{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D11","name":"Test Reliability","shortDescription":{"text":"Test Reliability"},"helpUri":"https://codehealth.canine.dev/dimensions/D11"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D22","name":"Internal API Consistency","shortDescription":{"text":"Internal API Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D22"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D37","name":"Vulnerability-disclosure Policy","shortDescription":{"text":"Vulnerability-disclosure Policy"},"helpUri":"https://codehealth.canine.dev/dimensions/D37","relationships":[{"target":{"id":"CWE-1059","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1059"]}},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AX8","name":"Test isolation","shortDescription":{"text":"Test isolation"},"helpUri":"https://codehealth.canine.dev/dimensions/AX8"},{"id":"AX9","name":"CQS / query purity","shortDescription":{"text":"CQS / query purity"},"helpUri":"https://codehealth.canine.dev/dimensions/AX9"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P10","name":"Library API \u0026 versioning","shortDescription":{"text":"Library API \u0026 versioning"},"helpUri":"https://codehealth.canine.dev/dimensions/P10"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P2","name":"Observability","shortDescription":{"text":"Observability"},"helpUri":"https://codehealth.canine.dev/dimensions/P2"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"P7","name":"Outbound HTTP resilience","shortDescription":{"text":"Outbound HTTP resilience"},"helpUri":"https://codehealth.canine.dev/dimensions/P7"},{"id":"PF3","name":"Async \u0026 latency hygiene","shortDescription":{"text":"Async \u0026 latency hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/PF3"},{"id":"SC1","name":"Supply-chain hygiene","shortDescription":{"text":"Supply-chain hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/SC1"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X6","name":"Hand-rolled structured-format parsing","shortDescription":{"text":"Hand-rolled structured-format parsing"},"helpUri":"https://codehealth.canine.dev/dimensions/X6"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"spin_dependency_wit::extract_wits (cyclomatic 19): spin_dependency_wit::extract_wits has cyclomatic complexity 19 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/dependency-wit/src/lib.rs"},"region":{"startLine":149}}}],"partialFingerprints":{"codehealthFindingId/v1":"6c08aa223fb4bc1fdaba769f9c7f4014ac4756e432a827725efc07042d4fc7ab"}},{"ruleId":"D1","level":"warning","message":{"text":"FactorsTriggerCommand::run (cyclomatic 18): FactorsTriggerCommand::run has cyclomatic complexity 18 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/trigger/src/cli.rs"},"region":{"startLine":186}}}],"partialFingerprints":{"codehealthFindingId/v1":"69c6c615e8820aae105301ce70f9d23f9b250aab50d743eaff09fdd66e662d83"}},{"ruleId":"D2","level":"warning","message":{"text":"spin_dependency_wit::extract_wits (cognitive 41): spin_dependency_wit::extract_wits has cognitive complexity 41 (threshold 15). Drivers by points: if/else 5 (16 pts), match/switch 6 (13 pts), loops 6 (12 pts) (nesting depth added 24). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/dependency-wit/src/lib.rs"},"region":{"startLine":149}}}],"partialFingerprints":{"codehealthFindingId/v1":"0bdfcd95322d0aaddf9f7d81e1388ff7b43749f654d727fb4992da8b5ea54280"}},{"ruleId":"D2","level":"warning","message":{"text":"ModuleInfo::from_module (cognitive 28): ModuleInfo::from_module has cognitive complexity 28 (threshold 15). Drivers by points: if/else 6 (18 pts), match/switch 2 (6 pts), loops 2 (4 pts) (nesting depth added 18). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/componentize/src/module_info.rs"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"102e69d42a8990f7a9c0f86491761ecd33a0859904a6b9fadf75707b79751d9e"}},{"ruleId":"D2","level":"warning","message":{"text":"DoctorCommand::run (cognitive 24): DoctorCommand::run has cognitive complexity 24 (threshold 15). Drivers by points: match/switch 3 (12 pts), if/else 5 (11 pts), loops 1 (nesting depth added 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/doctor.rs"},"region":{"startLine":26}}}],"partialFingerprints":{"codehealthFindingId/v1":"209d26c83415bce3605770b6a5dcaec96121f4e7191f2381811862372f1d4e2a"}},{"ruleId":"D2","level":"warning","message":{"text":"spin_manifest::normalize::normalize_inline_components (cognitive 22): spin_manifest::normalize::normalize_inline_components has cognitive complexity 22 (threshold 15). Drivers by points: if/else 4 (14 pts), loops 3 (7 pts), boolean chains 1 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/manifest/src/normalize.rs"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"40cd04bf0d19ca02d1b6bd853723d1ba98eee3610ade596ce1e10dcc0fa1d845"}},{"ruleId":"D2","level":"warning","message":{"text":"Catalogue::list (cognitive 21): Catalogue::list has cognitive complexity 21 (threshold 15). Drivers by points: if/else 6 (16 pts), loops 2 (4 pts), boolean chains 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/environments/src/environment/catalogue.rs"},"region":{"startLine":136}}}],"partialFingerprints":{"codehealthFindingId/v1":"eab41452b738992c7a5bd19a74eb179e6be7c0ca9027f246598a1e3b86e0acc4"}},{"ruleId":"D2","level":"warning","message":{"text":"spin_manifest::normalize::normalize_dependency_component_refs (cognitive 21): spin_manifest::normalize::normalize_dependency_component_refs has cognitive complexity 21 (threshold 15). Drivers by points: loops 6 (13 pts), if/else 2 (8 pts) (nesting depth added 13). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/manifest/src/normalize.rs"},"region":{"startLine":186}}}],"partialFingerprints":{"codehealthFindingId/v1":"355695122d46cae8e1718c498a7b51bc7215a7b9535cb679067ce9ded9844ec9"}},{"ruleId":"D2","level":"warning","message":{"text":"ComponentStdioWriter::poll_write (cognitive 21): ComponentStdioWriter::poll_write has cognitive complexity 21 (threshold 15). Drivers by points: if/else 4 (10 pts), match/switch 5 (10 pts), loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/trigger/src/cli/stdio.rs"},"region":{"startLine":220}}}],"partialFingerprints":{"codehealthFindingId/v1":"9340b8bc84359c2e5af321506f5a8a66d243613b62fd29b71871f8f433b4339a"}},{"ruleId":"D2","level":"warning","message":{"text":"TemplateNewCommandCore::run (cognitive 21): TemplateNewCommandCore::run has cognitive complexity 21 (threshold 15). Drivers by points: if/else 8 (10 pts), match/switch 6 (10 pts), boolean chains 1 (nesting depth added 6). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/new.rs"},"region":{"startLine":148}}}],"partialFingerprints":{"codehealthFindingId/v1":"a0b024df9ab51f0ad0fa9a18e53cf8656a665591162e531a272d9a4000056686"}},{"ruleId":"D2","level":"warning","message":{"text":"spin_manifest::normalize::normalize_trigger_ids (cognitive 20): spin_manifest::normalize::normalize_trigger_ids has cognitive complexity 20 (threshold 15). Drivers by points: if/else 4 (14 pts), loops 3 (6 pts) (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/manifest/src/normalize.rs"},"region":{"startLine":75}}}],"partialFingerprints":{"codehealthFindingId/v1":"6ba856680cb1629377aec16b251138a159c849a4304b43d1703728cc937370ce"}},{"ruleId":"D2","level":"warning","message":{"text":"Upgrade::repos_to_upgrade (cognitive 20): Upgrade::repos_to_upgrade has cognitive complexity 20 (threshold 15). Drivers by points: if/else 11 (14 pts), loops 2 (3 pts), match/switch 1 (2 pts), boolean chains 1 (nesting depth added 5). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/templates.rs"},"region":{"startLine":277}}}],"partialFingerprints":{"codehealthFindingId/v1":"c301b5afddc3a81db573a4193989028aa986fa10c876d034bc57a7b178929002"}},{"ruleId":"D2","level":"warning","message":{"text":"WitBindgenVersion::detect (cognitive 19): WitBindgenVersion::detect has cognitive complexity 19 (threshold 15). Drivers by points: if/else 7 (16 pts), boolean chains 3 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/componentize/src/lib.rs"},"region":{"startLine":75}}}],"partialFingerprints":{"codehealthFindingId/v1":"bc52ec9c16f6762b7ca70fdb9e8464a3727e1b0d87fafb9f6cdc34c3c85516d8"}},{"ruleId":"D2","level":"warning","message":{"text":"UpCommandInner::run (cognitive 19): UpCommandInner::run has cognitive complexity 19 (threshold 15). Drivers by points: if/else 12 (17 pts), loops 1 (2 pts) (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/up.rs"},"region":{"startLine":174}}}],"partialFingerprints":{"codehealthFindingId/v1":"3fa928ce41bf974a0b8447fae18852c55c4486565ed65a18230d5dc14ecb5c61"}},{"ruleId":"D2","level":"warning","message":{"text":"spin_cli::commands::new::env_templates_and_plugins (cognitive 19): spin_cli::commands::new::env_templates_and_plugins has cognitive complexity 19 (threshold 15). Drivers by points: if/else 5 (12 pts), match/switch 4 (7 pts) (nesting depth added 10). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/new.rs"},"region":{"startLine":295}}}],"partialFingerprints":{"codehealthFindingId/v1":"4b477b44f735522094a1f42a3730fe71c1aab2b969ff5bf1147f40b4990fd37e"}},{"ruleId":"D2","level":"warning","message":{"text":"spin_build::build (cognitive 18): spin_build::build has cognitive complexity 18 (threshold 15). Drivers by points: if/else 8 (11 pts), loops 2 (6 pts), boolean chains 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/build/src/lib.rs"},"region":{"startLine":23}}}],"partialFingerprints":{"codehealthFindingId/v1":"9921dc8c6a26ec9c6d0f8b854a9d23541c69278298c8ca44a8fa6f073670773e"}},{"ruleId":"D2","level":"warning","message":{"text":"Id::try_from (cognitive 18): Id::try_from has cognitive complexity 18 (threshold 15). Drivers by points: if/else 8 (13 pts), loops 2 (3 pts), boolean chains 2 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/serde/src/id.rs"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"40bae801ea065054c1ad8df98179a5ad0285b85384fbba0094e24e24f8a53ad4"}},{"ruleId":"D2","level":"warning","message":{"text":"Install::print_installed_templates (cognitive 18): Install::print_installed_templates has cognitive complexity 18 (threshold 15). Drivers by points: loops 3 (9 pts), if/else 5 (8 pts), boolean chains 1 (nesting depth added 9). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/templates.rs"},"region":{"startLine":163}}}],"partialFingerprints":{"codehealthFindingId/v1":"81cc4c873300eb4dccddd9e3b80e2248b43d5c9f07f2454cfc0bf522b96da76b"}},{"ruleId":"D2","level":"warning","message":{"text":"spin_componentize::retarget_imports_and_get_exports (cognitive 17): spin_componentize::retarget_imports_and_get_exports has cognitive complexity 17 (threshold 15). Drivers by points: if/else 3 (8 pts), loops 3 (7 pts), match/switch 1 (2 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/componentize/src/lib.rs"},"region":{"startLine":183}}}],"partialFingerprints":{"codehealthFindingId/v1":"6a3d1b8c0e5be4b86b3381e2de5c5205ac7519794117f4445fc62303fc9e0ddf"}},{"ruleId":"D2","level":"warning","message":{"text":"PooledTokioClient::query_async (cognitive 17): PooledTokioClient::query_async has cognitive complexity 17 (threshold 15). Drivers by points: if/else 3 (11 pts), match/switch 2 (5 pts), loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-pg/src/client.rs"},"region":{"startLine":266}}}],"partialFingerprints":{"codehealthFindingId/v1":"73b3e9255e9f7e9929fc1b4c2e0b570b821112640fe889c673f05d87fa9ae38a"}},{"ruleId":"D2","level":"warning","message":{"text":"spin_http::wagi::compose_response (cognitive 17): spin_http::wagi::compose_response has cognitive complexity 17 (threshold 15). Drivers by points: match/switch 3 (8 pts), if/else 4 (6 pts), boolean chains 2, loops 1 (nesting depth added 7). This file\u0027s own header attributes it to another copyright holder, so it is code this repository carries rather than code it wrote: restructuring the body in place forks it from upstream and turns every future re-sync into a manual merge. The performable moves are to leave the body as close to its upstream form as possible and keep it behind a narrow interface of your own, and to re-sync it when upstream changes \u2014 or, if it has already diverged far enough that you maintain it here, adopt it deliberately and then split the body into named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/http/src/wagi/mod.rs"},"region":{"startLine":217}}}],"partialFingerprints":{"codehealthFindingId/v1":"90599d7ca3d6d611642662efdeda87e373c0f3f70621dbf6a50d6e3e9d0d4825"}},{"ruleId":"D2","level":"warning","message":{"text":"ResolvedRuntimeConfig::summarize (cognitive 17): ResolvedRuntimeConfig::summarize has cognitive complexity 17 (threshold 15). Drivers by points: if/else 7 (10 pts), boolean chains 4, loops 2 (3 pts) (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/runtime-config/src/lib.rs"},"region":{"startLine":58}}}],"partialFingerprints":{"codehealthFindingId/v1":"759fdb7eee888d9261de9423fa7e484ecb28c447fda95f9f6b40de38eb3277aa"}},{"ruleId":"D2","level":"warning","message":{"text":"FactorsTriggerCommand::run (cognitive 17): FactorsTriggerCommand::run has cognitive complexity 17 (threshold 15). Drivers by points: if/else 9 (11 pts), match/switch 4 (5 pts), loops 1 (nesting depth added 3). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/trigger/src/cli.rs"},"region":{"startLine":186}}}],"partialFingerprints":{"codehealthFindingId/v1":"6b2a0820f87d1a30f14199f005b39b0d2a28b22ea91b244ea1ba6261f54721c4"}},{"ruleId":"D2","level":"warning","message":{"text":"List::print_templates_table (cognitive 17): List::print_templates_table has cognitive complexity 17 (threshold 15). Drivers by points: if/else 8 (13 pts), loops 2 (4 pts) (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/templates.rs"},"region":{"startLine":568}}}],"partialFingerprints":{"codehealthFindingId/v1":"bac8e49ca819025ca319a87d08a486cd4914348ae88a17a0fe2da3cc8c421736"}},{"ruleId":"D2","level":"warning","message":{"text":"List::print_plain (cognitive 16): List::print_plain has cognitive complexity 16 (threshold 15). Drivers by points: if/else 6 (11 pts), match/switch 1 (3 pts), loops 1 (2 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/plugins.rs"},"region":{"startLine":817}}}],"partialFingerprints":{"codehealthFindingId/v1":"e625daa27abf9eb8d3eaf0c48629b0724e1f7ac76bf4f96c2d67e252691f5792"}},{"ruleId":"D2","level":"warning","message":{"text":"Uppificator::run (cognitive 16): Uppificator::run has cognitive complexity 16 (threshold 15). Drivers by points: if/else 3 (6 pts), match/switch 2 (5 pts), loops 3 (4 pts), boolean chains 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/watch/uppificator.rs"},"region":{"startLine":30}}}],"partialFingerprints":{"codehealthFindingId/v1":"6b8768c9984f6628fc4c43c4f7b8ca3e889adfe6cd7c2b4c8496ae971bd28384"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: Adapter: ClassTooLong \u2014 1408 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 0 methods, 65 blocks, lines 64-1785. The bar is 400 significant lines; this is 1008 over it, 3.52\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/capabilities/deny-adapter/src/lib.rs"},"region":{"startLine":61}}}],"partialFingerprints":{"codehealthFindingId/v1":"1e20db249be6844c1f8272cb11abbc25c307487670a723780b34107e18e80403"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/lib.rs: FileTooLong \u2014 1464 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), about 96% of them inside a single declaration: Adapter (65 blocks, 64-1785). The bar is 500 significant lines; this is 964 over it, 2.93\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/capabilities/deny-adapter/src/lib.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"034e35f72ec604d06c21953cff5b516a94f88a8239c75f7a0d86aed690498b5d"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/wasi_2023_10_18.rs: FileTooLong \u2014 1268 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 768 over it, 2.54\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-wasi/src/wasi_2023_10_18.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"22a36a5871e793a23e8380131890cabac626e818e324ed79ad989ef2be9d2a19"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/wasi_2023_11_10.rs: FileTooLong \u2014 1138 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 638 over it, 2.28\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-wasi/src/wasi_2023_11_10.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"55152affe7704d3ebb69bf79b9005fe5cdf297fec5b555eaad0aa5aee2268bd7"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/wasi_2026_03_15.rs: FileTooLong \u2014 1042 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 542 over it, 2.08\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-wasi/src/wasi_2026_03_15.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"78cc286600e389d9b063207cedf7ddc21a1be1a902cdfcf996b942856edfc894"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: spin_factors_derive::expand_factors: FunctionTooLong \u2014 spin_factors_derive::expand_factors runs 205 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 105 over it, 2.05\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factors-derive/src/lib.rs"},"region":{"startLine":23}}}],"partialFingerprints":{"codehealthFindingId/v1":"cdf83044f4e32f1d16b8159e641b1c8d7e3113f1948adeda849ac33804c51d36"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/local.rs: FileTooLong \u2014 756 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 256 over it, 1.51\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/loader/src/local.