist the identical part into a shared location the whole family can reach and give what differs a parameter or a seam, so a change lands once instead of once per sibling; extracting one helper per block leaves every sibling to drift on its own. The \u0060return\u0060 at the foot of the matched lines is the enclosing body\u0027s own terminal exit, not an early one: it moves with them unchanged, and each site calls the extracted unit from the position that \u0060return\u0060 occupied \u2014 no decision has to be handed back and re-acted on."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tool-sandbox-examples/kubernetes-with-approval/https-front-proxy.py"},"region":{"startLine":90}}}],"partialFingerprints":{"codehealthFindingId/v1":"bce4c9945f9f01443e6d571320c5927a710d47398e1f126a774fca1dc5731b15"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: nono: nono: abstractness 0.01, instability 0.00, distance 0.99 \u2014 zone of pain \u2014 concrete and depended on by 3 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"03107e968428a15dc3588721a1ff5c74e1fbcd6ca93cc5e3a0cdf47ed1ff7846"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: CapabilitySet (LCOM4 12): CapabilitySet\u0027s methods fall into 12 groups that share no field and call none of each other, against a bar of more than 3 for this run (LCOM4, configurable \u2014 your repository\u0027s bar is the one quoted here). Each group is a set of methods reachable from one another through shared fields or direct calls, so 12 groups means the type has that many internally-connected clusters with nothing tying them together. Types whose shape makes a high count expected \u2014 and which would otherwise dominate this list \u2014 are excluded before this row is raised, so this is a genuine split candidate rather than a metric reading. It is still a shape, not a defect: confirm the groups match responsibilities you can name before splitting."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/capability.rs"},"region":{"startLine":951}}}],"partialFingerprints":{"codehealthFindingId/v1":"a7ec063506d2b49fe8b6f0251a96388f347c0b14301c70a11389e20c38e06fd2"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/exec_strategy.rs: crates/nono-cli/src/exec_strategy.rs changed 20 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 106 in nono_cli::exec_strategy::execute_supervised at line 550. 11 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/exec_strategy.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":550}}}],"partialFingerprints":{"codehealthFindingId/v1":"6de4d2ff27c93790e7f304124c55cfadfb52a2d8cfb7465ff21c7a9e09d8860c"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/tool-sandbox/platform/linux.rs: crates/nono-cli/src/tool-sandbox/platform/linux.rs changed 36 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 39 in nono_cli::tool-sandbox::platform::linux::handle_shim_stream_inner at line 1265. 20 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/tool-sandbox/platform/linux.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/linux.rs"},"region":{"startLine":1265}}}],"partialFingerprints":{"codehealthFindingId/v1":"e69ff64e49708bb9f7de2f1c13a8ee9466773e6bf074fb6b8dedd2b68b2ab697"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/tool-sandbox/platform/macos.rs: crates/nono-cli/src/tool-sandbox/platform/macos.rs changed 32 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 38 in nono_cli::tool-sandbox::platform::macos::handle_shim_stream_inner at line 972. 20 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/tool-sandbox/platform/macos.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":972}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee17a4fb2cdd9289d755a4c4059b26e296b25cdb6acbc66ca597f3b92c36a56a"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/profile/mod.rs: crates/nono-cli/src/profile/mod.rs changed 35 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 33 in nono_cli::profile::validate_custom_credential at line 607. 16 of those changes were fix/bug commits, and the other 19 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/profile/mod.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":607}}}],"partialFingerprints":{"codehealthFindingId/v1":"f6f406f4a653c82167f49e7820fe056a4a4b19120e0af4b6ef0b6df791465a2c"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-proxy/src/server.rs: crates/nono-proxy/src/server.rs changed 22 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 41 in nono_proxy::server::handle_connection at line 1477. 11 of those changes were fix/bug commits, and the other 11 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-proxy/src/server.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/server.rs"},"region":{"startLine":1477}}}],"partialFingerprints":{"codehealthFindingId/v1":"5617fe3c2e639010ce4b75db85238a6a52bff534143917e2f688c2ab5451a8f6"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/execution_runtime.rs: crates/nono-cli/src/execution_runtime.rs changed 17 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 53 in nono_cli::execution_runtime::execute_sandboxed at line 203. 11 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/execution_runtime.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/execution_runtime.rs"},"region":{"startLine":203}}}],"partialFingerprints":{"codehealthFindingId/v1":"bcc94192d3d52bbb5061a5029ba81f49f21ba5d25ee8351464d47a44fd12449c"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/sandbox_prepare.rs: crates/nono-cli/src/sandbox_prepare.rs changed 21 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 37 in nono_cli::sandbox_prepare::prepare_sandbox at line 1427. 11 of those changes were fix/bug commits, so the churn is repair rather than feature work. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/sandbox_prepare.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/sandbox_prepare.rs"},"region":{"startLine":1427}}}],"partialFingerprints":{"codehealthFindingId/v1":"25d5fe84a1f66fc3cb6da11b3be4527dfd460095d4678f3af0726a3dbea102c3"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/proxy_runtime.rs: crates/nono-cli/src/proxy_runtime.rs changed 27 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 25 in nono_cli::proxy_runtime::prepare_proxy_launch_options at line 1430. 13 of those changes were fix/bug commits, and the other 14 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/proxy_runtime.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_runtime.rs"},"region":{"startLine":1430}}}],"partialFingerprints":{"codehealthFindingId/v1":"b82f899d39481a5f19b93767c4dfb6653f1f80b0d2ce86d959e08754238a47db"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/policy.rs: crates/nono-cli/src/policy.rs changed 17 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 32 in nono_cli::policy::apply_macos_keychain_db_exception at line 1435. 7 of those changes were fix/bug commits, and the other 10 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/policy.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/policy.rs"},"region":{"startLine":1435}}}],"partialFingerprints":{"codehealthFindingId/v1":"bb2ab0557edf650538596eb373b4627edc1e66527254b6f454b443beff940fe3"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/profile_cmd.rs: crates/nono-cli/src/profile_cmd.rs changed 10 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 54 in nono_cli::profile_cmd::cmd_show at line 855. 