{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D11","name":"Test Reliability","shortDescription":{"text":"Test Reliability"},"helpUri":"https://codehealth.canine.dev/dimensions/D11"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D24","name":"Comment Value","shortDescription":{"text":"Comment Value"},"helpUri":"https://codehealth.canine.dev/dimensions/D24"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D39","name":"IL Efficiency","shortDescription":{"text":"IL Efficiency"},"helpUri":"https://codehealth.canine.dev/dimensions/D39"},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AX5","name":"Architecture \u0026 structure","shortDescription":{"text":"Architecture \u0026 structure"},"helpUri":"https://codehealth.canine.dev/dimensions/AX5"},{"id":"AX8","name":"Test isolation","shortDescription":{"text":"Test isolation"},"helpUri":"https://codehealth.canine.dev/dimensions/AX8"},{"id":"AXB1","name":"Runtime evidence locked \u2014 no reproducible boot","shortDescription":{"text":"Runtime evidence locked \u2014 no reproducible boot"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB1"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"ED5","name":"Idempotency","shortDescription":{"text":"Idempotency"},"helpUri":"https://codehealth.canine.dev/dimensions/ED5"},{"id":"GD1","name":"Unfinished \u0026 placeholder code","shortDescription":{"text":"Unfinished \u0026 placeholder code"},"helpUri":"https://codehealth.canine.dev/dimensions/GD1"},{"id":"IC1","name":"Incompleteness \u0026 stubs","shortDescription":{"text":"Incompleteness \u0026 stubs"},"helpUri":"https://codehealth.canine.dev/dimensions/IC1"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P10","name":"Library API \u0026 versioning","shortDescription":{"text":"Library API \u0026 versioning"},"helpUri":"https://codehealth.canine.dev/dimensions/P10"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"PF1","name":"Benchmark discipline","shortDescription":{"text":"Benchmark discipline"},"helpUri":"https://codehealth.canine.dev/dimensions/PF1"},{"id":"PF2","name":"Allocation hygiene","shortDescription":{"text":"Allocation hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/PF2"},{"id":"PF3","name":"Async \u0026 latency hygiene","shortDescription":{"text":"Async \u0026 latency hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/PF3"},{"id":"SC1","name":"Supply-chain hygiene","shortDescription":{"text":"Supply-chain hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/SC1"},{"id":"X1","name":"Async correctness","shortDescription":{"text":"Async correctness"},"helpUri":"https://codehealth.canine.dev/dimensions/X1"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X12","name":"Unreachable branch","shortDescription":{"text":"Unreachable branch"},"helpUri":"https://codehealth.canine.dev/dimensions/X12"},{"id":"X13","name":"Undrained process stream","shortDescription":{"text":"Undrained process stream"},"helpUri":"https://codehealth.canine.dev/dimensions/X13"},{"id":"X14","name":"Bypassable address classification","shortDescription":{"text":"Bypassable address classification"},"helpUri":"https://codehealth.canine.dev/dimensions/X14"},{"id":"X15","name":"Unvalidated length from an untrusted reader","shortDescription":{"text":"Unvalidated length from an untrusted reader"},"helpUri":"https://codehealth.canine.dev/dimensions/X15"},{"id":"X16","name":"Unfloored truncation loop","shortDescription":{"text":"Unfloored truncation loop"},"helpUri":"https://codehealth.canine.dev/dimensions/X16"},{"id":"X17","name":"Uncapped recursion over a caller-supplied document","shortDescription":{"text":"Uncapped recursion over a caller-supplied document"},"helpUri":"https://codehealth.canine.dev/dimensions/X17"},{"id":"X18","name":"Disposal-pattern correctness","shortDescription":{"text":"Disposal-pattern correctness"},"helpUri":"https://codehealth.canine.dev/dimensions/X18"},{"id":"X19","name":"Unrestored process-global state","shortDescription":{"text":"Unrestored process-global state"},"helpUri":"https://codehealth.canine.dev/dimensions/X19"},{"id":"X20","name":"Mistyped argument