{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D7","name":"Architectural Integrity","shortDescription":{"text":"Architectural Integrity"},"helpUri":"https://codehealth.canine.dev/dimensions/D7"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D25","name":"ADR Conformance","shortDescription":{"text":"ADR Conformance"},"helpUri":"https://codehealth.canine.dev/dimensions/D25"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D33","name":"JS/npm Dependency Vulnerabilities","shortDescription":{"text":"JS/npm Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D33","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D37","name":"Vulnerability-disclosure Policy","shortDescription":{"text":"Vulnerability-disclosure Policy"},"helpUri":"https://codehealth.canine.dev/dimensions/D37","relationships":[{"target":{"id":"CWE-1059","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1059"]}},{"id":"D38","name":"OSV Dependency Vulnerabilities","shortDescription":{"text":"OSV Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D38","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}}]}},"results":[{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (21 lines \u00D7 2): boundaries/link/internal/infrastructure/repository/crud/mongo/mongo.go:59-79 | boundaries/link/internal/infrastructure/repository/crud/postgres/postgres.go:63-83 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060boundaries/link/internal/infrastructure/repository/crud/mongo/mongo.go:59\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"boundaries/link/internal/infrastructure/repository/crud/mongo/mongo.go"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"602e6e827990a2e447d7ef97d44ffd430284b72155561c775f2163175e7cd78c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 3): boundaries/api/api-gateway/gateways/cloudevents/cmd/api.go:24-39 | boundaries/api/api-gateway/gateways/graphql/cmd/api.go:24-39 | boundaries/api/api-gateway/gateways/grpc-web/cmd/api.go:24-39 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 3 call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made 3 times. The matched lines also register a scope-exit action (a \u0060defer\u0060-style statement) that runs when the function holding them returns: moved into a called unit it would run when THAT unit returns instead \u2014 before the caller uses what it releases \u2014 so keep the registration at the call site and extract only the work around it, or have the extracted unit hand the resource back for the caller to register."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"boundaries/api/api-gateway/gateways/cloudevents/cmd/api.go"},"region":{"startLine":24}}}],"partialFingerprints":{"codehealthFindingId/v1":"da9ec941c13597e7ffe710ae1c32259c1b13fd18d86d57979a8aea42c63b50da"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): boundaries/link/internal/usecases/link_cqrs/api.go:53-67 | boundaries/link/internal/usecases/link_cqrs/api.go:96-110 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060boundaries/link/internal/usecases/link_cqrs/api.go:53\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"boundaries/link/internal/usecases/link_cqrs/api.go"},"region":{"startLine":53}}}],"partialFingerprints":{"codehealthFindingId/v1":"2a31f90bf6172c6d92b925cb5c84c2c09c532edfa53f8465b00988f9e62ccefd"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): boundaries/api/api-gateway/gateways/cloudevents/infrastructure/server/server.go:33-46 | boundaries/api/api-gateway/gateways/graphql/infrastructure/server/server.go:35-48 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"boundaries/api/api-gateway/gateways/cloudevents/infrastructure/server/server.go"},"region":{"startLine":33}}}],"partialFingerprints":{"codehealthFindingId/v1":"657d7905eb6621c13c7c69f87408eaf9898d7558ab3c1e2b447718b1177cb422"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): boundaries/link/internal/infrastructure/repository/cqrs/cqs/postgres/cqs_link.go:18-31 | boundaries/link/internal/infrastructure/repository/cqrs/cqs/postgres/cqs_link.go:59-72 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"boundaries/link/internal/infrastructure/repository/cqrs/cqs/postgres/cqs_link.go"},"region":{"startLine":18}}}],"partialFingerprints":{"codehealthFindingId/v1":"c793c9df4c6fedb0b4122c2bdea41eb9d2e89a126444ca94423633aca5f43605"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): boundaries/link/internal/usecases/link/add.go:47-60 | boundaries/link/internal/usecases/link/delete.go:31-44 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060boundaries/link/internal/usecases/link/add.go:47\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"boundaries/link/internal/usecases/link/add.go"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"063943c14c874d22faf2b512b36debffc5cfd8f14392ce7ddd2f30fc2b2c9a79"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): boundaries/link/internal/infrastructure/repository/crud/ram/ram.go:107-119 | boundaries/link/internal/infrastructure/repository/crud/mongo/mongo.go:90-102 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060boundaries/link/internal/infrastructure/repository/crud/ram/ram.go:107\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"boundaries/link/internal/infrastructure/repository/crud/ram/ram.go"},"region":{"startLine":107}}}],"partialFingerprints":{"codehealthFindingId/v1":"92a3356af3592ed3bc435572739d69304e658d3e6a0bed184e219187888d1342"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): boundaries/link/internal/infrastructure/repository/cqrs/query/postgres/get.go:51-63 | boundaries/link/internal/infrastructure/repository/cqrs/query/postgres/list.go:75-87 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060boundaries/link/internal/infrastructure/repository/cqrs/query/postgres/get.go:51\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"boundaries/link/internal/infrastructure/repository/cqrs/query/postgres/get.go"},"region":{"startLine":51}}}],"partialFingerprints":{"codehealthFindingId/v1":"323853367a71da8d8d8fb9976ad74060f12bdb7379bd6b446dcf0c9fac20fb80"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 3): boundaries/link/internal/usecases/link_cqrs/api.go:40-51 | boundaries/link/internal/usecases/link_cqrs/api.go:83-94 | boundaries/link/internal/usecases/link/get.go:43-54 \u2014 there are 3 copies across 2 file(s) \u2014 more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 3 sites; resolving a subset leaves the remainder to drift apart. Read the line range as the matched WINDOW rather than a finished unit: at \u0060boundaries/link/internal/usecases/link_cqrs/api.go:40\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"boundaries/link/internal/usecases/link_cqrs/api.go"},"region":{"startLine":40}}}],"partialFingerprints":{"codehealthFindingId/v1":"ca66d15ee205f02e11a17e48ea84c88a922a0a54e4affa4ea2419cb68bb7eda0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): boundaries/link/internal/infrastructure/repository/crud/dgraph/dgraph.go:61-71 | boundaries/link/internal/infrastructure/repository/crud/dgraph/dgraph.go:162-172 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited. Read the line range as the matched WINDOW rather than a finished unit: at \u0060boundaries/link/internal/infrastructure/repository/crud/dgraph/dgraph.go:61\u0060 it does not close everything it opens, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also register a scope-exit action (a \u0060defer\u0060-style statement) that runs when the function holding them returns: moved into a called unit it would run when THAT unit returns instead \u2014 before the caller uses what it releases \u2014 so keep the registration at the call site and extract only the work around it, or have the extracted unit hand the resource back for the caller to register."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"boundaries/link/internal/infrastructure/repository/crud/dgraph/dgraph.go"},"region":{"startLine":61}}}],"partialFingerprints":{"codehealthFindingId/v1":"541ce3ad104a1690593c55f83535026a3a6698c417821e4087868a8ec4907b76"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): boundaries/link/internal/usecases/link/error.go:18-28 | boundaries/link/internal/usecases/link_cqrs/api.go:18-28 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060boundaries/link/internal/usecases/link/error.go:18\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. The matched lines also transfer control out of the body holding them, which cannot survive a move into a called unit unchanged: have the extracted unit return that decision and let each site act on it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"boundaries/link/internal/usecases/link/error.go"},"region":{"startLine":18}}}],"partialFingerprints":{"codehealthFindingId/v1":"e0f33b81a8e795c5d844906ca30ae55c1b9ce5133f754d22abb4dd771abc971b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): boundaries/link/internal/usecases/sitemap/parser.go:89-98 | boundaries/link/internal/usecases/link/add.go:183-192 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060boundaries/link/internal/usecases/sitemap/parser.go:89\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"boundaries/link/internal/usecases/sitemap/parser.go"},"region":{"startLine":89}}}],"partialFingerprints":{"codehealthFindingId/v1":"ae3623c8c75aad97e721b6120911864d9de51825afbb1fb2282eb08c9c6c36b7"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): boundaries/link/internal/usecases/link/get.go:55-64 | boundaries/link/internal/usecases/link/list.go:111-120 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060boundaries/link/internal/usecases/link/get.go:55\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"boundaries/link/internal/usecases/link/get.go"},"region":{"startLine":55}}}],"partialFingerprints":{"codehealthFindingId/v1":"526cb29a14496353fb5ed6ab0e97285a12807fd4e0a3e51fec12ed53cf8e116b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): boundaries/link/internal/usecases/link_cqrs/handle_add.go:18-27 | boundaries/link/internal/usecases/link_cqrs/handle_update.go:18-27 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060boundaries/link/internal/usecases/link_cqrs/handle_add.go:18\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"boundaries/link/internal/usecases/link_cqrs/handle_add.go"},"region":{"startLine":18}}}],"partialFingerprints":{"codehealthFindingId/v1":"8453de1f304a7fd10f9b0d0c961bf9fba77c564c3a8b39f7f2679da3ee76d9b4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): boundaries/link/internal/infrastructure/rpc/link/v1/get.go:31-38 | boundaries/link/internal/infrastructure/rpc/link/v1/update_response_dto.go:10-17 \u2014 the copies sit in sibling files of one directory: extract the block into a single shared function in that directory and call it from each site, so a change lands once. Read the line range as the matched WINDOW rather than a finished unit: at \u0060boundaries/link/internal/infrastructure/rpc/link/v1/get.go:31\u0060 it begins part-way through the construct above it, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. Note that the copies do not run to the end of the range shown: their LAST lines are different code, not the same code under different names \u2014 the matched region ends inside that line. Extract the lines above it, and read the last line of each site separately."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"boundaries/link/internal/infrastructure/rpc/link/v1/get.go"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"e309e034f416d9346cfe840ab52dedf33ad2950805172424c72c1e0638d0f5cd"}},{"ruleId":"D13","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a526c02cb449a711d12bc0a2ad73c577addf63753dd8521ed97d55a0c37f6ace"},"taxa":[{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D13","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"02145dd5d60a070c8fe90b198c4169306e0b55029728f6a8483a52efc2b5e069"},"taxa":[{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D13","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bb7f46508bbd8f5b6801292bbb39c34eb74fe0087918df45e517806299bb5750"},"taxa":[{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #1: If anonymized user #1 becomes unavailable, 53 significant file(s) lose their only recent owner: boundaries/ui/src/app/add-link/page.tsx, boundaries/ui/src/components/Profile/Personal.tsx, boundaries/ui/src/components/Profile/Profile.tsx, boundaries/ui/src/app/admin/sitemap/page.tsx, boundaries/proxy/src/infrastructure/messaging/RabbitMQMessageBus.ts, boundaries/metadata/internal/usecases/metadata/metadata.go, boundaries/proxy/src/infrastructure/telemetry.ts, boundaries/proxy/src/di/container.ts (\u002B45 more). Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4b80ca84433dab97a1e0b9dad1c519a787816e17901cf98e82766def03c7dda5"}},{"ruleId":"D20","level":"warning","message":{"text":"Context and consequences are both cited to an external source (Michael Nygard\u0027s blog \u002B adr-tools repo), leaving the ADR itself uninformative and its own rationale buried in links: Replace the Context/Consequences with a one-paragraph rationale explaining why records matter and where they will live, then explicitly state the decision and any trade-offs of adopting an external tool"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/ADR/decisions/0001-record-architecture-decisions.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f3b2050cbac819c83fdb6f2dd5de8850846adeddbc647447990819b058ac7a80"}},{"ruleId":"D20","level":"warning","message":{"text":"Informative title (\u00223. Observability\u0022) is generic rather than naming the observable problem or decision; trade-offs of adding HTTP endpoints and probes are not stated: Give the ADR a specific title reflecting the observable problem (e.g., \u0022Standardised Health/Performance Monitoring for Services\u0022) so readers know what it addresses, plus add a Consequences section on trade-offs such as added routing overhead and the cost of maintaining three new endpoints per service"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/ADR/decisions/0003-observability-health-check.