{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D10","name":"Test Quality","shortDescription":{"text":"Test Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D10"},{"id":"D11","name":"Test Reliability","shortDescription":{"text":"Test Reliability"},"helpUri":"https://codehealth.canine.dev/dimensions/D11"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D23","name":"Boundary Type-Coupling","shortDescription":{"text":"Boundary Type-Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D23"},{"id":"D24","name":"Comment Value","shortDescription":{"text":"Comment Value"},"helpUri":"https://codehealth.canine.dev/dimensions/D24"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D37","name":"Vulnerability-disclosure Policy","shortDescription":{"text":"Vulnerability-disclosure Policy"},"helpUri":"https://codehealth.canine.dev/dimensions/D37","relationships":[{"target":{"id":"CWE-1059","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1059"]}},{"id":"D39","name":"IL Efficiency","shortDescription":{"text":"IL Efficiency"},"helpUri":"https://codehealth.canine.dev/dimensions/D39"},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AC2","name":"Forms \u0026 labels","shortDescription":{"text":"Forms \u0026 labels"},"helpUri":"https://codehealth.canine.dev/dimensions/AC2"},{"id":"AC3","name":"Page structure","shortDescription":{"text":"Page structure"},"helpUri":"https://codehealth.canine.dev/dimensions/AC3"},{"id":"AC4","name":"Keyboard semantics","shortDescription":{"text":"Keyboard semantics"},"helpUri":"https://codehealth.canine.dev/dimensions/AC4"},{"id":"AC5","name":"ARIA correctness","shortDescription":{"text":"ARIA correctness"},"helpUri":"https://codehealth.canine.dev/dimensions/AC5"},{"id":"AC6","name":"Visual \u0026 motion safety","shortDescription":{"text":"Visual \u0026 motion safety"},"helpUri":"https://codehealth.canine.dev/dimensions/AC6"},{"id":"AC7","name":"A11y enforcement","shortDescription":{"text":"A11y enforcement"},"helpUri":"https://codehealth.canine.dev/dimensions/AC7"},{"id":"AX1","name":"Captive dependencies","shortDescription":{"text":"Captive dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/AX1"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX2","name":"Stateful singletons","shortDescription":{"text":"Stateful singletons"},"helpUri":"https://codehealth.canine.dev/dimensions/AX2"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX5","name":"Architecture \u0026 structure","shortDescription":{"text":"Architecture \u0026 structure"},"helpUri":"https://codehealth.canine.dev/dimensions/AX5"},{"id":"AX6","name":"Interface segregation","shortDescription":{"text":"Interface segregation"},"helpUri":"https://codehealth.canine.dev/dimensions/AX6"},{"id":"AX8","name":"Test isolation","shortDescription":{"text":"Test isolation"},"helpUri":"https://codehealth.canine.dev/dimensions/AX8"},{"id":"AX9","name":"CQS / query purity","shortDescription":{"text":"CQS / query purity"},"helpUri":"https://codehealth.canine.dev/dimensions/AX9"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"C2","name":"Access Controls","shortDescription":{"text":"Access Controls"},"helpUri":"https://codehealth.canine.dev/dimensions/C2"},{"id":"C3","name":"Audit Trail","shortDescription":{"text":"Audit Trail"},"helpUri":"https://codehealth.canine.dev/dimensions/C3"},{"id":"DM1","name":"Aggregate boundaries","shortDescription":{"text":"Aggregate boundaries"},"helpUri":"https://codehealth.canine.dev/dimensions/DM1"},{"id":"DM10","name":"One transaction, one aggregate","shortDescription":{"text":"One transaction, one aggregate"},"helpUri":"https://codehealth.canine.dev/dimensions/DM10"},{"id":"DM11","name":"Constructible invalid state","shortDescription":{"text":"Constructible invalid state"},"helpUri":"https://codehealth.canine.dev/dimensions/DM11"},{"id":"DM12","name":"Ambient inputs in the domain","shortDescription":{"text":"Ambient inputs in the domain"},"helpUri":"https://codehealth.canine.dev/dimensions/DM12"},{"id":"DM2","name":"Strongly-typed ids","shortDescription":{"text":"Strongly-typed ids"},"helpUri":"https://codehealth.canine.dev/dimensions/DM2"},{"id":"DM4","name":"Rich vs anemic model","shortDescription":{"text":"Rich vs anemic model"},"helpUri":"https://codehealth.canine.dev/dimensions/DM4"},{"id":"DM5","name":"Encapsulated state","shortDescription":{"text":"Encapsulated state"},"helpUri":"https://codehealth.canine.dev/dimensions/DM5"},{"id":"DM6","name":"Domain \u2194 infrastructure boundary","shortDescription":{"text":"Domain \u2194 infrastructure boundary"},"helpUri":"https://codehealth.canine.dev/dimensions/DM6"},{"id":"DM7","name":"Repository granularity","shortDescription":{"text":"Repository granularity"},"helpUri":"https://codehealth.canine.dev/dimensions/DM7"},{"id":"DM8","name":"Value-object opportunities","shortDescription":{"text":"Value-object opportunities"},"helpUri":"https://codehealth.canine.dev/dimensions/DM8"},{"id":"DM9","name":"Scattered domain decisions","shortDescription":{"text":"Scattered domain decisions"},"helpUri":"https://codehealth.canine.dev/dimensions/DM9"},{"id":"ED1","name":"Handler temporal coupling","shortDescription":{"text":"Handler temporal coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/ED1"},{"id":"ED2","name":"Event/command shape","shortDescription":{"text":"Event/command shape"},"helpUri":"https://codehealth.canine.dev/dimensions/ED2"},{"id":"ED3","name":"Event naming","shortDescription":{"text":"Event naming"},"helpUri":"https://codehealth.canine.dev/dimensions/ED3"},{"id":"ED4","name":"Outbox / dual-write","shortDescription":{"text":"Outbox / dual-write"},"helpUri":"https://codehealth.canine.dev/dimensions/ED4"},{"id":"ED5","name":"Idempotency","shortDescription":{"text":"Idempotency"},"helpUri":"https://codehealth.canine.dev/dimensions/ED5"},{"id":"GD1","name":"Unfinished \u0026 placeholder code","shortDescription":{"text":"Unfinished \u0026 placeholder code"},"helpUri":"https://codehealth.canine.dev/dimensions/GD1"},{"id":"IC1","name":"Incompleteness \u0026 stubs","shortDescription":{"text":"Incompleteness \u0026 