3 of those changes were fix/bug commits, and the other 7 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/profile_cmd.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_cmd.rs"},"region":{"startLine":855}}}],"partialFingerprints":{"codehealthFindingId/v1":"77670b88d3dcf3b39aa7917241f22ed483a9c7db4e71a333359c06aba949c716"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/capability_ext.rs: crates/nono-cli/src/capability_ext.rs changed 9 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 52 in CapabilitySet::from_profile at line 693. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/capability_ext.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/capability_ext.rs"},"region":{"startLine":693}}}],"partialFingerprints":{"codehealthFindingId/v1":"1f3967dd29e9b09eeff4c7c07e58612a36ee8601944c4b56b7c2a2bc5cafe6c0"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-proxy/src/tls_intercept/handle.rs: crates/nono-proxy/src/tls_intercept/handle.rs changed 12 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 34 in nono_proxy::tls_intercept::handle::handle_inner_request at line 1030. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-proxy/src/tls_intercept/handle.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/handle.rs"},"region":{"startLine":1030}}}],"partialFingerprints":{"codehealthFindingId/v1":"3594a88073005acf736204290e78e298e21adeaea613cb4f062fa29f8863799f"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/command_policy.rs: crates/nono-cli/src/command_policy.rs changed 19 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 21 in nono_cli::command_policy::validate_command at line 1597. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/command_policy.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_policy.rs"},"region":{"startLine":1597}}}],"partialFingerprints":{"codehealthFindingId/v1":"43cc526d9192df0b4359dcb6ab90d3e81616e76980db3cba6d9c034238c8b6e8"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/profile_runtime.rs: crates/nono-cli/src/profile_runtime.rs changed 16 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 22 in nono_cli::profile_runtime::prepare_profile_with_options at line 658. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/profile_runtime.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_runtime.rs"},"region":{"startLine":658}}}],"partialFingerprints":{"codehealthFindingId/v1":"d9d0f80ec8ebcfbda9ed9030ea5fc1ee791888fd6b6cefd1537ac357718eae7e"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/exec_strategy/supervisor_linux.rs: crates/nono-cli/src/exec_strategy/supervisor_linux.rs changed 8 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 44 in nono_cli::exec_strategy::supervisor_linux::handle_received_filesystem_notification at line 195. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/exec_strategy/supervisor_linux.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy/supervisor_linux.rs"},"region":{"startLine":195}}}],"partialFingerprints":{"codehealthFindingId/v1":"8be58c0f91761b8c26e8c6cf5af9115ff6617939f8be8a3289f3db3d4cf8c0ec"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono/src/sandbox/linux.rs: crates/nono/src/sandbox/linux.rs changed 10 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 33 in nono::sandbox::linux::apply_with_abi_inner at line 1037. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono/src/sandbox/linux.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/sandbox/linux.rs"},"region":{"startLine":1037}}}],"partialFingerprints":{"codehealthFindingId/v1":"00a066b7d0371ceef2b795464457777bbed753a0bf7d647bec17ad73023f3c69"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono/src/sandbox/macos.rs: crates/nono/src/sandbox/macos.rs changed 6 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 51 in nono::sandbox::macos::generate_profile at line 498. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono/src/sandbox/macos.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/sandbox/macos.rs"},"region":{"startLine":498}}}],"partialFingerprints":{"codehealthFindingId/v1":"31f3ca47ddf1b4468ee87eaedf6f9677166b1676e56415eb678a22dc1a70ed95"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-proxy/src/tls_intercept/h2_forward.rs: crates/nono-proxy/src/tls_intercept/h2_forward.rs changed 9 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 31 in nono_proxy::tls_intercept::h2_forward::handle_h2_stream at line 232. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-proxy/src/tls_intercept/h2_forward.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/tls_intercept/h2_forward.rs"},"region":{"startLine":232}}}],"partialFingerprints":{"codehealthFindingId/v1":"b5f91ce28c62e9a9cb27f2ef7db47599902eca8698df54ad2648bf58bdf99818"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-proxy/src/reverse.rs: crates/nono-proxy/src/reverse.rs changed 7 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 37 in nono_proxy::reverse::handle_reverse_proxy at line 128. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-proxy/src/reverse.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/reverse.rs"},"region":{"startLine":128}}}],"partialFingerprints":{"codehealthFindingId/v1":"3c346fd5bf176e85f17f7bb37813ba544bb8fc35ae9e54adfb776e0c35b1376e"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/audit_commands.rs: crates/nono-cli/src/audit_commands.rs changed 7 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 33 in nono_cli::audit_commands::cmd_show at line 348. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/audit_commands.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_commands.rs"},"region":{"startLine":348}}}],"partialFingerprints":{"codehealthFindingId/v1":"119ca6364d05d60067eefa11b3bb7d4fae60b028d894c515e485d6b8188a9188"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/launch_runtime.rs: crates/nono-cli/src/launch_runtime.rs changed 13 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 17 in nono_cli::launch_runtime::prepare_run_launch_plan at line 333. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/launch_runtime.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/launch_runtime.rs"},"region":{"startLine":333}}}],"partialFingerprints":{"codehealthFindingId/v1":"83d31aa5342f237b598b11f938c0f7443fd81b7b7d3cf8a98bec8eb67d8734c1"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/app_runtime.rs: crates/nono-cli/src/app_runtime.rs changed 7 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 31 in nono_cli::app_runtime::dispatch_command at line 36. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/app_runtime.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/app_runtime.rs"},"region":{"startLine":36}}}],"partialFingerprints":{"codehealthFindingId/v1":"8900034ba6bbbc2cddf6c45358f424f06f189dc2bee2e0a2f636b9d7a13289ca"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/output.rs: crates/nono-cli/src/output.rs changed 8 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 26 in nono_cli::output::print_capabilities at line 73. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/output.