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"84a7c4052826c6934c1077282703279f1ec122a6af5d6a5594360939632d058e"}},{"ruleId":"D20","level":"warning","message":{"text":"Decision and consequences are present but the visible text clips mid-context before any trade-offs (e.g. storage overhead, lookup cost) can be assessed: "},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/ADR/decisions/0004-use-uuid-as-primary-keys.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a2ea39fe8dbca6e5db23e65455b1ab6e1051dae06c24139747daa90432a5db93"}},{"ruleId":"D20","level":"warning","message":{"text":"Informative title (uninformative) plus thin context (only one sentence about CODEOWNERS purpose) with no trade-offs; the decision is a bulleted example linked to an external blog post but there are no consequences in text form: Rename the ADR to something like \u00276. Codeowners: defining responsible teams and projects\u0027 so readers know what it addresses, then add a Consequences section covering trade-offs such as how team/project additions scale with growth"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/ADR/decisions/0006-codeowner.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"740a413d0c9aa5950a78773acb1f79725c2a6db54d9edf5f91f75ab5a446852e"}},{"ruleId":"D20","level":"warning","message":{"text":"The decision (what change was proposed) and its trade-offs are not visible before the stub clip: "},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/ADR/decisions/0007-optimization-network.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"553614f07e97028cf837982aa7882caa98ba92c884af0392d68be5a1da9153b8"}},{"ruleId":"D20","level":"warning","message":{"text":"Context is \u0027We want to know product metrics by each services.\u0027 and Decision is \u0027We made grafana dashboard for product-metrics by each services.\u0027 with Consequences only beginning (\u00271. Requirements dashboard\u0027): Add the real problem (e.g. lack of single source of product-level performance across services) so Context is informative, and flesh out the consequences section to explain what each Requirement type means"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/ADR/decisions/0008-product-metrics-by-services.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"933e19bd7c220f27f7d34dfd94f1ae053bddf3d5da24d63adecc09d5ea300170"}},{"ruleId":"D20","level":"warning","message":{"text":"Context is a one-line rationale (\u0027We use tracing and logging systems to track application events\u0027) with no trade-offs; consequences are citations rather than real consequences: Expand the Context section to state why OTLP naming matters (e.g. reproducibility, debugging) and add a Consequences section on how not following it breaks observability"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/ADR/decisions/0009-naming-spans-and-attributes.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1f042cdddb8d88bd443b3d90940dca22fd3dad9f68fa6d22dee043195124151f"}},{"ruleId":"D20","level":"warning","message":{"text":"Consequences are thin (\u0027We use next material for made our logger format\u0027) rather than trade-offs such as OTel integration cost or operational complexity: Add a Consequences section covering the trade-offs of relying on OTel distributed tracing (e.g. trace_id storage, sampling overhead) and how they will be managed"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/ADR/decisions/0010-logger-format.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0962deea80521a21395bdabad44994f4cde94453682292cb3c1b0cf2d689e2b3"}},{"ruleId":"D20","level":"warning","message":{"text":"Consequences are restatements rather than trade-offs (e.g. learning curve for PlantUML/C4-PlantUML vs existing tools): Add a Consequences section on the skill/learning curve needed to adopt C4-PlantUML and maintain the documentation set"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/ADR/decisions/0011-application-architecture-documentation.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"6f59320e3d388a43abd73ac9e73628069d152f3de3da3cdbc02b3b253ace8849"}},{"ruleId":"D20","level":"warning","message":{"text":"Context and decision are identical (\u0027We want to have a monorepository...\u0027) with no context/problem and no consequences; only one sentence in body: Replace the duplicate title with an informative problem (e.g. \u0027Centralize platform code across services so shared libraries and CI work seamlessly\u0027) then flesh out Context, add Consequences/trade-offs, and document why a monorepo is preferred over multiple repos"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/ADR/decisions/0012-use-monorepository.