stubs"},"helpUri":"https://codehealth.canine.dev/dimensions/IC1"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P2","name":"Observability","shortDescription":{"text":"Observability"},"helpUri":"https://codehealth.canine.dev/dimensions/P2"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P7","name":"Outbound HTTP resilience","shortDescription":{"text":"Outbound HTTP resilience"},"helpUri":"https://codehealth.canine.dev/dimensions/P7"},{"id":"P8","name":"Schema migrations","shortDescription":{"text":"Schema migrations"},"helpUri":"https://codehealth.canine.dev/dimensions/P8"},{"id":"S1","name":"Web-Security Posture","shortDescription":{"text":"Web-Security Posture"},"helpUri":"https://codehealth.canine.dev/dimensions/S1"},{"id":"SC1","name":"Supply-chain hygiene","shortDescription":{"text":"Supply-chain hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/SC1"},{"id":"X1","name":"Async correctness","shortDescription":{"text":"Async correctness"},"helpUri":"https://codehealth.canine.dev/dimensions/X1"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X12","name":"Unreachable branch","shortDescription":{"text":"Unreachable branch"},"helpUri":"https://codehealth.canine.dev/dimensions/X12"},{"id":"X13","name":"Undrained process stream","shortDescription":{"text":"Undrained process stream"},"helpUri":"https://codehealth.canine.dev/dimensions/X13"},{"id":"X14","name":"Bypassable address classification","shortDescription":{"text":"Bypassable address classification"},"helpUri":"https://codehealth.canine.dev/dimensions/X14"},{"id":"X15","name":"Unvalidated length from an untrusted reader","shortDescription":{"text":"Unvalidated length from an untrusted reader"},"helpUri":"https://codehealth.canine.dev/dimensions/X15"},{"id":"X16","name":"Unfloored truncation loop","shortDescription":{"text":"Unfloored truncation loop"},"helpUri":"https://codehealth.canine.dev/dimensions/X16"},{"id":"X17","name":"Uncapped recursion over a caller-supplied document","shortDescription":{"text":"Uncapped recursion over a caller-supplied document"},"helpUri":"https://codehealth.canine.dev/dimensions/X17"},{"id":"X18","name":"Disposal-pattern correctness","shortDescription":{"text":"Disposal-pattern correctness"},"helpUri":"https://codehealth.canine.dev/dimensions/X18"},{"id":"X19","name":"Unrestored process-global state","shortDescription":{"text":"Unrestored process-global state"},"helpUri":"https://codehealth.canine.dev/dimensions/X19"},{"id":"X2","name":"Cancellation propagation","shortDescription":{"text":"Cancellation propagation"},"helpUri":"https://codehealth.canine.dev/dimensions/X2"},{"id":"X20","name":"Mistyped argument guard","shortDescription":{"text":"Mistyped argument guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X20"},{"id":"X21","name":"Side-effecting pattern guard","shortDescription":{"text":"Side-effecting pattern guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X21"},{"id":"X22","name":"Contradicted release guard","shortDescription":{"text":"Contradicted release guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X22"},{"id":"X23","name":"Unguarded diagnostic materialisation","shortDescription":{"text":"Unguarded diagnostic materialisation"},"helpUri":"https://codehealth.canine.dev/dimensions/X23"},{"id":"X24","name":"Document value interpolated into markup unescaped","shortDescription":{"text":"Document value interpolated into markup unescaped"},"helpUri":"https://codehealth.canine.dev/dimensions/X24"},{"id":"X25","name":"Inert configuration knob","shortDescription":{"text":"Inert configuration knob"},"helpUri":"https://codehealth.canine.dev/dimensions/X25"},{"id":"X26","name":"Unsynchronised callback handoff","shortDescription":{"text":"Unsynchronised callback handoff"},"helpUri":"https://codehealth.canine.dev/dimensions/X26"},{"id":"X27","name":"Collection changed while being enumerated","shortDescription":{"text":"Collection changed while being enumerated"},"helpUri":"https://codehealth.canine.dev/dimensions/X27"},{"id":"X28","name":"Index access outside its own emptiness guard","shortDescription":{"text":"Index access outside its own emptiness guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X28"},{"id":"X29","name":"Per-element action decided by a fixed element","shortDescription":{"text":"Per-element action decided by a fixed element"},"helpUri":"https://codehealth.canine.dev/dimensions/X29"},{"id":"X3","name":"Exception handling","shortDescription":{"text":"Exception handling"},"helpUri":"https://codehealth.canine.dev/dimensions/X3"},{"id":"X30","name":"Support guard that admits what it rejects","shortDescription":{"text":"Support guard that admits what it rejects"},"helpUri":"https://codehealth.canine.dev/dimensions/X30"},{"id":"X32","name":"Type resolved by simple name across every loaded assembly","shortDescription":{"text":"Type resolved by simple name across every loaded assembly"},"helpUri":"https://codehealth.canine.dev/dimensions/X32"},{"id":"X4","name":"Structured logging","shortDescription":{"text":"Structured logging"},"helpUri":"https://codehealth.canine.dev/dimensions/X4"},{"id":"X5","name":"Nullable reference types","shortDescription":{"text":"Nullable reference types"},"helpUri":"https://codehealth.canine.dev/dimensions/X5"},{"id":"X6","name":"Hand-rolled structured-format parsing","shortDescription":{"text":"Hand-rolled structured-format parsing"},"helpUri":"https://codehealth.canine.dev/dimensions/X6"},{"id":"X7","name":"Silent fallback defaults","shortDescription":{"text":"Silent fallback defaults"},"helpUri":"https://codehealth.canine.dev/dimensions/X7"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (18 lines \u00D7 2): src/Domain/Entities/Permission.cs:5-22 | src/Web/Shared/Identity/Permission.cs:3-20 \u2014 before extracting anything, compare \u0060src/Domain/Entities/Permission.cs\u0060 and \u0060src/Web/Shared/Identity/Permission.cs\u0060 as WHOLE FILES: 87% of the shorter file\u0027s lines also appear in the other, so this reads as one file having been copied from the other rather than as a helper waiting to be extracted. The 1 duplicated block(s) this scan matched between them are fragments of that copy, not the extent of it \u2014 treat the file pair as the unit. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place. Read the line range as the matched WINDOW rather than a finished unit: at \u0060src/Domain/Entities/Permission.cs:5\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Domain/Entities/Permission.cs"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"97a214ad13a8175ffcdc49786e50d32ab2e88e91477676ca9b0f5bed2c5a0edc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6\u201311 lines \u00D7 2): src/Domain/Entities/WorkItem.cs:10-15 | src/Web/ApiServer/ViewModels/WorkItemDto.cs:9-19 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Domain/Entities/WorkItem.cs"},"region":{"startLine":10}}}],"partialFingerprints":{"codehealthFindingId/v1":"0f2f546ab5d49aa5df3fd134f2203e651298aaae5f1d9814572eec45f85ad3f6"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: Shared: Shared: abstractness 0.00, instability 0.00, distance 1.00 \u2014 the shape a shared-kernel / building-block library has BY DESIGN \u2014 concrete and widely depended-on is what makes it useful, and this dimension does not penalise it (the distance is reported for completeness, not as a defect). Worth a look only if it has grown past one coherent kernel into an everything-bucket."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9a6075584bf1a071b89754c93f688530ad9c449d73224f95d418320ea318e68b"}},{"ruleId":"D8","level":"warning","message":{"text":"Coverage not measured \u2014 no coverage collector is wired up: Coverage NOT MEASURED: \u0060--collect:\u0022XPlat Code Coverage\u0022\u0060 names a data collector that ships in the \u0060coverlet.collector\u0060 package, and this repository wires up none \u2014 no test project references it and no runsettings declares one. The absence of coverage here is therefore not evidence about the suite or about our analyzer environment: without a collector, \u0060--collect\u0060 produces nothing even from a suite that builds and passes. Add a \u0060coverlet.collector\u0060 PackageReference to the test project(s) (or commit the Cobertura/OpenCover/lcov report your CI produces) and real coverage will be measured. It is excluded from the score rather than counted as a near-zero defect."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"62e63e619c28f057e129f2997c965d32a457366a9ce18ca019ffb6bdfba85c99"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: MSTest.TestAdapter: MSTest.TestAdapter 3.4.3 \u2014 Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ee87da37b644f339f553a0b6c3bf2f114f23a951f9421d14ed870e71f7ad60e3"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: MSTest.TestFramework: MSTest.TestFramework 3.4.3 \u2014 Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b69cdd194a49be37271a696938cb22ebf3e9388aead8d7b5e3d69a29082d5e0d"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Blazored.FluentValidation: Blazored.FluentValidation 2.2.0 \u2014 Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7bd585338e6ac2b24a2bc212c8e1a1e448a7917811230d33b5dd5965a1381638"}},{"ruleId":"D13","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"adf51cb9730d89400577e57f8ce709484771729512e48942be6143dc511c5882"},"taxa":[{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D17","level":"warning","message":{"text":"CoverageExclusion: class ApplicationDbContextInitialiser \u2014 this shipped code is lifted out of the coverage measurement, so it is not that the code is reported as untested: it is not reported at all. The excluded lines leave the denominator, which means the percentage the team publishes goes UP when code stops being covered, and the gap is invisible in the artefact that would otherwise disclose it. Nothing here is written by a compiler or a build \u2014 the attribute is only ever typed by an author \u2014 so it is a standing decision, and the only record of it is this line. Test what it covers and delete the attribute; where the code genuinely cannot be exercised (a debugger display, a platform branch this build cannot reach), narrow the exclusion to the smallest declaration that is really untestable rather than the type around it, so members added later are not silently excluded too. If it is correct as it stands, say why \u2014 in the attribute\u0027s own Justification, or in a comment above it: that is what turns it from unexplained debt into a recorded decision, and it clears this row."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Infrastructure/Data/ApplicationDbContextInitialiser.cs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"1eceb4a609a39d735ec58f93c9c2d45809e3953e62dc397db80d4a430f13b795"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no architecture or design documentation: The PragmaticCleanArchitecture README is an architectural example rather than an architecture document; no design or layered-overview documentation exists in the visible text. Add a short Architecture section describing the Clean/Onion layers and how they interact."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"086460f2da112d94904fac5439f54a7780bc7778ff9375a067e428a1cc9a8a4c"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no licence statement: The README contains license badges but there is no licence statement in the visible text. State the project\u0027s MIT license under the heading \u0027License\u0027 or add a LICENSE file."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"bc71d4465cafafc3df7a1b646a8cd5f9a306761b307dc199a6de8c1c35d8b21d"}},{"ruleId":"D24","level":"note","message":{"text":"misleading comment: \u0022replace with real implementation\u0022 \u2014 delete - this is a stub/Arrange line restating the code; it misnames the comment as \u0027replace with real implementation\u0027 rather than documenting why the call is empty."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Application/WorkItems/Events/WorkItemAssignedDomainEventHandler.cs"},"region":{"startLine":19}}}],"partialFingerprints":{"codehealthFindingId/v1":"99b9b30946640eb85775642fae0e45f7e0276076f7173625ff6f7220e9df24a3"}},{"ruleId":"D27","level":"note","message":{"text":"Scattered collaborators: 99 % of calls cross a namespace and only 57 % of collaborators are co-located \u2014 group each feature\u0027s code into a vertical slice so a call\u0027s collaborators sit together."