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"844b8fb9d6fa2f56d53df0cd47f37bf7c3417f34f5faf8677de6e1f02383dd16"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: commands/plugins.rs: FileTooLong \u2014 743 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 243 over it, 1.49\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/plugins.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"97acd1acad4a1e44cd2ef6aa995d15dd896e1563a400fe449bcff9e4d8c53ce1"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/client.rs: FileTooLong \u2014 671 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), about 71% of them inside a single declaration: Client (2 blocks, 87-824). The bar is 500 significant lines; this is 171 over it, 1.34\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/oci/src/client.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"cd5355c27af722d2bf0ae732cb801667ed30db1d08d8a6b4c8e513033a88bf60"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: SpinSocketsView: ClassTooLong \u2014 535 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 4 methods, 16 blocks, lines 47-843. The bar is 400 significant lines; this is 135 over it, 1.34\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-wasi/src/sockets.rs"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"bba75494af5ca6d3c4cd05158ac13ae21bc648d77e19813f3fa6dd5216ccbd21"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/sockets.rs: FileTooLong \u2014 628 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), about 85% of them inside a single declaration: SpinSocketsView (16 blocks, 47-843). The bar is 500 significant lines; this is 128 over it, 1.26\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-wasi/src/sockets.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c0a5bd7eff87c7a1ad352089294884203c6ca2f65a6d0770a0209cb6589eac05"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/host.rs: FileTooLong \u2014 618 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), about 65% of them inside a single declaration: KeyValueDispatch (12 blocks, 70-817). The bar is 500 significant lines; this is 118 over it, 1.24\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-key-value/src/host.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b9f8576dda833adaf2ea0ce69f9d34c984f5052498125da40d7a5701cea6d866"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/server.rs: FileTooLong \u2014 605 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), about 68% of them inside a single declaration: HttpServer (2 blocks, 78-678). The bar is 500 significant lines; this is 105 over it, 1.21\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/trigger-http/src/server.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c1caf01a724ceb46fe54b4e3bd4d2016aa1152cba6a4b903d62883fa36698724"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: Client: ClassTooLong \u2014 477 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 23 methods, 2 blocks, lines 87-824. The bar is 400 significant lines; this is 77 over it, 1.19\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/oci/src/client.rs"},"region":{"startLine":87}}}],"partialFingerprints":{"codehealthFindingId/v1":"db3b61f3763fe1a8ffa87f40a970e33e26dda97983d532d728247d8520a1c300"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: spin_dependency_wit::extract_wits: FunctionTooLong \u2014 spin_dependency_wit::extract_wits runs 118 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 18 over it, 1.18\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/dependency-wit/src/lib.rs"},"region":{"startLine":149}}}],"partialFingerprints":{"codehealthFindingId/v1":"3af221b53bf989187c2ac665017495ca537a2b46e40ed024064199c38b28ec94"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/host.rs: FileTooLong \u2014 561 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 61 over it, 1.12\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-redis/src/host.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e8a51d6dd9dca524afe2576be965327d8e74e309767fa155055565f9914a3d6a"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/wasi.rs: FileTooLong \u2014 554 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 54 over it, 1.11\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-http/src/wasi.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"fd9224ba4a0e40b3c75f76b7274f51110bc4d17078fc49d8d2d6eaa5ca37a095"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: LocalLoader: ClassTooLong \u2014 436 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 20 methods, 2 blocks, lines 26-646. The bar is 400 significant lines; this is 36 over it, 1.09\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/loader/src/local.rs"},"region":{"startLine":26}}}],"partialFingerprints":{"codehealthFindingId/v1":"4e53dd7951b1f55d5c266200cb41f01e95324d7cae1188bf67c7ff3f5b838374"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: commands/deps.rs: FileTooLong \u2014 536 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 36 over it, 1.07\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/deps.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a611f079a217c4f1cced941abf7784b1c417038b0de35cda94585b9d79889199"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: HttpServer: ClassTooLong \u2014 414 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 20 methods, 2 blocks, lines 78-678. The bar is 400 significant lines; this is 14 over it, 1.04\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/trigger-http/src/server.rs"},"region":{"startLine":78}}}],"partialFingerprints":{"codehealthFindingId/v1":"ea358dbb3a5a667a3f3e6c679e5dafcc32793f63c1a4a6aeacc5008352df2f9e"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/wasi_2023_11_10.rs: FileTooLong \u2014 505 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 5 over it, 1.01\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-http/src/wasi_2023_11_10.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1a7044c835018fbd4506fab04f9adde6119ae9a3ab0f77265536b73be4db2e1d"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: KeyValueDispatch: ClassTooLong \u2014 403 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 11 methods, 12 blocks, lines 70-817. The bar is 400 significant lines; this is 3 over it, 1.01\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-key-value/src/host.rs"},"region":{"startLine":70}}}],"partialFingerprints":{"codehealthFindingId/v1":"0d712c2866a68bccf754c28a9852f71db1c52e04f2cdcc1ac07ebcd79d544935"}},{"ruleId":"D4","level":"warning","message":{"text":"Members sharing a duplicated core (5 members, 50\u002B identical tokens): crates/key-value-azure/src/store.rs:154-171 | crates/key-value-azure/src/store.rs:401-444 | crates/key-value-redis/src/store.rs:77-97 | crates/key-value-redis/src/store.rs:262-287 | crates/key-value-spin/src/store.rs:104-130 \u2014 These 5 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below \u2014 it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 5 times. The repair is at the members\u0027 grain \u2014 factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 5 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/key-value-azure/src/store.rs"},"region":{"startLine":154}}}],"partialFingerprints":{"codehealthFindingId/v1":"7776d7d480171fca66189356163892e46be7162b7edaf41d830c33c7c03dbebd"}},{"ruleId":"D4","level":"warning","message":{"text":"Members sharing a duplicated core (4 members, 50\u002B identical tokens): crates/factor-key-value/src/host.rs:350-365 | crates/factor-key-value/src/host.rs:371-386 | crates/factor-key-value/src/host.rs:392-407 | crates/factor-key-value/src/host.rs:412-434 \u2014 These 4 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below \u2014 it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 4 times. The repair is at the members\u0027 grain \u2014 factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 4 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-key-value/src/host.rs"},"region":{"startLine":350}}}],"partialFingerprints":{"codehealthFindingId/v1":"4e8db457a21ce3245ad9f1feb9ab4e6b8039f9ef017dac0ee76b91426ff7d6cb"}},{"ruleId":"D4","level":"warning","message":{"text":"Members sharing a duplicated core (4 members, 50\u002B identical tokens): crates/factor-sqlite/src/host.rs:122-132 | crates/factor-sqlite/src/host.rs:137-147 | crates/factor-sqlite/src/host.rs:235-250 | crates/factor-sqlite/src/host.rs:255-270 \u2014 These 4 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below \u2014 it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 4 times. The repair is at the members\u0027 grain \u2014 factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 4 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-sqlite/src/host.rs"},"region":{"startLine":122}}}],"partialFingerprints":{"codehealthFindingId/v1":"54f07c498b494591f3f6339112efbb64ac7581beefc76f2f0bd1228ed00b7969"}},{"ruleId":"D4","level":"warning","message":{"text":"Members sharing a duplicated core (4 members, 50\u002B identical tokens): crates/llm-remote-http/src/default.rs:39-90 | crates/llm-remote-http/src/default.rs:97-138 | crates/llm-remote-http/src/open_ai/mod.rs:46-96 | crates/llm-remote-http/src/open_ai/mod.rs:103-151 \u2014 These 4 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below \u2014 it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 4 times. The repair is at the members\u0027 grain \u2014 factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 4 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/llm-remote-http/src/default.rs"},"region":{"startLine":39}}}],"partialFingerprints":{"codehealthFindingId/v1":"404e45705764a25bd05c2edea1a5d2f078a6ceafa683dfacbb5f16d78f0521ba"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (25 lines \u00D7 2): crates/key-value-aws/src/store.rs:412-436 | crates/key-value-aws/src/store.rs:446-470 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/key-value-aws/src/store.rs"},"region":{"startLine":412}}}],"partialFingerprints":{"codehealthFindingId/v1":"be4534847d4c95216de252b6f3ef4d7f8035e21b75079ee3b882641c5643ffb2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (19 lines \u00D7 2): crates/factor-outbound-http/src/spin.rs:206-224 | crates/factor-outbound-http/src/spin.rs:261-279 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-http/src/spin.rs"},"region":{"startLine":206}}}],"partialFingerprints":{"codehealthFindingId/v1":"3a1178ef21c49ed2315c446caf64f189c7d959f331a452e82240280534ed9e71"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): crates/environments/src/environment/catalogue.rs:216-230 | crates/plugins/src/git.rs:32-46 \u2014 before extracting anything, compare \u0060crates/environments/src/environment/catalogue.rs\u0060 and \u0060crates/plugins/src/git.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 43 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/environments/src/environment/catalogue.rs"},"region":{"startLine":216}}}],"partialFingerprints":{"codehealthFindingId/v1":"a65ebd683e6cbc8171d6b2c22c15939cb45c044d2b1dd3f44e0f64ebe8285dee"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10\u201315 lines \u00D7 2): crates/factor-outbound-mysql/src/host.rs:307-321 | crates/factor-outbound-pg/src/host.rs:656-665 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-mysql/src/host.rs"},"region":{"startLine":307}}}],"partialFingerprints":{"codehealthFindingId/v1":"4b917ee91575840fde114a21fb216ddf4e7a5ce832f7fa75f3734cbc3be796b6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): crates/compose/src/lib.rs:134-147 | crates/oci/src/validate.rs:57-70 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/compose/src/lib.rs"},"region":{"startLine":134}}}],"partialFingerprints":{"codehealthFindingId/v1":"af3421e5900f02b6bb95f199b95df3905242628bc555c7bec2d9cd6e2a8eb267"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): crates/factor-outbound-http/src/wasi.rs:265-278 | crates/factor-outbound-http/src/wasi.rs:288-301 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-http/src/wasi.rs"},"region":{"startLine":265}}}],"partialFingerprints":{"codehealthFindingId/v1":"6db0c0cd565de1e751ad3a19de527b53635478ab7987190b34c28e4cd50ec302"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/factor-sqlite/src/host.rs:236-248 | crates/factor-sqlite/src/host.rs:256-268 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-sqlite/src/host.rs"},"region":{"startLine":236}}}],"partialFingerprints":{"codehealthFindingId/v1":"6f6f6bb3dfb088182f5961444186442bc5fffcb127e1821b04b433d8583b190a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): src/commands/templates.rs:203-215 | src/commands/templates.rs:403-415 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/templates.rs"},"region":{"startLine":203}}}],"partialFingerprints":{"codehealthFindingId/v1":"2a083221bed2938d26a2f67a236f9de274286115a55413952b31655890283d8e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/environments/src/environment/catalogue.rs:234-245 | crates/plugins/src/git.rs:50-61 \u2014 before extracting anything, compare \u0060crates/environments/src/environment/catalogue.rs\u0060 and \u0060crates/plugins/src/git.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 43 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/environments/src/environment/catalogue.rs"},"region":{"startLine":234}}}],"partialFingerprints":{"codehealthFindingId/v1":"30d6e6d897c223de43e5ee0e84f4edb11e41c678a48f6fefbaf02a7a8ad86864"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): src/commands/plugins.rs:1080-1091 | src/commands/plugins.rs:1117-1128 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/plugins.rs"},"region":{"startLine":1080}}}],"partialFingerprints":{"codehealthFindingId/v1":"564a0b0d4d6b9f0ddb7032f2429483d8817007c7bdbcefe260ec4fcecdba8218"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/key-value-redis/src/store.rs:82-92 | crates/key-value-redis/src/store.rs:272-282 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/key-value-redis/src/store.rs"},"region":{"startLine":82}}}],"partialFingerprints":{"codehealthFindingId/v1":"21fde54c7fe58f359683d42f0a25e8a419ce4287edf8ff7fb534b1030e2d54a2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/telemetry/src/logs.rs:75-85 | crates/telemetry/src/traces.rs:24-34 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/telemetry/src/logs.rs"},"region":{"startLine":75}}}],"partialFingerprints":{"codehealthFindingId/v1":"86b9c9cb6d3a163b2fd2d3383507c746f9fb74b2472b11ee4acf618f4ee3200a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): src/commands/templates.rs:173-183 | src/commands/templates.rs:386-396 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/templates.rs"},"region":{"startLine":173}}}],"partialFingerprints":{"codehealthFindingId/v1":"be3ff4be617598b8ea88fa18da8ab8a079c2d3ae118feafafdba0690b1a68bb3"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 5): crates/key-value-azure/src/store.rs:162-171 | crates/key-value-azure/src/store.rs:435-444 | crates/key-value-redis/src/store.rs:88-97 | crates/key-value-redis/src/store.rs:278-287 | crates/key-value-spin/src/store.rs:121-130 \u2014 there are 5 copies across 3 file(s) \u2014 more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 5 sites; resolving a subset leaves the remainder to drift apart."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/key-value-azure/src/store.rs"},"region":{"startLine":162}}}],"partialFingerprints":{"codehealthFindingId/v1":"46f54de656305b4ba39748ec302ded86c9df03183ad6288d5cca6b96d79a0552"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9\u201310 lines \u00D7 4): crates/factor-key-value/src/host.rs:351-359 | crates/factor-key-value/src/host.rs:372-380 | crates/factor-key-value/src/host.rs:393-401 | crates/factor-key-value/src/host.rs:413-422 \u2014 all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-key-value/src/host.rs"},"region":{"startLine":351}}}],"partialFingerprints":{"codehealthFindingId/v1":"a1b60ac11483f5579d0536fd01b62b8418cc825b7cf2bb49bf91c54f4f39bf2c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 4): crates/llm-remote-http/src/default.rs:40-49 | crates/llm-remote-http/src/default.rs:98-107 | crates/llm-remote-http/src/open_ai/mod.rs:47-56 | crates/llm-remote-http/src/open_ai/mod.rs:104-113 \u2014 there are 4 copies across 2 file(s) \u2014 more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 4 sites; resolving a subset leaves the remainder to drift apart."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/llm-remote-http/src/default.rs"},"region":{"startLine":40}}}],"partialFingerprints":{"codehealthFindingId/v1":"7dcfabed94f83a1aeb97e41fad66c6d6cb081ff6f26cdf44cb96be0f90a89970"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/factor-outbound-mqtt/src/host.rs:129-138 | crates/factor-outbound-redis/src/host.rs:250-259 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-mqtt/src/host.rs"},"region":{"startLine":129}}}],"partialFingerprints":{"codehealthFindingId/v1":"44bd56759a52645c6aa27089dc21fb5f92442f21fd8ed9adbf24c02e4619f442"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/factor-wasi/src/wasi_2023_10_18.rs:1292-1301 | crates/factor-wasi/src/wasi_2023_10_18.rs:1321-1330 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-wasi/src/wasi_2023_10_18.rs"},"region":{"startLine":1292}}}],"partialFingerprints":{"codehealthFindingId/v1":"e867e73183bea3074eaa1e0bdb5b8a95a8dad6c2ac61cef60e9a2610a1e3262d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/llm-local/src/bert.rs:338-347 | crates/llm-local/src/bert.rs:422-431 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/llm-local/src/bert.rs"},"region":{"startLine":338}}}],"partialFingerprints":{"codehealthFindingId/v1":"27b4e7c90db6d9967fdba81f1552921b5dd9bb3c17203fd81183aa386b09106c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8\u201310 lines \u00D7 2): crates/oci/src/client.rs:633-640 | crates/oci/src/client.rs:655-664 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/oci/src/client.rs"},"region":{"startLine":633}}}],"partialFingerprints":{"codehealthFindingId/v1":"4ea98dc6a845f71963b2efc388e6b161217d7416a981c788059602f9fa2ec535"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 3): crates/environments/src/environment/catalogue.rs:258-266 | crates/plugins/src/git.rs:74-82 | crates/templates/src/git.rs:15-23 \u2014 before extracting anything, compare \u0060crates/environments/src/environment/catalogue.rs\u0060 and \u0060crates/plugins/src/git.