guard","shortDescription":{"text":"Mistyped argument guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X20"},{"id":"X21","name":"Side-effecting pattern guard","shortDescription":{"text":"Side-effecting pattern guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X21"},{"id":"X22","name":"Contradicted release guard","shortDescription":{"text":"Contradicted release guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X22"},{"id":"X23","name":"Unguarded diagnostic materialisation","shortDescription":{"text":"Unguarded diagnostic materialisation"},"helpUri":"https://codehealth.canine.dev/dimensions/X23"},{"id":"X24","name":"Document value interpolated into markup unescaped","shortDescription":{"text":"Document value interpolated into markup unescaped"},"helpUri":"https://codehealth.canine.dev/dimensions/X24"},{"id":"X25","name":"Inert configuration knob","shortDescription":{"text":"Inert configuration knob"},"helpUri":"https://codehealth.canine.dev/dimensions/X25"},{"id":"X26","name":"Unsynchronised callback handoff","shortDescription":{"text":"Unsynchronised callback handoff"},"helpUri":"https://codehealth.canine.dev/dimensions/X26"},{"id":"X27","name":"Collection changed while being enumerated","shortDescription":{"text":"Collection changed while being enumerated"},"helpUri":"https://codehealth.canine.dev/dimensions/X27"},{"id":"X28","name":"Index access outside its own emptiness guard","shortDescription":{"text":"Index access outside its own emptiness guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X28"},{"id":"X29","name":"Per-element action decided by a fixed element","shortDescription":{"text":"Per-element action decided by a fixed element"},"helpUri":"https://codehealth.canine.dev/dimensions/X29"},{"id":"X3","name":"Exception handling","shortDescription":{"text":"Exception handling"},"helpUri":"https://codehealth.canine.dev/dimensions/X3"},{"id":"X30","name":"Support guard that admits what it rejects","shortDescription":{"text":"Support guard that admits what it rejects"},"helpUri":"https://codehealth.canine.dev/dimensions/X30"},{"id":"X32","name":"Type resolved by simple name across every loaded assembly","shortDescription":{"text":"Type resolved by simple name across every loaded assembly"},"helpUri":"https://codehealth.canine.dev/dimensions/X32"},{"id":"X4","name":"Structured logging","shortDescription":{"text":"Structured logging"},"helpUri":"https://codehealth.canine.dev/dimensions/X4"},{"id":"X5","name":"Nullable reference types","shortDescription":{"text":"Nullable reference types"},"helpUri":"https://codehealth.canine.dev/dimensions/X5"},{"id":"X6","name":"Hand-rolled structured-format parsing","shortDescription":{"text":"Hand-rolled structured-format parsing"},"helpUri":"https://codehealth.canine.dev/dimensions/X6"},{"id":"X7","name":"Silent fallback defaults","shortDescription":{"text":"Silent fallback defaults"},"helpUri":"https://codehealth.canine.dev/dimensions/X7"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): src/App/Program.fs:117-130 | src/App/Program.fs:168-181 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/App/Program.fs"},"region":{"startLine":117}}}],"partialFingerprints":{"codehealthFindingId/v1":"97011513fb90c3f66fded4130b8fbab031a024951d2d1e9c0348122cbc9292cf"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 16): src/Checksums/ripemd160.cs:279-288 | src/Checksums/ripemd160.cs:290-298 | src/Checksums/ripemd160.cs:300-308 | src/Checksums/ripemd160.cs:310-318 | src/Checksums/ripemd160.cs:320-328 | src/Checksums/ripemd160.cs:330-338 | src/Checksums/ripemd160.cs:340-348 | src/Checksums/ripemd160.cs:350-358 | src/Checksums/ripemd160.cs:846-855 | src/Checksums/ripemd160.cs:857-865 | src/Checksums/ripemd160.cs:867-875 | src/Checksums/ripemd160.cs:877-885 | src/Checksums/ripemd160.cs:887-895 | src/Checksums/ripemd160.cs:897-905 | src/Checksums/ripemd160.cs:907-915 | src/Checksums/ripemd160.cs:917-925 \u2014 all 16 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":279}}}],"partialFingerprints":{"codehealthFindingId/v1":"3ada02024cce561ec3d03e2d9421b568103afe2ed077d7ff80937912459e2ace"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 