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5aad4a4530bac3928d3a065a664be89d023ecfc865f9bf79ac05754b3bffe322"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ddc49ef52c93f5d89390c80bf8f0444bb97743496eeea781d1b7fcf904a3ea48"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"565cb0a25235d1502010c8d34a025c6ae5aeb826c7d5e305b97bb45399050c67"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fdd80ff4efa055538dc59aafc5e380459b7d05030fbc7ee936f19fa678b3e896"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"73fff3c6c9e2d9da7d4f738c40b8a223e17cfd14b0555814ffc82880faec5f41"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f6d629032dff8af67a8377dc92a11bc9f3174a637468e2db142a019acc12e4ab"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"062485f6781ed6796413a785d933e1d7c3adf38170e7e59a76f609834d07c5a5"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f8b0273a26edcd3672c360adea5453cbdec7b91bd85f6a6cd68a015bd3cd5eff"},"taxa":[{"id":"CWE-862","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"42a33c0a557419a8d56d707a2eb0fc26a005e95199082dbc8bc04b29a034da5e"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"232013a63d845603c2a626f52ada8d8ad59691f3c568e940aad78d11f17c4f7b"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"03b31df8570933308505a1624e4fd5ee0390537c65b94f5898a4ad85f2c0b177"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c475b5d776175d1181892c3e7e72c31acdbe224ac300e32808399947498db6c9"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"045e9eaf2ec62fceb60477dd379a801f46340dedb0c9415d1920e111d035db30"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d8bff52f24a5a42d76902f0abaec68c13b358c5066fd8aa89920a5d6e963d9ef"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"438d8dc74930ecd1b568daade46d8fe926bf9700c6d5ae5197bc71a6ee251442"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fe2d688610b51e0a5a02c7c5dd1724a4986e40f2689fb84510e2ec0164c27d6a"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ec1b042386f30e6ec10894c5e7ac948b1eec9ec65136f98beabc15d88a0e9410"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"41e7af7b96de625288980b527daf7e582c4c3eacdb660e3022f0c15f6c25479a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1f51a163f26d94ce6b6f473117dde579d091c8cbf9e59810475c94d9fc921120"}},{"ruleId":"D34","level":"note","message":{"text":"Orphaned files with no living knowledge: 5 of 5 analysed file(s) have no living knowledge left \u2014 their last meaningful change has decayed away, so if one breaks, no one currently understands it (counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 5 of the 111 production source files in this repository met that bar). None is large enough to earn a read-through of its own, so this row stands in for the per-file rows rather than raising one each \u2014 most significant first: src/Infrastructure/Identity/IdentityService.cs, src/Web/UI/Pages/ProjectBoard.razor.cs, src/Web/UI/Pages/WorkItems.razor.cs, src/Infrastructure/Data/ApplicationDbContextInitialiser.cs, src/Web/ApiServer/Filters/ApiExceptionFilterAttribute.cs. Attach the read to the next change that touches one of them: have a second person review that change, and leave behind a short comment or test recording what the file is for, so the knowledge comes back at the cost of a change you were making anyway."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ce861fd78f6935114d3a342cb90ad25870f984e1042954fcbbe27c0e23be3658"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0752d0df7434000fcabf1048e2de30a7a1a8b982b3db9a19898c4dec199856b4"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ace515990e7ee0f17b5c17e44dd168a5bdecf90804a3a3dd845cf05540978013"}},{"ruleId":"D37","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9d03e50e45de791a350ebf595fcb3269575c0543260ac6707c4b73e65639738e"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Cbutton\u003E with no accessible text: A button with no text and no aria-label has no accessible name. Add visible text or an aria-label (an icon-only button still needs one)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Components/Projects/DeleteProjectDialog.razor"},"region":{"startLine":6}}}],"partialFingerprints":{"codehealthFindingId/v1":"4bc7777f164017de93cde2c52b9f7979c309ccc958f51dd88a298da690276a23"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Cbutton\u003E with no accessible text: A button with no text and no aria-label has no accessible name. Add visible text or an aria-label (an icon-only button still needs one)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Components/Projects/ProjectDialog.razor"},"region":{"startLine":6}}}],"partialFingerprints":{"codehealthFindingId/v1":"aa19e2fc74857bfe2d26dbc900e743be8dfbc21e1fa6a5a7ba0f71daff0e0f48"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Cbutton\u003E with no accessible text: A button with no text and no aria-label has no accessible name. Add visible text or an aria-label (an icon-only button still needs one)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Components/Projects/ProjectItem.razor"},"region":{"startLine":4}}}],"partialFingerprints":{"codehealthFindingId/v1":"443686ea0ddf8c4913a499ca59014477a3f5b29ca7d7763dce09e2d786d592a0"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Cbutton\u003E with no accessible text: A button with no text and no aria-label has no accessible name. Add visible text or an aria-label (an icon-only button still needs one)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Components/Projects/ProjectItem.razor"},"region":{"startLine":7}}}],"partialFingerprints":{"codehealthFindingId/v1":"919424d600f1de1a22d7bbfb46d8d6f0d73f3494f30262cf77cf16abb7d40910"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Cbutton\u003E with no accessible text: A button with no text and no aria-label has no accessible name. Add visible text or an aria-label (an icon-only button still needs one)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Components/WorkItems/CreateWorkItemDialog.razor"},"region":{"startLine":6}}}],"partialFingerprints":{"codehealthFindingId/v1":"2b30a9debcc75323da406ff68900c7684695202311e34353e03903508a19172e"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Cbutton\u003E with no accessible text: A button with no text and no aria-label has no accessible name. Add visible text or an aria-label (an icon-only button still needs