{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D10","name":"Test Quality","shortDescription":{"text":"Test Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D10"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D22","name":"Internal API Consistency","shortDescription":{"text":"Internal API Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D22"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D37","name":"Vulnerability-disclosure Policy","shortDescription":{"text":"Vulnerability-disclosure Policy"},"helpUri":"https://codehealth.canine.dev/dimensions/D37","relationships":[{"target":{"id":"CWE-1059","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1059"]}},{"id":"D40","name":"Network Egress Confinement","shortDescription":{"text":"Network Egress Confinement"},"helpUri":"https://codehealth.canine.dev/dimensions/D40"},{"id":"D41","name":"Kernel \u0026 Syscall Confinement","shortDescription":{"text":"Kernel \u0026 Syscall Confinement"},"helpUri":"https://codehealth.canine.dev/dimensions/D41"},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AX5","name":"Architecture \u0026 structure","shortDescription":{"text":"Architecture \u0026 structure"},"helpUri":"https://codehealth.canine.dev/dimensions/AX5"},{"id":"AX8","name":"Test isolation","shortDescription":{"text":"Test isolation"},"helpUri":"https://codehealth.canine.dev/dimensions/AX8"},{"id":"AX9","name":"CQS / query purity","shortDescription":{"text":"CQS / query purity"},"helpUri":"https://codehealth.canine.dev/dimensions/AX9"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"DM1","name":"Aggregate boundaries","shortDescription":{"text":"Aggregate boundaries"},"helpUri":"https://codehealth.canine.dev/dimensions/DM1"},{"id":"DM2","name":"Strongly-typed ids","shortDescription":{"text":"Strongly-typed ids"},"helpUri":"https://codehealth.canine.dev/dimensions/DM2"},{"id":"DM4","name":"Rich vs anemic domain model","shortDescription":{"text":"Rich vs anemic domain model"},"helpUri":"https://codehealth.canine.dev/dimensions/DM4"},{"id":"DM5","name":"Encapsulated state","shortDescription":{"text":"Encapsulated state"},"helpUri":"https://codehealth.canine.dev/dimensions/DM5"},{"id":"DM6","name":"Domain \u2194 infrastructure boundary","shortDescription":{"text":"Domain \u2194 infrastructure boundary"},"helpUri":"https://codehealth.canine.dev/dimensions/DM6"},{"id":"ED5","name":"Idempotency","shortDescription":{"text":"Idempotency"},"helpUri":"https://codehealth.canine.dev/dimensions/ED5"},{"id":"ES1","name":"Fold determinism","shortDescription":{"text":"Fold determinism"},"helpUri":"https://codehealth.canine.dev/dimensions/ES1"},{"id":"ES2","name":"Immutable events","shortDescription":{"text":"Immutable events"},"helpUri":"https://codehealth.canine.dev/dimensions/ES2"},{"id":"GD1","name":"Unfinished \u0026 placeholder code","shortDescription":{"text":"Unfinished \u0026 placeholder code"},"helpUri":"https://codehealth.canine.dev/dimensions/GD1"},{"id":"IC1","name":"Incompleteness \u0026 stubs","shortDescription":{"text":"Incompleteness \u0026 stubs"},"helpUri":"https://codehealth.canine.dev/dimensions/IC1"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P2","name":"Observability","shortDescription":{"text":"Observability"},"helpUri":"https://codehealth.canine.dev/dimensions/P2"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P5","name":"DR \u0026 Backup","shortDescription":{"text":"DR \u0026 Backup"},"helpUri":"https://codehealth.canine.dev/dimensions/P5"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"R1","name":"Type Safety","shortDescription":{"text":"Type Safety"},"helpUri":"https://codehealth.canine.dev/dimensions/R1"},{"id":"R10","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/R10"},{"id":"R2","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/R2"},{"id":"R3","name":"Large Files","shortDescription":{"text":"Large Files"},"helpUri":"https://codehealth.canine.dev/dimensions/R3"},{"id":"R5","name":"Dependency Freshness","shortDescription":{"text":"Dependency Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/R5"},{"id":"R6","name":"Tooling","shortDescription":{"text":"Tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/R6"},{"id":"R7","name":"Dead Code","shortDescription":{"text":"Dead Code"},"helpUri":"https://codehealth.canine.dev/dimensions/R7"},{"id":"R8","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/R8"},{"id":"R9","name":"Circular Imports","shortDescription":{"text":"Circular Imports"},"helpUri":"https://codehealth.canine.dev/dimensions/R9"},{"id":"SC1","name":"Supply-chain hygiene","shortDescription":{"text":"Supply-chain hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/SC1"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X5","name":"Nullable reference types","shortDescription":{"text":"Nullable reference types"},"helpUri":"https://codehealth.canine.dev/dimensions/X5"},{"id":"X6","name":"Hand-rolled structured-format parsing","shortDescription":{"text":"Hand-rolled structured-format parsing"},"helpUri":"https://codehealth.canine.dev/dimensions/X6"},{"id":"X7","name":"Silent