16): src/Checksums/ripemd160.cs:360-369 | src/Checksums/ripemd160.cs:371-379 | src/Checksums/ripemd160.cs:381-389 | src/Checksums/ripemd160.cs:391-399 | src/Checksums/ripemd160.cs:401-409 | src/Checksums/ripemd160.cs:411-419 | src/Checksums/ripemd160.cs:421-429 | src/Checksums/ripemd160.cs:431-439 | src/Checksums/ripemd160.cs:765-774 | src/Checksums/ripemd160.cs:776-784 | src/Checksums/ripemd160.cs:786-794 | src/Checksums/ripemd160.cs:796-804 | src/Checksums/ripemd160.cs:806-814 | src/Checksums/ripemd160.cs:816-824 | src/Checksums/ripemd160.cs:826-834 | src/Checksums/ripemd160.cs:836-844 \u2014 all 16 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":360}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7e3df7d5d689a1455e94fb412fbef02f19b4563a6a62b1d0979881e4983938f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 16): src/Checksums/ripemd160.cs:441-450 | src/Checksums/ripemd160.cs:452-460 | src/Checksums/ripemd160.cs:462-470 | src/Checksums/ripemd160.cs:472-480 | src/Checksums/ripemd160.cs:482-490 | src/Checksums/ripemd160.cs:492-500 | src/Checksums/ripemd160.cs:502-510 | src/Checksums/ripemd160.cs:512-520 | src/Checksums/ripemd160.cs:684-693 | src/Checksums/ripemd160.cs:695-703 | src/Checksums/ripemd160.cs:705-713 | src/Checksums/ripemd160.cs:715-723 | src/Checksums/ripemd160.cs:725-733 | src/Checksums/ripemd160.cs:735-743 | src/Checksums/ripemd160.cs:745-753 | src/Checksums/ripemd160.cs:755-763 \u2014 all 16 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":441}}}],"partialFingerprints":{"codehealthFindingId/v1":"57a0dd22c5e8376e7a49db9a2797b11ee48468fb30bc5cbb637aad5bfaa5fe3e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 16): src/Checksums/ripemd160.cs:522-531 | src/Checksums/ripemd160.cs:533-541 | src/Checksums/ripemd160.cs:543-551 | src/Checksums/ripemd160.cs:553-561 | src/Checksums/ripemd160.cs:563-571 | src/Checksums/ripemd160.cs:573-581 | src/Checksums/ripemd160.cs:583-591 | src/Checksums/ripemd160.cs:593-601 | src/Checksums/ripemd160.cs:603-612 | src/Checksums/ripemd160.cs:614-622 | src/Checksums/ripemd160.cs:624-632 | src/Checksums/ripemd160.cs:634-642 | src/Checksums/ripemd160.cs:644-652 | src/Checksums/ripemd160.cs:654-662 | src/Checksums/ripemd160.cs:664-672 | src/Checksums/ripemd160.cs:674-682 \u2014 all 16 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":522}}}],"partialFingerprints":{"codehealthFindingId/v1":"dfb40f830d11ac5311d38f625c7656599658285abc025ed852c09c62de855e78"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 8): src/Checksums/ripemd160.cs:191-207 | src/Checksums/ripemd160.cs:209-217 | src/Checksums/ripemd160.cs:219-227 | src/Checksums/ripemd160.cs:229-237 | src/Checksums/ripemd160.cs:239-247 | src/Checksums/ripemd160.cs:249-257 | src/Checksums/ripemd160.cs:259-267 | src/Checksums/ripemd160.cs:269-277 \u2014 all 8 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":191}}}],"partialFingerprints":{"codehealthFindingId/v1":"f24cde3546766b42d1c11623bdc20b554d8f5b65cffd856247793f80cd6a2a64"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 8): src/Checksums/ripemd160.cs:927-936 | src/Checksums/ripemd160.cs:938-946 | src/Checksums/ripemd160.cs:948-956 | src/Checksums/ripemd160.cs:958-966 | src/Checksums/ripemd160.cs:968-976 | src/Checksums/ripemd160.cs:978-986 | src/Checksums/ripemd160.cs:988-996 | src/Checksums/ripemd160.cs:998-1006 \u2014 all 8 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":927}}}],"partialFingerprints":{"codehealthFindingId/v1":"afe4be874eafa591b4d4aca222ab831593bacce2f0b8fec97a73b1fc8ac6e11f"}},{"ruleId":"D8","level":"warning","message":{"text":"No test project references Checksums: No test project in this repository references Checksums (1 production source file(s)), so \u0060dotnet test\u0060 never loads it and no coverage tool can measure it \u2014 its code is absent from the 89.4% above rather than counted at zero. This is the whole assembly, not a gap within one: add a test project that references it (or a ProjectReference from an existing suite) and its coverage starts being measured."