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/output.rs"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"b6cf7e1051476e338567a5c41277ef98fbf731fff2862dfdc5c7a0741f1906b3"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/profile_save_runtime.rs: crates/nono-cli/src/profile_save_runtime.rs changed 9 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 23 in nono_cli::profile_save_runtime::interactive_denial_selector at line 1450. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/profile_save_runtime.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile_save_runtime.rs"},"region":{"startLine":1450}}}],"partialFingerprints":{"codehealthFindingId/v1":"84cfb41e1fde4b5050f538ee23fc999ffa2e2afc1adf02bf4126d6f3a3486d79"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/diagnostic/formatter.rs: crates/nono-cli/src/diagnostic/formatter.rs changed 7 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 25 in DiagnosticFormatter::format_supervised_footer_with_diagnostics at line 1250. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/diagnostic/formatter.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/diagnostic/formatter.rs"},"region":{"startLine":1250}}}],"partialFingerprints":{"codehealthFindingId/v1":"864e62e420624fc9e762ce1ff7b6d19b07472e188f504be6552bbf2c08639e82"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/why_runtime.rs: crates/nono-cli/src/why_runtime.rs changed 8 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 21 in nono_cli::why_runtime::run_why at line 117. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/why_runtime.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/why_runtime.rs"},"region":{"startLine":117}}}],"partialFingerprints":{"codehealthFindingId/v1":"b3b473566fc2f5f72e6e79d750fa4f3337f50cc22d2d6fd8a48cbb71794eb1db"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/supervised_runtime.rs: crates/nono-cli/src/supervised_runtime.rs changed 7 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 19 in nono_cli::supervised_runtime::execute_supervised_runtime at line 210. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/supervised_runtime.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/supervised_runtime.rs"},"region":{"startLine":210}}}],"partialFingerprints":{"codehealthFindingId/v1":"213dd4824122dba430052d39906f4a6de381983d3210592d8502a01a1c2855fe"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/proxy_command.rs: crates/nono-cli/src/proxy_command.rs changed 8 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 16 in nono_cli::proxy_command::build_launch_options at line 188. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/proxy_command.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/proxy_command.rs"},"region":{"startLine":188}}}],"partialFingerprints":{"codehealthFindingId/v1":"26168d1789e4ef4008c14a105779df99f579b04432cedbbbca46471e72772a82"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/query_ext.rs: crates/nono-cli/src/query_ext.rs changed 7 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 18 in nono_cli::query_ext::query_network at line 240. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/query_ext.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/query_ext.rs"},"region":{"startLine":240}}}],"partialFingerprints":{"codehealthFindingId/v1":"3edce72a940d9cb062722866430f57ed209be48f34ca37559b0821dfbec3e576"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-proxy/src/credential.rs: crates/nono-proxy/src/credential.rs changed 6 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 19 in CredentialStore::load_with_diagnostics at line 222. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-proxy/src/credential.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/credential.rs"},"region":{"startLine":222}}}],"partialFingerprints":{"codehealthFindingId/v1":"cdf96a79c23132a8ad009a1d88293595de4e760b2e5c86bfb5ccf4cf2e294777"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/profile/credential_provider.rs: crates/nono-cli/src/profile/credential_provider.rs changed 4 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 20 in nono_cli::profile::credential_provider::validate_credential_provider_entries at line 149. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/profile/credential_provider.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/credential_provider.rs"},"region":{"startLine":149}}}],"partialFingerprints":{"codehealthFindingId/v1":"ca8ad997c9cec1397c46ecdc27c27b20225b6e96cb576b77430224add2c0fff2"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: bindings/c/src/lib.rs: bindings/c/src/lib.rs changed 3 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 23 in nono_ffi::map_error at line 87. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- bindings/c/src/lib.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"bindings/c/src/lib.rs"},"region":{"startLine":87}}}],"partialFingerprints":{"codehealthFindingId/v1":"f9cca680e9cfb2d96e9ff4ee20ffa7042783dd0af1eee333e6d60605fce5ce2b"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/nono-cli/src/rollback_runtime.rs: crates/nono-cli/src/rollback_runtime.rs changed 3 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 17 in nono_cli::rollback_runtime::finalize_supervised_exit at line 505. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/rollback_runtime.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/rollback_runtime.rs"},"region":{"startLine":505}}}],"partialFingerprints":{"codehealthFindingId/v1":"9756bd3ef03559c56b6e6a6d535ee5db5420247c637efc398fa990d506c9c77d"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: crates/nono-cli/src/tool-sandbox/mod.rs: crates/nono-cli/src/tool-sandbox/mod.rs changed 12 times in last 90 days and 10 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 6 (its worst body is nono_cli::tool-sandbox::restore_dir_tree_writable at line 330), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix: file grants negate filesystem.deny - #1949 (#2019)\u201D; \u201Cfix(tool-sandbox): derive shim broker socket from executable path (#2002)\u201D; \u201Cfix(tool-sandbox): isolate network policy by effective command scope (#1981)\u201D; \u201Cfix(exec): keep session temp files alive against the OS reaper (#1942)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/tool-sandbox/mod.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/mod.rs"},"region":{"startLine":330}}}],"partialFingerprints":{"codehealthFindingId/v1":"a6f83320f4ef21bae0f64dbf12454b7e60dd16b06cbab1596e461c6e33e03402"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: crates/nono-cli/src/tool-sandbox/policy.rs: crates/nono-cli/src/tool-sandbox/policy.rs changed 9 times in last 90 days and 5 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 12 (its worst body is nono_cli::tool-sandbox::policy::evaluate_invocation_policy at line 277), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix(keystore): refuse empty sanitized PATH for host-side brokers (#1895)\u201D; \u201Cfix(tool-sandbox): isolate network policy by effective command scope (#1981)\u201D; \u201Cfix(proxy): fail closed on non-granted endpoint approvals in TLS intercept (#1585)\u201D; \u201Cfix(cli): add explicit intercept match predicates (#1364)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/tool-sandbox/policy.