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"510d6121c212d1f82459310f8082dadaf8a1c89bf591964b86f8885a24aad0d1"}},{"ruleId":"D20","level":"warning","message":{"text":"Context is a single sentence (\u0027We want to use integration tests to verify the correctness of our code.\u0027) and decision restates \u0027We will use k6\u0027 with no rationale; consequences are boilerplate install commands (go install \u002B xk6 build) plus one plugin link: Add why k6 was chosen over alternatives, a trade-off section on test coverage vs tooling cost, and the benefits of distributed tracing"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/ADR/decisions/0020-k6.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3e201ebb2fbc07f43e2ea382704834c0cef28f4b7b76398e02b07bc1db2207c9"}},{"ruleId":"D20","level":"warning","message":{"text":"Uninformative title and thin context (only one sentence) with only the decision and an ADR template present: Rename the ADR to something like \u002721. microservices structure: context, decision, consequences\u0027 so readers know what each section is about."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/ADR/decisions/0021-microservice-structure.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c0107b7b5f05871e21ba6dec2baa7ffeb37564b5cdbb4dec29c5e49629ff0de1"}},{"ruleId":"D20","level":"warning","message":{"text":"Context is thin (\u0022This ADR addresses the need to standardize our code style tool, considering efficiency and developer experience.\u0022), decision is a one-line rationale with no trade-offs or alternatives considered: Expand Context by stating why Flake8 was rejected (e.g. slower on large files) and add Consequences covering alternative tools\u0027 shortcomings"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/ADR/decisions/0032-python-code-style-selection.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"2bb1d6492baab059002012b5ff551a91621352918f58fd59d7bb0a663c7ef492"}},{"ruleId":"D20","level":"warning","message":{"text":"Consequences are thin: only one bullet stating the outcome and no trade-offs (e.g. performance cost of reduced transparency): Add a Consequences section noting any downsides such as slower rendering under high contrast or increased blur on dark backgrounds"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/ADR/decisions/0039-ui-accessibility.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"53e3b34277f997d61ad5a532a33ccd6749a0d02519f439f32fbec9d4a32fda1a"}},{"ruleId":"D20","level":"warning","message":{"text":"Consequences section is sparse and only lists benefits with no trade-offs (e.g. vendor lock-in to Storybook tools, component quality vs. third-party alternatives): Add a Consequences section on trade-offs such as the long-term maintenance burden of relying on external UI kits and how decisions will be made when components are not yet written"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"docs/ADR/decisions/0040-ui-kit.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"da916a9cd7c2555a31b06a9e2f8d02105f5d70fdf4fb2259f56f8d71247cd81d"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"256403a5de896bc3a5563255f5aad9ccb643795f44607568978a4397ea1c7d09"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c14da509a3d48db62381bf22288d3864f192d878019719a972090015aadd50f6"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c0ed5730bfec04c7a48cd86da55e18068be0ddf70eceb3d0734206068f3155d2"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"754f58b04eff32e12b41e73bd5455d92171f17ce044a08f2cf19d1f92c91a946"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"08a0bb5c5d80dbc784cf8b29bd84051166f63f01c9243da23490ab501dd31c8d"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ce293b1c9f2a10be2d65409e0a5ed57a6b6152fd1f74f4318cfef80b2ba063fa"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cc3146b32c817e72a03ba611a1ae8e06ae90ad7e2d5541e4ea7fc77410fd60ca"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"171e9fa725d3d0a2e7dcf9b3d8540553ecf8a10b1f55826573c887d71d70eccf"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"435bf0b5ad3b538bb049492ef5b901e119c085b2090f129a11721fe82dc247c3"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"451e33d24437ecac4fc9e35c6114b6447a53e538e21c1fcfd62b313a4b55f59a"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"462728ab201c476416afc68c89eacdd1282ad657a6cab7a8c7fd935593506970"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4f5ea080e6e8e0f9bc3037518d28bb78ddae198be1dec8e506062fc3274c69df"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7f2a8e20dd4060e45bc577bd2cd7117d401d84e81b8312c934a8901c24648028"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"45ed4ac225ce5d42e2dda6b14de374116aa71b91f4e67785b69c6627036c3b87"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fbed55884e403c8daf6c40e357850477962eaf9c8a73f706f2fd