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/Checksums.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"37711c3d73548587839cbadeb5101435d6ad5004d3b8e9bd749c7ce125bdb720"}},{"ruleId":"D12","level":"warning","message":{"text":"Deprecated: xunit: xunit 2.9.3 \u2014 Legacy \u2014 the publisher\u0027s replacement is \u0060xunit.v3\u0060; that is the next major line under a new package id, so the move is a breaking rename rather than a version bump \u2014 budget for API changes in the code that uses it, not only the reference swap."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d37c8c0e8046c9e8358e976373216abfb78e9fdef63ed53d3edcaa7d2238edcd"}},{"ruleId":"D12","level":"warning","message":{"text":"Prerelease dependency: System.CommandLine: System.CommandLine resolves to 2.0.0-beta4.22272.1, a prerelease build. Prerelease packages carry no support policy, may change breaking between previews and can be unlisted \u2014 pin a stable release before shipping, or record the reason this preview is required."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"143d8e30f82a6359cbf400529b8e1c9bc711ab856997abfdea491a7c9f9e009e"}},{"ruleId":"D12","level":"warning","message":{"text":"Prerelease dependency: Glob: Glob resolves to 1.2.0-alpha0037, a prerelease build. Prerelease packages carry no support policy, may change breaking between previews and can be unlisted \u2014 pin a stable release before shipping, or record the reason this preview is required."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"5cfa79da22b30c0374eefa8c4a60fd937e652aed4dc0dc94acb61c487e74eb84"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found. No recognised ADR directory (\u0060docs/adr/\u0060, \u0060docs/decisions/\u0060, \u0060adr/\u0060, \u0060docs/rfcs/\u0060, an \u0060ADR0001/\u0060 folder, or their siblings) exists anywhere in this tree. What was searched, so you can tell an empty log from a search that missed one: every directory under the tree (build output, dependencies and VCS metadata excepted), for a document that is either any non-index page inside a recognised ADR directory, whatever its name and however deeply nested (\u0060docs/adr/use-postgres.md\u0060, \u0060docs/adr/2024/0001-x.md\u0060); or a file anywhere whose name is ADR-shaped (\u00600001-use-postgres.md\u0060, \u0060adr-012-caching.md\u0060); or, when neither turned anything up, a document carrying the decision-record signature (an \u0022Architecture Decision Record\u0022 heading, or Status / Context / Decision / Consequences as section headings). A decision log that clears none of these \u2014 unnumbered files outside any recognised directory, without those headings \u2014 is not seen by this check and this row is then wrong. If that is your case, say so rather than renaming anything; otherwise, consider recording architectural decisions in \u0060docs/adr/\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D24","level":"note","message":{"text":"redundant comment: \u0022public constructors\u0022 \u2014 delete - comment restates public RIPEMD160()"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":15}}}],"partialFingerprints":{"codehealthFindingId/v1":"c7b9a37f771aa020fd0e3d51c49bb51aa4994caee5025a291f6d62442f7dfa36"}},{"ruleId":"D24","level":"note","message":{"text":"misleading comment: \u0022Update the state of the hash object\u0022 \u2014 fix - the comment restates a line that adds nothing; it is not clear why this line updates the hash state rather than some unrelated value"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":1010}}}],"partialFingerprints":{"codehealthFindingId/v1":"8216896f51d53d8bed7683210fa769d4cebde9515eb216028b94d5e6ff445855"}},{"ruleId":"D24","level":"note","message":{"text":"redundant comment: \u0022Update the state of the hash object\u0022 \u2014 delete - restates the line; only add value if it notes why this assignment matters, which it does