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 43 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/environments/src/environment/catalogue.rs"},"region":{"startLine":258}}}],"partialFingerprints":{"codehealthFindingId/v1":"7d965f88797f0f40e4db337248ab88188033eebbe2f7472b5d1c4a32e6cbb042"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/factor-sqlite/src/host.rs:124-132 | crates/factor-sqlite/src/host.rs:242-250 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-sqlite/src/host.rs"},"region":{"startLine":124}}}],"partialFingerprints":{"codehealthFindingId/v1":"8d88f1a331c060887902d450526ac6e31d30be4697e447ab08e17860cadb691c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/factor-sqlite/src/host.rs:139-147 | crates/factor-sqlite/src/host.rs:262-270 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-sqlite/src/host.rs"},"region":{"startLine":139}}}],"partialFingerprints":{"codehealthFindingId/v1":"c7209d98038f74cddbe746024740a961068fc045c3c42ed2b817c7b8fdabc4b6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/factors-executor/src/lib.rs:298-306 | crates/factors-executor/src/lib.rs:327-335 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factors-executor/src/lib.rs"},"region":{"startLine":298}}}],"partialFingerprints":{"codehealthFindingId/v1":"94f669d4838092cdf2106d01aa6be29d1218522748980bf7c4dd6873eb2b5a70"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/trigger/src/cli/stdio.rs:286-294 | crates/trigger/src/cli/stdio.rs:307-315 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/trigger/src/cli/stdio.rs"},"region":{"startLine":286}}}],"partialFingerprints":{"codehealthFindingId/v1":"7f6392a66423df4e4d13416ae5c4a483f67333e4a72e0ff5665481c1fefbaffa"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 3): crates/environments/src/loader.rs:237-244 | crates/environments/src/loader.rs:250-257 | crates/environments/src/loader.rs:263-270 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/environments/src/loader.rs"},"region":{"startLine":237}}}],"partialFingerprints":{"codehealthFindingId/v1":"3a27c9a90d45abfab2632a99632d85efbda8880c5d12e495e2fc95abdabd07cf"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (4\u20138 lines \u00D7 3): crates/expressions/src/lib.rs:73-76 | crates/expressions/src/lib.rs:194-201 | crates/expressions/src/lib.rs:245-252 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/expressions/src/lib.rs"},"region":{"startLine":73}}}],"partialFingerprints":{"codehealthFindingId/v1":"29a9ab2b4935721be807440824e39c4711c1e46ac25b6ee0ca8b914a157d7676"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/factor-llm/src/host.rs:17-24 | crates/factor-llm/src/host.rs:47-54 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-llm/src/host.rs"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"b7023feb34d190a032c33f0cfbf2dde538a024adfa0982b27eded8c4db4f21c9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (4\u20138 lines \u00D7 3): crates/factor-key-value/src/host.rs:427-430 | crates/factor-outbound-pg/src/host.rs:325-332 | crates/factor-sqlite/src/host.rs:219-226 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 3 call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made 3 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-key-value/src/host.rs"},"region":{"startLine":427}}}],"partialFingerprints":{"codehealthFindingId/v1":"76b2ed8a4fc68f7fff436f4fd6b2e76c1667ff9c4e59ef774bdf63ff82c22ae1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/factor-sqlite/src/host.rs:123-130 | crates/factor-sqlite/src/host.rs:138-145 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-sqlite/src/host.rs"},"region":{"startLine":123}}}],"partialFingerprints":{"codehealthFindingId/v1":"cb9d36c832294f5914b41d1289270af64b5b730a384fca3d8b88ce7d4df6f4c0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/factor-wasi/src/wasi_2023_10_18.rs:1620-1627 | crates/factor-wasi/src/wasi_2023_11_10.rs:587-594 \u2014 before extracting anything, compare \u0060crates/factor-wasi/src/wasi_2023_10_18.rs\u0060 and \u0060crates/factor-wasi/src/wasi_2023_11_10.rs\u0060 as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 47 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-wasi/src/wasi_2023_10_18.rs"},"region":{"startLine":1620}}}],"partialFingerprints":{"codehealthFindingId/v1":"1f5772521e72e9a348d117bce7b816c127dc6a5f928419161394f7c57632c5fc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/factor-outbound-http/src/spin.rs:195-201 | crates/factor-outbound-http/src/spin.rs:250-256 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-http/src/spin.rs"},"region":{"startLine":195}}}],"partialFingerprints":{"codehealthFindingId/v1":"e4bdcb539d293fac7335cb436ffa8654cc7aa23dc4b3b9eaaa91b372f380abb8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/factor-variables/src/host.rs:106-112 | crates/factor-variables/src/host.rs:122-128 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-variables/src/host.rs"},"region":{"startLine":106}}}],"partialFingerprints":{"codehealthFindingId/v1":"c11fc4d49b45cf39efa443ea0d7ae427abd1567d09fae2bfe9af278bb4a55249"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/oci/src/client.rs:422-428 | src/commands/up.rs:471-477 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/oci/src/client.rs"},"region":{"startLine":422}}}],"partialFingerprints":{"codehealthFindingId/v1":"25ae5b32ce7b8b6f21bf942205ba2cad57ea26c5d8e70913270e0dd3b152f8fe"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): crates/factor-outbound-mysql/src/host.rs:125-130 | crates/factor-outbound-mysql/src/host.rs:147-152 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-mysql/src/host.rs"},"region":{"startLine":125}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c3967acfb09ba1272087073a4824a07d4efef36c465147471fcbaa1b72a9ba5"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/environments/src/environment/catalogue.rs:206-212 | crates/plugins/src/git.rs:22-28 \u2014 before extracting anything, compare \u0060crates/environments/src/environment/catalogue.rs\u0060 and \u0060crates/plugins/src/git.rs\u0060 as WHOLE FILES: this scan already matched 4 separate duplicated blocks between them, totalling at least 43 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. The two sit in different directories, so one cannot simply be deleted in favour of the other while both are reached separately: hoist the shared part into a location both already depend on and have each file call it, and retire whichever file turns out to have no caller of its own left. Extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/environments/src/environment/catalogue.rs"},"region":{"startLine":206}}}],"partialFingerprints":{"codehealthFindingId/v1":"6b873f0c5ac493f7c9a3b6d0a1cc87a87f3119c59d2f02bae471089a42870be5"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 3): crates/factor-outbound-http/src/wasi.rs:823-834 | crates/factor-outbound-http/src/wasi.rs:837-848 | crates/trigger-http/src/lib.rs:471-482 \u2014 there are 3 copies across 2 file(s) \u2014 more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 3 sites; resolving a subset leaves the remainder to drift apart."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-http/src/wasi.rs"},"region":{"startLine":823}}}],"partialFingerprints":{"codehealthFindingId/v1":"8889f4cf1cbd2d11571d0b610d206b3bad9e7a56af26072ecc493aa4ecf41cf0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/factor-outbound-http/src/wasi.rs:850-857 | crates/trigger-http/src/lib.rs:484-491 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-http/src/wasi.rs"},"region":{"startLine":850}}}],"partialFingerprints":{"codehealthFindingId/v1":"0ec760c71b910b8c29ccd73aaab9bcaee79470f177d6b31c90d5d1ad5bf611ab"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): crates/factor-outbound-http/src/wasi_2023_10_18.rs:61-65 | crates/factor-outbound-http/src/wasi_2023_11_10.rs:65-69 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-http/src/wasi_2023_10_18.rs"},"region":{"startLine":61}}}],"partialFingerprints":{"codehealthFindingId/v1":"0315fea50ed4c2cfb2d70a82de8e19dc1c0d44b892dfa16a68cb14c7a355adf8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/factor-outbound-mqtt/src/host.rs:92-99 | crates/factor-outbound-redis/src/host.rs:74-81 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-mqtt/src/host.rs"},"region":{"startLine":92}}}],"partialFingerprints":{"codehealthFindingId/v1":"180b43a473c0092501a41ed351fdc92d33c55cba26f72769ddbcef84d3a956d7"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/factor-wasi/src/wasi_2023_10_18.rs:915-925 | crates/factor-wasi/src/wasi_2023_11_10.rs:846-856 \u2014 before extracting anything, compare \u0060crates/factor-wasi/src/wasi_2023_10_18.rs\u0060 and \u0060crates/factor-wasi/src/wasi_2023_11_10.rs\u0060 as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 47 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-wasi/src/wasi_2023_10_18.rs"},"region":{"startLine":915}}}],"partialFingerprints":{"codehealthFindingId/v1":"6dd4d3e8c64ad98c39fa8cb9e7fe4e3c51872b715a41df15a15f04de2e5cc87d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/factor-wasi/src/wasi_2023_10_18.rs:1575-1583 | crates/factor-wasi/src/wasi_2023_11_10.rs:1402-1410 \u2014 before extracting anything, compare \u0060crates/factor-wasi/src/wasi_2023_10_18.rs\u0060 and \u0060crates/factor-wasi/src/wasi_2023_11_10.rs\u0060 as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 47 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-wasi/src/wasi_2023_10_18.rs"},"region":{"startLine":1575}}}],"partialFingerprints":{"codehealthFindingId/v1":"8d243b110cf7079abd467748275eb647570161d15b5cc6e7b4ae865c4418e7c6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): src/commands/plugins.rs:959-971 | src/commands/templates.rs:466-478 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/plugins.rs"},"region":{"startLine":959}}}],"partialFingerprints":{"codehealthFindingId/v1":"cb0f5a519479afea725eebe72ca85a317d1e05a2934b76cd6a6dfdf89ada3cae"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): crates/llm-local/src/lib.rs:188-203 | crates/llm-local/src/lib.rs:211-227 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/llm-local/src/lib.rs"},"region":{"startLine":188}}}],"partialFingerprints":{"codehealthFindingId/v1":"62926a90f9d5ef5311f48a61cd1ed00c67c5922d2f8ed53f53f4a1bab1674027"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): crates/runtime-config/src/lib.rs:263-275 | crates/runtime-config/src/lib.rs:296-308 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/runtime-config/src/lib.rs"},"region":{"startLine":263}}}],"partialFingerprints":{"codehealthFindingId/v1":"35ec8c5e4e9d78763a400c6f5064d414bfc0c7d912f8c353761fe7621d378044"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/llm-remote-http/src/open_ai/mod.rs:75-85 | crates/llm-remote-http/src/open_ai/mod.rs:130-140 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/llm-remote-http/src/open_ai/mod.rs"},"region":{"startLine":75}}}],"partialFingerprints":{"codehealthFindingId/v1":"8ca7a504a46f4469dc146d2fd0bed6c79403ed10015d83582c87e2d467ef56dc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/oci/src/client.rs:323-333 | crates/oci/src/client.rs:364-373 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/oci/src/client.rs"},"region":{"startLine":323}}}],"partialFingerprints":{"codehealthFindingId/v1":"ad8f36cd91b867b51d4d0c58e7432b13fe3c1a0a1f05b5962ede4a8f3a265561"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/dependency-wit/src/lib.rs:328-335 | crates/dependency-wit/src/lib.rs:344-351 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/dependency-wit/src/lib.rs"},"region":{"startLine":328}}}],"partialFingerprints":{"codehealthFindingId/v1":"7463133f3fb2a08c425f369f75e383032eaec23f5d217509953df6c8325d56dd"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/factor-wasi/src/wasi_2023_10_18.rs:155-165 | crates/factor-wasi/src/wasi_2023_11_10.rs:150-160 \u2014 before extracting anything, compare \u0060crates/factor-wasi/src/wasi_2023_10_18.rs\u0060 and \u0060crates/factor-wasi/src/wasi_2023_11_10.rs\u0060 as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 47 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-wasi/src/wasi_2023_10_18.rs"},"region":{"startLine":155}}}],"partialFingerprints":{"codehealthFindingId/v1":"d30471d6ec738b3e052ab288b804d29eb794eaa0a740f374311f433585c50477"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/factor-wasi/src/wasi_2023_10_18.rs:142-149 | crates/factor-wasi/src/wasi_2023_11_10.rs:137-144 \u2014 before extracting anything, compare \u0060crates/factor-wasi/src/wasi_2023_10_18.rs\u0060 and \u0060crates/factor-wasi/src/wasi_2023_11_10.rs\u0060 as WHOLE FILES: this scan already matched 5 separate duplicated blocks between them, totalling at least 47 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-wasi/src/wasi_2023_10_18.rs"},"region":{"startLine":142}}}],"partialFingerprints":{"codehealthFindingId/v1":"37274000e1f1d75aff5e413054d2be263586c3456c612110cabad99f25631867"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/componentize/src/abi_conformance/test_mysql.rs:139-147 | crates/componentize/src/abi_conformance/test_postgres.rs:146-154 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/componentize/src/abi_conformance/test_mysql.rs"},"region":{"startLine":139}}}],"partialFingerprints":{"codehealthFindingId/v1":"7438494c9974269e590cd8335136bdc7ec7fc9e806852824e0f1ac903d814e1b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): crates/componentize/src/abi_conformance/test_mysql.rs:93-98 | crates/componentize/src/abi_conformance/test_postgres.rs:97-102 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/componentize/src/abi_conformance/test_mysql.rs"},"region":{"startLine":93}}}],"partialFingerprints":{"codehealthFindingId/v1":"516e29c19341884a6347152e8a3de60938a7a313b7bdb8652f0fc4f3bb80d440"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): crates/componentize/src/abi_conformance/test_mysql.rs:149-162 | crates/componentize/src/abi_conformance/test_postgres.rs:156-169 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/componentize/src/abi_conformance/test_mysql.rs"},"region":{"startLine":149}}}],"partialFingerprints":{"codehealthFindingId/v1":"36d121a1e7d4bcd81ed6a35fb3c450864d53b322c0963bc7759de452289eaba9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): crates/componentize/src/abi_conformance/test_inbound_http.rs:13-18 | crates/componentize/src/abi_conformance/test_inbound_redis.rs:13-18 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/componentize/src/abi_conformance/test_inbound_http.rs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"842874c5bf4e57edd20bed949fef624a3a144c675701698dd572b0af24af11f2"}},{"ruleId":"D5","level":"warning","message":{"text":"Unstable project spin-build: spin-build has instability 0.86 with 1 dependents."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"236b8c9e7d7d01f2da3f174dff31bb74938f5df6c17223c4a7874447e20d02d3"}},{"ruleId":"D5","level":"warning","message":{"text":"Unstable project spin-factor-outbound-pg: spin-factor-outbound-pg has instability 0.83 with 2 dependents."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5cc6597a46056d9b461cd640219b9d872b295858ea402df0d981a8dd87d76f6c"}},{"ruleId":"D5","level":"warning","message":{"text":"Unstable project spin-runtime-config: spin-runtime-config has instability 0.96 with 1 dependents."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3c5996dcffe2f0dd900b1b739cccbb27f2bbcb5df7d7a8b1199693184abcf123"}},{"ruleId":"D5","level":"warning","message":{"text":"Unstable project spin-runtime-factors: spin-runtime-factors has instability 0.95 with 1 dependents."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e2a0242cae9d5ae96e9e4aca7bf68ae2ef15dc5b724978038734d94f3126b18f"}},{"ruleId":"D5","level":"warning","message":{"text":"Unstable project spin-trigger-http: spin-trigger-http has instability 0.93 with 1 dependents."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"41328744db712e10691f193f7295f92fe42502b908544b26b6297b1320dd6820"}},{"ruleId":"D5","level":"warning","message":{"text":"Unstable project spin-trigger-redis: spin-trigger-redis has instability 0.83 with 1 dependents."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d4234777f741cc43230bb400f3c9ca973b32cf68f36d64b61686b4acb46033eb"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: spin-common: spin-common: abstractness 0.00, instability 0.00, distance 1.00 \u2014 the shape a shared-kernel / building-block library has BY DESIGN \u2014 concrete and widely depended-on is what makes it useful, and this dimension does not penalise it (the distance is reported for completeness, not as a defect). Worth a look only if it has grown past one coherent kernel into an everything-bucket."