fallback defaults","shortDescription":{"text":"Silent fallback defaults"},"helpUri":"https://codehealth.canine.dev/dimensions/X7"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"warpgate::commands::setup::command (cyclomatic 49): warpgate::commands::setup::command has cyclomatic complexity 49 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate/src/commands/setup.rs"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"9546a4146d9c0e8a95ab2bd5a887605cc1fbd6e121bde703712507ce065a4203"}},{"ruleId":"D1","level":"warning","message":{"text":"ServerSession::handle_remote_event (cyclomatic 47): ServerSession::handle_remote_event has cyclomatic complexity 47 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/session.rs"},"region":{"startLine":1260}}}],"partialFingerprints":{"codehealthFindingId/v1":"9e25cc722ac2e2aaac853db2fc8a4aa272a601c30039f68d2f66d580f826a9ed"}},{"ruleId":"D1","level":"warning","message":{"text":"warpgate_protocol_rdp::server::control_loop (cyclomatic 34): warpgate_protocol_rdp::server::control_loop has cyclomatic complexity 34 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-rdp/src/server/mod.rs"},"region":{"startLine":209}}}],"partialFingerprints":{"codehealthFindingId/v1":"ad988fd78187fcf806cf8bfa40efbdf6dd77236923e0202f641eff8af443316e"}},{"ruleId":"D1","level":"warning","message":{"text":"SessionChannel::run (cyclomatic 26): SessionChannel::run has cyclomatic complexity 26 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/client/channel_session.rs"},"region":{"startLine":40}}}],"partialFingerprints":{"codehealthFindingId/v1":"87482722d446ac444a266582f8d94a8c274781ab05a81a8ab5ded34e3c082cc9"}},{"ruleId":"D1","level":"warning","message":{"text":"ServerSession::handle_event (cyclomatic 25): ServerSession::handle_event has cyclomatic complexity 25 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top. This is NOT this file\u0027s highest cyclomatic complexity: ServerSession::handle_server_handler_event (cyclomatic 30) is higher and carries no row of its own \u2014 it was excluded as a flat dispatcher (a long switch/match over independent cases: many branches, almost no nesting), which this dimension does not treat as a refactor obligation. It is named here so the ranking you see in this file is not mistaken for the whole of it; the excluded function is counted neither in this dimension\u0027s figures nor in its score."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/session.rs"},"region":{"startLine":830}}}],"partialFingerprints":{"codehealthFindingId/v1":"cab1ca2b9d53f2e264aa893cae0f5acf7ec987bb1a967671b1492c9de90a12b3"}},{"ruleId":"D1","level":"warning","message":{"text":"warpgate_protocol_kubernetes::server::handlers::_handle_normal_request_inner (cyclomatic 24): warpgate_protocol_kubernetes::server::handlers::_handle_normal_request_inner has cyclomatic complexity 24 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-kubernetes/src/server/handlers.rs"},"region":{"startLine":229}}}],"partialFingerprints":{"codehealthFindingId/v1":"946b6db6bb2ce523703c853a9eafe6543b3e619dac321ee3d96b8be2b83280be"}},{"ruleId":"D1","level":"warning","message":{"text":"warpgate::commands::run::command (cyclomatic 23): warpgate::commands::run::command has cyclomatic complexity 23 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate/src/commands/run.rs"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"370c3d20b618cd818b1ffbd57fe8d37e0af86d2efa5841ade105fe78cda61092"}},{"ruleId":"D1","level":"warning","message":{"text":"warpgate_protocol_rdp::client::active_loop (cyclomatic 22): warpgate_protocol_rdp::client::active_loop has cyclomatic complexity 22 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-rdp/src/client/mod.rs"},"region":{"startLine":153}}}],"partialFingerprints":{"codehealthFindingId/v1":"b8ebd7d4cc2ef383baa1dabbee56b8b56d5c9c00657e1732b0f161ec4a9bc8ae"}},{"ruleId":"D1","level":"warning","message":{"text":"ServerSession::start (cyclomatic 21): ServerSession::start has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top. This is NOT this file\u0027s highest cyclomatic complexity: ServerSession::handle_server_handler_event (cyclomatic 30) is higher and carries no row of its own \u2014 it was excluded as a flat dispatcher (a long switch/match over independent cases: many branches, almost no nesting), which this dimension does not treat as a refactor obligation. It is named here so the ranking you see in this file is not mistaken for the whole of it; the excluded function is counted neither in this dimension\u0027s figures nor in its score."