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/policy.rs"},"region":{"startLine":277}}}],"partialFingerprints":{"codehealthFindingId/v1":"78811e6a3af6f96a815456a9113ed796e1cf1ea8c867a5a87559a31f0cc4d28e"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: crates/nono-cli/src/sandbox_state.rs: crates/nono-cli/src/sandbox_state.rs changed 7 times in last 90 days and 4 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 11 (its worst body is nono_cli::sandbox_state::cleanup_stale_state_files at line 606), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix: file grants negate filesystem.deny - #1949 (#2019)\u201D; \u201Cfix(why): tolerate volatile process-relative aliases in --self reload (#1873)\u201D; \u201Cfix(why): evaluate network.deny_domain in nono why host queries (#1751)\u201D; \u201Cfix(policy): survive atomic replacement of resolv.conf; report stale \u2026 (#1448)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/sandbox_state.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/sandbox_state.rs"},"region":{"startLine":606}}}],"partialFingerprints":{"codehealthFindingId/v1":"0ba0f6117fc4a49413ae9e9b23ca42cbb18e51b3c6b377fdf4e76bb212272178"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: crates/nono-cli/src/command_runtime.rs: crates/nono-cli/src/command_runtime.rs changed 5 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 12 (its worst body is nono_cli::command_runtime::run_sandbox at line 155), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix: allow non-UTF-8 command line arguments (#1521)\u201D; \u201Cfix(cli): reject upstream proxy with block net (#1392)\u201D; \u201Cfix(tool-sandbox): resolve command policy paths against the live cwd (#1339)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/command_runtime.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_runtime.rs"},"region":{"startLine":155}}}],"partialFingerprints":{"codehealthFindingId/v1":"9eae8274fa2c179ba25336d6bdecb8cfa373ac9041ba4b1cb865f8b8b51e3c27"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: crates/nono-proxy/src/token.rs: crates/nono-proxy/src/token.rs changed 5 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 5 (its worst body is nono_proxy::token::validate_proxy_auth at line 319), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix(credentials): configurable phantom format for prefix-sniffing clients (#1489)\u201D; \u201Cfix(proxy): add redeem_phantoms for by-value phantom redemption (#1469)\u201D; \u201Cfix(proxy): decode Basic auth for basic_auth phantom validation (#1683)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-proxy/src/token.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/token.rs"},"region":{"startLine":319}}}],"partialFingerprints":{"codehealthFindingId/v1":"b3a944dc02e7b4a1c09b888f88c22744f4ea9624a908376a4f3b2e56fc2b763e"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: crates/nono-cli/src/terminal_approval.rs: crates/nono-cli/src/terminal_approval.rs changed 4 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 13 (its worst body is nono_cli::terminal_approval::sanitize_for_terminal at line 139), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix(cli): stop save-prompt failures from overriding the child exit code (#1804)\u201D; \u201Cfix(cli): guard consent prompts against type-ahead\u201D; \u201Cfix(proxy): fail closed on non-granted endpoint approvals in TLS intercept (#1585)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/terminal_approval.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/terminal_approval.rs"},"region":{"startLine":139}}}],"partialFingerprints":{"codehealthFindingId/v1":"2b17dd9058e3cd5a966c78ffe5f8d376913edc98232ee1635ec438520430bab8"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: crates/nono-cli/src/tool-sandbox/credentials.rs: crates/nono-cli/src/tool-sandbox/credentials.rs changed 4 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 9 (its worst body is nono_cli::tool-sandbox::credentials::resolve_credentials at line 39), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix(tool-sandbox): isolate network policy by effective command scope (#1981)\u201D; \u201Cfix(sandbox): expand env vars anywhere in local-socket path, not just as prefix (#1762)\u201D; \u201Cfix(credentials): configurable phantom format for prefix-sniffing clients (#1489)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/tool-sandbox/credentials.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/credentials.rs"},"region":{"startLine":39}}}],"partialFingerprints":{"codehealthFindingId/v1":"badf22f95e46fe0540d63733866319f29ca36e432b6d4ccce22ba7d92563d08b"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: crates/nono-cli/src/tool-sandbox/token_broker.rs: crates/nono-cli/src/tool-sandbox/token_broker.rs changed 4 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 10 (its worst body is TokenBroker::scan_and_reissue at line 273), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix(cli): always re-invoke the credential source for ambient captures (#1849)\u201D; \u201Cfix(credentials): configurable phantom format for prefix-sniffing clients (#1489)\u201D; \u201Cfix(proxy): add redeem_phantoms for by-value phantom redemption (#1469)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-cli/src/tool-sandbox/token_broker.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/token_broker.rs"},"region":{"startLine":273}}}],"partialFingerprints":{"codehealthFindingId/v1":"dee482fed6b92f19d76d435622950898c3b85a54c1390e0f58be959e10f26f1a"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: crates/nono/src/error.rs: crates/nono/src/error.rs changed 4 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 12 (its worst body is NonoError::diagnostic_code at line 225), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix(cli): stop save-prompt failures from overriding the child exit code (#1804)\u201D; \u201Cfix(fs): validate unix socket nodes and normalize landlock (#1654)\u201D; \u201Cfix(audit): propogate errors after unparseable ledger (#1596)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono/src/error.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono/src/error.rs"},"region":{"startLine":225}}}],"partialFingerprints":{"codehealthFindingId/v1":"812b126e37c6a2d627c9def6e592f194236c14910bd5ed8d3092ac93dce4e234"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: crates/nono-proxy/src/forward.rs: crates/nono-proxy/src/forward.rs changed 4 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 14 (its worst body is nono_proxy::forward::rewrite_http1_response at line 367), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfix(proxy): fail closed when upstream DNS returns no addresses (#1894)\u201D; \u201Cfix(proxy): add authenticated WebSocket tunneling for CONNECT/TLS-intercept routes (#1443)\u201D; \u201Cfix(oauth): harden capture security boundaries\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-07-02..2026-09-30, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-02 16:27:11 \u002B01:00\u0027 --until=\u00272026-09-30 16:27:11 \u002B01:00\u0027 --full-history --no-merges -- crates/nono-proxy/src/forward.