05b6f3b9f7be"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4d64f99b925466b86c49ff0b558f7277171fa96baf089545afc013ed205f4972"}},{"ruleId":"D28","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c73b9c5c9943eec6fbcfcf740e26d058cd829126abf46e1282ec569b5695d8be"}},{"ruleId":"D28","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3cdfd7beb31b791ae18dcb425e21eb157c842e7bbcd522cc330573c1a6538db1"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d5b8f11381d61a58459ffc7c595fd52d09c03c711894a63a9578043d2338412b"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0dbb915274563a1a1c7710b67a8c19d2a107f22fcaf0daddfce999f66be50e9d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"660a039871eda04d22de1035682b01bfb3cc6c55847583c400a67bfd7aab72e1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"84a571574668926c8d5853e5beb6190c6c005e2be119759dbaa9f8d2b9b76f8d"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9b3e1c898f4f876b5803e8c3bd01b43565fd21336d151f9cebc74d8c62144d54"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"273fb3644d18fb77448684b24ef5a2d9b7c255e71b167a673f3a2bda41ae5cfb"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3842a4f62189a963036f0f8279b3e2799b928bc36e336c420a98353f68b11197"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d85645f4300e3c28f53c1bc52e738083178299bb8a8208c0511926c45cd16395"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7db91c974bdb4b9ffcf749f1cf7d68dcb9ed6627cd4fc5f873677322ffcd3c5a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"05a3c4fdaa9c905243681c9118b8f249b6550d288dc63f66c0c61fb26ad4ff21"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3dbd0109eefda6898f61b747e7c89ff3a307fc793f87c40a4b4e1cc4eb46ec5f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"11afabd813a757493f6ea486f5b18b9dafd992bc911fb4dbfa05e9e8a982d11e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2e3592cfce6a24664249de2cc3acc3bef9a904ad326ec246bab4c70c2a448c20"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cbd3d624124d38d7b0db2a48fe847a4850744ea6b3bf89f53cce11343feba44d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cea4758f472639b0596e20b022ff490cbdfeceb666ba5ab90566b53604032ee3"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5f9b719191a901c97f01c5e5e76befce5e2679e5d0bd6a590a50a4e8feab95fb"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a4398f497236384369192d466ae7e17c0896d536ad1c642c11288fb6356eb122"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1049ca8441da201ad496107433b81fcc7ec243e0d22e5f4392b6d35b21f6d725"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3885a597ac8fc78a2ccce384ecbb83bc7d7bdf60f7b84c7409b9fb1bc2c26448"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1ed57be97f6afb66322377390bca04d498d5fdb3e7c9be4f34fe91512aa83f86"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"34bdd3bb7c39cee83f062d482821f1a629324bdd109e4735e99b7817a77f87a6"},"taxa":[{"id":"CWE-319","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a4229016e0349461002641ae3ffd5cbc4a63b47e1778602733903564a482aee3"},"taxa":[{"id":"CWE-319","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dc6c29db9027588bb9faf4e7c10d4d626789d6bcc164dd1e901d493041a21e8d"},"taxa":[{"id":"CWE-328","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d15db16088cc1dd271a7380a5b72cacea855db1440921d17ccfb69eb2c0dc9eb"},"taxa":[{"id":"CWE-326","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eb2643de229430ef429eb8d794af666e0a7cd6f5390c34f026662f38b42a9ff3"},"taxa":[{"id":"CWE-319","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"538390f10484424f29cd55eddde95d2b44e00b1c4aa581cc557db65e8501df41"},"taxa":[{"id":"CWE-319","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6393db20dc172f40d7eaf701bab81c99da9118cd8901df36f350c64a64664b24"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e2f4165f7aad1e5332f4f23fc11cfc20503d038fd07a0a3144028f0b079f3299"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6f78ec4c432e5caec1ea41ea7d9719cf219b01b8316245f36af02d309cccc642"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c95ae5500a6ebe4d0ae0dd193649f41c83189a8f02eb0951ed4242a6df6d863f"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"df75ad0149bdabbfbd390e748fab510a76166ecac97d59b5dcbbfb5607f561c8"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b23492a91e4440243e4e2422c618078bc6ef839ac3891a4cdc931fb96d27fcaf"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8d04ce2f24096720c24b1be66ba69cd398c8b515e54074837112a56adf7cefcf"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"78f0eceb5e954a2365c6fdbd4cc5b3cf0e9d0956636ccf75adaf26d203d63698"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"63ceabfaaf742dad3c0084aee451968f73d82f8c1ae40df480ae287889bbf8b3"