not"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":1010}}}],"partialFingerprints":{"codehealthFindingId/v1":"aee360fef5a7e0f450f451feb158f6cbd19ad2d2aa79bc2ca576b4bd044b2b8e"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9603565aa6069e0abcf535dcde33980e7f55a15fa6af1c7abedeeffe7f52bf08"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"aa8ee490371acdad2b62b958843583a0e94f30a79a22194bc3bc46d8eab253e9"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1ebfc6454926adc8bcdd9a383a1f7e392ddea375507c6f03377190653a98f9ce"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1860570359a470af836045ccde59aa139484b5636e06db9e68f8d1e72788a7a8"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b53edd3ffe456b3414ec4b73ab23cd56cbd460b29f570e5a953862fea809eaa3"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4b226188d1dc251c1add7fde7ae49fe525cf2b72a590704a7f29503b40ddb8d6"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0a8e60466bba6b96003bcd026906fff4235bf3f201cc44735671edd3b31a95ba"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"80c00f2049416bab719ec0cacc6dac6196fa5ea661ed186021d40153c3d40861"},"taxa":[{"id":"CWE-214","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-532","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b21ef51d97f04d1a8b921e635aca9ef4e877341aa2c3b0f6eaeabc61234774b6"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e5e03fba904e79b7b1d4565350973aeb74376fa92f220e40cf985cc8ebb59eb"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"63c4a093cd4d8270d8663d7b47af1062c73ee032c2d6873d217251d788ab2402"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6504d8d1633fd2629c17cb911821ef9d4b240f323d5e1ebac2df01ac4726a04a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fdc133beeee66a9f12363c597e9def89558e6d7da081a0ccfb4fe21c529a678e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1de4e8df69f8ea88743a72dc79ebdff0df14ccb12667fe14ae5c33266501ddc5"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5a0307a0e95589e470722eaa1f6edefde899ff9d045423b92eaede73ef396b02"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"59bdb5a1e8e9e2536fc49c741fcb4259a61a8678fc811d3adeb596662203897f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f96de53a9c41aa9762bf4bb7d8c6ceb5328ca215e45d4016e18c2ff1458e371c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b923d2a6d4bf9f3d17a069114b8d29dce8e6bc49ce4ae2931de0efd9a515de40"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a5ca04c0cb1b89928781b2af4d0cbb058a385aeba0b5535a0878e046c51b41cf"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d659c6e92a7152c126c6f4f0fc9ba5fe47371839fd50fc47de98d04bb26be48f"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fc8e3260a6c033ace48052bc5585a8cc2936d0b5587266777a503e1a6fae5cac"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1b213f6eedd4b140d0bc37bdf1496f72811a643f34064f12518b32e9e83bcfc7"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e17f71490e4d120a48b2b2881ab866c93b272bef2febb673a3e8e42b2c288ab"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eb00976a698a5d68999b7ee6d27206fd374e916853e7ff1ead5eed42386f043f"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"90f83b4fa27db32740afe9540c905f3c0499caed87f61049a8a903ecc95b41c3"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9658270ba49f37ed04e99ab1263b6393cd42aed8bdfb7aafd9fa1070f5491895"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d657599f6f99da1927d3377533dfc0888b34c4d84aa7d5579841fd72d0e39bce"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ace515990e7ee0f17b5c17e44dd168a5bdecf90804a3a3dd845cf05540978013"}},{"ruleId":"D39","level":"note","message":{"text":"IL efficiency: 1 authored method(s) exceed the IL budget: 1 of 16 first-party methods compile to oversized IL bodies (\u003E 250 instructions); worst: Checksums.RIPEMD160.MDTransform, 5579 IL instructions; that pulled this dimension to 8.8/10. These bodies are far past the JIT\u0027s inline budget, so splitting them does not make them inlinable \u2014 what moves the number is emitting less: collapsing LINQ chains and closures on hot paths, and interpolation built eagerly where it is only sometimes used."