one)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Components/WorkItems/WorkItem.razor"},"region":{"startLine":10}}}],"partialFingerprints":{"codehealthFindingId/v1":"53765b39204dec03e504973f6c9ce6b260a85ffb168c1a5ebdd6ef7c893f7712"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Cbutton\u003E with no accessible text: A button with no text and no aria-label has no accessible name. Add visible text or an aria-label (an icon-only button still needs one)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Components/WorkItems/WorkItem.razor"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b8cc9ebe0f77da1430ada528b634ec9db262be47f904e6165e08ace9e77f10e"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Cbutton\u003E with no accessible text: A button with no text and no aria-label has no accessible name. Add visible text or an aria-label (an icon-only button still needs one)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Components/WorkItems/WorkItemDialog.razor"},"region":{"startLine":8}}}],"partialFingerprints":{"codehealthFindingId/v1":"2067cdb72e6ef8d891800971aa9baf5650af0314a17995260d52ea272baa8331"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Cbutton\u003E with no accessible text: A button with no text and no aria-label has no accessible name. Add visible text or an aria-label (an icon-only button still needs one)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Pages/RoleManager.razor"},"region":{"startLine":39}}}],"partialFingerprints":{"codehealthFindingId/v1":"7eacc82d8039893b7cc03dbc57ec963b66567d8290c9481df75e3662cff131e6"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Cbutton\u003E with no accessible text: A button with no text and no aria-label has no accessible name. Add visible text or an aria-label (an icon-only button still needs one)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Pages/RoleManager.razor"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"2a703080f5ee937434debedafc434ed9c960e1767e9cf91ad6059a7d7cf35450"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Cinput\u003E without a programmatic label: This control has only a placeholder \u2014 a placeholder is not a label (it vanishes on input and many AT ignore it). Add a \u003Clabel for\u003E, a wrapping \u003Clabel\u003E, or aria-label."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Pages/RoleManager.razor"},"region":{"startLine":53}}}],"partialFingerprints":{"codehealthFindingId/v1":"c6c4fc15b9294eed46ac7dda34e48d341d92471069d5b0620e7748587c62f09e"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Cbutton\u003E with no accessible text: A button with no text and no aria-label has no accessible name. Add visible text or an aria-label (an icon-only button still needs one)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Pages/RoleManager.razor"},"region":{"startLine":58}}}],"partialFingerprints":{"codehealthFindingId/v1":"72314d9e9fea46cccc9fa941d73994f160dbc3284980d65d27293867b83d8e9d"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Cbutton\u003E with no accessible text: A button with no text and no aria-label has no accessible name. Add visible text or an aria-label (an icon-only button still needs one)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Pages/RoleManager.razor"},"region":{"startLine":74}}}],"partialFingerprints":{"codehealthFindingId/v1":"bfda3a876314ac4dbd6d90edaac891539522fbd47c12eedca192a15da7dddf52"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Cinput\u003E without a programmatic label: This control has no associated label. Add a \u003Clabel for\u003E / wrapping \u003Clabel\u003E / aria-label / aria-labelledby so assistive tech can name it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Pages/RoleManager.razor"},"region":{"startLine":77}}}],"partialFingerprints":{"codehealthFindingId/v1":"da5b1ae212c8af4304e9bdd5fde1bfce80de481e6206f6d237ad4b163280ac41"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Cbutton\u003E with no accessible text: A button with no text and no aria-label has no accessible name. Add visible text or an aria-label (an icon-only button still needs one)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Pages/UserManager.razor"},"region":{"startLine":39}}}],"partialFingerprints":{"codehealthFindingId/v1":"4ca8c1177af41d26dbf3f6772a91d78b76e526ffa2f7328c82454dc77be9f86e"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Cbutton\u003E with no accessible text: A button with no text and no aria-label has no accessible name. Add visible text or an aria-label (an icon-only button still needs one)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Pages/UserManager.razor"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"88ab78edfb4a423766cc78f10b4777524dc6f69ff27bc300ad8bb7db7f1f4ff6"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Cbutton\u003E with no accessible text: A button with no text and no aria-label has no accessible name. Add visible text or an aria-label (an icon-only button still needs one)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Pages/WorkItems.razor"},"region":{"startLine":44}}}],"partialFingerprints":{"codehealthFindingId/v1":"9607cd4a022e449ebe158b61a1aeea0d15b711dedd111f7353d41b3728c8b786"}},{"ruleId":"AC2","level":"error","message":{"text":"\u003Cbutton\u003E with no accessible text: A button with no text and no aria-label has no accessible name. Add visible text or an aria-label (an icon-only button still needs one)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Pages/WorkItems.razor"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"350e2ab9c59e04ef27cb87c05a01ed1ce2334f1d81745d49f73a2becadcbb95c"}},{"ruleId":"AC3","level":"error","message":{"text":"Routed page without a \u003CPageTitle\u003E: A route with no \u003CPageTitle\u003E gives no name in the tab, history or screen-reader page list \u2014 the host\u0027s \u003CHeadOutlet /\u003E projects whatever title the routed component supplies, and this one supplies none. Add a \u003CPageTitle\u003E to this component (a literal \u003Ctitle\u003E in the host document would be overwritten by the outlet)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Pages/Authentication.razor"},"region":{"startLine":3}}}],"partialFingerprints":{"codehealthFindingId/v1":"45b7ad81bba61aa6ff6cd65edf4083b37c08711e3e9266ba7ec56e12b047f32b"}},{"ruleId":"AC3","level":"warning","message":{"text":"Heading level jumps from h1 to h5: Skipping heading levels breaks the document outline assistive tech relies on. Don\u0027t jump levels \u2014 increase by at most one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Pages/RoleManager.razor"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"3f499834fa1a773484505197cd4c5fcad3cc1a44e8d30ebcc484742e5f7398c3"}},{"ruleId":"AC3","level":"error","message":{"text":"Viewport restricts zoom: user-scalable=no/0 or a maximum-scale below 2 stops low-vision users zooming to 200%. Remove the zoom restriction from the viewport meta."