{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D10","name":"Test Quality","shortDescription":{"text":"Test Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D10"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}]},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D24","name":"Comment Value","shortDescription":{"text":"Comment Value"},"helpUri":"https://codehealth.canine.dev/dimensions/D24"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}]},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29"},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}]},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}]},{"id":"D39","name":"IL Efficiency","shortDescription":{"text":"IL Efficiency"},"helpUri":"https://codehealth.canine.dev/dimensions/D39"}]}},"results":[{"ruleId":"D12","level":"error","message":{"text":"Vulnerable: Microsoft.NETCore.App: Microsoft.NETCore.App [2.2.0, \u2014 ) severity. 2.2.0"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3da898dbcce723c8ee1dc50d4d7951e2d5a14124438106622ae3d27bb04f52d0"}},{"ruleId":"D12","level":"error","message":{"text":"Vulnerable: AutoMapper: AutoMapper 8.0.0 \u2014 High severity. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7ad907f4096422e42924a00fab6889d83782c07f3031eeb825e84a391fcadb56"}},{"ruleId":"D12","level":"error","message":{"text":"Vulnerable: Microsoft.AspNetCore.App: Microsoft.AspNetCore.App [2.2.0, \u2014 ) severity. 2.2.0"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c72bbe4321fb127d6cc9b85658249b6ee2b3899889a565f12b3f98219478a284"}},{"ruleId":"D12","level":"error","message":{"text":"Vulnerable: Microsoft.AspNetCore.All: Microsoft.AspNetCore.All 2.2.1 \u2014 High severity. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"263291342aa6d88d441414083e1c0184faff4c837e3f1a77caf1e5005224f465"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.NETCore.App: Microsoft.NETCore.App [2.2.0, \u2014 ) 2.2.0 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ce6d813d57adca232bc4212fbef3bebcacfb7b5c70c31743e424855fae79830b"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.EntityFrameworkCore.InMemory: Microsoft.EntityFrameworkCore.InMemory 2.2.2 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5c8592a5050877a3cf5e60c2d6b5859d6f94c26b67b26a9ac3bd28a55143d74e"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.Extensions.Configuration.Json: Microsoft.Extensions.Configuration.Json 2.2.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"62219dced23cdbad1cd1a2f976df020980c7a5cba70dfeeeccddb341c0281026"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.AspNetCore.Http: Microsoft.AspNetCore.Http 2.2.2 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"08189aaceaa0905e7a055035e195e1d15fb24a0cd7c8de3debe4b5d03cc7d0a6"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.Extensions.DependencyInjection: Microsoft.Extensions.DependencyInjection 2.2.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4eaeceb9306993efdfbf1c62712c2a9161c7d7b8c6dae6eb8c525d120feaaaa3"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.AspNetCore.App: Microsoft.AspNetCore.App [2.2.0, \u2014 ) 2.2.0 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4488388874752d49ec788e1f23dca47e12ce753841d5512af81ff430e2f81f15"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.AspNetCore.Razor.Design: Microsoft.AspNetCore.Razor.Design 2.2.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"47bf7b6210ed7a925679131e77c854e544e11e431d162eae8263b75b30842913"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.AspNetCore.All: Microsoft.AspNetCore.All 2.2.1 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"537258430316d772388e9580563407bc241c674c2c0930b917164a0706a59723"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: Microsoft.AspNetCore.TestHost: Microsoft.AspNetCore.TestHost 2.2.0 \u2014 Other,Legacy"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d73c5ce36d903dd473072c63ce4920b196e8ce0de11490d29f232d9f7247eefb"}},{"ruleId":"D16","level":"warning","message":{"text":"single-maintainer \u2014 knowledge-concentration (bus factor) risk: single-maintainer \u2014 knowledge-concentration (bus factor) risk (1 author(s) across 25 commit(s) sampled)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b4b49d961df742f0e507f4cc5c8094fb077ba0391a27fd015d18320865187719"}},{"ruleId":"D18","level":"note","message":{"text":"Thin analysable surface across projects: 1 project(s) carry only a thin slice of real code (e.g. \u0060LivrariaOnline.CrossCutting.IoC\u0060 with 24 significant line(s)). The mean analysable-surface weight is 87 %, lowering Solution Shape by about 1.0 point(s). Consolidate thin projects or grow them into substantial, well-scoped assemblies."