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/session.rs"},"region":{"startLine":253}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c3fa2f2636afc67fbab479929b941afe0541698a011abf4ea289d68946eb767"}},{"ruleId":"D1","level":"warning","message":{"text":"warpgate_web_desktop::api::ws_handler (cyclomatic 21): warpgate_web_desktop::api::ws_handler has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web-desktop/src/api.rs"},"region":{"startLine":19}}}],"partialFingerprints":{"codehealthFindingId/v1":"7a63206be2899ecdf111b3a8638f521d3fcf1865d1e498a5d92bc56be1d49907"}},{"ruleId":"D1","level":"warning","message":{"text":"warpgate_protocol_vnc::server::protocol::read_client_messages (cyclomatic 20): warpgate_protocol_vnc::server::protocol::read_client_messages has cyclomatic complexity 20 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-vnc/src/server/protocol.rs"},"region":{"startLine":266}}}],"partialFingerprints":{"codehealthFindingId/v1":"4907a100c2972b073db0ab624bf6126e1c3d5132552c98c6b21277f889d32340"}},{"ruleId":"D1","level":"warning","message":{"text":"warpgate_protocol_vnc::server::bridge::run_proxy_session (cyclomatic 20): warpgate_protocol_vnc::server::bridge::run_proxy_session has cyclomatic complexity 20 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-vnc/src/server/bridge.rs"},"region":{"startLine":108}}}],"partialFingerprints":{"codehealthFindingId/v1":"412b3772d71a27e7e89b795e32ff9dcf957cb884593b30a222171e0ac0299173"}},{"ruleId":"D1","level":"warning","message":{"text":"warpgate_core::db_auth::authorize_user (cyclomatic 19): warpgate_core::db_auth::authorize_user has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/db_auth.rs"},"region":{"startLine":189}}}],"partialFingerprints":{"codehealthFindingId/v1":"c5803882b0c87779df94356af2243f64a80c65700114a4914708343a14b18aac"}},{"ruleId":"D1","level":"warning","message":{"text":"Api::api_get_info (cyclomatic 19): Api::api_get_info has cyclomatic complexity 19 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/api/info.rs"},"region":{"startLine":164}}}],"partialFingerprints":{"codehealthFindingId/v1":"6acf7c69e2819293937d8562bed503bfd8b151f7d7542f73f00fc84fa7c8c67f"}},{"ruleId":"D1","level":"warning","message":{"text":"MySqlClient::connect (cyclomatic 19): MySqlClient::connect has cyclomatic complexity 19 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-mysql/src/client.rs"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"909a18e0352a84202e74874f99e2cfb0f35edb48bedb4d19a4a8187a04f25dab"}},{"ruleId":"D1","level":"warning","message":{"text":"PostgresClient::connect (cyclomatic 18): PostgresClient::connect has cyclomatic complexity 18 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-postgres/src/client.rs"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"1682be67071afedad8ea49d817f5cdfe697eb5f997551098056577808fb280e0"}},{"ruleId":"D1","level":"warning","message":{"text":"warpgate_web_ssh::api::ws_handler (cyclomatic 18): warpgate_web_ssh::api::ws_handler has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web-ssh/src/api.rs"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"40f46b787a202f4fe0bbbb016c7345bf7d9fdf642a5a9395620ef0aa43e22532"}},{"ruleId":"D1","level":"warning","message":{"text":"warpgate_core::ticket_requests::create_ticket_request (cyclomatic 17): warpgate_core::ticket_requests::create_ticket_request has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/ticket_requests.rs"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"c524732e0d32408f1e54fbf76bfa28397c028509519baaaf45d33f78075513a8"}},{"ruleId":"D1","level":"warning","message":{"text":"TargetMenu::handle_input (cyclomatic 17): TargetMenu::handle_input has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/target_menu.rs"},"region":{"startLine":191}}}],"partialFingerprints":{"codehealthFindingId/v1":"f3813703a58adf9e332fd1c04ab127a9c1c7936960da75418d4cfb40ff8c0034"}},{"ruleId":"D1","level":"warning","message":{"text":"PlaybackController.doSeek (cyclomatic 17): PlaybackController.doSeek has cyclomatic complexity 17 (threshold 15). To reduce it, split the body: these branches sit side by side rather than nested inside one another, so extracting each one on its own would leave a function per branch. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/player/playbackController.ts"},"region":{"startLine":173}}}],"partialFingerprints":{"codehealthFindingId/v1":"7ab12093ff547f31351a3130e34542e22e7b8f43953bfbb64d86982d768b93cd"}},{"ruleId":"D1","level":"warning","message":{"text":"warpgate_core::credential_encryption::rewrite_all (cyclomatic 16): warpgate_core::credential_encryption::rewrite_all has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/credential_encryption.rs"},"region":{"startLine":230}}}],"partialFingerprints":{"codehealthFindingId/v1":"1cc7be1f91cf48538ba729c73f39f3f8d36f41bf8933721d3f375e92d56f663b"}},{"ruleId":"D1","level":"warning","message":{"text":"warpgate_desktop_auth::hold_screen::run_hold_screen (cyclomatic 16): warpgate_desktop_auth::hold_screen::run_hold_screen has cyclomatic complexity 16 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-desktop-auth/src/hold_screen.rs"},"region":{"startLine":145}}}],"partialFingerprints":{"codehealthFindingId/v1":"7bbc354228eb7b99419721854e196aca857569d374d85a0e83bbb67722db69ca"}},{"ruleId":"D1","level":"warning","message":{"text":"CookieHostMiddlewareEndpoint::call (cyclomatic 16): CookieHostMiddlewareEndpoint::call has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/middleware/cookie_host.rs"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"22a5c625ddc6072843e5651033f9fd9b2a5697cb34d764671f191bc07bf7c45d"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate::commands::setup::command (cognitive 97): warpgate::commands::setup::command has cognitive complexity 97 (threshold 15). Drivers by points: if/else 61 (92 pts), match/switch 3, boolean chains 1, loops 1 (nesting depth added 31). