{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}]},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D24","name":"Comment Value","shortDescription":{"text":"Comment Value"},"helpUri":"https://codehealth.canine.dev/dimensions/D24"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}]},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"}]}},"results":[{"ruleId":"D2","level":"warning","message":{"text":"ManageController.Index (cognitive 21): ManageController.Index has cognitive complexity 21 (threshold 15)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Presentation/Controllers/ManageController.cs"},"region":{"startLine":55}}}],"partialFingerprints":{"codehealthFindingId/v1":"13edd55967f7d05bd3cb29dd4ba6a56c2c92841991c0154e56789943117ffaad"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): Presentation/Controllers/HomeController.cs:43-52 | Presentation/Controllers/placesController.cs:37-46"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Presentation/Controllers/HomeController.cs"},"region":{"startLine":43}}}],"partialFingerprints":{"codehealthFindingId/v1":"bdf5322e1d4b054abfede4b605a40cfd7d37213818dd24ba0b44dcaca4783b99"}},{"ruleId":"D8","level":"error","message":{"text":"No automated tests: No automated tests \u2014 the solution has no test code. Untested code is the largest single risk to changing it safely."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3132564c6310e5d01a231f252a02d5d2f5a542c0a8fa29a14c89693f1e3df871"}},{"ruleId":"D9","level":"note","message":{"text":"No tests found: No test projects found in the repository."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c9bf64cbb5a4ae13d6bcd01fa3bc8d2879d860c73bc67f176ee3c2cecb8adce3"}},{"ruleId":"D13","level":"error","message":{"text":"Leaked secret: gcp-api-key: gcp-api-key detected."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Presentation/Views/Home/Details.cshtml"},"region":{"startLine":38}}}],"partialFingerprints":{"codehealthFindingId/v1":"906823dfb83c8e69c185899b08d331387e1cfbf1685069672f87b20ffce84f22"}},{"ruleId":"D17","level":"warning","message":{"text":"CommentedOutCode: 5 consecutive commented-code lines"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Presentation/App_Start/Startup.Auth.cs"},"region":{"startLine":61}}}],"partialFingerprints":{"codehealthFindingId/v1":"6deea59570fd91fd85ce1135ad80a3f8b46144ddf18fcd4f91fb6e2200080390"}},{"ruleId":"D17","level":"warning","message":{"text":"CommentedOutCode: 3 consecutive commented-code lines"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Presentation/Controllers/AccountController.cs"},"region":{"startLine":162}}}],"partialFingerprints":{"codehealthFindingId/v1":"9d81de8f3b7545d8e83062b948ffe76cf341575d60901601d895e7526474e317"}},{"ruleId":"D17","level":"warning","message":{"text":"CommentedOutCode: 4 consecutive commented-code lines"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Presentation/Controllers/AccountController.cs"},"region":{"startLine":214}}}],"partialFingerprints":{"codehealthFindingId/v1":"9d81de8f3b7545d8e83062b948ffe76cf341575d60901601d895e7526474e317"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: Presentation: Presentation: 1 % XML-doc coverage (2/234)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Presentation/Presentation.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"15b1466b370a8af93f887a2ae3d63eda4776950b09540ab9016be219a44f91c6"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: Domain: Domain: 0 % XML-doc coverage (0/68)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Domain/Domain.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c741529f6ef0304a2999bf2f01543f5683f06281812b6ac180d9aef73e36596d"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: Application: Application: 0 % XML-doc coverage (0/22)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Application/Application.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"2aeec7a7dbf3c65b4293a8d2cfcad4e587040c2cb0c96edad580878e17220300"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: Infra: Infra: 0 % XML-doc coverage (0/23)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Infra/Infra.