{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"}]}},"results":[{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: request/request_editor.dart: FileTooLong \u2014 842 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/ui/mobile/request/request_editor.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"66c1bb15c5147915f36de8a308ca1dfa369991aa9c11364d8a987e77a0fa4437"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: request/request_editor.dart: FileTooLong \u2014 830 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/ui/desktop/request/request_editor.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f5341782983263042093d23e825f41e8c401036d64b4368b98be2972dac29ab5"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: setting/script.dart: FileTooLong \u2014 815 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/ui/mobile/setting/script.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"afe231e18a597470b4d0a18e13021c636dd4321a1d693a5197ae65dc0be9d361"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: setting/script.dart: FileTooLong \u2014 717 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/ui/desktop/setting/script.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f2f78409e749e177ea5b12347b8480e16ce2c843ebfcc0eadd56ba0566a640bc"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: setting/weak_network.dart: FileTooLong \u2014 677 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/ui/desktop/setting/weak_network.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a934282cb3c4abeca13b16704edcedc5f16978eff859bbb54b381a8192cc2dd2"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: content/body.dart: FileTooLong \u2014 652 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/ui/content/body.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"2a1c9119b1697a38780fcff581d6c9c89ebe146feceee9211f55aadaeb2a88de"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: cert/x509.dart: FileTooLong \u2014 586 significant lines (blank, comment-only and punctuation-only lines excluded), about 98% of them inside a single declaration: X509Utils (20-891). Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/network/util/cert/x509.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ffca20b50d2db64b3d08d06c7c8af71f680bc7ebd2f3bb45b7192fa96a3ca2f9"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: setting/request_crypto.dart: FileTooLong \u2014 574 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/ui/desktop/setting/request_crypto.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"69c03f959e757ea4288cbc7a3a69ac61eff7b984362be3f3bc838f08c22903fd"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: setting/ssl.dart: FileTooLong \u2014 570 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/ui/mobile/setting/ssl.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"54d8ecaae88e78161d2cf807785ad4aaf5e43883a7e35a5331456c0f3b79ae28"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: setting/request_crypto.dart: FileTooLong \u2014 568 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/ui/mobile/setting/request_crypto.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b135d9974ce0fb301e2f852236ca8937c0507ad57e18c3215cfafaa3e88bf85a"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: setting/weak_network.dart: FileTooLong \u2014 540 significant lines (blank, comment-only and punctuation-only lines excluded). To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/ui/mobile/setting/weak_network.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1be2ac3fb32e99fbb4f4d320eb3cae74b2cad9061176f82304f48e087f1c8302"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #1: If anonymized user #1 becomes unavailable, 151 significant file(s) lose their only recent owner: lib/ui/mobile/setting/script.dart, lib/ui/mobile/request/request_editor.dart, lib/ui/desktop/request/request_editor.dart, lib/ui/desktop/setting/script.dart, lib/ui/desktop/setting/request_crypto.dart, lib/network/util/cert/x509.dart, lib/ui/content/body.dart, lib/ui/mobile/setting/ssl.dart (\u002B143 more). Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"cebe6c2bed483e306b3a4e34ed085dda10ff0d6688e8e4fa20ec122c5360bf07"}},{"ruleId":"D19","level":"note","message":{"text":"The README lists features but does not state the supported platforms beyond Windows/Mac/Android/iOS/Linux and a brief full-platform line; the \u0027Support Windows\u3001Mac\u3001Android\u3001IOS\u3001Linux Full platform system\u0027 opening is cut by the scanner, so the exact supported OSes are not visible.: Add a short Platforms section listing each supported OS with minimal setup steps (e.g. Android SDK, iOS Developer account) for new contributors."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"85d7e928219ac4b4d9d7408ea8a0a15fd63a46b2386ccac8a3f1a271314fa118"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: host_filter.dart \u2194 ssl.dart: \u0060lib/network/components/host_filter.dart\u0060 (context network) and \u0060lib/ui/desktop/ssl/ssl.dart\u0060 (context ui) sit in DIFFERENT parts of the tree yet change together 62% of the time (10 of the 16 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/network/components/host_filter.