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/forward.rs"},"region":{"startLine":367}}}],"partialFingerprints":{"codehealthFindingId/v1":"abd4a94be5e14b7d85a065286f4ab08096cd675c050eb83339130bf935547f81"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #1: If anonymized user #1 becomes unavailable, 10 significant file(s) lose their only recent owner: crates/nono-cli/src/connect_client.rs, crates/nono/src/trust/signing.rs, crates/nono-cli/src/platform.rs, crates/nono-cli/src/platform_client.rs, crates/nono/src/undo/object_store.rs, crates/nono/src/undo/merkle.rs, crates/nono-proxy/src/oauth_capture/persist.rs, crates/nono-proxy/src/approval.rs (\u002B2 more). Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"29b7eada007e1f9c4322454c28607edc1e8597a3e1c2e82e28900cb0b0469023"}},{"ruleId":"D16","level":"note","message":{"text":"Further sole-owners (lower concentration): 4 other contributor(s) are each the sole owner of a small amount of code below the off-boarding threshold \u2014 folded into the bus-factor score and metrics (16 single-owned of 192 analysed files in total, counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 192 of the 205 production source files in this repository met that bar). They are anonymized user #2 (2 file(s)), anonymized user #3 (2 file(s)), anonymized user #4 (1 file(s)), anonymized user #5 (1 file(s)) \u2014 spread or document their files in the same way, at lower priority than the named off-boarding risks above."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6eac528f2429e724e1a97ed868f79eefbcf1888dab4af9a9e673429369bb5b2f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Refactor to return build_config_uri extension if the same as workflow. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/trust_cmd.rs"},"region":{"startLine":1519}}}],"partialFingerprints":{"codehealthFindingId/v1":"e545534874d06463e698ad385bc66b7899fb0ad7893d8a39c6f39a09882c6755"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: /// TODO: Refactor \u0060crate::url_open::validate_url\u0060 to return \u0060UrlDenial\u0060 directly \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/exec_strategy.rs"},"region":{"startLine":3796}}}],"partialFingerprints":{"codehealthFindingId/v1":"d54a898b61ce0e58a2cef1db56174af0b24ae4414cc9268ba7f83342d3bf3ede"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no project overview: The root README is a marketing banner with no description of what nono does or what it is for. Replace the centered logo and boilerplate links with an overview paragraph explaining that nono provides capability-based OS-enforced sandboxing, its security goals (secure attestation), and which tools it protects."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"66dbf18d06aa983c06246108610908ba99aae6784280b3aacd1a6655733d71be"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no contributor guidance: The root README gives no contribution guidance. Link to the repository\u0027s CONTRIBUTING doc or add a short PR/bug-reporting note."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"620f29787918fa3406ae55cb63eefa1b50410845435c4e47bda852816aaea084"}},{"ruleId":"D26","level":"note","message":{"text":"Split crates/nono-cli: The cli is huge and sprawls across seven namespaces (profile, config, tool-sandbox), a classic grab-bag. Suggested: split into focused sub-commands or tools over the listed namespaces"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"002bc925e6b1c1b79b237c097c803ed01c4ba322eb3dfd3256083a406f7dee94"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a6c11203751867c8a0c85e708317d4ca2e48c62273e59e07d59c91da88409047"},"properties":{"commitSha":"51251ee2a0af5eaefd31d8097b585f6c1404d52a"}},{"ruleId":"D28","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3cdfd7beb31b791ae18dcb425e21eb157c842e7bbcd522cc330573c1a6538db1"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d5b8f11381d61a58459ffc7c595fd52d09c03c711894a63a9578043d2338412b"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1512220af25771141d05c8c7f0b4bb60b91838e817363fd0f17ff2f31862369b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"482e3b19efd040fb2215efbc5e65f5b9996234817368c5a9198eb89910e46231"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"66c146f8abb78c72dee6f3c9b72e18e415582d6aa88c9bd0c1a790369f994ff3"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"def82dfc51c6d24497a09b58894eac5985cc76f5b0d70a0bd974bcfded4972d8"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1823670305e43a169b48fbd917e572e29e7aa49da335641c631705df063824a1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"28ab008102def74a04e8d1b002c47f0a1413e8c4abcde4eb3daa54b559b2d678"},"taxa":[{"id":"CWE-214","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-532","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8e53f4b66ba3b0fdcde6a38fb8bb6016b79bff509494d658533609e7bca38e3e"},"taxa":[{"id":"CWE-214","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-532","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"52123342ecad2571831f7a780e9c0ca16aefd94bc39614a3ae8237b65cf8f603"},"taxa":[{"id":"CWE-214","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-532","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"59ebe449dfcbae7d4e354b30c32ea96381c71acf0ab25728efdfdd549a7c7d3b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bcea129e205ddd7b6d66add6e9645cf6327f990bc1fe6250b82e2f45f2b8f713"},"taxa":[{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"af1fddfddc6075c955ad4f89186d263ba5423c0cbb35e3c1183d745073d64ed2"},"taxa":[{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b3d412717b19e6d29a64747ffa27cf6983525295cb96a77cedb22a05ff19c48c"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"10b0b07f0686ab5e093b9362ee74b76f4cc5d2d638e54a8db376117300d3a648"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"73dc63e9a80d7539f9513ca3aceb7a08096851ba1c08e5e1e42b0fb7160a7369"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"095db69ee536088bf604ca7233ec7561eb5d4dd1110edce1b31f08cfd8a24b9d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3fa80d44b864f2e2bcf4cae9780fdf19bb85d5962086c8f67a9ffd3c01a75281"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"389dedacee1756a925632c34e82db77b969fb5c7350bc05994e63e077c3989d5"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"19129fa0c6765e9e62ea9158577a96d5bcac97e0a7a22f37ddc382bf9c88ca6d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0f6c7a38a464f2735b8f8daca7a0f02e5da8a89bff5ad634198b21daea68100d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a46a46fd7fc80b3564fa3746a17533aa9fa7969db09f0f27d6c56cfc91c35829"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2126f9f1016f8fb9ef0af7505a66541fe44efd1519718411626ac2dfda06431e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"41acf20e6f54fd2ad8ce68c68a0be3e7a6b32183d4ebb0101d46d37df6759a63"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6bb72ce3cb748ef47495eb5d9a2e119d1b1b867c985e39df1150fbe83d4930be"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"99fd4f3a2b1d12801514bb6cd197878d9bf07569a0b8d83af5b6698e41b75773"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7ae7dcc92c9f9c973bcf9552d4d86445d8bb29b8178503d3c8f6cbf78412f6a2"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cb9a0819de91220a1f1bb6cb7def2eec20344a5686109713f769ea71f1fddd53"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c98c65f0e669d3c1dcd0125c6bf0413d7c7161ce70d884b663a667c11a1f150f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"25a1f93611ba39dcf5d0b288bfee449d4ea6e9ff854c77ef1704808cb1fa4a82"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"231274ae991