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b8a2ecf2c4d5b528386cb5fab72f2bbcf8c3894e1825a41ec84505f1f182e292"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":29}}}],"partialFingerprints":{"codehealthFindingId/v1":"3b6376c1c436f6f4b4f2c494b456166c6be7c825c3864a20e48eade31f3d57c0"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":108}}}],"partialFingerprints":{"codehealthFindingId/v1":"438b30505b40baa2fbae69c6461b5daa0c8713dd6873f736407551e521e85493"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":119}}}],"partialFingerprints":{"codehealthFindingId/v1":"4cfaae00acac422762cdf3857e35aa76a62cac3451cc88935c5f93ac7b8530c3"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":128}}}],"partialFingerprints":{"codehealthFindingId/v1":"65ba6bbef2a798ff0cbe16c9b663b06de598956840c30d9d41e2c7bb2f3409a7"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":201}}}],"partialFingerprints":{"codehealthFindingId/v1":"61a8d310143beffd216b771aa257a25d36d0690f081a4b51a21b760c7fcc535a"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":206}}}],"partialFingerprints":{"codehealthFindingId/v1":"d639d06b9aadc838d0d6903e6c3b4c23a67fa96d7fbffe347bc99483028f32c2"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":211}}}],"partialFingerprints":{"codehealthFindingId/v1":"05d46535e70ba05569d843b278360dd595c17e7a97ae0ce99e10246b03e9611d"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":216}}}],"partialFingerprints":{"codehealthFindingId/v1":"dbd5fcfd502659d81bbbd58a81e22391f9f5514d743cab4cf575174891291e4e"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":221}}}],"partialFingerprints":{"codehealthFindingId/v1":"47134218686ad17c1b2ba625ae02b46852231be872823e12914ad85c2ee0c338"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":226}}}],"partialFingerprints":{"codehealthFindingId/v1":"31f8782c5fd3163b20336494c609c66c74ffb367f9249ad21d5e9b4e1ccc5e1e"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":231}}}],"partialFingerprints":{"codehealthFindingId/v1":"e7e9a8ed9926e17ffed7ed829d87aeb6929c8c1b83dddbd6ccd96b7764d97934"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":236}}}],"partialFingerprints":{"codehealthFindingId/v1":"b16a6710c81975441ac7218ddcc8edf491328da0eb4f57d0cf07e1ce760898f0"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":241}}}],"partialFingerprints":{"codehealthFindingId/v1":"2511e9db9bfda6339288568d10787daee38b627c825d9916bd0a96c2884b76aa"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":246}}}],"partialFingerprints":{"codehealthFindingId/v1":"04263eca29d35c5e841ad414573902048fd6fb3ca6d8e63ded37103feb682014"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":251}}}],"partialFingerprints":{"codehealthFindingId/v1":"5af77e7fa37dbbf80d756df22fdd5e5dfd1569f186562099dac05cc6a34e45b3"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":256}}}],"partialFingerprints":{"codehealthFindingId/v1":"e5400b6a74a50bb5a6301e625b24bc622b327edb39925200d3a91acd36767800"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":261}}}],"partialFingerprints":{"codehealthFindingId/v1":"886e0b122f501a23c8cc8d1eec23b3d423d876ee14b778af2c5ecd41ca6ec963"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":266}}}],"partialFingerprints":{"codehealthFindingId/v1":"2a65f7d08fa77f93d0c38897049ee2b9100ce790377f9989b897a7be27432131"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":271}}}],"partialFingerprints":{"codehealthFindingId/v1":"332413bb9d97a1fbe1e8dd28007c4033aa17c19755f369cde19d00fffad35571"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":276}}}],"partialFingerprints":{"codehealthFindingId/v1":"2c6543742571a2d1b6658e89e977eee7b3c132215cc886be2b7367f4d4c8b3f4"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":282}}}],"partialFingerprints":{"codehealthFindingId/v1":"daf82023cfe724f32d5a9b4ffb172ed8445a8ab95f8c86a88f2b2d7de3ecf087"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":287}}}],"partialFingerprints":{"codehealthFindingId/v1":"25b9fc0f19804dea3e0c7a4f82059e75137509e426f7c30926f21373f1718114"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":292}}}],"partialFingerprints":{"codehealthFindingId/v1":"6ca205d3dbf13f728ceab35a926cffada5329be186f37a347d13b19d4f4bf42e"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":297}}}],"partialFingerprints":{"codehealthFindingId/v1":