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate/src/commands/setup.rs"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"95c9dd57b73c8455ac56f30325ea185d454dc2fd02d7cb9d9ce5414d22e00bf8"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_protocol_rdp::server::control_loop (cognitive 78): warpgate_protocol_rdp::server::control_loop has cognitive complexity 78 (threshold 15). Drivers by points: if/else 19 (56 pts), match/switch 5 (18 pts), boolean chains 3, loops 1 (nesting depth added 50). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-rdp/src/server/mod.rs"},"region":{"startLine":209}}}],"partialFingerprints":{"codehealthFindingId/v1":"2cf7af92351ddd1c1b3ec920efc22e09c484a6d5f905b8d2e49f359aa35e95ba"}},{"ruleId":"D2","level":"warning","message":{"text":"ServerSession::handle_remote_event (cognitive 61): ServerSession::handle_remote_event has cognitive complexity 61 (threshold 15). Drivers by points: if/else 20 (51 pts), match/switch 4 (7 pts), boolean chains 3 (nesting depth added 34). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/session.rs"},"region":{"startLine":1260}}}],"partialFingerprints":{"codehealthFindingId/v1":"439a93c677f6ea4e6d590558d8b24ded3d14fc22388997ffa8fdac6c4a79cc8e"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_protocol_rdp::client::active_loop (cognitive 45): warpgate_protocol_rdp::client::active_loop has cognitive complexity 45 (threshold 15). Drivers by points: if/else 9 (26 pts), loops 4 (9 pts), match/switch 3 (8 pts), boolean chains 2 (nesting depth added 27). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-rdp/src/client/mod.rs"},"region":{"startLine":153}}}],"partialFingerprints":{"codehealthFindingId/v1":"74cebc0aa9a376d7cc1fb52cab3cb888e4f5ec81cf8d997b96bb682508a16811"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_web_desktop::api::ws_handler (cognitive 41): warpgate_web_desktop::api::ws_handler has cognitive complexity 41 (threshold 15). Drivers by points: if/else 8 (25 pts), match/switch 4 (9 pts), boolean chains 4, loops 2 (3 pts) (nesting depth added 23). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web-desktop/src/api.rs"},"region":{"startLine":19}}}],"partialFingerprints":{"codehealthFindingId/v1":"fa4748dfa0e4397334acd44cc321f76ae81d425d0fa83ddb9a6513beede7c6e0"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_core::db_auth::authorize_user (cognitive 40): warpgate_core::db_auth::authorize_user has cognitive complexity 40 (threshold 15). Drivers by points: if/else 12 (34 pts), match/switch 2 (5 pts), loops 1 (nesting depth added 25). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/db_auth.rs"},"region":{"startLine":189}}}],"partialFingerprints":{"codehealthFindingId/v1":"c65a21884fb82fd96a86cf65dce3836f0c824fd04a37095906104ae0dbe30345"}},{"ruleId":"D2","level":"warning","message":{"text":"Api::api_get_info (cognitive 37): Api::api_get_info has cognitive complexity 37 (threshold 15). Drivers by points: if/else 24 (31 pts), boolean chains 3, match/switch 3 (nesting depth added 7). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/api/info.rs"},"region":{"startLine":164}}}],"partialFingerprints":{"codehealthFindingId/v1":"1bbdcc162d1eac21c37c0a068dbd2cf862cd7f72b3dee9eb58a04a00cd9a3552"}},{"ruleId":"D2","level":"warning","message":{"text":"ServerSession::start (cognitive 35): ServerSession::start has cognitive complexity 35 (threshold 15). Drivers by points: if/else 11 (24 pts), match/switch 3 (6 pts), loops 5 (nesting depth added 16). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/session.rs"},"region":{"startLine":253}}}],"partialFingerprints":{"codehealthFindingId/v1":"45571e72ba937accc17eb89897bf83ad01e295f1939d329db581b83ad52c2176"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_web_ssh::api::ws_handler (cognitive 35): warpgate_web_ssh::api::ws_handler has cognitive complexity 35 (threshold 15). Drivers by points: if/else 7 (22 pts), match/switch 3 (6 pts), loops 3 (5 pts), boolean chains 2 (nesting depth added 20). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web-ssh/src/api.rs"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"fd104f79e42e9bbad3511476036b700670e2e9bcda9040cd0c11194c24243f40"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_protocol_kubernetes::server::handlers::_handle_normal_request_inner (cognitive 34): warpgate_protocol_kubernetes::server::handlers::_handle_normal_request_inner has cognitive complexity 34 (threshold 15). Drivers by points: if/else 14 (21 pts), boolean chains 6, loops 4 (5 pts), match/switch 1 (2 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-kubernetes/src/server/handlers.rs"},"region":{"startLine":229}}}],"partialFingerprints":{"codehealthFindingId/v1":"268de41d84e3e56ebaa92efd8fb1770d6ee853354a68d538f65d6cd84babff2a"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_protocol_vnc::server::bridge::run_proxy_session (cognitive 32): warpgate_protocol_vnc::server::bridge::run_proxy_session has cognitive complexity 32 (threshold 15). Drivers by points: if/else 5 (18 pts), match/switch 4 (12 pts), boolean chains 1, loops 1 (nesting depth added 21). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-vnc/src/server/bridge.rs"},"region":{"startLine":108}}}],"partialFingerprints":{"codehealthFindingId/v1":"4406cf42ebabf5e4df7ca1d72b6446507bbeab916f72b8cccfe393a30ee98cb1"}},{"ruleId":"D2","level":"warning","message":{"text":"ServerSession::handle_event (cognitive 31): ServerSession::handle_event has cognitive complexity 31 (threshold 15). Drivers by points: if/else 12 (23 pts), match/switch 3 (6 pts), boolean chains 2 (nesting depth added 14). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/session.rs"},"region":{"startLine":830}}}],"partialFingerprints":{"codehealthFindingId/v1":"79f2a27cf1918d7c8f32520dfa0cdc89900a4647c6bcbe14720ceeb947a5d786"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate::commands::run::command (cognitive 28): warpgate::commands::run::command has cognitive complexity 28 (threshold 15). Drivers by points: match/switch 6 (12 pts), if/else 7 (9 pts), loops 5 (7 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate/src/commands/run.rs"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"86fda591309822031733250ab6b172d764317b2adbb12b7369ee385723fb08b2"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_desktop_auth::hold_screen::run_hold_screen (cognitive 28): warpgate_desktop_auth::hold_screen::run_hold_screen has cognitive complexity 28 (threshold 15). Drivers by points: match/switch 4 (15 pts), if/else 3 (9 pts), loops 2 (3 pts), boolean chains 1 (nesting depth added 18). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-desktop-auth/src/hold_screen.rs"},"region":{"startLine":145}}}],"partialFingerprints":{"codehealthFindingId/v1":"555171be38976dc8a2406aca99dececfc19cc2cb8b48f13eb642957a548d3f8b"}},{"ruleId":"D2","level":"warning","message":{"text":"ServerSession::try_auth_eager (cognitive 27): ServerSession::try_auth_eager has cognitive complexity 27 (threshold 15). Drivers by points: if/else 10 (22 pts), match/switch 3 (5 pts) (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/session.rs"},"region":{"startLine":2375}}}],"partialFingerprints":{"codehealthFindingId/v1":"3c4059ef7f41536e237bb58b26bc0c00ab9c5f7044f0a94ca359a22cd9b18f19"}},{"ruleId":"D2","level":"warning","message":{"text":"DirtyTracker::take_settled (cognitive 27): DirtyTracker::take_settled has cognitive complexity 27 (threshold 15). Drivers by points: loops 6 (16 pts), if/else 3 (11 pts) (nesting depth added 18). To reduce it, break up the iteration: give each loop body a named function, and split a multi-phase loop into one function per phase so no single body carries the whole pipeline."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web-desktop/src/dirty.rs"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"50b4459bb6e6334e037da8c80e10bb8e13807f252a3b7b0fe7aa615351fa1356"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_admin::api::recordings_detail::serve_live_stream (cognitive 26): warpgate_admin::api::recordings_detail::serve_live_stream has cognitive complexity 26 (threshold 15). Drivers by points: match/switch 5 (14 pts), if/else 4 (10 pts), boolean chains 1, loops 1 (nesting depth added 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-admin/src/api/recordings_detail.rs"},"region":{"startLine":270}}}],"partialFingerprints":{"codehealthFindingId/v1":"d3569cffc4100b0d7a6ba1ccd6ef942371335ac742778e4a1e889b3324d1bb11"}},{"ruleId":"D2","level":"warning","message":{"text":"CookieHostMiddlewareEndpoint::call (cognitive 26): CookieHostMiddlewareEndpoint::call has cognitive complexity 26 (threshold 15). Drivers by points: if/else 11 (20 pts), loops 2 (3 pts), boolean chains 2, match/switch 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/middleware/cookie_host.rs"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"0407dbfec666b6940c6bb631558e7a1c3dbc0e26b3e4443689ab90e5af2b4cf3"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_core::credential_encryption::rewrite_all (cognitive 25): warpgate_core::credential_encryption::rewrite_all has cognitive complexity 25 (threshold 15). Drivers by points: if/else 11 (21 pts), loops 4 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/credential_encryption.rs"},"region":{"startLine":230}}}],"partialFingerprints":{"codehealthFindingId/v1":"d944b2ab6462591b17461cb4b884bf7e922467d383bf733856f5f9252a31254a"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_protocol_vnc::client::run (cognitive 25): warpgate_protocol_vnc::client::run has cognitive complexity 25 (threshold 15). Drivers by points: if/else 2 (9 pts), match/switch 4 (9 pts), loops 3 (6 pts), boolean chains 1 (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-vnc/src/client.rs"},"region":{"startLine":161}}}],"partialFingerprints":{"codehealthFindingId/v1":"45e12ab9b7e2fb8670fa54bf2f1e7edccd707c59936f7fa0ad648fc06c53a11a"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate::config::check_and_migrate_config (cognitive 24): warpgate::config::check_and_migrate_config has cognitive complexity 24 (threshold 15). Drivers by points: if/else 7 (16 pts), match/switch 1 (4 pts), loops 1 (3 pts), boolean chains 1 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate/src/config.rs"},"region":{"startLine":74}}}],"partialFingerprints":{"codehealthFindingId/v1":"dcc0998646cdc36a4a143d71ef5c2247eabad71ee66cff70cadef757220eb71b"}},{"ruleId":"D2","level":"warning","message":{"text":"Connector::authenticate_session (cognitive 24): Connector::authenticate_session has cognitive complexity 24 (threshold 15). Drivers by points: if/else 9 (19 pts), boolean chains 2, loops 1 (2 pts), match/switch 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/client/mod.rs"},"region":{"startLine":872}}}],"partialFingerprints":{"codehealthFindingId/v1":"9cdb4b9c57c0ecfc895328be94575e94a6ad9f6bc2351ff79c9c252d8656d471"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_protocol_ssh::server::target_menu::run_target_menu_loop (cognitive 24): warpgate_protocol_ssh::server::target_menu::run_target_menu_loop has cognitive complexity 24 (threshold 15). Drivers by points: if/else 6 (17 pts), match/switch 2 (5 pts), boolean chains 1, loops 1 (nesting depth added 14). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/target_menu.rs"},"region":{"startLine":499}}}],"partialFingerprints":{"codehealthFindingId/v1":"5cad5f326ae8c6c40a968f1e9b4c07f5ccd9889e6faf9e2f1cecb332cb38af83"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_protocol_vnc::server::protocol::read_client_messages (cognitive 24): warpgate_protocol_vnc::server::protocol::read_client_messages has cognitive complexity 24 (threshold 15). Drivers by points: match/switch 4 (11 pts), if/else 3 (9 pts), loops 2 (4 pts) (nesting depth added 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-vnc/src/server/protocol.rs"},"region":{"startLine":266}}}],"partialFingerprints":{"codehealthFindingId/v1":"846d1bcfa69370074ca521d4ed99d66922a8128fdea2ef90d7ad6910800f1afb"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_protocol_http::catchall::get_target_for_request (cognitive 23): warpgate_protocol_http::catchall::get_target_for_request has cognitive complexity 23 (threshold 15). Drivers by points: if/else 16 (22 pts), boolean chains 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/catchall.rs"},"region":{"startLine":128}}}],"partialFingerprints":{"codehealthFindingId/v1":"170ad0ff4b2f4e986498f2ec85e06e4f3c80f25571cfd47e6a4e0acd69d6228c"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_core::config_providers::sso_user::resolve_and_map_sso_user (cognitive 22): warpgate_core::config_providers::sso_user::resolve_and_map_sso_user has cognitive complexity 22 (threshold 15). Drivers by points: if/else 12 (19 pts), loops 1 (3 pts) (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/config_providers/sso_user.rs"},"region":{"startLine":11}}}],"partialFingerprints":{"codehealthFindingId/v1":"9fedbb330cd0b4d7428c808bbba9c6dc35c14267553e3140abdbc2f43b3fa270"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_protocol_kubernetes::correlator::correlated_authorization (cognitive 22): warpgate_protocol_kubernetes::correlator::correlated_authorization has cognitive complexity 22 (threshold 15). Drivers by points: if/else 6 (13 pts), match/switch 3 (7 pts), boolean chains 1, loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-kubernetes/src/correlator.rs"},"region":{"startLine":92}}}],"partialFingerprints":{"codehealthFindingId/v1":"5956f8200490657f063824437a12340ab2e943884ce60fa6f0c1597454dbf624"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_protocol_kubernetes::server::auth::authenticate (cognitive 22): warpgate_protocol_kubernetes::server::auth::authenticate has cognitive complexity 22 (threshold 15). Drivers by points: if/else 6 (11 pts), match/switch 3 (8 pts), loops 1 (2 pts), boolean chains 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-kubernetes/src/server/auth.rs"},"region":{"startLine":295}}}],"partialFingerprints":{"codehealthFindingId/v1":"1da68d4d74507a1461b350c03eb520757d59f14d22d8dcde8c2c7b9d03cc6873"}},{"ruleId":"D2","level":"warning","message":{"text":"PostgresClient::connect (cognitive 22): PostgresClient::connect has cognitive complexity 22 (threshold 15). Drivers by points: if/else 6 (13 pts), match/switch 4 (8 pts), loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-postgres/src/client.rs"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"ce072a1aa0402049858a2aa39b57b05748b28e88324baa8592da3f4e1ce53d74"}},{"ruleId":"D2","level":"warning","message":{"text":"TlsCertificateBundle::sni_names (cognitive 22): TlsCertificateBundle::sni_names has cognitive complexity 22 (threshold 15). Drivers by points: if/else 7 (13 pts), loops 2 (4 pts), match/switch 1 (4 pts), boolean chains 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-tls/src/cert.rs"},"region":{"startLine":83}}}],"partialFingerprints":{"codehealthFindingId/v1":"4d06f1e4c4547c226c63ca962214409435fca337a7f30b3caa7509b184ecbfd3"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_web_desktop::manager::spawn_event_loop (cognitive 22): warpgate_web_desktop::manager::spawn_event_loop has cognitive complexity 22 (threshold 15). Drivers by points: match/switch 4 (11 pts), if/else 2 (5 pts), loops 2 (4 pts), boolean chains 2 (nesting depth added 12). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web-desktop/src/manager.rs"},"region":{"startLine":235}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a19287c4a6c169d84b38b2f21f4f2ad5c7acfc4f5a41f66d6ceecd2075ff52c"}},{"ruleId":"D2","level":"warning","message":{"text":"Migration::up (cognitive 21): Migration::up has cognitive complexity 21 (threshold 15). Drivers by points: if/else 8 (16 pts), match/switch 2 (4 pts), loops 1 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00038_fix_target_auth_tags.rs"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"1072b122204da027164de8e514edb7c7f64f6bbfa990c07229cc52990a1ee816"}},{"ruleId":"D2","level":"warning","message":{"text":"ServerSession::_auth_keyboard_interactive (cognitive 21): ServerSession::_auth_keyboard_interactive has cognitive complexity 21 (threshold 15). Drivers by points: if/else 11 (20 pts), match/switch 1 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/session.rs"},"region":{"startLine":2173}}}],"partialFingerprints":{"codehealthFindingId/v1":"8de7a8cba31efc8e3a01ff1173250ded0325514742a132c141cf7ecd08d2cce7"}},{"ruleId":"D2","level":"warning","message":{"text":"MySqlClient::connect (cognitive 20): MySqlClient::connect has cognitive complexity 20 (threshold 15). Drivers by points: if/else 8 (11 pts), match/switch 3 (6 pts), boolean chains 2, loops 1 (nesting depth added 6). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-mysql/src/client.rs"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"70dcc1a735b88d0250bccdedff745b4f14dfdce2eae6c43b09417e029942600a"}},{"ruleId":"D2","level":"warning","message":{"text":"ListenerSupervisor::run (cognitive 19): ListenerSupervisor::run has cognitive complexity 19 (threshold 15). Drivers by points: if/else 4 (12 pts), match/switch 3 (6 pts), loops 1 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate/src/listener_supervisor.rs"},"region":{"startLine":115}}}],"partialFingerprints":{"codehealthFindingId/v1":"71d875304e759f39d254690a1a710c26afcf40880dc87312464fd2f876ee3965"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_desktop_auth::authenticate (cognitive 19): warpgate_desktop_auth::authenticate has cognitive complexity 19 (threshold 15). Drivers by points: if/else 6 (14 pts), match/switch 3 (5 pts) (nesting depth added 10). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-desktop-auth/src/lib.rs"},"region":{"startLine":72}}}],"partialFingerprints":{"codehealthFindingId/v1":"f4ff25bbfe0047ca3e871bb234fc0b288450ab4144385201831c200d8b403817"}},{"ruleId":"D2","level":"warning","message":{"text":"Connector::_handle_auth_result (cognitive 19): Connector::_handle_auth_result has cognitive complexity 19 (threshold 15). Drivers by points: loops 3 (11 pts), match/switch 2 (5 pts), if/else 1 (3 pts) (nesting depth added 13). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/client/mod.rs"},"region":{"startLine":1038}}}],"partialFingerprints":{"codehealthFindingId/v1":"039a94e05d3220b32ee06955968927265bf89fd1010ce9b88f2dd42d178a9846"}},{"ruleId":"D2","level":"warning","message":{"text":"helpers.toClassName (cognitive 19): helpers.toClassName has cognitive complexity 19 (threshold 15). Drivers by points: if/else 6 (14 pts), loops 1 (3 pts), boolean chains 2 (nesting depth added 10). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/common/helpers.ts"},"region":{"startLine":55}}}],"partialFingerprints":{"codehealthFindingId/v1":"bfe78a5fb9d594859e7476eb92169f8c0875057ca7112ec15561a21812d801d8"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_core::ticket_requests::create_ticket_request (cognitive 18): warpgate_core::ticket_requests::create_ticket_request has cognitive complexity 18 (threshold 15). Drivers by points: if/else 12 (13 pts), boolean chains 4, match/switch 1 (nesting depth added 1). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/ticket_requests.rs"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"7fff7edd1077f92eb4d3c8b577db952d3bc79a00320637c4adc26d5590ec746a"}},{"ruleId":"D2","level":"warning","message":{"text":"HandshakeResponse::encode_with (cognitive 18): HandshakeResponse::encode_with has cognitive complexity 18 (threshold 15). Drivers by points: if/else 14 (18 pts) (nesting depth added 4). To reduce it, split the body: most of this score is breadth rather than depth \u2014 checks laid out side by side rather than stacked \u2014 so group the statements between the checks into named steps and move each step into its own function. Some of it IS depth: where a check sits inside another whose only job is to reach it, merge the two into one condition, and where an else follows a branch that already returns, drop the trailing else and let the rest of the body continue at one level."