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c4fab2ef484a19b861b0d89ef0c831dd9c9a8d533cdd81226d281fb50c479b22"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: spin-componentize: spin-componentize: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and depended on by 2 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"eedef1e537ee873b207b4f2dca9bd1a66868a8b286e5754ad07aceb0d77f7e2d"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: spin-resource-table: spin-resource-table: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and depended on by 7 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5ab11d7c93dce0718324e24b489679704c1d5e2e13dfe8c65c4ca81a325f67e9"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: spin-serde: spin-serde: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and depended on by 9 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a759966cf4a288990c6c0770cb5554ea807e7a2f1170121ca322619c81dae85f"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: terminal: terminal: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and depended on by 12 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f78e3fa1a8a374ff2cc990cbb0a9f41463439c33fa6333c73536fd7acceb1ffa"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: spin-telemetry: spin-telemetry: abstractness 0.00, instability 0.06, distance 0.94 \u2014 zone of pain \u2014 concrete and depended on by 15 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"43128de193781a3872661f46c105f7a4db881724a6a291124a855b9f4ad15d02"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: spin-app: spin-app: abstractness 0.00, instability 0.13, distance 0.88 \u2014 zone of pain \u2014 concrete and depended on by 7 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1f2b028e85a5246581b482d5df5d62031a32f54da7f7b5a55efadd07f899630c"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: spin-core: spin-core: abstractness 0.13, instability 0.00, distance 0.88 \u2014 zone of pain \u2014 concrete and depended on by 16 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"972f80258974ac1eb6503f6fc114de0a6bda12909093a3e77f596342e5729e52"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: spin-wasi-async: spin-wasi-async: abstractness 0.00, instability 0.14, distance 0.86 \u2014 zone of pain \u2014 concrete and depended on by 6 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e6b12a3d9aec200f0f9273586997632d17c6cc15b6dfc3a5d01679c39669dbda"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: spin-http-routes: spin-http-routes: abstractness 0.17, instability 0.00, distance 0.83 \u2014 zone of pain \u2014 concrete and depended on by 1 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f1dd7e4292b44ba0907f8a1a5da7543ebb0690539a63d64c3e4ab2454ef27fc3"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: spin-locked-app: spin-locked-app: abstractness 0.09, instability 0.09, distance 0.82 \u2014 zone of pain \u2014 concrete and depended on by 10 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"02352137d5019c175e12f0d2643191443d288df8565ff276ddc79cecebbafae2"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: spin-connection-semaphore: spin-connection-semaphore: abstractness 0.00, instability 0.20, distance 0.80 \u2014 zone of pain \u2014 concrete and depended on by 4 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e95bbd99941b1b262ff4f50fa9d82d37e77a1fd06a62628c66ea91863c82d8ef"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: spin-manifest: spin-manifest: abstractness 0.00, instability 0.20, distance 0.80 \u2014 zone of pain \u2014 concrete and depended on by 8 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"73bcced1279f6b9eb0c733885d91ba8d1b476c3465b3de91913f17868ffc0303"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: spin-factor-otel: spin-factor-otel: abstractness 0.00, instability 0.29, distance 0.71 \u2014 zone of pain \u2014 concrete and depended on by 12 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a0c33fc6a5a6ab55b814fdb82c4d72b4d5a99c9cac6de056c932f05e4d791c52"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: KeyValueDispatch (LCOM4 8): KeyValueDispatch\u0027s methods fall into 8 groups that share no field and call none of each other, against a bar of more than 3 for this run (LCOM4, configurable \u2014 your repository\u0027s bar is the one quoted here). Each group is a set of methods reachable from one another through shared fields or direct calls, so 8 groups means the type has that many internally-connected clusters with nothing tying them together. Types whose shape makes a high count expected \u2014 and which would otherwise dominate this list \u2014 are excluded before this row is raised, so this is a genuine split candidate rather than a metric reading. It is still a shape, not a defect: confirm the groups match responsibilities you can name before splitting."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-key-value/src/host.rs"},"region":{"startLine":70}}}],"partialFingerprints":{"codehealthFindingId/v1":"c872404efa888b889e1b58bec14efadaa9d4eaf5b0a2bc2f090c6caadeff7733"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: KeyValue (LCOM4 6): KeyValue\u0027s methods fall into 6 groups that share no field and call none of each other, against a bar of more than 3 for this run (LCOM4, configurable \u2014 your repository\u0027s bar is the one quoted here). Each group is a set of methods reachable from one another through shared fields or direct calls, so 6 groups means the type has that many internally-connected clusters with nothing tying them together. Types whose shape makes a high count expected \u2014 and which would otherwise dominate this list \u2014 are excluded before this row is raised, so this is a genuine split candidate rather than a metric reading. It is still a shape, not a defect: confirm the groups match responsibilities you can name before splitting."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/componentize/src/abi_conformance/test_key_value.rs"},"region":{"startLine":26}}}],"partialFingerprints":{"codehealthFindingId/v1":"810830fb1bdec2f670aa35717b18c2120a0c2c45c09d75dbecfadd48a09f374d"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: Template (LCOM4 4): Template\u0027s methods fall into 4 groups that share no field and call none of each other, against a bar of more than 3 for this run (LCOM4, configurable \u2014 your repository\u0027s bar is the one quoted here). Each group is a set of methods reachable from one another through shared fields or direct calls, so 4 groups means the type has that many internally-connected clusters with nothing tying them together. Types whose shape makes a high count expected \u2014 and which would otherwise dominate this list \u2014 are excluded before this row is raised, so this is a genuine split candidate rather than a metric reading. It is still a shape, not a defect: confirm the groups match responsibilities you can name before splitting."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/templates/src/template.rs"},"region":{"startLine":23}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee5b16d13ed991d4843ecb16ec76bf2068207335839a0eb6469ed99ee61247c5"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: ComponentStdioWriter (LCOM4 4): ComponentStdioWriter\u0027s methods fall into 4 groups that share no field and call none of each other, against a bar of more than 3 for this run (LCOM4, configurable \u2014 your repository\u0027s bar is the one quoted here). Each group is a set of methods reachable from one another through shared fields or direct calls, so 4 groups means the type has that many internally-connected clusters with nothing tying them together. Types whose shape makes a high count expected \u2014 and which would otherwise dominate this list \u2014 are excluded before this row is raised, so this is a genuine split candidate rather than a metric reading. It is still a shape, not a defect: confirm the groups match responsibilities you can name before splitting."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/trigger/src/cli/stdio.rs"},"region":{"startLine":165}}}],"partialFingerprints":{"codehealthFindingId/v1":"23e17d1e4f6271d491f58f84363c0d164d7f02a4860636aab504d6d16cd07ff6"}},{"ruleId":"D11","level":"error","message":{"text":"Test declared unreliable: disallowed_private_ips_fails: This test is disabled or skipped with a reason naming unreliability \u2014 the repository\u0027s own words: \u0022flaky\u0022. A test that is skipped for flakiness is neither passing nor protecting the code it covers; either stabilise it or delete it, but do not leave it disabled indefinitely. (Found by reading the repository\u0027s own test source \u2014 the suite itself was not re-run, since the reliability runner does not support this ecosystem.)"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-http/tests/factor_test.rs"},"region":{"startLine":92}}}],"partialFingerprints":{"codehealthFindingId/v1":"5f8421b69e943bfff06e21edd65ace7670b540fb937bf7f2eea5832d903cdf6f"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: src/lib.rs: src/lib.rs changed 2 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 18 in SpinApp::run at line 143. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 07:42:18 \u002B13:00\u0027 --until=\u00272026-09-29 07:42:18 \u002B13:00\u0027 --full-history --no-merges -- src/lib.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/lib.rs"},"region":{"startLine":143}}}],"partialFingerprints":{"codehealthFindingId/v1":"2c530fbeeba83c04da61dff30496df913b8ad97db9ae2ce4ec912d047bc7cc0a"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #1: If anonymized user #1 becomes unavailable, 13 significant file(s) lose their only recent owner: crates/plugins/src/manager.rs, crates/manifest/src/schema/v2/dependency.rs, crates/manifest/src/schema/v2/component.rs, crates/environments/src/environment/env_loader.rs, crates/environments/src/loader.rs, crates/factor-outbound-pg/src/types/convert.rs, crates/environments/src/environment/catalogue.rs, src/commands/watch/filters.rs (\u002B5 more). Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c66b279a2ecc6a0afb5b4c1f30fc442f510f742d516f7b951c6bff99d288169a"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #2: If anonymized user #2 becomes unavailable, 3 significant file(s) lose their only recent owner: crates/templates/src/filters.rs, crates/templates/src/renderer.rs, crates/common/src/paths.rs. Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"2d313e9011d6791b23ff1ea8184bf73b5d8ebce7decd41f0367908f10be7d259"}},{"ruleId":"D16","level":"note","message":{"text":"Further sole-owners (lower concentration): 2 other contributor(s) are each the sole owner of a small amount of code below the off-boarding threshold \u2014 folded into the bus-factor score and metrics (18 single-owned of 210 analysed files in total, counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 210 of the 310 production source files in this repository met that bar). They are anonymized user #3 (1 file(s)), anonymized user #4 (1 file(s)) \u2014 spread or document their files in the same way, at lower priority than the named off-boarding risks above."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6eac528f2429e724e1a97ed868f79eefbcf1888dab4af9a9e673429369bb5b2f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Make Bindgen::decode_custom_section public? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/componentize/src/module_info.rs"},"region":{"startLine":97}}}],"partialFingerprints":{"codehealthFindingId/v1":"39005de7ddfef568ca23f42e8c0dbfe951be240df72a4756a33545ffa34e0c08"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: fix test to pass \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/componentize/src/abi_conformance/test_wasi.rs"},"region":{"startLine":199}}}],"partialFingerprints":{"codehealthFindingId/v1":"db1eec8d4a5428daaa9438f16f64bcfbd454c58913fb69fc70280b38ba6fff90"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: remove this when wasmtime is updated to \u003E= v27.0.0 \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/core/src/lib.rs"},"region":{"startLine":88}}}],"partialFingerprints":{"codehealthFindingId/v1":"f752c78cfbb008181a21b4cbacedd1ed2e6278718b9e536126830797ea9a16c2"}},{"ruleId":"D17","level":"warning","message":{"text":"FixmeComment: // FIXME: racy timing test \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/core/tests/integration_test.rs"},"region":{"startLine":45}}}],"partialFingerprints":{"codehealthFindingId/v1":"2eb8ab122a4b342788839c13c1e02bc678ea402658090a224bc5003d104d88fa"}},{"ruleId":"D17","level":"warning","message":{"text":"FixmeComment: // FIXME: this should be \u0060anyhow::Error\u0060 and below there should be no usages \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/core/tests/integration_test.rs"},"region":{"startLine":107}}}],"partialFingerprints":{"codehealthFindingId/v1":"8560bee6096a2cce8d4497b5c364ca462186b4c59d8f33cf2c6bf526b252c596"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: figure out what to do if we import two itfs from same dep \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/dependency-wit/src/lib.rs"},"region":{"startLine":163}}}],"partialFingerprints":{"codehealthFindingId/v1":"fa6ed2012cf3f8548732c70a09ba59f4e52b29f071069338da72544e2c529964"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: We probably need a doctor check to see if the path can be expanded! \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/doctor/src/wasm.rs"},"region":{"startLine":45}}}],"partialFingerprints":{"codehealthFindingId/v1":"93025f250537bac4e550e7e5c981d4363d17f1d34c2bf4d63ca1b719d5e1f20b"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: this, down to the \u0022does the app use Rust\u0022 check, probably ought to move up to the Rust level \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/doctor/src/rustlang/target.rs"},"region":{"startLine":15}}}],"partialFingerprints":{"codehealthFindingId/v1":"0759849195f204d46048025511bc35b3369e97c2a03ab2744dc583df26c6ddb6"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: make this an export on \u0060wac_types::Types\u0060. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/environments/src/lib.rs"},"region":{"startLine":198}}}],"partialFingerprints":{"codehealthFindingId/v1":"163c595b812abaa7f1ea54c8e36889ca43d350af34c4e2119208606358457daa"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: parallel all the things \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/environments/src/environment/env_loader.rs"},"region":{"startLine":196}}}],"partialFingerprints":{"codehealthFindingId/v1":"0cb497f40e3f8536e664a11698772703cdf20b8a5644f5da8587fe0064c96970"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: this loads _all_ triggers not just the ones we need \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/environments/src/environment/env_loader.rs"},"region":{"startLine":197}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a5b2d1fcec313e83f53b1cd2b0709bd20a0a51a76e32fecae8f2c724727fb44"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: surely we can cope with worlds from unversioned packages? surely? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/environments/src/environment/env_loader.rs"},"region":{"startLine":327}}}],"partialFingerprints":{"codehealthFindingId/v1":"5f602f4fea4d04d57e6f844a38f10cd0686a344dead47688b3f36a8da2d29937"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: I suppose we should stop people making up path injectiony kind of names \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/environments/src/environment/catalogue.rs"},"region":{"startLine":122}}}],"partialFingerprints":{"codehealthFindingId/v1":"d26ec4351265ee60fb830b0f01e1d822ba43665f91129b760ed956ef4ee29be7"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: the following and templates/git.rs are duplicates \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/environments/src/environment/catalogue.rs"},"region":{"startLine":248}}}],"partialFingerprints":{"codehealthFindingId/v1":"fbee574805870726930dad4c962257ff5dc97396cd75983b7fee791e1bd1d4b0"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: the following and templates/git.rs are duplicates \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/plugins/src/git.rs"},"region":{"startLine":64}}}],"partialFingerprints":{"codehealthFindingId/v1":"5913daf405f51342ce3b7e8c5f89b6b820d1f0392ca21db12a33f3e45e27ad9e"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: consider cases like insufficient permission? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/environments/src/environment/catalogue.rs"},"region":{"startLine":284}}}],"partialFingerprints":{"codehealthFindingId/v1":"b7d47fac42816240b761631f1bff51c2d445e14e3eaec0ca4dce0e52967520a3"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: consider cases like insufficient permission? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/plugins/src/git.rs"},"region":{"startLine":100}}}],"partialFingerprints":{"codehealthFindingId/v1":"faa06418b5cbf4f3d0cc9700c128951b46e8eceef25ae30238f50ad9d5abda5e"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: consider cases like insufficient permission? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/templates/src/git.rs"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7cf9d76262393975687b333b89b674a4e003b97a5e03e50a80106369c109152"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: port nicer errors from KeyValueComponent (via error type?) \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-key-value/src/lib.rs"},"region":{"startLine":83}}}],"partialFingerprints":{"codehealthFindingId/v1":"1dda17c4691a2920750da40975213eac3c1bacd836b1f328951f5424b638a603"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: warn (?) on unused store? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-key-value/src/lib.rs"},"region":{"startLine":90}}}],"partialFingerprints":{"codehealthFindingId/v1":"1949338e50902eb4252d09094a63fb1d43892b7fa90aba630f8d2645384e48e4"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: probably need to figure out a better mapping between \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-http/src/wasi_2023_10_18.rs"},"region":{"startLine":372}}}],"partialFingerprints":{"codehealthFindingId/v1":"9031a32f5ee42c4a0e9063a9f72d2b62438de3ad2867f4119cd159177d8607bc"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: should probably categorize this better given the typed info \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-http/src/wasi_2023_10_18.rs"},"region":{"startLine":541}}}],"partialFingerprints":{"codehealthFindingId/v1":"096c952b00b3416390ff0c465a51667ec260f4a4c485d05e56ec8d58908567f5"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Can we plumb connection errors through to here, or \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-http/src/wasi.rs"},"region":{"startLine":158}}}],"partialFingerprints":{"codehealthFindingId/v1":"0974bac2117f2211b33e3750d57033d825d9b52390124e9e8ab1c31efeb51216"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: We could move this to \u0060AppState\u0060 like the \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-http/src/lib.rs"},"region":{"startLine":110}}}],"partialFingerprints":{"codehealthFindingId/v1":"3db54c0f4874af4b9d36a2960fd4da4302d0cf537c981f623c711cc365cea7d5"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: is this right or is this an \u0022index out of range\u0022 thing \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-mysql/src/client.rs"},"region":{"startLine":312}}}],"partialFingerprints":{"codehealthFindingId/v1":"dffaeb9db085f6e9a8d74b4f347b821a649c3a9a680d6eacbc8655e461b06c2b"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: We can expand this mock to track calls and simulate return values \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-mysql/tests/factor_test.rs"},"region":{"startLine":108}}}],"partialFingerprints":{"codehealthFindingId/v1":"a0b31a5a2c1ee6eb646788eb8d3beba63bbe1dbc0b08551c179d7ba35678754f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: We can expand this mock to track calls and simulate return values \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-pg/tests/factor_test.rs"},"region":{"startLine":109}}}],"partialFingerprints":{"codehealthFindingId/v1":"ffaa7ce78a067ca8af7cd9ae04542ab76e457639cb7780bba58f4a2676892db6"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: should this trap (somehow)? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-networking/src/lib.rs"},"region":{"startLine":347}}}],"partialFingerprints":{"codehealthFindingId/v1":"1580e64feae709903dc4164a5aa9a96451b2a84ea7b09f23bceecd36699fdddc"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: what is our max size heuristic?  Should this be passed in so that different \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-pg/src/client.rs"},"region":{"startLine":128}}}],"partialFingerprints":{"codehealthFindingId/v1":"00ca37f8bfdb790101e986f19ade2c754f420f1323b0b14f37a3a33e7f8911ce"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: this duplicates \u0060open_impl\u0060 logic but split up to move \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-sqlite/src/host.rs"},"region":{"startLine":160}}}],"partialFingerprints":{"codehealthFindingId/v1":"361bb2d5931ff5c9f0bbda25995d6293e0eb14b825b599c56908384f1a606f2d"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Parse this out of uri.authority? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/http/src/wagi/mod.rs"},"region":{"startLine":100}}}],"partialFingerprints":{"codehealthFindingId/v1":"b6bfa72cd59aecfcc7edcbb35a1ea4d2123389b238a05418112ccc3ec78c14e6"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: The function should parse the new value from the return response \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/key-value-azure/src/store.rs"},"region":{"startLine":324}}}],"partialFingerprints":{"codehealthFindingId/v1":"936b696d00878fcd90b608cb03e82096b9bbd7a24264cee838c53d2570cab5ee"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: flash attention is supposed to minimize memory read and writes - Do we want to turn it on \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/llm-local/src/llama.rs"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"4379751257b239e08f0b04b7ce6f94540326dacf7789e01313f6bc2d5fba1e61"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: /// TODO: Remove this file when a new release of Candle makes it obsolete. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/llm-local/src/bert.rs"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"90d9d33034643719e34184abdd00653908473b9657d3a3de1478e63d73ea3795"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: The all-MiniLM-L6-v2 model uses \u0022gelu\u0022 whereas this is \u0022gelu_new\u0022, this explains some \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/llm-local/src/bert.rs"},"region":{"startLine":32}}}],"partialFingerprints":{"codehealthFindingId/v1":"680b8fbf46148e50e1e9a7b8276b01624bee3746f07de4e4bffa3eca305e50c0"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/llm-local/src/bert.rs"},"region":{"startLine":183}}}],"partialFingerprints":{"codehealthFindingId/v1":"2fab2e0e0a2c1595545a313c4b6b1b748e98eb0e717d92b96177dae1757efc3c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/routes/src/lib.rs"},"region":{"startLine":420}}}],"partialFingerprints":{"codehealthFindingId/v1":"61e03d581d0640c3530ab430373c583b63ded2a1e685d367f129e4bdb7b270bd"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/trigger-http/src/wagi.rs"},"region":{"startLine":51}}}],"partialFingerprints":{"codehealthFindingId/v1":"ebbabe85524213fec4984f6bf8849a83c53920897257ad93c5c016c00adb5c9a"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Proper absolute positions? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/llm-local/src/bert.rs"},"region":{"startLine":251}}}],"partialFingerprints":{"codehealthFindingId/v1":"3555ec76c948a38797bdd3e1418964a1fdaf87bd7a9213b3ddbf48e5cd65ac2b"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Support cross-attention? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/llm-local/src/bert.rs"},"region":{"startLine":468}}}],"partialFingerprints":{"codehealthFindingId/v1":"8acdd28d2b588d6b5102d52c68e3c65056a758dc0273360569c3c3b1c1eea0ed"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Support something similar to \u0060apply_chunking_to_forward\u0060? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/llm-local/src/bert.rs"},"region":{"startLine":470}}}],"partialFingerprints":{"codehealthFindingId/v1":"b26c71631e25c9d5933508add849728f625615981bdbe0c78597e37a6b01eae9"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Make Role customizable \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/llm-remote-http/src/open_ai/mod.rs"},"region":{"startLine":66}}}],"partialFingerprints":{"codehealthFindingId/v1":"60ba95482458ee81189af5d0a4340b47c07af8930e09a224a421145b03d834e7"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: it turns out that using an enum for this results in bad \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/locked-app/src/locked.rs"},"region":{"startLine":33}}}],"partialFingerprints":{"codehealthFindingId/v1":"92959d3a2ecbe0f793631dbb5f53fd86615c817227689b8681007578b5977699"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: would it be faster to parse into a toml::Table rather than parse twice? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/manifest/src/lib.rs"},"region":{"startLine":24}}}],"partialFingerprints":{"codehealthFindingId/v1":"dbe7704211ec3f2c652605b8d5fec9bf6fcf6abc584310eaa4bf80816e4e0fac"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: use zstd? May be more performant \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/oci/src/utils.rs"},"region":{"startLine":27}}}],"partialFingerprints":{"codehealthFindingId/v1":"d1b14095e281307f6a0cf2a264f6eac8804a745936baa794cbf3d68d95904dbe"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: parallelize \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/oci/src/loader.rs"},"region":{"startLine":166}}}],"partialFingerprints":{"codehealthFindingId/v1":"689da8e8a0007af5d6e529e8258ee57eca9e70ec345880ad54667f4f3886bde9"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: the media types for application, data and archive layer are not final \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/oci/src/client.rs"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"04d60d9a3cc9c0a1c486ae75fdde0f5ccf241593176597614d4e56da0f0d75d9"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: We don\u0027t need an extra copy here for each asset to prepare the application. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/oci/src/client.rs"},"region":{"startLine":149}}}],"partialFingerprints":{"codehealthFindingId/v1":"ef46dfcac4af1f0677139dd2d857aa78e70c1ba3fe23bf6852350fb77eabda7c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Explore adding data applicable to the Spin app being published. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/oci/src/client.rs"},"region":{"startLine":256}}}],"partialFingerprints":{"codehealthFindingId/v1":"1bf3ee082dd3f52b2968773410188bbe5db5f56c9d30bf5f1676cffe443094fe"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: add a way to override this path. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/oci/src/auth.rs"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"772a5bbbf0038e14ce53c78143410536cd638735f2cf687fc76221af7e695571"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/outbound-networking-config/src/allowed_hosts.rs"},"region":{"startLine":368}}}],"partialFingerprints":{"codehealthFindingId/v1":"3ce8ba000fd7ba1d2a4403ea572a5915152fc2e486d57519e50c4bf9be64ca70"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: consider if we want other schemes too? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/outbound-networking-config/src/allowed_hosts.rs"},"region":{"startLine":482}}}],"partialFingerprints":{"codehealthFindingId/v1":"638a6acc915b34d7dc965d8b5f6daa2b664601b5fcdd1e8aa6db63287ccfc76b"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: This is very similar to some logic in the badger module - look for consolidation opportunities. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/plugins/src/lookup.rs"},"region":{"startLine":37}}}],"partialFingerprints":{"codehealthFindingId/v1":"d383ac2cf1b80a90c1a877d3318fd7602905d2422912bd6e9d04bacd8d89d27b"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: maybe always need a spin.toml file in there? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/templates/src/template.rs"},"region":{"startLine":33}}}],"partialFingerprints":{"codehealthFindingId/v1":"1a5bd91aac3c11c7d0e272c830af4eb877969a007051b0706418a387c7005bdc"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: possibly abstract to a ValidationCriteria type? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/templates/src/template.rs"},"region":{"startLine":127}}}],"partialFingerprints":{"codehealthFindingId/v1":"9ab3b298a362f74194ac1b979378a08137f2ee09ee16c04d198be38981111a21"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: this is kind of specialised - should we do the discarding of \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/templates/src/template.rs"},"region":{"startLine":244}}}],"partialFingerprints":{"codehealthFindingId/v1":"c46a757f52f417925f027d48551a46a9e9696febc20e3a05e5d7a9729607e697"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: we should resolve this once at the start of Run and then use that forever \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/templates/src/template.rs"},"region":{"startLine":288}}}],"partialFingerprints":{"codehealthFindingId/v1":"4f41b0a496a70a219a47f5ba93d65b3c5d563ca8940b36bce769b368b8f09fdb"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: for now \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/templates/src/template.rs"},"region":{"startLine":300}}}],"partialFingerprints":{"codehealthFindingId/v1":"0df24e45d368abca99e2627e02f3173ab62b7196db570f85a04c02303c93eac9"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: for now \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/templates/src/template.rs"},"region":{"startLine":332}}}],"partialFingerprints":{"codehealthFindingId/v1":"c260f2c294676cf1ae8f7a0884ef74e9f706d3bee6961e03c024a03aafb54510"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: for now \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/templates/src/template.rs"},"region":{"startLine":445}}}],"partialFingerprints":{"codehealthFindingId/v1":"cbbc91714b54ce604c10b31b090687f4e94008d361dbcc3a8d0fa557906e6f54"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: rationalise \u0060path\u0060 and \u0060dir\u0060 \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/templates/src/run.rs"},"region":{"startLine":102}}}],"partialFingerprints":{"codehealthFindingId/v1":"10abb17ffce9f33a17512011453adaba8fd236c7ff4f9b64a54505d51d8fa442"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: better to provide this as a structured object and let the caller choose how to present it \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/templates/src/run.rs"},"region":{"startLine":229}}}],"partialFingerprints":{"codehealthFindingId/v1":"ce20800daec9835476f8b36ca0ea5a5e3f3521b6bbcb8f0d7cc2c18c00125039"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: async when we know where things sit \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/templates/src/run.rs"},"region":{"startLine":398}}}],"partialFingerprints":{"codehealthFindingId/v1":"b2657183e45a486e30b13305f49c17f7f7c62f767f492af679024e370226d9b3"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: should we validate that \u0060rendered\u0060 was relative?\u0060 \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/templates/src/renderer.rs"},"region":{"startLine":80}}}],"partialFingerprints":{"codehealthFindingId/v1":"162613a45b2fa6cb9adf2bf64eb2e7b616624a371c6d16568d8bb0d2999d74fb"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: try other encodings! \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/templates/src/renderer.rs"},"region":{"startLine":94}}}],"partialFingerprints":{"codehealthFindingId/v1":"c3c5d678451ef7241fbf3e8a37a27904bedb407792a14230f0af60fb82fa7985"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: emit a warning? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/templates/src/renderer.rs"},"region":{"startLine":100}}}],"partialFingerprints":{"codehealthFindingId/v1":"6cb40f8cf0894c7888c4ed69d448eee5a830468fbb3bc2c31f03256b547dd712"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: the following and the second half of plugins/git.rs are duplicates \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/templates/src/git.rs"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"14372e903156f772b3fadacbb98d405774bc7c26f08b25e33e73f312745c8cbe"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: dedupe with spin-factor-outbound-networking (spin-tls crate?) \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/trigger-http/src/tls.rs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c6bec37541f8682344708b6c4e73b011abbee1078ed4b19aaebe5ff99f175a7"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: add a dedicated \u0060post_return_timeout\u0060 config setting \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/trigger-http/src/server.rs"},"region":{"startLine":742}}}],"partialFingerprints":{"codehealthFindingId/v1":"33de3caf9e6a182fa63094867ad86904da89fa6f0a5057651bd5a8559dd06319"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: /// TODO: the combination of functions and objects and traits is a bit funny and we may/should be able to streamline it. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/trigger/src/lib.rs"},"region":{"startLine":55}}}],"partialFingerprints":{"codehealthFindingId/v1":"4a609e14d89730cfa78245efbf8824362e510e69f52b9df91c12b446a851f0c4"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: make this configurable \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/world/src/lib.rs"},"region":{"startLine":63}}}],"partialFingerprints":{"codehealthFindingId/v1":"2000a2aa17058c8991945b129c2197df512d5a140c9f696ed27cb4a544f15e0c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: We could make the \u0060--help\u0060 experience a little faster if \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/up.rs"},"region":{"startLine":496}}}],"partialFingerprints":{"codehealthFindingId/v1":"2f54753e382171886174fa5fe0e1bf3e7a6ed3c7bd332c5da0a6d66607ce5c03"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: consider running the update checked? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/external.rs"},"region":{"startLine":124}}}],"partialFingerprints":{"codehealthFindingId/v1":"c665f606f562224cb187ee58aec04bfd81b38fc8e9284d4cb72d0252ff5e40af"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: remove this eventually once very unlikely to not have updated \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/external.rs"},"region":{"startLine":150}}}],"partialFingerprints":{"codehealthFindingId/v1":"81b12d47451a997b8bd9283bb71a7a1cf46a65bc6a0c33ef29e7c3ed9b4f5f57"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: refine which component(s) a change affects \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/watch/buildifier.rs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"5f8bc627ee6cf9a887e700121e784e5c15e1b30d85c267ceaf174bf9cabf72f9"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Test on Windows \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/integration.rs"},"region":{"startLine":1225}}}],"partialFingerprints":{"codehealthFindingId/v1":"5ade0f8353a88135795116fdbb3a3f2e9b26fdec9ef0c49876a86f5e89bf6141"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: consider removing this test or rewriting \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/integration.rs"},"region":{"startLine":2036}}}],"partialFingerprints":{"codehealthFindingId/v1":"caa7a3c10dd9ea657841a029da466b7398411e2fef6b45f98b66a42622b41f71"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: refactor this function to not take so many arguments \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/testcases/mod.rs"},"region":{"startLine":166}}}],"partialFingerprints":{"codehealthFindingId/v1":"bedeafd46b88ef11cb5b786ffd00e6e8892d24a596f754f4204434137f1c14d2"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: refactor this function to not take so many arguments \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/testcases/mod.rs"},"region":{"startLine":257}}}],"partialFingerprints":{"codehealthFindingId/v1":"faf6d0a93b103a9f4d46b8246cd91352d49f5ec54e2c8559486288816495603b"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO this is a hack to wait for the redis service to start \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/testing-framework/src/runtimes/spin_cli.rs"},"region":{"startLine":146}}}],"partialFingerprints":{"codehealthFindingId/v1":"03b753a61f5b6f6c4c405a42ed2bf727a1313b77f8c3361eb8401661e60b6b52"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO(rylev): convert body as well \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/testing-framework/src/runtimes/in_process_spin.rs"},"region":{"startLine":69}}}],"partialFingerprints":{"codehealthFindingId/v1":"11bcb5095ff628a31b80d63c6a95e2155bb447761d51d8e1710d9835e17b6fba"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no project overview: The first paragraph under \u0027What is Spin?\u0027 gives an overview, but it does not state what the repository itself is for and how to get started with Spin. Add a one-line purpose line (what Spin is for) above the What-is-Spin section so the root README\u0027s overview scope is clear."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"66dbf18d06aa983c06246108610908ba99aae6784280b3aacd1a6655733d71be"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found. No recognised ADR directory (\u0060docs/adr/\u0060, \u0060docs/decisions/\u0060, \u0060adr/\u0060, \u0060docs/rfcs/\u0060, an \u0060ADR0001/\u0060 folder, or their siblings) exists anywhere in this tree. What was searched, so you can tell an empty log from a search that missed one: every directory under the tree (build output, dependencies and VCS metadata excepted), for a document that is either any non-index page inside a recognised ADR directory, whatever its name and however deeply nested (\u0060docs/adr/use-postgres.md\u0060, \u0060docs/adr/2024/0001-x.md\u0060); or a file anywhere whose name is ADR-shaped (\u00600001-use-postgres.md\u0060, \u0060adr-012-caching.md\u0060); or, when neither turned anything up, a document carrying the decision-record signature (an \u0022Architecture Decision Record\u0022 heading, or Status / Context / Decision / Consequences as section headings). A decision log that clears none of these \u2014 unnumbered files outside any recognised directory, without those headings \u2014 is not seen by this check and this row is then wrong. If that is your case, say so rather than renaming anything; otherwise, consider recording architectural decisions in \u0060docs/adr/\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D22","level":"warning","message":{"text":"Inconsistent error handling strategy for metadata retrieval. \u0060get_metadata\u0060 implies a Result (likely returning an error on missing key), while \u0060require_metadata\u0060 implies a Result (likely panicking or returning a specific \u0027not found\u0027 error variant). The naming convention is inconsistent with standard Rust patterns where \u0060get\u0060 often returns \u0060Option\u0060 and \u0060require\u0060/\u0060expect\u0060 panics, or \u0060get\u0060 returns \u0060Result\u0060 and \u0060require\u0060 is not present. Here, both return \u0060Result\u0060, making the distinction unclear and redundant.: Standardize on \u0060get_metadata\u0060 returning \u0060Result\u003CMetadataValue, MetadataError\u003E\u0060 (where error indicates not found) and remove \u0060require_metadata\u0060, OR use \u0060get_metadata\u0060 returning \u0060Option\u003CMetadataValue\u003E\u0060 and \u0060require_metadata\u0060 returning \u0060MetadataValue\u0060 (panicking on missing). Given the \u0060Result\u0060 return type, \u0060get_metadata\u0060 should be the sole method. (signatures: App.get_metadata(key: MetadataKey): Result | App.require_metadata(key: MetadataKey): Result | AppComponent.get_metadata(key: MetadataKey): Result | AppComponent.require_metadata(key: MetadataKey): Result)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f794e0a715f406d3a3a2107d13334e39d5a6a072bd2604b30498a62e7e247d9a"}},{"ruleId":"D22","level":"warning","message":{"text":"Redundant methods for retrieving the App ID. \u0060id()\u0060 and \u0060id_shared()\u0060 appear to return the same type (\u0060str\u0060) and likely the same value. The distinction between \u0027shared\u0027 and non-shared is not visible in the signature and suggests an internal implementation detail leaking into the public API.: Remove \u0060id_shared()\u0060 and keep only \u0060id()\u0060, or vice versa, depending on whether the shared reference is necessary for the caller\u0027s use case. If the return type is \u0060\u0026str\u0060, the lifetime management should be handled internally. (signatures: App.id(): str | App.id_shared(): str)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9304decd7aadcaf1c3a9ba63eb0cb135d5f4cbac2e478d7e1e5c1ef0b68ac8f2"}},{"ruleId":"D22","level":"warning","message":{"text":"Ambiguous naming for build functions. \u0060build\u0060 takes many parameters including \u0060target_checks\u0060 and \u0060wit_generation\u0060, while \u0060build_default\u0060 takes fewer. The name \u0060build_default\u0060 suggests it is a convenience wrapper, but \u0060build\u0060 is not named \u0060build_full\u0060 or \u0060build_advanced\u0060. This creates confusion about which method to use for standard builds.: Rename \u0060build\u0060 to \u0060build_with_options\u0060 or \u0060build_advanced\u0060 and \u0060build_default\u0060 to \u0060build\u0060 if it is the primary entry point, or clearly document that \u0060build_default\u0060 is the recommended simple API. (signatures: spin_build.build(...) | spin_build.build_default(...))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"8922e9cf9bdc83e45ea39750090c299c1d60fa4505e16b93263d27adbbd61ef6"}},{"ruleId":"D22","level":"warning","message":{"text":"Overlapping functionality for path resolution. \u0060find_manifest_file_path\u0060 and \u0060resolve_manifest_file_path\u0060 have similar names and likely similar purposes (locating a manifest file). The difference in input types (\u0060str\u0060 vs \u0060impl AsRef\u003CPath\u003E\u0060) is minor, but the semantic difference between \u0027find\u0027 and \u0027resolve\u0027 is not clear from the signatures alone.: Unify into a single method \u0060resolve_manifest_path\u0060 with a consistent input type (\u0060impl AsRef\u003CPath\u003E\u0060). If \u0027find\u0027 implies searching upwards and \u0027resolve\u0027 implies strict path resolution, rename them to \u0060search_for_manifest\u0060 and \u0060resolve_manifest_path\u0060 respectively. (signatures: paths.find_manifest_file_path(provided_path: str): Result | paths.resolve_manifest_file_path(provided_path: impl AsRef\u003CPath\u003E): Result)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d8151f7fa38d0ce2d0aae7207345396bed82cc3ad70df0b303802dbac8041363"}},{"ruleId":"D22","level":"warning","message":{"text":"Ambiguous API for componentization. \u0060componentize_if_necessary\u0060 suggests a check-then-act pattern, while \u0060componentize\u0060 suggests an unconditional action. However, without clear documentation, it is unclear if \u0060componentize\u0060 also performs a check internally or if it always transforms. This leads to potential double-processing or confusion about when to use which.: If \u0060componentize_if_necessary\u0060 is the safe, idempotent operation, make it the primary API and deprecate \u0060componentize\u0060. If \u0060componentize\u0060 is the core transformation, ensure \u0060componentize_if_necessary\u0060 is clearly documented as a wrapper that checks a cache or metadata. (signatures: spin_componentize.componentize_if_necessary(module_or_component: \u0026[u8]): Result | spin_componentize.componentize(module: \u0026[u8]): Result)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"84418223bd09174c71110572add482de8706b5ff97df17c52bd97c9c11a4e324"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"081c7178ecf06cde9696c7b7bdf14ff01fb1df5ff9786bd22da5f9ad36a19603"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"df4d870cea99dde7b47720be88e0ff65a311c56f3b2a77f362ab04b924b563e5"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"88d699fa5df60c6c335198faf8c7c4345968928fd768d3fb9f7d7123617330ab"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"87e6bf301bc9c1315d6868e68204bc7525429c7788d5071f66be9f18e28ebec7"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2916218672ecd559fca23016fda1c63b7ad7bab60f9a09c62396ba5f4d1bdac2"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"730806473195638226c0c7109c9ef348c9201d14c3fe485bd154a478e9b0ac42"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e543103b70282916df59226a4902bd8ee5051d45bb90879c6bd7eabc25031b27"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c4b2b814ad48851b10a5e2a592bf7650b6e8559ded752702667855508200fcce"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7bacc6a9fcc44df907c5a3d277c8f51e47c62ebd348fc4d1bb4024f4c631c0e3"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1542ac657294a7960a3ca68607ef7a17d9ed3d2457fb06dcd777067445c6a3cf"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9051866e960591bbb38116ae7a528b773ac64a37d8470df0b82e7d7e7e48ec5b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1f3e3a96386d3cf2a09fa1b2ee086568b14149ffbb176c4b92b8ecf6af2fa512"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a378eb575e3f20eca26f26f9af5fcfc839b4b37f9977c04073aa58942c61cd4f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e10dd1c37af22b497f72f89b2c46e91ef5c8fc9d8d3b51a11f187eb59b3d5d0b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9413d177ee3dfb094dc7ceb596e3a2705c4a851450d2130bbb4a0076070eb76d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"15ad88b38fff2e6e26a2e5c51db46b5d95f5a0ab9ae8764a426454804472d49b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"db881e73c52138a6f7ff5ee50fe3521b5eaac3c9506cc29e6359b9deafcc2aac"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"045562b35b2b2c227e5b0cdf3d286d2cf31f63072d8abf407d04a8619cd89e10"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"78f0c8809c3544bdde3c0c0fd5a3fd27a61c1626608ecac38a7b6254d1fb476d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2d344060610c3f78f345c793f6ba35bf55c98212e67a2c600f593cd361819a53"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9604785261ce3e1e3f4a3ebb783ce55daff85affb1ffbf874b62445a42572d1e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eea2f576f5277541af28ae5a69be82ce0b391c7e23dca26cfa8bc7e416f5a027"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6a0ebfc99851edacf7e5fa039c041fe057d6184c18c14f3a569b022dfc05d955"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8b94788142453864a6eb8ad854d04a2a4ee21056435f3ff8473a268b077121d5"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8f177b03a37c3ab9978e4a819ef0a3bfd633f205db9f8d5e791297e027c6df34"},"taxa":[{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c7155ef539c11431eedbd29fb54f7565cfcc13ba4ba088f0563a46679cb845fd"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eafeb40cc9237b92e1f3239ea68672cf16bd9926e9db6bf7a1f37c7e069c403a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0a07d822ea7e0f34f53d41d1f74560116df71876856f79a57aba8ac7508feac9"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d6b446272cfb8026bf8d14434ed76bcbd85c2863cbacbc1f4ab423770d5029a5"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"23eeadd1dbc3a609306b5258f9ec4166053cc5990ce02f2e8d1ac20b5f993fb9"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5b122aadcac48c589fe4957a0ebd6aefd58196177166337f98148aff87e03c65"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d8abfbcd6e5a9b952f164ea67cfbf55eb8d9229a5e07f3a5a544db57600b6a3c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c26285ed6963913f8fadb770eaaa16ed61cfe683b0cbe5a354bdd683a185daed"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3ae5344d47b66a6f2657dd8f92e86a68310a1c286894686feea12c758905e76e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"82a2207476a127b31de3a0576cbda80c85d78783164ed4c9afe27e559d2392c7"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e73bdcb7fba04e1b5cc0d274f97c7d6c3d7c3a2d6c2582f1538d6d428758e3f4"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f4586c477b66288337a300e2662831968031f302c33d441bb484d34cba89797d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8294a597483fe7b465902677c4f18924aa03967efe58c6a136a2c26440bcbde6"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7cac3cd196047a4fb74227384fc5d56f875fcc568a9b7dfb8629f7a7cb616f45"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c29780b8b835db3c4185d1e7492a81ccc7d447f3053af489e4dad00443988186"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"503900b97428c0efe5602b37f8035388f68ba5f127e9849e536d7c8552dc5b2b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c56dab2786dc5bd7af86f325dbb311f22812e318af3abe47ca5ac08b78ea5cf0"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"28e6a5f4bfbff2c739f254f48181dc378c8ffbf8ee906a00bd336de337be887c"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"354a13b6588c02f7d0eff75a5499ba15039b8888cab6254abd80d4ac0506f886"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f6dfb9111a34cfb2424401f629a84dcdf4e7a64e9d82eb93265e33bb8ecae10e"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"30c072bfb4acd11f57726cbf034b3fcdf802e3be858a1ebf1733fb21f8b02823"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fd6c69a21d468d9dbf078073e90e133c2ff361ac81602fa3e7673f294e1227a4"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"10b428b198f1b41504938d06776339f32187c52c538ff7a2ef8b163e8dfef011"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"729f37828e0482e2193ce4f3128b51b767750d7b0737e2cb008abad297756ef1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e0d2e9ad990e07eac0e16d05e1e21bfbe953e519eb6672ccdfd1d79e621f49a5"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"47a3d780dd219da87b80139c525b9a49156c2740b7c530a74c7207254781eb44"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a42dc120bd46fb4788a1b828a60af2a09440f48f835f2ff39f3415f1f7c689b8"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fcf708b309722c86a3e694df7145e757bc7d4d166c316400b1bda8158153fa77"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f91284b51980bd50a974e885fc87f0e44b952e1bdc99b3d33fa4176dd7a3dfe5"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"289c9fe343fca285cd6e3cd2b59c7cc81d477acfd507fb7f29a1294f3db8007a"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d0d7ca99e864b49402068626c1f02a0647df89286c9459101cee2597995f60b7"},"taxa":[{"id":"CWE-214","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-532","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"580ae9e8d56f834bfa61b79f81c8a9007e93e87b65d7bbef3d46633d2629c340"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"28782cd3b7d1e91b3bf2ca54e3649a21934e6d35a5edc57bd422145a899863fc"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b07db4549c8963d847f5f779a7a2659d8fe6826973c5069828ce972fc322d35b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c75e7f413c977735eacec43bf87866d93a3c2173fb65f99b670874b75d1ecc74"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4332298e540ce34c0e50c4655d324c99ac964078ee44483ca1d57798c5ed8e19"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2887e2ce9c8b513384019a859b0cdd48821ecbf1d05d390f8d84ed6062433ae8"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5f65e3b124e6de4f7c73afc0585a7d758a65df761542c0df7a969ecf4c5fac53"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4b364f9f1fd6da2ee08208dc803c4afb5889ed1d6a8b535ae71f6af91bbd1a68"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"407752ae21de844d4ee90705bdf65d9077311729dae593bfbcecc2e56f658ecf"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e9f459beff7992516555873911ffd3fa244119f39cc6f5cd5521ac2d23ca9086"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"95557da72ef37adf5b2dcd5cffa9786f76a887244e6c2c53366fe22ddeddde63"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b21ef51d97f04d1a8b921e635aca9ef4e877341aa2c3b0f6eaeabc61234774b6"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bee54b729227d7b1a968ba28c8c6c1d422e961a286b5433aaf96369f27b609d1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6819b36024d45f5f0e1d43e74427f1e72c7d8dae5d09101e0f966a51bf6829ab"