"83fe4ff24440a15d90340b429f833e2bd954e4ce9d8b16b8017a3af69b164c2c"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":302}}}],"partialFingerprints":{"codehealthFindingId/v1":"ee7f743e8f362e11e78731de5eb892828a1c9c3d9fb5c283c4bad1a330084c65"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":307}}}],"partialFingerprints":{"codehealthFindingId/v1":"a7c76656c1c4bb717cb4cf3dd46b6b854b5aa8ae857631abfca6179da7bee92f"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":312}}}],"partialFingerprints":{"codehealthFindingId/v1":"5068822d389c3057762359ebb850fe1258ddf510e83bcccd437597ea54ea6f71"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":317}}}],"partialFingerprints":{"codehealthFindingId/v1":"57961bc0297ebefceed1e4c8c33ff1504d3fe38cbf74d280131264c46c7fc708"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":322}}}],"partialFingerprints":{"codehealthFindingId/v1":"5e2fa6416c7010e86ddd21d86fd12bf6cd0b589be8939f38bae1347793acace1"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":327}}}],"partialFingerprints":{"codehealthFindingId/v1":"82de776431fcd8fe6550ca8f9cf30c5e4f25f80b363110c07eb20058afb7e0e0"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":332}}}],"partialFingerprints":{"codehealthFindingId/v1":"e327e5335e676666b451e69ab6f2788551a3a181b5451e68fb112dbfae8ba0e2"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":337}}}],"partialFingerprints":{"codehealthFindingId/v1":"5c49f758790fe28375ea48ab8bd5534387403302c7c2e381f5dc13f6ecdc9fb5"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":342}}}],"partialFingerprints":{"codehealthFindingId/v1":"8a088e99fb8f641c07b98312f5c5e1792bdbfd896750e30be6bcaec60daff7b4"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":347}}}],"partialFingerprints":{"codehealthFindingId/v1":"137833b092059b963902a0741bc5408668d79591f38c7df11d096e90d3a2ecc4"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":352}}}],"partialFingerprints":{"codehealthFindingId/v1":"99dd02cd005edd06d935515bbff4c751b42da241f425787ad009f2c754b5d309"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":357}}}],"partialFingerprints":{"codehealthFindingId/v1":"c82080cff684476ac1805ed0e5480a5fca3af66661ac997b379ee3845609f2c6"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":363}}}],"partialFingerprints":{"codehealthFindingId/v1":"6f81af83194a1059f364b734b79e4452bfcf513a3ac9e05691518f30110e45de"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":368}}}],"partialFingerprints":{"codehealthFindingId/v1":"45fed74de9846a14d17c87f32e6b9557aada9cdbbe0d65c5c7c6173c713da5b0"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":373}}}],"partialFingerprints":{"codehealthFindingId/v1":"0eaed17c88c303b854ae3ceb5e0c70006c81a5f91b1bb8ffa44ad3cb6087b11a"}},{"ruleId":"IC1","level":"note","message":{"text":"Commented-out code: A line of code has been commented out rather than removed \u2014 dead weight that rots and confuses. Delete it (version control remembers)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"src/Checksums/ripemd160.cs"},"region":{"startLine":378}}}],"partialFingerprints":{"codehealthFindingId/v1":"b5edebe41b695a60ec5caf358ba392bf5115343c57ce9e2bf613325127816c7a"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"P12","level":"warning","message":{"text":"Coverage collected but not gated: CI collects a coverage report but no step enforces a minimum \u2014 coverage could halve and CI stays green. Add a step that fails the build when coverage drops below a floor (your coverage tool\u0027s minimum-threshold flag, or a coverage-gate action) so the number guards something. What was searched, so you can tell an absence from a miss: this repository\u0027s CI files AND its coverage configuration \u2014 the well-known coverage and test-runner config files, read at the repository root and inside workspace package directories two levels down, so a floor declared beside the tests rather than in the pipeline is credited \u2014 matched against the threshold settings this check knows by name. A floor set in your coverage service\u0027s web UI rather than in a committed file, or under a setting whose name is not