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3b159f2f11ce38fdd355ff7a7cb492f1e17763bae510d7533205ddd7e10ae13d"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: body.dart \u2194 curl.dart: \u0060lib/ui/content/body.dart\u0060 (context ui) and \u0060lib/utils/curl.dart\u0060 (context utils) sit in DIFFERENT parts of the tree yet change together 50% of the time (7 of the 14 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/ui/content/body.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"7476ab04293d7033315fedeb6911f50c40d4994f9f6022df72126d43a2e8166f"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: mobile.dart \u2194 curl.dart: \u0060lib/ui/mobile/mobile.dart\u0060 (context ui) and \u0060lib/utils/curl.dart\u0060 (context utils) sit in DIFFERENT parts of the tree yet change together 50% of the time (7 of the 14 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/ui/mobile/mobile.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"957cfa16bb716102bb2e929954d6d6e755ee1da8ee6816659408d1eb5e0d42e2"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: PacketTunnelProvider.swift \u2194 VpnManager.swift: \u0060ios/ProxyPin/PacketTunnelProvider.swift\u0060 and \u0060ios/Runner/VpnManager.swift\u0060 change together 70% of the time (7 of the 10 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well). They sit in different directories, but in this ecosystem the namespace is declared in the FILE, not by the folder \u2014 so the two may well share one namespace and reference each other with no import for this pass to see. Read the pair before acting: if one derives from or overrides the other, the dependency is explicit in the type declaration and the co-change is definitional; if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE and the thing to add is a comment saying so; if they simply belong together, co-locate them; if none of these holds, the coupling is hidden and worth breaking."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"ios/ProxyPin/PacketTunnelProvider.swift"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"feace6258055ebdf58284f2454f8a93b3041c47dfecc4fed3ac25c2e1eaff805"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: desktop.dart \u2194 mobile.dart: \u0060lib/ui/desktop/desktop.dart\u0060 and \u0060lib/ui/mobile/mobile.dart\u0060 change together 58% of the time (53 of the 92 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/ui/desktop/desktop.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d65346dd829014290bcfe1890dbfbbf181bc534ab981ac9b590f6ef5f8abec98"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: domains.dart \u2194 request_sequence.dart: \u0060lib/ui/desktop/request/domains.dart\u0060 and \u0060lib/ui/desktop/request/request_sequence.dart\u0060 change together 56% of the time (9 of the 16 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/ui/desktop/request/domains.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d4c1d6901819d562c5c631d67689fc4c1dcf75a755774f98526c7cee8daaae51"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: http_proxy_handle.dart \u2194 body_reader.dart: \u0060lib/network/handle/http_proxy_handle.dart\u0060 and \u0060lib/network/http/parse/body_reader.dart\u0060 change together 54% of the time (7 of the 13 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/network/handle/http_proxy_handle.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"956180dbdece278c290b88fc89e8baaf2d963e8f25ef93106c2dd84cc29e216f"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: filter.dart \u2194 request_rewrite.dart: \u0060lib/ui/mobile/setting/filter.dart\u0060 and \u0060lib/ui/mobile/setting/request_rewrite.dart\u0060 change together 54% of the time (15 of the 28 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/ui/mobile/setting/filter.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"af49a597dcbe6aa3df6ee18ea1a7157babf408381183268c5101bdb7145f8fa7"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: http_proxy_handle.dart \u2194 codec.dart: \u0060lib/network/handle/http_proxy_handle.dart\u0060 and \u0060lib/network/http/codec.dart\u0060 change together 50% of the time (19 of the 38 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/network/handle/http_proxy_handle.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"55cd63ea41a7922353f4e77409eb0004b3f77aec6212cfa0abb090ac5d84ae93"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: favorite.dart \u2194 request.dart: \u0060lib/ui/desktop/left_menus/favorite.dart\u0060 and \u0060lib/ui/desktop/request/request.dart\u0060 change together 50% of the time (17 of the 34 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"lib/ui/desktop/left_menus/favorite.dart"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"958ed61bb25d84a8a3a5d6ee4e3cd116d884b503d156ac5dbed837693683f25a"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":0,"secretScannerRunsExcluded":0}}}]}