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/wwwroot/index.html"},"region":{"startLine":6}}}],"partialFingerprints":{"codehealthFindingId/v1":"d02076a59d98d695546ee7de0bead8986709ffacec8660731e5274f7017fd3f6"}},{"ruleId":"AC4","level":"error","message":{"text":"Click handler on a non-interactive \u003Cli\u003E: A click handler on a plain element isn\u0027t keyboard-operable. Use a \u003Cbutton\u003E, or add role \u002B tabindex=\u00220\u0022 \u002B a key handler."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Components/Projects/ProjectItem.razor"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"499cefe6153d7935345bff14292034b26959daadc49060e4250322d8ec6aa616"}},{"ruleId":"AC4","level":"error","message":{"text":"Click handler on a non-interactive \u003Cdiv\u003E: A click handler on a plain element isn\u0027t keyboard-operable. Use a \u003Cbutton\u003E, or add role \u002B tabindex=\u00220\u0022 \u002B a key handler."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Shared/NavMenu.razor"},"region":{"startLine":10}}}],"partialFingerprints":{"codehealthFindingId/v1":"e9260a4376b23101616c2a8e3892acae986f400a4a4625ebaf2e75099715fd01"}},{"ruleId":"AC4","level":"warning","message":{"text":"Anchor without href: An \u003Ca\u003E with no href, role or tabindex isn\u0027t focusable or keyboard-activatable. Give it a real href, or use a \u003Cbutton\u003E for an action."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/wwwroot/index.html"},"region":{"startLine":22}}}],"partialFingerprints":{"codehealthFindingId/v1":"a4aa910ffc3d0e590d97a03910387135c29d3e449d78765379c4e6324d0b6c6f"}},{"ruleId":"AC6","level":"warning","message":{"text":"Low contrast colour pair in CSS (4.0:1): \u0060.modal-header\u0060 sets color: #fff on background-color: #007bff \u2014 4.0:1, below the 4.5:1 WCAG AA minimum for normal text. Darken or lighten one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/UI/Components/WorkItems/WorkItemDialog.razor.css"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"2791a731517f6a379ddf646ce37dea26e45567041839ab4c272d1ed64eac5aab"}},{"ruleId":"AC7","level":"warning","message":{"text":"Accessibility enforcement below the top rung: No accessibility enforcement found \u2014 no automated accessibility check runs over the HTML your app renders. Assert the accessibility invariants over that HTML in the test suite you already have (parse the output and assert, or drive a browser), and gate that test in CI so a regression blocks the merge. What was searched, so you can tell an absence from a miss: the 23 markup file(s) this pass actually assessed, the linter configuration checked in beside them, and this repository\u0027s test and CI files \u2014 matched by name against the accessibility checkers this dimension carries. An audit run outside the repository, a hosted scanner, or a check whose name is not one of those, is not seen here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d46019b86eff5ddad9db289e6802ac158899e980df54c34f67722442787ead62"}},{"ruleId":"C3","level":"note","message":{"text":"Partial audit-trail evidence: An audit mechanism is present, but the trail is not yet complete \u2014 missing: an immutable audit-log / audit-trail type to write to, [Audited] per-entity coverage."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"274a04e524f3228d241c99316455563739cb06cfd10a01e446d00b8a14956083"}},{"ruleId":"DM1","level":"error","message":{"text":"Aggregate holds a reference to another aggregate: Project.WorkItems: \u0060Project\u0060 references the aggregate root \u0060WorkItem\u0060 directly (via \u0060WorkItems\u0060) \u2014 hold its \u0060WorkItemId\u0060 instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Domain/Entities/Project.cs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"178ed0da3575c1c776032e17c532c3c261df64a9779fa8f770d5c90977b5dd3a"}},{"ruleId":"DM1","level":"error","message":{"text":"Aggregate holds a reference to another aggregate: WorkItem.Project: \u0060WorkItem\u0060 references the aggregate root \u0060Project\u0060 directly (via \u0060Project\u0060) \u2014 hold its \u0060ProjectId\u0060 instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Domain/Entities/WorkItem.cs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"72800782166ff87ea0d941e08a37441451f7ae799e8c085f97d8f97167920c1a"}},{"ruleId":"DM10","level":"warning","message":{"text":"One operation mutates 2 aggregates: ApplicationDbContextInitialiser.SeedAsync: \u0060ApplicationDbContextInitialiser.SeedAsync\u0060 saves \u0060WorkItem\u0060, \u0060IdentityUser\u0060 in a single operation. Each is its own consistency boundary, so committing them together makes the second\u0027s invariants depend on the first\u0027s transaction, holds a lock across both for the whole operation, and means the pair can no longer be separated \u2014 into different services, or different databases. Mutate one aggregate here and let the others follow from a domain event."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Infrastructure/Data/ApplicationDbContextInitialiser.cs"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"cc46c720b08db8e7e5863f8d5487f46b1b16abcb00d26ef5b4e089de92f665e4"}},{"ruleId":"DM2","level":"note","message":{"text":"Primitive id on a domain type: WorkItem.ProjectId: \u0060WorkItem.ProjectId\u0060 is a raw \u0060Int32\u0060 \u2014 give it a strongly-typed id: a dedicated single-field type wrapping the \u0060Int32\u0060, in whatever form your language spells that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Domain/Entities/WorkItem.cs"},"region":{"startLine":8}}}],"partialFingerprints":{"codehealthFindingId/v1":"d5892baad673dae922f504c65fb9cc1c64be42a936ce18808f28ca414238fdbe"}},{"ruleId":"DM4","level":"warning","message":{"text":"Anemic entity: Project: \u0060Project\u0060 is an aggregate/entity with 2 data propert(ies) but no state-changing behaviour (only data and queries) \u2014 the business logic lives in a service."