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"70d2ca790df7898f59fc88e189b8987e0064981b84ac3f54d40da1a1c5408ed3"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f59d4ceca84b16348523f481a1c985ad3a94855bdc72777cfdc7e69ffd0b9ebf"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f31b1bb579034c5b60aafee41b02e7f83447b36b60d44708dc4eae8d5a1d378a"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9800b808c010043ee2be80f2b70cc0c3d9dff44405954b647981f3b86fa05c10"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b1d8ef6597fbcad6abc1eca6d1ab703561745ec5fbcfdf425984e837974284a9"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d7ef420840681696e7af55b48b3eb4f75070897d792b107f9a562f75555daf66"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a95f2ee8c848972c4df5b265c78ef871e6ab6ea9c4fe4145f102708d7c8c0383"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"14b420e21ce451ef7548e4a03bd5ba6c7198c7743e735ded1294efc25efd4ace"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8d9cd89f3c763230da5d68f78b125e9d346771270304e05d60a458d3b573c7cf"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"774192c9b3569f4c38b6c59be671cb9ce42f8791bf04a15a243f58a2b718b61e"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"97c0656ffcd148236d600dd102796c7c70865f2900fac765261b36263c20c336"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fbaf342e9d9dba49e6e49b63fb25c78d46c2e3d3c0cdef5838b85e419cfe106d"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"785333831f39191afc3c487add075c31652424e687b1ace118405237f27987a2"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"04d0302c5bec5b40310cfa0ab7a3a7c1dca668a2cf1ebee9520488bd5d4e9665"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f20e3a9d77e24ace111617d96c4a6844523f6033de28fc878d90122a62a9bd0d"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"02782358f737e11e6666c80748f25909102e8cfac2f57c5fbc07f9cf68d7ac3a"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d3056fbda73296575a1748e50cac8147a55dd57c25affbc52671fd34db7e02c4"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bb45a202ec277ba549890fe3b25e5ca61b51bc542657b2358244470c34e2cb6d"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3ac01101633fe8a3e7f0679a1d110d32fb5cf958f3ade30964be052929e8d53a"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"90f83b4fa27db32740afe9540c905f3c0499caed87f61049a8a903ecc95b41c3"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"722c547b215239e42316a80b48590426726707a5ab6bf0478d2ae02f08d6b1ab"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"030a1028a649077bbd601452ee38388b8f2728890c58d7ed63963544937f6893"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"763c2783fe0daf884c0583b5eff5332fe2501dd898f7ce39d786f46d86d85809"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c6324eca0ba26d90fb6c22ca07558346c0ba9c5cb9d007545d135ac6c4fd3870"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"968dff166277ce5f72eefc614f9c23c0007aa751beee24eac8fcac4984698123"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2c161ba6b803a74531701391ce6029192d4a94690ce78b6fd3a30ea8c688fa61"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"97f0a24d3e54245bbdfce07affeb2a4f49647797b42ba64eafcbb80768380f7c"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"314442f672a16ffb0b37297a4b583438ee58d9177d03d4a32de2430b0fd4468a"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6af07f7483db572fcba1f7950f895babd142b37586974c203aa62bf6972d76a5"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d6c8a4776c883c63c764677cfc2de35b6db8c6709810dda97a4f02070d7c13af"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b859e0a2014a4f57460faf05861e6fd392543d15b6e667d534e345b46fd2c062"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d48a7673beb545891807d7996534b08b10140017189cdb606783bd2285cd7723"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7baec785d9653c49f1cb2ece45c75b2880c35aaad7c516e91bc02abaebeedd86"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a47d49aa1b00367fd244a82dfb36d1951b0513e771a9366ff96590f817df5665"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cd8e6a57c729078c783b071daf709919631220a6d981a09cff3e2294db77e4bc"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"de9a163daeadd3eda97ac69dff65168def458b015c925ef2b632c3d52ae8bcc1"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7a115f477c46533a1aef0c5b4e112c5b3010a9dc03af89071a4b6027d3446625"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"340e74401ec92a7dbfbd4f5fd1d8ff864dbe731fc46402e9169eefc4e09a0b7a"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a6d5a4bf36e553861b0ed91eb35688e3382028b0def0c543b180a8b6b3367d3e"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eb61f5da9504f576b8288cc011363e63330008be67538e1248bacb86c0333162"