c4aead6a6506fbd3b677da9f920cc222e83a656dd66bc62b80b1a"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e6a2812c37eb8df20ca7f8cc03c3636e80609b27967f6f72c4730c673b614f5"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8adcc0ea6e99610431c01c251783644fffb0f87e71f1f09ae76971bfd5cd6f50"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"51cf582e7a6009a73e8f1a410cf0b276afda83d2f1bc502ecc9a23309859ce40"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6f6b71b8df6bf3452ba0adc9a94b542b6384282938605d2efa74c9a90f9d69c2"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f8773f48f3a3465fd5547513c8da2d5df8dce846a681e3b57ed111ba36ec9134"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c3a3ae75fcee5230267fdfb25cdfc67ed95b28e25f6161d71c58d841f3bd6f23"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"03fdb174775c458af486fbf39e631253081d198e0c96bc1f5c86e25c6fcac21a"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a92ea2bd84d601d6b822fe5762cf467d7d4566bdba36e8683beeaf83e84164ec"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9842386f4c163a195024c95ff7bea5192b8a8c20ec3efa38a7169812d8d82f6e"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1fbaa2eb70962c8c8fee4d7bcf45ff73221643db67e1689d36f29f58e4cc0c90"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"997873d0ee0e50577d9f69525d4edaeaeb756649a3544823f4f98b9b8543fc0a"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"afe662341085c3b2ac776e238c5c905a8c49f69be977c7a1ef5af49fce51ac12"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"763c6654ec3424a178bce02083c1ff83561ea2de5e888e526c7f9e677a0e148a"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ede1024b6937ae896717e4631af94f34aba96dec80de97d74fff95d4c996212b"},"taxa":[{"id":"CWE-250","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c70df01e801d740e2292d61425dacb619642c4dd925d9128e6626e93525ff0a8"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c1758cbcaa2058d7b3720d85b06cb11e2ad82d70ce039dde014034ce98e1c64a"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"68775cb2263be493a4c396b8656df26ba15e97a861330c1a61caca7ea73a8623"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b43a4d396accfb35be563895093da83b212c649b2a3ee4cc8d9db57f270f6811"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e0284b3b7874f3ea2e35a59d366e5bb6bd229cc1b9ce15cee4b110365b27c249"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bfce86cd6b384e0f9835ff465e4153f4d6cab72e1844b893f5d521a14b90ce05"}},{"ruleId":"D34","level":"note","message":{"text":"Orphaned files with no living knowledge: 1 of 192 analysed file(s) have no living knowledge left \u2014 their last meaningful change has decayed away, so if one breaks, no one currently understands it (counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 192 of the 205 production source files in this repository met that bar). None is large enough to earn a read-through of its own, so this row stands in for the per-file rows rather than raising one each \u2014 most significant first: crates/nono-cli/src/deprecation_warnings.rs. Attach the read to the next change that touches one of them: have a second person review that change, and leave behind a short comment or test recording what the file is for, so the knowledge comes back at the cost of a change you were making anyway."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ce861fd78f6935114d3a342cb90ad25870f984e1042954fcbbe27c0e23be3658"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: app_runtime.rs \u2194 cli_bootstrap.rs: \u0060crates/nono-cli/src/app_runtime.rs\u0060 and \u0060crates/nono-cli/src/cli_bootstrap.rs\u0060 change together 73% of the time (8 of the 11 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking. You can check this without leaving the row: of the 8 shared commits counted here, the most recent 3 are \u00609078ffcf\u0060 feat(remote): add remote session connect and ps (#1656); \u00604d221938\u0060 chore: remove deprecated nono learn command (#1543); \u0060c5c7f56e\u0060 feat(cli): add platform enrollment and audit delivery (#1538) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/app_runtime.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"35d6eb8b59ba1099266536b9b7e67e555703c5f2eb7e9a4d3b2401b4156f6ec7"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: network_policy.rs \u2194 credential.rs: \u0060crates/nono-cli/src/network_policy.rs\u0060 and \u0060crates/nono-proxy/src/credential.rs\u0060 change together 50% of the time (15 of the 30 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 15 shared commits counted here, the most recent 3 are \u00607301ac2e\u0060 fix(proxy): add redeem_phantoms for by-value phantom redemption (#1469); \u00605bb098cd\u0060 feat: [aws] implement aws_auth config (#1166); \u006057005737\u0060 fix(proxy): honor explicit credential_format on custom inject headers \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/network_policy.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"45de0c8405d170871061a8959e37ed9ffe79e5793e11ca30ddd1b02cc14104e3"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: mod.rs \u2194 credential.rs: \u0060crates/nono-cli/src/profile/mod.rs\u0060 and \u0060crates/nono-proxy/src/credential.rs\u0060 change together 50% of the time (15 of the 30 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 15 shared commits counted here, the most recent 3 are \u00609488c4c5\u0060 feat(cleanup)!: remove remaining deprecated surfaces (#1871); \u00607301ac2e\u0060 fix(proxy): add redeem_phantoms for by-value phantom redemption (#1469); \u00605bb098cd\u0060 feat: [aws] implement aws_auth config (#1166) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"fd5cf13f5dc4f4a5e4778152db1207f37166ac337355397e8f7ed801b576644d"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: main.rs \u2194 snapshot.rs: \u0060crates/nono-cli/src/main.rs\u0060 and \u0060crates/nono/src/undo/snapshot.rs\u0060 change together 50% of the time (8 of the 16 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 8 shared commits counted here, the most recent 3 are \u00606ecade2e\u0060 feat(audit): add audit attestation for session merkle roots; \u00604f9552ec\u0060 feat(audit): add tamper-evident audit log integrity; \u00608897d29a\u0060 chore: remove Monitor strategy, make Supervised the default (#267) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/main.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"027b32a4b3c1d86a221fc04205537102eb62d0b472c1a54823e3542b5cf7602a"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: cli.rs \u2194 package.rs: \u0060crates/nono-cli/src/cli.rs\u0060 and \u0060crates/nono-cli/src/package.rs\u0060 change together 50% of the time (5 of the 10 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking. You can check this without leaving the row: of the 5 shared commits counted here, the most recent 3 are \u006064d9f283\u0060 feat(package): add package pinning and outdated commands; \u0060829c341a\u0060 add commands to manage profile drafts and check package status; \u0060d05672d5\u0060 fix(wiring): harden install and uninstall wiring \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/cli.