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f5094b2d5e2b7374452662e28eb17cbf9c95b071b71048d7b6f552f0ce3961b9"}},{"ruleId":"D21","level":"note","message":{"text":"Entity types are inconsistently named: some use plural forms (e.g., \u0027transport\u0027 is singular, \u0027hotels\u0027 is plural in controller, \u0027activities\u0027 is plural in controller, \u0027places\u0027 is plural in controller, \u0027users\u0027 is plural in context). The entity classes themselves use singular nouns for transport, hotel, activity, place, and user, but the context and controllers use plural forms or inconsistent casing.: Standardize entity class names to a consistent singular noun (e.g., Transport, Hotel, Activity, Place, User) and ensure all related references (controllers, contexts) use consistent plural forms (e.g., Transports, Hotels, Activities, Places, Users). (symbols: Domain.Entities.transport, Domain.Entities.hotel, Domain.Entities.activity, Domain.Entities.place, Domain.Entities.user)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3963a2881bdb884b0da2f9854bb38b34279038527ae484085c07585d3b0e1923"}},{"ruleId":"D21","level":"note","message":{"text":"Repository interfaces are inconsistently named: some follow a generic pattern (IRepositoryBase), while others are specific (IRepositoryPlace, IRepositoryActivity, IRepositoryTransport). This creates a mixed pattern where some entities have specific repository interfaces and others use the generic base.: Either use a single generic IRepository\u003CT\u003E for all entities, or create specific interfaces for each entity (e.g., IPlaceRepository, IActivityRepository) consistently. (symbols: Domain.Interface.Repositories.IRepositoryBase\u003CTEntity\u003E, Domain.Interface.Repositories.IRepositoryPlace, Domain.Interface.Repositories.IRepositoryActivity, Domain.Interface.Repositories.IRepositoryTransport)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f4f46026569ee1ee5a0ff0e63582c336000062db5e93a68de9b1d1fc0e3c38a4"}},{"ruleId":"D21","level":"note","message":{"text":"Service classes are inconsistently named: the base class is \u0027AppServiceBase\u0027, while specific services are named \u0027AppServiceTransport\u0027, \u0027AppServiceActivity\u0027, etc. This mixes a generic base with specific implementations that don\u0027t follow a consistent naming pattern (some use \u0027AppService\u0027, some use \u0027Service\u0027 in other parts of the codebase).: Standardize service naming to either \u0027AppService\u003CT\u003E\u0027 for all, or \u0027Service\u003CT\u003E\u0027 for all, ensuring consistency between base and derived classes. (symbols: Application.AppServiceBase\u003CTEntity\u003E, Application.AppServiceTransport, Application.AppServiceActivity, Application.AppServiceHotel, Application.AppServicePlace)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"32bba4a0ef222bce7bc592d4842a032b6dce14705f727e8cccaf9f45da35776b"}},{"ruleId":"D21","level":"note","message":{"text":"Service interfaces are inconsistently named: some follow a generic pattern (IServiceBase), while others are specific (IServiceActivity, IServiceHotel, etc.). This creates a mixed pattern where some entities have specific service interfaces and others use the generic base.: Either use a single generic IService\u003CT\u003E for all entities, or create specific interfaces for each entity (e.g., IActivityService, IHotelService) consistently. (symbols: Domain.Interface.Services.IServiceBase\u003CTEntity\u003E, Domain.Interface.Services.IServiceActivity, Domain.Interface.Services.IServiceHotel, Domain.Interface.Services.IServicePlace, Domain.Interface.Services.IServiceTransport)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"15b86ff0f944edb7bea7fa88abe13a668c9690caf7b8352bea52dc25ed8352c6"}},{"ruleId":"D21","level":"note","message":{"text":"Controller classes are inconsistently named: some use plural nouns (hotels, activities, places, transports) while others use singular or different patterns. This creates a lack of consistency in controller naming conventions.: Standardize controller naming to use plural nouns (e.g., HotelsController, ActivitiesController) consistently across all controllers. (symbols: Presentation.Controllers.hotelsController, Presentation.Controllers.activitiesController, Presentation.Controllers.placesController, Presentation.Controllers.transportsController)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c804ea689ea2d4271f10db7d4ea1b726c1c99ff724f61e9cf789ced3fa499961"}},{"ruleId":"D24","level":"note","message":{"text":"redundant comment: \u0022For more information on configuring authentication, please visit http://go.microsoft.com/fwlink/?LinkId=301864\u0022 \u2014 keep as guidance; links to a decision reference but is not restating ConfigureAuth"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"Presentation/App_Start/Startup.Auth.cs"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"df12d4f2c168254b00599d1cf50b2e873530580ecef577692bd94dda39c66e87"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-798","name":"Use of Hard-coded Credentials"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":0,"secretScannerRunsExcluded":0}}}]}