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"dd0b92fd965c2065080f16843920964ee00f7696ea03d87cdf61aed4cd2c746a"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found at common paths; consider documenting architectural decisions in Docs/ADL/ or similar."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent spelling of \u0027Author\u0027 and \u0027Between\u0027 in method names. \u0027Autor\u0027 (Portuguese) is used in some places, while \u0027Author\u0027 (English) is used in others. Similarly, \u0027Beetwen\u0027 (typo) is used instead of \u0027Between\u0027.: Standardize to \u0027Author\u0027 and \u0027Between\u0027 (English) or \u0027Autor\u0027 and \u0027Entre\u0027 (Portuguese) consistently across all interfaces, services, and controllers. (symbols: LivraOnline.Domain.Interfaces.Services.IBookService.GetByAutor, LivraOnline.Application.Api.Controllers.BooksController.FindByAutor, LivraOnline.UnitTest.Api.Test.BooksControllerTest.FindByAutorOkResultTest, LivraOnline.Domain.Services.BookService.GetByAuthor, LivraOnline.Domain.Interfaces.Services.IBookService.GetByAuthor, LivraOnline.Domain.Services.BookService.GetByName, LivraOnline.Domain.Interfaces.Services.IBookService.GetByName, LivraOnline.Domain.Services.BookService.GetBeetwenDatePublish, LivraOnline.Domain.Interfaces.Services.IBookService.GetBeetwenDatePublish, LivraOnline.Application.Api.Controllers.BooksController.FindBeetwenDatePublish, LivraOnline.UnitTest.Api.Test.BooksControllerTest.FindBeetwenDatePublishOkResultTest)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ecd3b751f023b1d5531de8076d61ee4f23c8c27e7d652e9699bbf45e208a2be7"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent naming for the author field. The entity uses \u0027Autor\u0027 (Portuguese) while the DTO also uses \u0027Autor\u0027. However, the interface and service methods use \u0027Author\u0027 (English) or \u0027Name\u0027 for books. This creates a mismatch between the domain model and the service/DTO layer.: Align the property name in the Entity and DTO to match the service/interface naming convention (e.g., \u0027Author\u0027 in English or \u0027Autor\u0027 in Portuguese, but be consistent). (symbols: LivraOnline.Domain.Entities.Book.Autor, LivraOnline.Application.Api.Dto.BookDto.Autor)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"848ad1f6d535f036c192822c38165ba8bed7ee297bb256e5105411b1ef38087d"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent naming for price. The entity and DTO use \u0027Preco\u0027 (Portuguese), while the service/DTO might expect \u0027Price\u0027 (English) or \u0027Cost\u0027.: Standardize to \u0027Price\u0027 (English) or \u0027Preco\u0027 (Portuguese) consistently across all layers. (symbols: LivraOnline.Domain.Entities.Book.Preco, LivraOnline.Application.Api.Dto.BookDto.Preco)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"62d4199afc2d6e8e9d2454a89aa50b47f8f2928e1dac765b1188f2f75960e452"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent naming for publication date. The entity and DTO use \u0027DataPublicacao\u0027 (Portuguese), while the service/DTO might expect \u0027PublicationDate\u0027 (English).: Standardize to \u0027PublicationDate\u0027 (English) or \u0027DataPublicacao\u0027 (Portuguese) consistently across all layers. (symbols: LivraOnline.Domain.Entities.Book.DataPublicacao, LivraOnline.Application.Api.Dto.BookDto.DataPublicacao)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9dae4ef089c98a1ca5943d374c61ebd9ffd9aebefaf001b76b708ccd82a57e83"}},{"ruleId":"D24","level":"note","message":{"text":"redundant comment: \u0022.NET Native DI Abstraction\u0022 \u2014 delete - .NET Native is self-describing; the DI abstraction is clear from context"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"LivrariaOnline.Application.Api/Startup.cs"},"region":{"startLine":49}}}],"partialFingerprints":{"codehealthFindingId/v1":"5fd2aed7d19b41bd189fa798952af159e9161daec5d81ffe1db4c9f97a976936"}},{"ruleId":"D30","level":"error","message":{"text":"Critical