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e850b1ae5b8b69c772a52dc485fa51784cfd9ceff2bcb64f7fc93846d1ecf6c5"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eb00976a698a5d68999b7ee6d27206fd374e916853e7ff1ead5eed42386f043f"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"846b30a1b59c15f4c7e9cf91e9f74a8d2ae05df2ba50fce54dfeb7cbaac9918c"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"988c2dd01d89ecc7e74358b5e31b60718ff2ca841ab706b9a2cc6a36e2384ca1"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c5928b81075799790cb18fed2980a6b6e8aa5072772041c9951633efe8eb3542"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d657599f6f99da1927d3377533dfc0888b34c4d84aa7d5579841fd72d0e39bce"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c593d4dbd23724f337bfb8d2c1653812f143ae255bd9b59d4b3e9c37779fa6f4"}},{"ruleId":"D40","level":"note","message":{"text":"No network policy: No Kubernetes NetworkPolicy (or Cilium policy) found. Without one, every pod can talk to every other pod and reach out to the internet by default. Add a default-deny policy and open only the flows you need."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"295828650a2aaa1b03ae9b32ae6843a0c38011e5a70b1926442c4fa7187de5f0"}},{"ruleId":"D41","level":"note","message":{"text":"No seccomp profile: Workloads do not set a seccomp profile (RuntimeDefault or a Localhost profile). Seccomp blocks the syscalls a container never needs, shrinking the kernel attack surface a container escape would use."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3f418e9f76c3ac90484e0e94a454bfe9b08e914e1cdd218e1fc9e3b261a3bf6e"}},{"ruleId":"D41","level":"note","message":{"text":"No AppArmor/SELinux confinement: Workloads declare no AppArmor or SELinux profile. A mandatory-access-control profile confines what a compromised container can touch on the host, complementing seccomp\u0027s syscall filter."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e83fbc31033373d6c51983ed230eb4ba61f7775ed02afb30f5fc1840bde01d4f"}},{"ruleId":"D42","level":"note","message":{"text":"No runtime threat detection: No runtime threat-detection engine (Tetragon TracingPolicy / Falco) is committed. These observe process, file and network activity in-kernel and can alert or kill on malicious behaviour a static scan cannot catch."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"aade9827a37dfc7ee064f80a997f47b5d11e31bc09704e26b9252bef00aa0c58"}},{"ruleId":"M4","level":"note","message":{"text":"README/code drift: README claims nono runs on macOS, Linux, WSL2; the evidence has no such claim \u2014 reported by the model that read the README against this repository; no term search was run for this one, so nothing here has been checked against the tree. Treat it as a reading to confirm, not as a measured contradiction: verify it against the code before acting on it, and if the footprint it describes does exist, this row is wrong."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"343bbbd51ceb8de7a9ff88d79f7c797abf9b5921f8727b67b4d0f4f8a22c5e49"}},{"ruleId":"P10","level":"note","message":{"text":"Large public API surface: 205/262 types (78%) declared in the published library are public. For a library, every public type is a stability contract \u2014 keep implementation types off the surface and expose only the intended API."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ed2ba843444ae377c17142f58f714e281e4bd3f183ab100ee1fbef389875d3e6"}},{"ruleId":"P2","level":"note","message":{"text":"Logging is not universal: Only 3/5 runnable modules use logging (modules with no entry point or server are excluded \u2014 they are libraries a runnable module hosts). Silent: \u0060.\u0060, \u0060.\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"91a94e21d6d4d0e6a2003f94505b0b02b157176f0b24c4820f3f82b4447a97fe"}},{"ruleId":"S1","level":"note","message":{"text":"No security response headers detected: No Content-Security-Policy / X-Frame-Options / X-Content-Type-Options configuration found \u2014 defense in depth, even when a reverse proxy could set them. This is reported because \u0060server.conf\u0060 is committed to this repository and declares the server that serves it, so the configuration that would carry these headers is in this repository and was read in full. (\u22122.0 on this card.)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"testdata/spire/server.conf"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"6d322b9a428968cced35758447417895a7d05a797603eb2c6c1b10419aedad31"}},{"ruleId":"X10","level":"note","message":{"text":"Duplicated predicate: \u0060self.headers.get(\u0022Content-Length\u0022, \u00220\u0022) or \u00220\u0022\u0060 appears character-identically in 2 files \u2014 tool-sandbox-examples/kubernetes-with-approval/https-front-proxy.py, tool-sandbox-examples/kubernetes/https-front-proxy.py. It is one line, so the duplication detector\u0027s token window never sees it; the copies drift when only one is corrected. Give the condition a name and one home."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tool-sandbox-examples/kubernetes-with-approval/https-front-proxy.py"},"region":{"startLine":33}}}],"partialFingerprints":{"codehealthFindingId/v1":"78972c8391e4202ec8cc1ef4ea12e694ae8c8c970b7076bda06fbfc693ea0836"}},{"ruleId":"X10","level":"note","message":{"text":"Duplicated predicate: \u0060err.to_string().contains(\u0022--block-net\u0022) \u0026\u0026 err.to_string().contains(\u0022--upstream-proxy\u0022)\u0060 appears character-identically in 3 files \u2014 crates/nono-cli/src/command_runtime.rs, crates/nono-cli/src/launch_runtime.rs, crates/nono-cli/src/sandbox_prepare.rs. It is one line, so the duplication detector\u0027s token window never sees it; the copies drift when only one is corrected. Give the condition a name and one home."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/command_runtime.rs"},"region":{"startLine":452}}}],"partialFingerprints":{"codehealthFindingId/v1":"9aa352b3cbd7895c143f8f0e1e2fd91f720a08d282cff12f81c1d0543d59fe60"}},{"ruleId":"X10","level":"note","message":{"text":"Duplicated predicate: \u0060session_id.contains(std::path::MAIN_SEPARATOR) || session_id.contains(\u0027/\u0027) || session_id.contains(\u0022..\u0022) || session_id.contains(\u0027\\0\u0027)\u0060 appears character-identically in 2 files \u2014 crates/nono-cli/src/audit_session.rs, crates/nono-cli/src/rollback_session.rs. It is one line, so the duplication detector\u0027s token window never sees it; the copies drift when only one is corrected. Give the condition a name and one home."