one of those, is not seen here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7f63c06044cf998d9a0698692df30d8873e29bc9b0c98ee829255017c1193d33"}},{"ruleId":"P3","level":"note","message":{"text":"No SAST: No static application security testing detected. For this repository\u0027s stack, add CodeQL\u0027s csharp pack, or a .NET security analyzer package (or \u0060semgrep --config=auto\u0060, which runs on any language) as a CI step. What was searched, so you can tell an absence from a miss: the 3648 CI workflow file(s) in this repository, and the scanner and linter configuration checked in beside them. A scan that runs outside CI, one configured in your forge\u0027s web UI rather than in a committed file, or a tool whose name is none of those this check carries, is not seen \u2014 if that is your case the row is wrong, and saying so is more useful than adding a second scanner."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6e54424179c892f03ef2fd003130ac4bd43f39bbf3b1ca0a0143e25acb80ec87"}},{"ruleId":"P6","level":"note","message":{"text":"No changelog: No CHANGELOG/HISTORY/RELEASES file \u2014 what shipped when isn\u0027t easy to reconstruct for support or audit. (Versioning/tagging makes releases traceable, but a changelog records the what.)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"dda5aa5aed8cbb292c3ef2b733bc138f614293ae6426c85e98bf31ef330d9415"}},{"ruleId":"PF1","level":"note","message":{"text":"No performance benchmarks: No benchmark suite was found by the two searches this check runs. FIRST, a BenchmarkDotNet package reference in any project file \u2014 every project the workspace loaded, plus a walk of project files on disk that never loaded, because a benchmark suite is exactly the project a partial load drops. SECOND, a script harness: a file whose name contains \u0060benchmark\u0060 and ends \u0060.py\u0060, \u0060.sh\u0060, \u0060.ps1\u0060, \u0060.bash\u0060, \u0060.rb\u0060, \u0060.js\u0060 or \u0060.mjs\u0060, credited ONLY when this repository\u0027s CI text also mentions benchmarks \u2014 a harness no pipeline runs is read as a fixture, deliberately. Neither search can see a benchmark suite in another ecosystem\u0027s idiom (a Go \u0060testing.B\u0060 file, a JMH or criterion project, a pytest-benchmark run), so this is \u0027no benchmark found by those two searches\u0027, not a verdict that the repository has none. Where code is performance-sensitive, a benchmark guards against silent regressions \u2014 but it\u0027s a bonus here, not a deduction."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"fd90d18ee3bb127e8033d41e8efe4e131487a6d794a5730a72c56105ef7485ea"}},{"ruleId":"PF2","level":"note","message":{"text":"No allocation-aware APIs detected: No Span/Memory, pooling (ArrayPool/ObjectPool), stackalloc, ValueTask or buffer-writer usage was found. If this code sits on a hot path, these reduce the GC pressure it creates \u2014 a bonus, not a requirement."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"62ddee2db21224079bdf78941df83f75eb632dc1a76b0da3669d47246d8251ea"}},{"ruleId":"SC1","level":"warning","message":{"text":"NuGet dependencies are not locked: No packages.lock.json and no central package management \u2014 restores aren\u0027t reproducible or pinned (SSDF PW.4.4). Enable \u003CRestorePackagesWithLockFile\u003Etrue\u003C/RestorePackagesWithLockFile\u003E (commit the lockfile) or adopt Directory.Packages.props. Advisory \u2014 never scored."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0a97b4f69ccac509400ece7eedefb06d3ede0522cd4d8bcb5c068bea719545a6"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-214","guid":"b10ad120-fb22-1351-9348-aa23b453e815","name":"CWE-214","shortDescription":{"text":"CWE-214"},"helpUri":"https://cwe.mitre.org/data/definitions/214.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-532","guid":"1cd8877a-76e8-ce54-b40b-779af23364a0","name":"CWE-532","shortDescription":{"text":"CWE-532"},"helpUri":"https://cwe.mitre.org/data/definitions/532.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":28,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}