CVE: System.Text.Encodings.Web 4.5.0: System.Text.Encodings.Web 4.5.0 (transitive) has a Critical advisory; affects 3 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"4e4448b31e8b4dd1a6489e264df38146de5afb770ee8e6556d999f07ae5800a8"}},{"ruleId":"D30","level":"error","message":{"text":"Critical CVE: Microsoft.AspNetCore.Server.Kestrel.Core 2.2.0: Microsoft.AspNetCore.Server.Kestrel.Core 2.2.0 (transitive) has a Critical advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"2fe60fcb09eccc26e5cb0c177fdabda6530875735b9f9591b677a79c942329d0"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: Microsoft.NETCore.App 2.2.0: Microsoft.NETCore.App 2.2.0 (direct) has a High advisory; affects 5 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5d82183a7311d26cb18869e138756268f6e06d462d3cbe1716583e725c61ec33"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: Microsoft.NETCore.App 2.2.0: Microsoft.NETCore.App 2.2.0 (direct) has a High advisory; affects 5 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5d82183a7311d26cb18869e138756268f6e06d462d3cbe1716583e725c61ec33"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: Newtonsoft.Json 11.0.2: Newtonsoft.Json 11.0.2 (transitive) has a High advisory; affects 4 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"58c61fd9b239c2505b291f9f0b42d311bc1fbae0ccfea9c8d6841fe9eba0ba49"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: AutoMapper 8.0.0: AutoMapper 8.0.0 (direct) has a High advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"322c04cc567fb823f253ebbb1c3ecb268a3cdc1f4d3819b255de20dc60397240"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: Microsoft.AspNetCore.App 2.2.0: Microsoft.AspNetCore.App 2.2.0 (direct) has a High advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"cf4c113eb288d39ee0c714e02d25d38147b0593df44e326d84a382302eed0a5d"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: Microsoft.AspNetCore.WebSockets 2.2.0: Microsoft.AspNetCore.WebSockets 2.2.0 (transitive) has a High advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9d805d44706f4fb5e01d1092c618ec845971c926ab6804be743839620ec95d1e"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: System.Data.SqlClient 4.6.0: System.Data.SqlClient 4.6.0 (transitive) has a High advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7a6deedcb6c36796a5b05c938981286d69e7f00ecdcce470f079f0282aa3b932"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: System.Net.Http 4.3.0: System.Net.Http 4.3.0 (transitive) has a High advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7cf85abffe732f2645ef95a624d6badc26f0263616284d6a4cc46ca8e983031d"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: System.Net.WebSockets.WebSocketProtocol 4.5.1: System.Net.WebSockets.WebSocketProtocol 4.5.1 (transitive) has a High advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6df3bf96c71d594dea329a64033fb3bc8969b3a50731a3a52bfaf748402b714e"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: System.Text.RegularExpressions 4.3.0: System.Text.RegularExpressions 4.3.0 (transitive) has a High advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b96b7173c4377d5bea4d6fd7b52323631c631c44172b743bec6f266c10a4e538"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: Microsoft.AspNetCore.All 2.2.1: Microsoft.AspNetCore.All 2.2.1 (direct) has a High advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f5015a636dd4ade8cbe2f6759f59c1023015c1201138e5df4af1939c690d0b71"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: MessagePack 1.7.3.4: MessagePack 1.7.3.4 (transitive) has a High advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1978c2767d212f654b2f64e03ec1f5635d06fcb005908efc0af4a811d68ba018"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: MessagePack 1.7.3.4: MessagePack 1.7.3.4 (transitive) has a High advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1978c2767d212f654b2f64e03ec1f5635d06fcb005908efc0af4a811d68ba018"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: Microsoft.AspNetCore.DataProtection.AzureStorage 2.2.0: Microsoft.AspNetCore.DataProtection.AzureStorage 2.2.0 (transitive) has a High advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"dfab8e0630f9043f2b2794de583069681867d10783e19c8c2b0c574cb806e33a"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: Microsoft.Data.OData 5.8.2: Microsoft.Data.OData 5.8.2 (transitive) has a High advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ec59fcb7a7059c4454a12f76a80a3c4dbfc9b9c71ed646014f600b3de94fd326"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: System.Net.Security 4.3.0: System.Net.Security 4.3.0 (transitive) has a High advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a86a12e3ccc1a17ddeefad88737edd27af0c1c4aa8efb5ef67df9bb7408654e3"}},{"ruleId":"D30","level":"error","message":{"text":"High CVE: System.Net.Security 4.3.0: System.Net.Security 4.3.0 (transitive) has a High advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a86a12e3ccc1a17ddeefad88737edd27af0c1c4aa8efb5ef67df9bb7408654e3"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: Microsoft.NETCore.App 2.2.0: Microsoft.NETCore.App 2.2.0 (direct) has a Medium advisory; affects 5 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0f59799bebe7ec015a274fd57703fda1a1ed6548c9307cbc5d281ab6e8e2ad91"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: Microsoft.AspNetCore.App 2.2.0: Microsoft.AspNetCore.App 2.2.0 (direct) has a Medium advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"221b41b2222ca064bdc17c24798240a7db688459ab3b7b2c9028aae096ce0085"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: Microsoft.AspNetCore.Server.HttpSys 2.2.0: Microsoft.AspNetCore.Server.HttpSys 2.2.0 (transitive) has a Medium advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"77697df5285a68b770e67a0507172de281b4e5b4e7d7b111e9351692474f9d62"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: Microsoft.AspNetCore.Server.IIS 2.2.0: Microsoft.AspNetCore.Server.IIS 2.2.0 (transitive) has a Medium advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b3c6c9e44f8b1b18670924e0d491aa4ac3c3285cc878ec61e4c1c236907d9b54"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: Microsoft.AspNetCore.SpaServices 2.2.0: Microsoft.AspNetCore.SpaServices 2.2.0 (transitive) has a Medium advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e43e7cabcefdd43f2ae865d029b7d7c4aadb428e3a61c970b0c665baf9cb07d7"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: Microsoft.IdentityModel.JsonWebTokens 5.3.0: Microsoft.IdentityModel.JsonWebTokens 5.3.0 (transitive) has a Medium advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"34a896eafb37e6adeb5946a6f685b0a9872817066e72ab5e8137341beac28830"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: System.Data.SqlClient 4.6.0: System.Data.SqlClient 4.6.0 (transitive) has a Medium advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"8d8c278def19a8f6336b906458fc4f81a91e298b69fa7e731683dc5e4e434d0f"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: System.IdentityModel.Tokens.Jwt 5.3.0: System.IdentityModel.Tokens.Jwt 5.3.0 (transitive) has a Medium advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"480166d4c2f8276af16c3234e7730fb32452e33b00e62210d0f5aad1ab292e2a"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: System.Security.Cryptography.Xml 4.5.0: System.Security.Cryptography.Xml 4.5.0 (transitive) has a Medium advisory; affects 2 projects \u2014 one upgrade fixes all. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"980f2166c13e3dcf8a85cee8e9f96b57957e94fb1607ef95391355b34cc8becf"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: Microsoft.AspNetCore.All 2.2.1: Microsoft.AspNetCore.All 2.2.1 (direct) has a Medium advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"631f1299d31635b63354f47602683aaca2f479a5cd9681da24ea5bb63fde8912"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: MessagePack 1.7.3.4: MessagePack 1.7.3.4 (transitive) has a Medium advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c2e442c7714f9bceb9ff13411c9f8dbc8d5f14682b7ba23b3c69cd716e5919da"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: MessagePack 1.7.3.4: MessagePack 1.7.3.4 (transitive) has a Medium advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c2e442c7714f9bceb9ff13411c9f8dbc8d5f14682b7ba23b3c69cd716e5919da"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: MessagePack 1.7.3.4: MessagePack 1.7.3.4 (transitive) has a Medium advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c2e442c7714f9bceb9ff13411c9f8dbc8d5f14682b7ba23b3c69cd716e5919da"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: MessagePack 1.7.3.4: MessagePack 1.7.3.4 (transitive) has a Medium advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c2e442c7714f9bceb9ff13411c9f8dbc8d5f14682b7ba23b3c69cd716e5919da"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: MessagePack 1.7.3.4: MessagePack 1.7.3.4 (transitive) has a Medium advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c2e442c7714f9bceb9ff13411c9f8dbc8d5f14682b7ba23b3c69cd716e5919da"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: MessagePack 1.7.3.4: MessagePack 1.7.3.4 (transitive) has a Medium advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c2e442c7714f9bceb9ff13411c9f8dbc8d5f14682b7ba23b3c69cd716e5919da"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: MessagePack 1.7.3.4: MessagePack 1.7.3.4 (transitive) has a Medium advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c2e442c7714f9bceb9ff13411c9f8dbc8d5f14682b7ba23b3c69cd716e5919da"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: MessagePack 1.7.3.4: MessagePack 1.7.3.4 (transitive) has a Medium advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c2e442c7714f9bceb9ff13411c9f8dbc8d5f14682b7ba23b3c69cd716e5919da"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: MessagePack 1.7.3.4: MessagePack 1.7.3.4 (transitive) has a Medium advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c2e442c7714f9bceb9ff13411c9f8dbc8d5f14682b7ba23b3c69cd716e5919da"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: MessagePack 1.7.3.4: MessagePack 1.7.3.4 (transitive) has a Medium advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c2e442c7714f9bceb9ff13411c9f8dbc8d5f14682b7ba23b3c69cd716e5919da"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: MessagePack 1.7.3.4: MessagePack 1.7.3.4 (transitive) has a Medium advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"c2e442c7714f9bceb9ff13411c9f8dbc8d5f14682b7ba23b3c69cd716e5919da"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: Microsoft.AspNetCore.Server.IIS 2.2.1: Microsoft.AspNetCore.Server.IIS 2.2.1 (transitive) has a Medium advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6f1b2a25650c1c8350d13cc6be884a97c4739975c069cdacba0897d0eb138440"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: Microsoft.Rest.ClientRuntime 2.3.8: Microsoft.Rest.ClientRuntime 2.3.8 (transitive) has a Medium advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7cc499c39633284b9d6eb8ed273907eb2ce6df1802b39aa40b012f34bd085546"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: System.Net.Security 4.3.0: System.Net.Security 4.3.0 (transitive) has a Medium advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d69e36ae6df9b389658f765645f6c9a60b575341ba4893073a576a8bdff0c230"}},{"ruleId":"D30","level":"warning","message":{"text":"Medium CVE: System.Net.Security 4.3.0: System.Net.Security 4.3.0 (transitive) has a Medium advisory. https://github.com/advisories/[GHSA redacted]"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d69e36ae6df9b389658f765645f6c9a60b575341ba4893073a576a8bdff0c230"}},{"ruleId":"D36","level":"note","message":{"text":"No build provenance: No SLSA provenance generation or build attestation found in CI (e.g. slsa-github-generator, actions/attest-build-provenance)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"1b213f6eedd4b140d0bc37bdf1496f72811a643f34064f12518b32e9e83bcfc7"}},{"ruleId":"D36","level":"note","message":{"text":"No artifact signing: No artifact signing found in CI (e.g. cosign / sigstore / gitsign)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0e17f71490e4d120a48b2b2881ab866c93b272bef2febb673a3e8e42b2c288ab"}},{"ruleId":"D36","level":"note","message":{"text":"No SBOM: No SBOM generation or committed SBOM found (e.g. syft / anchore/sbom-action / *.spdx.json / *.cdx.json)."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"eb00976a698a5d68999b7ee6d27206fd374e916853e7ff1ead5eed42386f043f"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1357","name":"Reliance on Insufficiently Trustworthy Component"},{"id":"CWE-1395","name":"Dependency on Vulnerable Third-Party Component"},{"id":"CWE-798","name":"Use of Hard-coded Credentials"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":0,"secretScannerRunsExcluded":0}}}]}