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Domain/Entities/Project.cs"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"207ce723a4650d9e1d2a37c15c6d91f0dded6d0ff8258001f732414636c481e2"}},{"ruleId":"DM4","level":"warning","message":{"text":"Anemic entity: WorkItem: \u0060WorkItem\u0060 is an aggregate/entity with 9 data propert(ies) but no state-changing behaviour (only data and queries) \u2014 the business logic lives in a service."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Domain/Entities/WorkItem.cs"},"region":{"startLine":6}}}],"partialFingerprints":{"codehealthFindingId/v1":"f3bd43e88b0d9b5b9b6b7a06f7ef890704a9ac11ebc9cb01fc1fb0f0f3a27d30"}},{"ruleId":"DM5","level":"note","message":{"text":"Mutable entity: Project: \u0060Project\u0060 exposes publicly writable state (Title)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Domain/Entities/Project.cs"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"c4e85cf0e9121139ab27ffc1d280c9503964b0f4deb8f2385b302298b0b5f3c5"}},{"ruleId":"DM5","level":"note","message":{"text":"Mutable entity: WorkItem: \u0060WorkItem\u0060 exposes publicly writable state (ProjectId, Title, Description, Iteration, AssignedTo, StartDate, and 2 more)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Domain/Entities/WorkItem.cs"},"region":{"startLine":6}}}],"partialFingerprints":{"codehealthFindingId/v1":"7f5b14aff5ce4f23f41ac6073ebb94b7b5d61ba011cf7058e4d2430c5ff837f6"}},{"ruleId":"DM7","level":"warning","message":{"text":"Repository for a non-root entity: ProjectRepository \u2192 Project: \u0060ProjectRepository\u0060 is a repository over \u0060Project\u0060, which is an entity but not an aggregate root. Repositories should be per aggregate ROOT \u2014 loading/saving a child entity independently lets callers bypass the root\u0027s invariants. Access \u0060Project\u0060 through its owning aggregate instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Infrastructure/Data/ProjectRepository.cs"},"region":{"startLine":6}}}],"partialFingerprints":{"codehealthFindingId/v1":"7410190436800dfd60f9d77d8fb88460b784ed205144910f97b921f88ea75665"}},{"ruleId":"DM7","level":"warning","message":{"text":"Repository for a non-root entity: WorkItemRepository \u2192 WorkItem: \u0060WorkItemRepository\u0060 is a repository over \u0060WorkItem\u0060, which is an entity but not an aggregate root. Repositories should be per aggregate ROOT \u2014 loading/saving a child entity independently lets callers bypass the root\u0027s invariants. Access \u0060WorkItem\u0060 through its owning aggregate instead."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Infrastructure/Data/WorkItemRepository.cs"},"region":{"startLine":6}}}],"partialFingerprints":{"codehealthFindingId/v1":"0407419f0b5180d0441dff7535df83cb5c608feedfb0000cc1ec1b5da8c155a8"}},{"ruleId":"GD1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: A shipped member still throws NotImplementedException \u2014 generated scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/ApiServer/Mapper/ProjectsViewModelMapper.cs"},"region":{"startLine":27}}}],"partialFingerprints":{"codehealthFindingId/v1":"cf4968589342b38760efe10205a5ebc89d9e7384da106cb3be4585385769db4e"}},{"ruleId":"GD1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: A shipped member still throws NotImplementedException \u2014 generated scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/ApiServer/Mapper/RolesViewModelMapper.cs"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"a55a53e374a9b74c87d27f642b2ef0f9344c93d63fbc75e5780cdd7e861a686e"}},{"ruleId":"GD1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: A shipped member still throws NotImplementedException \u2014 generated scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/ApiServer/Mapper/UserDetailsViewModelMapper.cs"},"region":{"startLine":18}}}],"partialFingerprints":{"codehealthFindingId/v1":"e15c319a4bf5c2709edd84a6bfcb9678daf1f34919cd9b4d21630ce2c56ca2aa"}},{"ruleId":"GD1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: A shipped member still throws NotImplementedException \u2014 generated scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/ApiServer/Mapper/WorkItemMapper.cs"},"region":{"startLine":24}}}],"partialFingerprints":{"codehealthFindingId/v1":"9b76c3160f94cfcd074e6865fdc18257132573416528bcef3d3de28ec2027c4d"}},{"ruleId":"GD1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: A shipped member still throws NotImplementedException \u2014 generated scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/ApiServer/Mapper/WorkItemViewModelMapper.cs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"2c41c50ca4146c5c4af8c91a2e937bc486d65a7de7783fb8f7fa75ade1b83718"}},{"ruleId":"IC1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: \u0060Map\u0060 is a shipped member whose whole body throws NotImplementedException \u2014 scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/ApiServer/Mapper/ProjectsViewModelMapper.cs"},"region":{"startLine":27}}}],"partialFingerprints":{"codehealthFindingId/v1":"1b05af0a711006e2c088c4a0769340870d294bf3ed8b33ee84dff9e95b412c74"}},{"ruleId":"IC1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: \u0060Map\u0060 is a shipped member whose whole body throws NotImplementedException \u2014 scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/ApiServer/Mapper/RolesViewModelMapper.cs"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"7c4192dc6f7486ceed9621e2197b5a28e39df3bd04eff99ad37c700946946956"}},{"ruleId":"IC1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: \u0060Map\u0060 is a shipped member whose whole body throws NotImplementedException \u2014 scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/ApiServer/Mapper/UserDetailsViewModelMapper.cs"},"region":{"startLine":18}}}],"partialFingerprints":{"codehealthFindingId/v1":"eac90aa8b7b82f02c774a3b496a668ddbb58af8fa46be6151c6be16b7e49f782"}},{"ruleId":"IC1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: \u0060Map\u0060 is a shipped member whose whole body throws NotImplementedException \u2014 scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/ApiServer/Mapper/WorkItemMapper.cs"},"region":{"startLine":24}}}],"partialFingerprints":{"codehealthFindingId/v1":"cdc18c36ffbcdfa3f2f56c10781647bf05056fdcbb3f02e635d8ea8af4ba5bde"}},{"ruleId":"IC1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: \u0060Map\u0060 is a shipped member whose whole body throws NotImplementedException \u2014 scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Web/ApiServer/Mapper/WorkItemViewModelMapper.cs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"e41c08ab24f9e22abe12b4061d712a3a8c1e0a226a8440db8227f5a1421961d1"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"M3","level":"note","message":{"text":"Inconsistent root namespaces: Only 2/10 projects share a common root namespace \u2014 the code\u0027s module identity is inconsistent."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c8031c9fb77ad97c2e4a8ddb29978f4bf30140d481913bd7fde8b5adbbb83ede"}},{"ruleId":"P2","level":"note","message":{"text":"Logging is not universal: Only 2/4 service-like projects use logging (pure contract/DTO projects are excluded \u2014 they have nothing to log). Of those 4, 1 ship a process this repository operates; the rest are libraries their consumer hosts, where the logging decision belongs to the host."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"91a94e21d6d4d0e6a2003f94505b0b02b157176f0b24c4820f3f82b4447a97fe"}},{"ruleId":"P4","level":"note","message":{"text":"No rollback/health safety: Deployment automation exists but no readiness/liveness probes, rolling-update strategy, lifecycle hooks or migration job were evidenced \u2014 a bad release is harder to detect and reverse."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"db6bab8a28a2145f47e5a4e6683cda39d2ba0296c723238e8057da979ae1c706"}},{"ruleId":"P7","level":"warning","message":{"text":"Outbound HTTP without resilience: The app makes outbound HTTP calls but no resilience handler was detected (Polly / AddStandardResilienceHandler / circuit-breaker). A slow or failing dependency will cascade \u2014 add timeouts, retries with back-off, and a circuit breaker."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ade5e84aadd8f28a7d64d01fa0cdf67f4f716f0df3ba2641e60599b08325bd5f"}},{"ruleId":"S1","level":"note","message":{"text":"No security response headers detected: No Content-Security-Policy / X-Frame-Options / X-Content-Type-Options configuration found \u2014 defense in depth, even when a reverse proxy could set them. (\u22122.0 on this card.)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"bd19c680309417e132c0be93c2002123f0664b42afe6172b1319da65a6a57ba7"}},{"ruleId":"SC1","level":"warning","message":{"text":"NuGet dependencies are not locked: No packages.lock.json and no central package management \u2014 restores aren\u0027t reproducible or pinned (SSDF PW.4.4). Enable \u003CRestorePackagesWithLockFile\u003Etrue\u003C/RestorePackagesWithLockFile\u003E (commit the lockfile) or adopt Directory.Packages.props. Advisory \u2014 never scored."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0a97b4f69ccac509400ece7eedefb06d3ede0522cd4d8bcb5c068bea719545a6"}},{"ruleId":"X1","level":"warning","message":{"text":"Sync-over-async (deadlock risk): Blocking on a Task with \u0060.Wait()\u0060/\u0060.GetAwaiter().GetResult()\u0060 can deadlock (and wastes a thread). Prefer awaiting it: make the caller \u0060async\u0060 and \u0060await\u0060 instead. Where a synchronous entry point must stay \u2014 a public sync API you cannot break, or a process entry point that must not return until the work finishes \u2014 the block belongs in ONE documented bridge and never inside code that is already async; and where it already is that bridge, give the wait a TIMEOUT so a hung task fails the call instead of hanging the process."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Infrastructure/Data/Interceptors/DomainEventsDispatcherInterceptor.cs"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"cd4e3b4e9815216f2394fbc9824b985ee26085905bff874f343a431e5c1a491d"}},{"ruleId":"X2","level":"note","message":{"text":"Not all async methods take a CancellationToken: Only 55/85 async methods accept a CancellationToken, so in-flight work can\u0027t be stopped early when the caller gives up \u2014 whatever ends it in your host (shutdown signal, timeout, abandoned request, user cancel). Thread a token through the call chain and honour it at each await and loop; where a method genuinely cannot be interrupted, omitting it is a deliberate choice \u2014 judge against your hosting model."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"bf623a92fb752b336427856888a9b386c434e686662a2cdc1bba21832c0a048c"}},{"ruleId":"X5","level":"note","message":{"text":"Null-forgiving operator (\u0060!\u0060) suppressions reduce the NRT score: ~1.1 \u0060!\u0060 suppressions per 1k syntax nodes \u2014 44 suppression(s) across the 39346 syntax node(s) in code where nullable warnings are ENABLED, which is the only code a \u0060!\u0060 can suppress anything in (a \u0060!\u0060 under \u0060#nullable disable\u0060 is inert and is not counted, and its file\u0027s nodes are not in the denominator). Each one tells the compiler to trust you about null, suppressing the very safety NRTs provide."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"93cfe05d4ad8c8c171267603b23dfe289b74842e38edd1b7bfed59cc32bda337"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-1059","guid":"a2381a08-60f6-9554-a8b8-f3018cfaaca5","name":"Insufficient Technical Documentation","shortDescription":{"text":"Insufficient Technical Documentation"},"helpUri":"https://cwe.mitre.org/data/definitions/1059.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-862","guid":"2d96ecd7-f7f1-7f55-9f3a-43bb5bafdf33","name":"CWE-862","shortDescription":{"text":"CWE-862"},"helpUri":"https://cwe.mitre.org/data/definitions/862.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":22,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}