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"390b8012bc89e7a27c0bdd6d4edeb93343d614b1307259698ac418ee5ac478d4"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"529651b3f1194d09a66bbbc478889b272be62b6bdeaa7e646a5196a593bc37dd"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4b591424247890fb01ca2378108fd01774bea688ef727ef07a3a8a9daf61422f"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2c274bae4605860c12c9ec00cdf9014794581fd7e5c7022320e6232ee67f7ba8"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8c80cfa998425c296ebaca18e20800456acb4eff51ddf57601b0935c6a540c72"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"db02609a650cce424f76c00ec98c0fcf0e2261ff952665f36804180e395229f5"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d7d64b7e0416163129284fd59d972de42a8cf1158efaba349ad3f58e34be13b6"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"242d27dd8d7cd0788a14c951b91e438bda99801d66bdd5748ab95cc07648e99b"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e7d2932f4990b46ca442c15d5f89cbc0a9c693342f8473d890ce4cfbedd4fa59"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"374f8fbf04faf33954065dfc4bbda3f42acfec50c097d76af1b4e62cbcbdf8a2"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cd390c9598adfed632e60ccefd14aea921658a19f1e091738d47cce4cde5567a"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5b50bc261c4de9a2ae473646ed827b33535ec107ebc2d9d517aa972725c586ca"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6477b556d54c5b418a0dd5630b7fa8fa85804588e2ceef7ba4c999625e5ad1c9"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"881acf838ed7aa01b5f94fdaafc46717c34340d50de801ebe074fb20e1c8b5c1"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"88f0085dcfecbcd4c46f5d91d2217e9271d7d13289c84036d3f3429c86b7b5e1"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4e8e0a2bd53315f54c9a597037e2551f8d86c1a1ebfece4828b44e0ebf4e6b94"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e098f68739e41f38ed33ca4482ca511ca7a8c7a67240fd4c3e381a48a35ef87"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4584a4269ec958ecfa7e7d7c70038049140f70e709fc078af394a97bb0f845e2"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"09abc75a9eec8c12e54e1ca31eed2bf5095f0c88472df9fd70ebdd29365a1e0e"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4cf0f5a5fa6b346727cbbf421bcd848c5ed10e2448dbe6f5498fc40c8f5f514a"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4e311ca15328c28acbc114da16fa05a6127920936e8e87a018792e3f0bfa1a99"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9c1451e585b663d5b14e052da2fadffb82a0574f5a636b9b5db4f28cfecd1c8a"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5b1fe9c47ef26173dab73de511f00c3a9c68037ad5a7736f21d26cb48a4ac620"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"81f75bdfc4f0d8358aa1ac9193fc386718abe59da3d5cf5e97cfd6108134c290"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"57610c5b50e55967936d82b9c14cd0d89ab9c86a857d32636f59ee47c4f268c5"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c69ac56d7fbfa27c0273224cfda6d5c954e0644338b1a7fb25fdc1d008a84cb1"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"aa589b4ed99473462a434ca5647456283aa2f168de9b9df769ffadffc1e2faee"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7e18a76669742c5a4733981768bca17468c117f6a03dd9181935dd4043f9724c"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"12673f7fb19df1545df372edad8526c1cdd8892d0b1c17c9fe5b8d884000c723"}},{"ruleId":"D38","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6500b63fa2cee5a187c77bd09d8c26d75d957e786e25d5076795af467985b3e6"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-1059","guid":"a2381a08-60f6-9554-a8b8-f3018cfaaca5","name":"Insufficient Technical Documentation","shortDescription":{"text":"Insufficient Technical Documentation"},"helpUri":"https://cwe.mitre.org/data/definitions/1059.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-319","guid":"7af97476-9f0d-4458-9163-3d2043918a1a","name":"CWE-319","shortDescription":{"text":"CWE-319"},"helpUri":"https://cwe.mitre.org/data/definitions/319.html"},{"id":"CWE-326","guid":"7ee78bef-7589-f65f-a9d7-619f3485e844","name":"CWE-326","shortDescription":{"text":"CWE-326"},"helpUri":"https://cwe.mitre.org/data/definitions/326.html"},{"id":"CWE-328","guid":"f0ffc869-97c3-dc5c-8825-be1159f1fc5f","name":"CWE-328","shortDescription":{"text":"CWE-328"},"helpUri":"https://cwe.mitre.org/data/definitions/328.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-829","guid":"13c33925-97fb-5a5e-b40c-56d328b8a4d7","name":"CWE-829","shortDescription":{"text":"CWE-829"},"helpUri":"https://cwe.mitre.org/data/definitions/829.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":126,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}