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/audit_session.rs"},"region":{"startLine":251}}}],"partialFingerprints":{"codehealthFindingId/v1":"3dc829ebeb96397656c8730421ac7c0ec0f9dd01b448a3b3435bd720757d3503"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060format_uptime\u0060 turns every \u0060Err\u0060 into \u0060\u0022-\u0022.to_string()\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/session_commands.rs"},"region":{"startLine":227}}}],"partialFingerprints":{"codehealthFindingId/v1":"cb7422f56d291bd153bc31097765d834acea4ef270880293b891510884ff0484"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060collect_profile_packs\u0060 turns every \u0060Err\u0060 into \u0060Vec::new()\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/pack_update_hint.rs"},"region":{"startLine":143}}}],"partialFingerprints":{"codehealthFindingId/v1":"0082767310212153541b6000f186cfce712476b877c5a356c7838c192b9ddf31"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060run_fsmonitor_socket\u0060 turns every \u0060Err\u0060 into \u0060Ok(vec![])\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/dynamic_providers.rs"},"region":{"startLine":259}}}],"partialFingerprints":{"codehealthFindingId/v1":"f3ab8e0596277cab3f5a975ba74e665c8bfa6284f2bd1632f21d9f6ae2c4e5fe"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060run_toplevel\u0060 turns every \u0060Err\u0060 into \u0060Ok(vec![])\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/dynamic_providers.rs"},"region":{"startLine":310}}}],"partialFingerprints":{"codehealthFindingId/v1":"f737beb7bafec86e445c30b24c54dc8d1abc5dd6b1c1b8e1c6ccfcc1e2d332e7"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060run_common_dir\u0060 turns every \u0060Err\u0060 into \u0060Ok(vec![])\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/dynamic_providers.rs"},"region":{"startLine":355}}}],"partialFingerprints":{"codehealthFindingId/v1":"4246b0226a056802beb839164f7205b342463a41ccf735d8da39c96464181b8c"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060run_with_path\u0060 turns every \u0060Err\u0060 into \u0060Ok(GitConfigPaths::default())\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/dynamic_providers.rs"},"region":{"startLine":468}}}],"partialFingerprints":{"codehealthFindingId/v1":"a7b9f399ddbbb5d8fc45bd99df5d449057f1b788db0b32fb22a1dd2c7849a303"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060detect_install_source\u0060 turns every \u0060Err\u0060 into \u0060\u0022unknown\u0022.to_string()\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/update_check.rs"},"region":{"startLine":354}}}],"partialFingerprints":{"codehealthFindingId/v1":"7169c96140a55739b6edb7e6dc49ce6a124d7e35b9aa762606d9d668a847eb44"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060detect_linux\u0060 turns every \u0060Err\u0060 into \u0060LinuxInfo::default()\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/platform.rs"},"region":{"startLine":100}}}],"partialFingerprints":{"codehealthFindingId/v1":"8552f8d985e204b8371f0f4f7eaea9e76005b8be402418df7e189049add36b88"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060signal_children_in_pgroup_for_state\u0060 turns every \u0060Err\u0060 into \u0060Vec::new()\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/tool-sandbox/platform/macos.rs"},"region":{"startLine":2810}}}],"partialFingerprints":{"codehealthFindingId/v1":"40778708cc99bb8233dff80c905c6b8d282f99a0d554694707ba74dd9542401e"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060claude_keychain_account_name\u0060 turns every \u0060Err\u0060 into \u0060\u0022claude-code-user\u0022.to_string()\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/sandbox_prepare.rs"},"region":{"startLine":282}}}],"partialFingerprints":{"codehealthFindingId/v1":"411324429ca2d0dfca09a715732fadadb54409166cb81735c6a65cfa2d18c509"}},{"ruleId":"X7","level":"note","message":{"text":"Silent fallback default on Err: \u0060route_diagnostics\u0060 turns every \u0060Err\u0060 into \u0060true\u0060 \u2014 a failure becomes a plausible value and a silent behavior change with no trail. Log the error or propagate it with \u0060?\u0060. If that constant is the correct answer rather than a stand-in for a value that could not be read, say so in a comment on the arm or in the doc comment, and the row stops firing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/server.rs"},"region":{"startLine":421}}}],"partialFingerprints":{"codehealthFindingId/v1":"da66104a0f168b429361ba3ce63bc2a21b8f845bfda463a0a4861227c22b71a7"}},{"ruleId":"X9","level":"note","message":{"text":"Subsumed condition operand: \u0060msg.contains(\u0022invalid CA certificate\u0022)\u0060 can never decide this \u0060||\u0060 \u2014 every value satisfying \u0060msg.contains(\u0022invalid CA certificate\u0022)\u0060 also satisfies \u0060msg.contains(\u0022CA certificate\u0022)\u0060, so the \u0060||\u0060 chain is already decided by the latter. The expression is equivalent to the chain without it, which means it is wider than it reads. Delete the dead operand, or narrow the surviving one if IT is the accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-proxy/src/route.rs"},"region":{"startLine":1954}}}],"partialFingerprints":{"codehealthFindingId/v1":"954ffdfe8ca5769c55f1f9cfce3023c0bbe3e0d91785a7fdb9babfe6ab24da41"}},{"ruleId":"X9","level":"note","message":{"text":"Subsumed condition operand: \u0060msg.contains(\u0022aws_auth\u0022)\u0060 can never decide this \u0060||\u0060 \u2014 every value satisfying \u0060msg.contains(\u0022aws_auth\u0022)\u0060 also satisfies \u0060msg.contains(\u0022auth\u0022)\u0060, so the \u0060||\u0060 chain is already decided by the latter. The expression is equivalent to the chain without it, which means it is wider than it reads. Delete the dead operand, or narrow the surviving one if IT is the accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/profile/mod.rs"},"region":{"startLine":11175}}}],"partialFingerprints":{"codehealthFindingId/v1":"043291647ee43bb308ea9abd6a4c8c3bb3c5c11e1e358582657cabd47fcd3cca"}},{"ruleId":"X9","level":"note","message":{"text":"Subsumed condition operand: \u0060lower.contains(\u0022file already exists\u0022)\u0060 can never decide this \u0060||\u0060 \u2014 every value satisfying \u0060lower.contains(\u0022file already exists\u0022)\u0060 also satisfies \u0060lower.contains(\u0022already exists\u0022)\u0060, so the \u0060||\u0060 chain is already decided by the latter. The expression is equivalent to the chain without it, which means it is wider than it reads. Delete the dead operand, or narrow the surviving one if IT is the accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/nono-cli/src/diagnostic/formatter.rs"},"region":{"startLine":268}}}],"partialFingerprints":{"codehealthFindingId/v1":"5c52f52e4c9da82d3ee8d352500fea405d906a6507199781a86ec78cd74c9a28"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-1059","guid":"a2381a08-60f6-9554-a8b8-f3018cfaaca5","name":"Insufficient Technical Documentation","shortDescription":{"text":"Insufficient Technical Documentation"},"helpUri":"https://cwe.mitre.org/data/definitions/1059.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-214","guid":"b10ad120-fb22-1351-9348-aa23b453e815","name":"CWE-214","shortDescription":{"text":"CWE-214"},"helpUri":"https://cwe.mitre.org/data/definitions/214.html"},{"id":"CWE-250","guid":"52ee12e8-390a-7351-b1e6-388afa694e54","name":"CWE-250","shortDescription":{"text":"CWE-250"},"helpUri":"https://cwe.mitre.org/data/definitions/250.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-522","guid":"71fb233e-ce6a-ae57-9419-ef8373540b09","name":"CWE-522","shortDescription":{"text":"CWE-522"},"helpUri":"https://cwe.mitre.org/data/definitions/522.html"},{"id":"CWE-532","guid":"1cd8877a-76e8-ce54-b40b-779af23364a0","name":"CWE-532","shortDescription":{"text":"CWE-532"},"helpUri":"https://cwe.mitre.org/data/definitions/532.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-829","guid":"13c33925-97fb-5a5e-b40c-56d328b8a4d7","name":"CWE-829","shortDescription":{"text":"CWE-829"},"helpUri":"https://cwe.mitre.org/data/definitions/829.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":58,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}