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ae59d5e9dd2c30e110a21be3f2f3e4339df91ffb4154cfcf5f17bedb858ec684"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"64478662fa5e1544368a8d37a73d78bfc90ea789fe52460bc2794d70b8e273b3"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1de4e8df69f8ea88743a72dc79ebdff0df14ccb12667fe14ae5c33266501ddc5"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"194a1865ac28c4ae38c004b2601f2b28923cef7e57a09e701d1f0c62e1a4f16b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6504d8d1633fd2629c17cb911821ef9d4b240f323d5e1ebac2df01ac4726a04a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5a0307a0e95589e470722eaa1f6edefde899ff9d045423b92eaede73ef396b02"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"59bdb5a1e8e9e2536fc49c741fcb4259a61a8678fc811d3adeb596662203897f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3f8be44253a1fb10b9f389d5dd0320ad2b3b36d016bfe0ed18d4ed7d651e8dd6"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e7aea5ad354bb944fe749ff0e5f574830ccdd11e2edd1cb16678dd3d93b52205"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fb4a23173542d7a1718b502d857067e50a3ab2bcd9e6cbc8252c0d9b2bd57371"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2c7c520ac0159e7422c4fd00b149a656fa2f3494d8fb041d9febe5ce74227709"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"04b15c1d822501a1f3b0513e178960337673a790f4f183f2453907ced2d2833f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b133c92a797fe3a5811e4feb04ad3f5f524ccfa6240f6c57edfa2c1c0e6f547d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8839a7514414d37c87253cbdf331fb961c53af1225976b5e124bef0624103c4c"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f6094983ed91f4666292cad10029bb1ed0d556c345b0cfc241cc8d674cd2beb1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"31e15292ee7781495cff3025f3779e23aded0d07be93120b45c65e1d6518c389"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9450c09ec144afa108c7ac2e0d6a2d57a40d7cb388adb272756c6580cff8457d"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9e05a9afdb159c3b4e03fba36ee6c997dfff609cf8e7411f86b673ca79d09a53"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"40b13e661977ec383b3447ceb5c9f2b5ad4da373f334fdb358e33166ce854f36"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6fefb5a862019e6537f48d1cc54cfb909690ae67b4719969c16dcad65a24a27d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d2afc5a81f5e606c4e1b87b7b2a2619fef6a3941060ed4ebb04aa258f3608437"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"189637438c98047c31a6811543f84e904c1462c24d23649c58776128a115651c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fc4496fc674ac0d0155a791281a5c9eac5a014da835f130329efef8dd7eae233"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8c440edafa04b881d1dc8316b85b880e8138dc95fcb96747df7e3bdbd95a8fad"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6de7e81d72b486d865f0796ad920c682dfa0f0540fd6fab81841cb8d2ea2e1d3"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a58b745cf183b99c2f21acd909e8439cf9cad125c45c04356c7739684999f69b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2c220acd115e5521e1d81a9fe4506793852ddd0b8d30973f93329e5d62b5cfeb"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c851ac67e69ad14d293f610e9cad0bc61eb94749be95a9175de927ef14612bf5"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8bc19cf20b5f8ff0cc440f3aa1492cabf0cc6223853e647e872ada03a029282d"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"36a51d34b46c0e3d188bb664e9095202edc613b9c0c0e294319eae675f63962b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"81e55f5f2c80660e2aca55dca178594e37fd2912be1b269640729b3f113bb68e"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e7e2e9d0ba37c9aeebae680ac036a5cb035cf1ccd1f461bf55f2edf4cee2b9ca"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"03db60ca71a74173a40d213a8084a4e1a8ed8914cb36740b4fa2b3f8af7803da"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d39aa87960b81538a2ac7c1c085ffeaefcb096bac99164731cded71403738b6d"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"683029807db7bb7d0091b56acaa3a8166eb87dbeb582d5dfe26883ff09e06304"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"629aa9166d9ae29b75e52535c41231f0b0c2dfad29f6a0403e771f1d791465e9"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"05898479868c44772aed7eaa82f2123034b2fe5a7282e9e1eed122a238fd357d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9e9fd5b39fd45960ed2be44fdd2c2fa5fd7324771835a869051b3d546e164063"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f40591f476e9b78b94181647b523c012617492a5f82f8248d51749c583fecffc"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d19bce59d518eeaf10035915ff14bd1639f62070ef523b898dd3f80bb46cb4f8"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1329","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b0fab00761cb5f839e07c0f96a36d5a74ab28793fa3dac8020291096521e1903"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8f4ad532a1d023bdfa1bb6bc8591bca82f00669be3d178a35609da0e0cae496a"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-552","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4ddd7110b9334b7748dd2e36633f0bd718d1d53dbbe243bf141b1ec6f9f4a427"},"properties":{"dependency":{"package":"rustls-webpki","version":"0.101.7","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","RUSTSEC-2026-0098","RUSTSEC-2026-0099","RUSTSEC-2026-0104"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fed5e1975df46d2185bfeb765ddbe9cb0f2ad0da96c92e619b12f8f4a99586e1"},"properties":{"dependency":{"package":"rustls-webpki","version":"0.102.8","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","[GHSA redacted]","RUSTSEC-2026-0049","RUSTSEC-2026-0098","RUSTSEC-2026-0099","RUSTSEC-2026-0104"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ea95485e0a87e0a063d5e2972f8eb803980b4a5389976d214dfe3b2149830b52"},"properties":{"dependency":{"package":"gix-fs","version":"0.18.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cc824fd2c3801e509d0f42f916654d8408a6b7d66369c77f60b1b64a2f9a550f"},"properties":{"dependency":{"package":"gix-validate","version":"0.10.1","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cfc4de93aab9abfd015e08be61479d8dec6c59b7aa4ffc50c058579f0315dc5c"},"properties":{"dependency":{"package":"gix-sec","version":"0.12.2","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"525150c79769e3a8552e1d639a767bc181c181d5c769963ba9e0faa9d03741e3"},"properties":{"dependency":{"package":"opentelemetry_sdk","version":"0.29.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ac07f6d7edfd49261e66a0ecf670dc83aeb27f637d0eaec58b89ac41744f7835"},"properties":{"dependency":{"package":"rsa","version":"0.9.10","advisory":"RUSTSEC-2023-0071","aliases":["[CVE redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1fbfaa54c6250c5bea6051f292aaedcc30665f84b088589f336a3c4988e91c18"},"properties":{"dependency":{"package":"http-types","version":"2.12.0","advisory":"RUSTSEC-2026-0174","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f48cf8c9f415048128045caa118a1e03769d0b4fe18d7f036c2f3766e3e8d8fb"},"properties":{"dependency":{"package":"instant","version":"0.1.13","advisory":"RUSTSEC-2024-0384","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5922a5beeab5ac077ffb485a783ad545036e79b56239f83da38f3fb84336b113"},"properties":{"dependency":{"package":"paste","version":"1.0.15","advisory":"RUSTSEC-2024-0436","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"705e8761c5e609601c0419d94a8bad1aeb6aee434f48ec4660c92e8bf534c9de"},"properties":{"dependency":{"package":"number_prefix","version":"0.4.0","advisory":"RUSTSEC-2025-0119","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b5524f25221308ec94b7206b58afaa59996104c20abaa242285d451f5344e44b"},"properties":{"dependency":{"package":"rustls-pemfile","version":"2.2.0","advisory":"RUSTSEC-2025-0134","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"904cd12f65d71ca63d739c739b4c100bf718e7d129ce5630aa4dba7fa6968b6e"},"properties":{"dependency":{"package":"bitmaps","version":"2.1.0","advisory":"RUSTSEC-2026-0247","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0897771ffd4e3ceb3419dde32bb5bb1ffcf0f4b413f8009f7ee61b96577e12ed"},"properties":{"dependency":{"package":"smartstring","version":"1.0.1","advisory":"RUSTSEC-2026-0249","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a460069b86f1a2735babc8688e0411f97ac3343bf61746d845872d161c95683b"},"properties":{"dependency":{"package":"im-rc","version":"15.1.0","advisory":"RUSTSEC-2026-0250","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0d5eb3c9e63b1f4e713840f0a870cb4fc4b0eadec98bf720c40fb49b919ccd26"},"properties":{"dependency":{"package":"sized-chunks","version":"0.6.5","advisory":"RUSTSEC-2026-0251","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bbe030f8c1c144f826bad4cbbd83ebd5ea8dfc9162bb9621a856f9f966813acf"},"properties":{"dependency":{"package":"lru","version":"0.12.5","advisory":"RUSTSEC-2026-0002","aliases":["[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d44a25813d8a9e18eb42fa5350a972c298292d454155c6472f091bfb670363df"},"properties":{"dependency":{"package":"rand","version":"0.7.3","advisory":"RUSTSEC-2026-0097","aliases":["[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"422864efbc32ee020d94634a443edac9d818b90faf02ac96d91c4d66ffa4da37"},"properties":{"dependency":{"package":"lru","version":"0.12.5","advisory":"RUSTSEC-2026-0253","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eb0001f1efbeb6758c9328ffac016bb7f7f69b0b96734f2fe260dcc9f13686c9"},"properties":{"dependency":{"package":"sized-chunks","version":"0.6.5","advisory":"RUSTSEC-2026-0255","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f98a5252cf643899a128d2b6f6d04b7713273d44fa70b088ba81df0a39c759a9"},"properties":{"dependency":{"package":"faster-hex","version":"0.10.0","advisory":"RUSTSEC-2026-0306","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f33134b914692cd6c5f119efdf542f3d6c34c918da971c9cc600e5d39c46efde"},"properties":{"dependency":{"package":"rkyv","version":"0.7.46","advisory":"RUSTSEC-2026-0235","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"80b5c22beae306eb623d7a60ec13361ab89285e1cc30fcf5b8daa2e87ffb5c69"},"properties":{"dependency":{"package":"h2","version":"0.3.27","advisory":"RUSTSEC-2026-0258","aliases":["[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"443e57c20a9811a8052be6d456f7f29c20a16c807dac3a9760fe516106724232"},"properties":{"dependency":{"package":"azure_core","version":"0.20.0","advisory":"RUSTSEC-2026-0275","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"43c685954762ec79deaced3856ad23243409cb4818baf115d40fe25043e418d3"},"properties":{"dependency":{"package":"azure_core","version":"0.21.0","advisory":"RUSTSEC-2026-0275","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3035e85b1a9c0c33df37dc333f490439b3fa52aefda24a401e2e75a177cdf778"},"properties":{"dependency":{"package":"rustls","version":"0.23.43","advisory":"RUSTSEC-2026-0285","aliases":["[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7bc4cebc189c77e9b2efc242d29ded72335825f057bb5cbfccfcb96e60a4606a"},"properties":{"dependency":{"package":"wasmtime-wasi-http","version":"49.0.0","advisory":"RUSTSEC-2026-0313","aliases":["[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a6ff3411563c25f2059f9b1effa6d2a7b6f55fc9af1634934c17ac2caed19608"},"properties":{"dependency":{"package":"wasmtime-wasi","version":"49.0.0","advisory":"RUSTSEC-2026-0314","aliases":["[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"650d11a84546e9b4f0f18d5db910fc981e160796d3d49458de6f28f250c09d10"},"properties":{"dependency":{"package":"wasmtime","version":"49.0.0","advisory":"RUSTSEC-2026-0315","aliases":["[GHSA redacted]","[GHSA redacted]","RUSTSEC-2026-0316"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ace97e2564814e77545d9c27b07627d44e1cc70105d7d23f1d38ef9f0b7008ec"},"properties":{"dependency":{"package":"libsql-sqlite3-parser","version":"0.13.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"58af007dcda9780e5b4e9e1a42e74dadc405e1b8589d6d468fa71891ae1b031c"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"20c958c93630de78622089b6c263b49d4e837324f0e8637ca1abb3c43ab7a180"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e738fd9e60d03185141f6f1a7f489d0300c1d088d3159245db74ce4dc3edd5fb"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"26a7c567fd303d4fdf69a266e708adf6912700bd90cc1ed48b0613e61e60f456"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b5567e7eea8f031ab402972972355ddff5b1395f61190d08c4442fb70b4079db"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e7c71bdc00eb7d1f6e5acdd8274f222d7c025e126d1ad8222fb899258be3a03f"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a892a5179958bce2140e44cd270c7834cbdc6d36757dcb81a8c3adbd2c33b33f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dfad2bea74e92fc2dc363ce53b8d9ddf79e60ce7ef95a25069b2c9bb279356c7"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0c032a1610e6ccbf81329296e3c0273c922449cabf98d4b19f12c7ac375d4ab4"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eb9444031fc35c41c430dc3b53755f2a9ad27d7cdf1bf4b7c3918e26c2d4d79b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3b1568673c97a5ce9b1ec5a08dba083d705b7ca92047378b6f33333438b27491"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c765e3a073ebf724df40dab1e785ed2171c29c55251db4dbd1ab4687cc6eba49"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"71bf0e7f35c3bef929185fd83d8146bbf0590e965986385a0444bb41733fea23"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a0253cdb433485d93f1259fe935cad7c5df0486a99bae72ae65dbbacb158f6f3"},"taxa":[{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"74ddc191ed8370cf59f1c4e6ca4abe37b4cc55971e294245d7f2cdf5fb7ac42c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D34","level":"note","message":{"text":"Orphaned files with no living knowledge: 3 of 210 analysed file(s) have no living knowledge left \u2014 their last meaningful change has decayed away, so if one breaks, no one currently understands it (counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 210 of the 310 production source files in this repository met that bar). None is large enough to earn a read-through of its own, so this row stands in for the per-file rows rather than raising one each \u2014 most significant first: crates/llm-remote-http/src/default.rs, crates/llm-remote-http/src/open_ai/schemas.rs, crates/llm-remote-http/src/open_ai/mod.rs. Attach the read to the next change that touches one of them: have a second person review that change, and leave behind a short comment or test recording what the file is for, so the knowledge comes back at the cost of a change you were making anyway."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ce861fd78f6935114d3a342cb90ad25870f984e1042954fcbbe27c0e23be3658"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: lib.rs \u2194 lib.rs: \u0060crates/variables-env/src/lib.rs\u0060 and \u0060crates/variables-static/src/lib.rs\u0060 change together 82% of the time (9 of the 11 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 9 shared commits counted here, the most recent 3 are \u0060294ad3a8\u0060 variables: Refactor Provider::kind into ::may_resolve; \u00600e4c4c19\u0060 Check required variables are potentially resolvable; \u00600a4c05ac\u0060 Factor out variable azure/vault providers into separate crates (#3215) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/variables-env/src/lib.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"93148da4647850a81fd231b8c541fe7fd85b1c66f3e67570603bad47d889f4d0"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: lib.rs \u2194 runtime_factors.rs: \u0060crates/factors-derive/src/lib.rs\u0060 and \u0060crates/factors/src/runtime_factors.rs\u0060 change together 79% of the time (15 of the 19 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 15 shared commits counted here, the most recent 3 are \u00603ce559f2\u0060 Fix rebasing issues; \u0060bfd36801\u0060 Allow dynamic querying of instance builders; \u00605e0d7297\u0060 triggers: Replace AsMut with AsInstanceState \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factors-derive/src/lib.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"eb1f0b320c7bc6536166707207d1a3b566a4fd7d61dc295d7f2b26e40b7317e8"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: spin.rs \u2194 wasi.rs: \u0060crates/factor-outbound-http/src/spin.rs\u0060 and \u0060crates/factor-outbound-http/src/wasi.rs\u0060 change together 71% of the time (15 of the 21 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking. You can check this without leaving the row: of the 15 shared commits counted here, the most recent 3 are \u0060a3990d87\u0060 Allow config for how low we await connection semaphore; \u006056fd1c99\u0060 Introduce global connection limit; \u00600b5917b8\u0060 Refactor to use OpenTelemetry attribute aliasing for HTTP span fields \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-http/src/spin.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"07cc58c235f3baeef90ac08323b6c85fb0074ceddc2dbe6b705f6468c575b489"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: util.rs \u2194 lib.rs: \u0060crates/factor-key-value/src/util.rs\u0060 and \u0060crates/key-value-redis/src/lib.rs\u0060 change together 60% of the time (6 of the 10 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 6 shared commits counted here, the most recent 3 are \u00601c1f8b0f\u0060 Merge host component key value implementations into new factor crates; \u0060833ad50d\u0060 Add KeyValueDefaultStoreSummaryHook (at that commit the file was still \u0060crates/key-value/src/util.rs\u0060); \u00605b6deb9f\u0060 feat(kv): Trace KV host components (at that commit the file was still \u0060crates/key-value/src/util.rs\u0060) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-key-value/src/util.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b5823fec578b46bff1a52334ada9a60b9dc3bfc5a218c85bda8f4626f0639126"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: lib.rs \u2194 lib.rs: \u0060crates/factors-derive/src/lib.rs\u0060 and \u0060crates/factors-test/src/lib.rs\u0060 change together 58% of the time (7 of the 12 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 7 shared commits counted here, the most recent 3 are \u0060a10730cb\u0060 factors: Update spin-factors-test\u0027s TestEnvironment; \u006092e74b3b\u0060 Separate out turning source into config; \u0060e9b32bdc\u0060 Implement @lann\u0027s suggestion \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factors-derive/src/lib.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"21953340572fbe0f2f003a95ccdfdd890cefc7769c23d19f1aac69d4abe1086f"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: client.rs \u2194 conversions.rs: \u0060crates/factor-outbound-pg/src/client.rs\u0060 and \u0060crates/world/src/conversions.rs\u0060 change together 57% of the time (8 of the 14 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 8 shared commits counted here, the most recent 3 are \u006085acd6e3\u0060 PostgreSQL certs from guest mount; \u0060e39e28c3\u0060 Structured errors for PostgreSQL DB errors; \u0060cfd02528\u0060 Decimal arrays and ranges \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-pg/src/client.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3473e8bc535d9746337d66ead783567f6a66cd95bdd62027d64a278200654dfe"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: lib.rs \u2194 lib.rs: \u0060crates/sqlite-inproc/src/lib.rs\u0060 and \u0060crates/sqlite-libsql/src/lib.rs\u0060 change together 55% of the time (11 of the 20 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 11 shared commits counted here, the most recent 3 are \u00603f0ced5e\u0060 Async key-value and SQLite; \u00602b13d88f\u0060 SQLite affected row count and last_insert_rowid; \u0060f5c911ba\u0060 Move instruments up a level of abstraction in sqlite \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/sqlite-inproc/src/lib.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0432e49bc9c02a5935d9b26571af7b9ac9881097e1174582894818b850fb0119"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: lib.rs \u2194 lib.rs: \u0060crates/factor-variables/src/lib.rs\u0060 and \u0060crates/variables-static/src/lib.rs\u0060 change together 55% of the time (6 of the 11 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 6 shared commits counted here, the most recent 3 are \u00600e4c4c19\u0060 Check required variables are potentially resolvable; \u00608fed0976\u0060 Default support for env variables (at that commit the file was still \u0060crates/factor-variables/src/spin_cli/statik.rs\u0060); \u0060bf2e257a\u0060 Make the variables factor non-generic (at that commit the file was still \u0060crates/factor-variables/src/spin_cli/statik.rs\u0060) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-variables/src/lib.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d442169cdf0d5e6f4621cf554ffd84dac6186070f678603d2d9078c2896f73eb"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: registry.rs \u2194 up.rs: \u0060src/commands/registry.rs\u0060 and \u0060src/commands/up.rs\u0060 change together 50% of the time (14 of the 28 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking. You can check this without leaving the row: of the 14 shared commits counted here, the most recent 3 are \u006033774932\u0060 Accept boolish values for env-settable bool flags; \u0060cd56d6a1\u0060 Fix Markdown reference missing \u0060spin up\u0060 bits; \u0060e238a1ad\u0060 Build profiles \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/registry.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0092e6627fa0c6f463af921f10b1e7faf5dcf1b9c43eee70d484a109a036ea0b"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: metrics.rs \u2194 traces.rs: \u0060crates/telemetry/src/metrics.rs\u0060 and \u0060crates/telemetry/src/traces.rs\u0060 change together 50% of the time (5 of the 10 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking. You can check this without leaving the row: of the 5 shared commits counted here, the most recent 3 are \u006081e22400\u0060 fix(telemetry): use rustls for OTLP HTTP exporter; \u006016d3541d\u0060 Upgrade OTel to stop Tokio being pinned; \u00609f56929a\u0060 Fix metrics and tracing providers not being set globally \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/telemetry/src/metrics.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d2114bf4791b8a50554284142ec9ccab8a68ca68e8940ed5caf26cb60c3d1fcd"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1b213f6eedd4b140d0bc37bdf1496f72811a643f34064f12518b32e9e83bcfc7"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eb00976a698a5d68999b7ee6d27206fd374e916853e7ff1ead5eed42386f043f"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"90f83b4fa27db32740afe9540c905f3c0499caed87f61049a8a903ecc95b41c3"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cc682cd7167c2c692b624e54d299d32b2ea2b5b3eb72f5516f0dfab9c0ce991d"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7be964b311a6380af50ea81671ece9780d741f767dc79e47c2b108618722cf0c"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0752d0df7434000fcabf1048e2de30a7a1a8b982b3db9a19898c4dec199856b4"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d068c977b62d9a977df1bb6f53e8b00b586c3abee955f91d715f92b8e019d624"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d657599f6f99da1927d3377533dfc0888b34c4d84aa7d5579841fd72d0e39bce"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4f1e7684f8281bd255ddef97105c7055c2ebae06964c8745716b83e174debe83"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"M4","level":"note","message":{"text":"README/code drift: README advertises a microservices architecture, but the repo is a single project with no service manifests \u2014 searched for: \u0060microservice\u0060, \u0060service-mesh\u0060, \u0060istio\u0060. Each was matched case- and separator-insensitively against file and directory NAMES anywhere in the tree, and against the CONTENTS of manifest files (package.json, *.csproj, *.props, *.slnx, *.yml, Dockerfile); the README\u0027s own prose never counts, so a claim is never refuted by merely being made. Nothing outside that search was read \u2014 a footprint living only in a submodule, in a file type not listed here, or under a name none of those terms matches is not seen, and this row is then wrong."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"343bbbd51ceb8de7a9ff88d79f7c797abf9b5921f8727b67b4d0f4f8a22c5e49"}},{"ruleId":"P12","level":"warning","message":{"text":"Coverage collected but not gated: CI collects a coverage report but no step enforces a minimum \u2014 coverage could halve and CI stays green. Add a step that fails the build when coverage drops below a floor (your coverage tool\u0027s minimum-threshold flag, or a coverage-gate action) so the number guards something. What was searched, so you can tell an absence from a miss: this repository\u0027s CI files AND its coverage configuration \u2014 the well-known coverage and test-runner config files, read at the repository root and inside workspace package directories two levels down, so a floor declared beside the tests rather than in the pipeline is credited \u2014 matched against the threshold settings this check knows by name. A floor set in your coverage service\u0027s web UI rather than in a committed file, or under a setting whose name is not one of those, is not seen here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7f63c06044cf998d9a0698692df30d8873e29bc9b0c98ee829255017c1193d33"}},{"ruleId":"P2","level":"note","message":{"text":"Logging is not universal: Only 37/39 runnable modules use logging (modules with no entry point or server are excluded \u2014 they are libraries a runnable module hosts). Silent: \u0060templates/http-go/content\u0060, \u0060templates/redis-go/content\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"91a94e21d6d4d0e6a2003f94505b0b02b157176f0b24c4820f3f82b4447a97fe"}},{"ruleId":"P4","level":"note","message":{"text":"No rollback/health safety: Deployment is orchestrated by compose, but no service declares a \u0060healthcheck:\u0060 and nothing pins a previous image to fall back to \u2014 the runtime can tell that the container is up, not that it is serving, so a bad release is harder to detect and reverse."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"db6bab8a28a2145f47e5a4e6683cda39d2ba0296c723238e8057da979ae1c706"}},{"ruleId":"P6","level":"note","message":{"text":"No changelog: No CHANGELOG/HISTORY/RELEASES file \u2014 what shipped when isn\u0027t easy to reconstruct for support or audit. (Versioning/tagging makes releases traceable, but a changelog records the what.)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"dda5aa5aed8cbb292c3ef2b733bc138f614293ae6426c85e98bf31ef330d9415"}},{"ruleId":"P7","level":"warning","message":{"text":"Outbound HTTP without resilience: \u0060reqwest::get(\u0060 makes an outbound HTTP call, and nothing bounds it: no timeout, deadline, retry or circuit breaker is set for it here, and the client has no process-wide default. A slow or failing dependency will hold this service\u0027s request, thread or connection until the call gives up on its own \u2014 or never, for a client with no default timeout. 9 of the 9 files that make outbound calls are unbounded; the first 9 are listed."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/doctor/src/rustlang/target.rs"},"region":{"startLine":189}}}],"partialFingerprints":{"codehealthFindingId/v1":"e22120f9a6c83d3dd9d59462b25e4f8568fcf97eb11222e6f2b1a800e4ea1588"}},{"ruleId":"P7","level":"warning","message":{"text":"Outbound HTTP without resilience: \u0060reqwest::get(\u0060 makes an outbound HTTP call, and nothing bounds it: no timeout, deadline, retry or circuit breaker is set for it here, and the client has no process-wide default. A slow or failing dependency will hold this service\u0027s request, thread or connection until the call gives up on its own \u2014 or never, for a client with no default timeout."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/environments/src/environment/env_loader.rs"},"region":{"startLine":141}}}],"partialFingerprints":{"codehealthFindingId/v1":"72543ab0533429497bc5694f9bc5ba1c6933f17c9bf442d5cb735fb22455d16d"}},{"ruleId":"P7","level":"warning","message":{"text":"Outbound HTTP without resilience: \u0060reqwest::Client::builder(\u0060 makes an outbound HTTP call, and nothing bounds it: no timeout, deadline, retry or circuit breaker is set for it here, and the client has no process-wide default. A slow or failing dependency will hold this service\u0027s request, thread or connection until the call gives up on its own \u2014 or never, for a client with no default timeout."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-http/src/spin.rs"},"region":{"startLine":103}}}],"partialFingerprints":{"codehealthFindingId/v1":"10b4f09080c15f9531e43e1e05045a739a1ad9feee1296035f6232aea486473b"}},{"ruleId":"P7","level":"warning","message":{"text":"Outbound HTTP without resilience: \u0060Client::builder(TokioExecutor\u0060 makes an outbound HTTP call, and nothing bounds it: no timeout, deadline, retry or circuit breaker is set for it here, and the client has no process-wide default. A slow or failing dependency will hold this service\u0027s request, thread or connection until the call gives up on its own \u2014 or never, for a client with no default timeout."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/factor-outbound-http/src/wasi.rs"},"region":{"startLine":549}}}],"partialFingerprints":{"codehealthFindingId/v1":"e65ab91de9b3ec362d5ab97a717756c297a006135eac000054b298298d7fa081"}},{"ruleId":"P7","level":"warning","message":{"text":"Outbound HTTP without resilience: \u0060reqwest::ClientBuilder::new(\u0060 makes an outbound HTTP call, and nothing bounds it: no timeout, deadline, retry or circuit breaker is set for it here, and the client has no process-wide default. A slow or failing dependency will hold this service\u0027s request, thread or connection until the call gives up on its own \u2014 or never, for a client with no default timeout."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/key-value-azure/src/store.rs"},"region":{"startLine":105}}}],"partialFingerprints":{"codehealthFindingId/v1":"590604936301ea95a8c5959c3fe377b352298ed4a1b6ae81c5d0c56e4278b3c7"}},{"ruleId":"P7","level":"warning","message":{"text":"Outbound HTTP without resilience: \u0060reqwest::get(\u0060 makes an outbound HTTP call, and nothing bounds it: no timeout, deadline, retry or circuit breaker is set for it here, and the client has no process-wide default. A slow or failing dependency will hold this service\u0027s request, thread or connection until the call gives up on its own \u2014 or never, for a client with no default timeout."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/loader/src/http.rs"},"region":{"startLine":45}}}],"partialFingerprints":{"codehealthFindingId/v1":"3534bf79121f2a5af99804e4687db3d324d7daec4ed713312b73ccccbc4cb823"}},{"ruleId":"P7","level":"warning","message":{"text":"Outbound HTTP without resilience: \u0060Client::new()\u0060 makes an outbound HTTP call, and nothing bounds it: no timeout, deadline, retry or circuit breaker is set for it here, and the client has no process-wide default. A slow or failing dependency will hold this service\u0027s request, thread or connection until the call gives up on its own \u2014 or never, for a client with no default timeout."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/plugins/src/manager.rs"},"region":{"startLine":225}}}],"partialFingerprints":{"codehealthFindingId/v1":"84776e52dd96207bfbb4fd492fa00d147b207432184742dbb0fce1776f3e58db"}},{"ruleId":"P7","level":"warning","message":{"text":"Outbound HTTP without resilience: \u0060reqwest::Client::builder(\u0060 makes an outbound HTTP call, and nothing bounds it: no timeout, deadline, retry or circuit breaker is set for it here, and the client has no process-wide default. A slow or failing dependency will hold this service\u0027s request, thread or connection until the call gives up on its own \u2014 or never, for a client with no default timeout."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/telemetry/src/lib.rs"},"region":{"startLine":123}}}],"partialFingerprints":{"codehealthFindingId/v1":"07491d33934902268536241466d6141b4fb76ea6eeb9fa9238dda14435802324"}},{"ruleId":"P7","level":"warning","message":{"text":"Outbound HTTP without resilience: \u0060reqwest::get(\u0060 makes an outbound HTTP call, and nothing bounds it: no timeout, deadline, retry or circuit breaker is set for it here, and the client has no process-wide default. A slow or failing dependency will hold this service\u0027s request, thread or connection until the call gives up on its own \u2014 or never, for a client with no default timeout."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/templates/src/source.rs"},"region":{"startLine":229}}}],"partialFingerprints":{"codehealthFindingId/v1":"b848dc921675713d2f2e7f0ba2cfba0e90a3cd6d23e98a2816c3251baed99252"}},{"ruleId":"PF3","level":"warning","message":{"text":"Sync-over-async blocking: \u0060run\u0060 is async and calls block_on \u2014 a blocking call inside async code stalls the executor thread, and every task scheduled on it for as long as it runs."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/commands/watch.rs"},"region":{"startLine":80}}}],"partialFingerprints":{"codehealthFindingId/v1":"09d012a3a8d7ee34c6d0f10e6905d7955c4a004b836a61673257e28de792edd9"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-1059","guid":"a2381a08-60f6-9554-a8b8-f3018cfaaca5","name":"Insufficient Technical Documentation","shortDescription":{"text":"Insufficient Technical Documentation"},"helpUri":"https://cwe.mitre.org/data/definitions/1059.html"},{"id":"CWE-1104","guid":"4c918cb5-b2a6-6c55-9963-a44ee464305e","name":"CWE-1104","shortDescription":{"text":"CWE-1104"},"helpUri":"https://cwe.mitre.org/data/definitions/1104.html"},{"id":"CWE-1329","guid":"f70f1c3f-4ccf-cb5e-bdd3-03ba4868d36d","name":"CWE-1329","shortDescription":{"text":"CWE-1329"},"helpUri":"https://cwe.mitre.org/data/definitions/1329.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-214","guid":"b10ad120-fb22-1351-9348-aa23b453e815","name":"CWE-214","shortDescription":{"text":"CWE-214"},"helpUri":"https://cwe.mitre.org/data/definitions/214.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-522","guid":"71fb233e-ce6a-ae57-9419-ef8373540b09","name":"CWE-522","shortDescription":{"text":"CWE-522"},"helpUri":"https://cwe.mitre.org/data/definitions/522.html"},{"id":"CWE-532","guid":"1cd8877a-76e8-ce54-b40b-779af23364a0","name":"CWE-532","shortDescription":{"text":"CWE-532"},"helpUri":"https://cwe.mitre.org/data/definitions/532.html"},{"id":"CWE-552","guid":"3492436b-eca2-9c54-9ba3-5dade427c903","name":"CWE-552","shortDescription":{"text":"CWE-552"},"helpUri":"https://cwe.mitre.org/data/definitions/552.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-829","guid":"13c33925-97fb-5a5e-b40c-56d328b8a4d7","name":"CWE-829","shortDescription":{"text":"CWE-829"},"helpUri":"https://cwe.mitre.org/data/definitions/829.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":166,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}