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-database-protocols/src/mysql/protocol/connect/handshake_response.rs"},"region":{"startLine":36}}}],"partialFingerprints":{"codehealthFindingId/v1":"479243a2d8f5a63c12824155e56d8ebada996d92a6d44c94c0b228471e081fb3"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_protocol_rdp::client::input::translate (cognitive 18): warpgate_protocol_rdp::client::input::translate has cognitive complexity 18 (threshold 15). Drivers by points: if/else 8 (15 pts), loops 1 (2 pts), match/switch 1 (nesting depth added 8). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-rdp/src/client/input.rs"},"region":{"startLine":11}}}],"partialFingerprints":{"codehealthFindingId/v1":"13258477853955d30ed08b0610e5e00cbff71ac8e13ec7597d65099e6f58c996"}},{"ruleId":"D2","level":"warning","message":{"text":"protocols.getEffectivePossibleCredentials (cognitive 18): protocols.getEffectivePossibleCredentials has cognitive complexity 18 (threshold 15). Drivers by points: if/else 5 (11 pts), boolean chains 5, loops 1 (2 pts) (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/common/protocols.ts"},"region":{"startLine":331}}}],"partialFingerprints":{"codehealthFindingId/v1":"20930f097654a5ba33363dcd74ffa775aec0906db8a248a559d9e3f3ff142c5f"}},{"ruleId":"D2","level":"warning","message":{"text":"Services::poll_admin_approval (cognitive 17): Services::poll_admin_approval has cognitive complexity 17 (threshold 15). Drivers by points: if/else 6 (11 pts), match/switch 4 (6 pts) (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/approvals/gate.rs"},"region":{"startLine":206}}}],"partialFingerprints":{"codehealthFindingId/v1":"297bbed2c7f31b4be893668e6e24033536822c044c904f7be61b56ba56a62669"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_protocol_http::common::inject_request_authorization (cognitive 17): warpgate_protocol_http::common::inject_request_authorization has cognitive complexity 17 (threshold 15). Drivers by points: if/else 12 (16 pts), boolean chains 1 (nesting depth added 4). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/common.rs"},"region":{"startLine":429}}}],"partialFingerprints":{"codehealthFindingId/v1":"07e74639ea1f32ceb3ff94b251a3e998b889a9793026f5b36de5ae47e83bf8f2"}},{"ruleId":"D2","level":"warning","message":{"text":"ResponseRelay::next (cognitive 17): ResponseRelay::next has cognitive complexity 17 (threshold 15). Drivers by points: if/else 9 (16 pts), boolean chains 1 (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-mysql/src/relay.rs"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"cd6939fc27f9705bb679fe7a61c0c2435153eb91c23eecd6ff0102bbaf527468"}},{"ruleId":"D2","level":"warning","message":{"text":"PostgresSession::run_authorized_inner (cognitive 17): PostgresSession::run_authorized_inner has cognitive complexity 17 (threshold 15). Drivers by points: match/switch 7 (13 pts), if/else 1 (3 pts), loops 1 (nesting depth added 8). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-postgres/src/session.rs"},"region":{"startLine":352}}}],"partialFingerprints":{"codehealthFindingId/v1":"2b8e8e175fcd3f537f06342ed7cf01a8a5cb341363066c9a8dc3dda0a02fe307"}},{"ruleId":"D2","level":"warning","message":{"text":"TargetMenu::handle_input (cognitive 17): TargetMenu::handle_input has cognitive complexity 17 (threshold 15). Drivers by points: if/else 6 (13 pts), match/switch 1 (2 pts), boolean chains 1, loops 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/target_menu.rs"},"region":{"startLine":191}}}],"partialFingerprints":{"codehealthFindingId/v1":"743e74a93bdc32f303c8fcd7ca0f2fd0ba83e6610fe118806183b07d33056d61"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_admin::api::recordings_detail::replay_scratch_span_awaiting (cognitive 16): warpgate_admin::api::recordings_detail::replay_scratch_span_awaiting has cognitive complexity 16 (threshold 15). Drivers by points: if/else 5 (12 pts), loops 2 (3 pts), boolean chains 1 (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-admin/src/api/recordings_detail.rs"},"region":{"startLine":213}}}],"partialFingerprints":{"codehealthFindingId/v1":"aa1371a7a0438ec0112ec7d1558082b4df67e3b60ffa27627f5a296ae646818f"}},{"ruleId":"D2","level":"warning","message":{"text":"Migration::up (cognitive 16): Migration::up has cognitive complexity 16 (threshold 15). Drivers by points: if/else 5 (12 pts), loops 3 (4 pts) (nesting depth added 8). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00087_drop_null_target_options.rs"},"region":{"startLine":78}}}],"partialFingerprints":{"codehealthFindingId/v1":"dfbee48526bf940dbeff1ea853a5b719b31d9a5a43bbfeff732ff7112bdf3b9c"}},{"ruleId":"D2","level":"warning","message":{"text":"warpgate_protocol_kubernetes::server::handlers::_handle_websocket_request_inner (cognitive 16): warpgate_protocol_kubernetes::server::handlers::_handle_websocket_request_inner has cognitive complexity 16 (threshold 15). Drivers by points: if/else 10 (11 pts), match/switch 3 (4 pts), boolean chains 1 (nesting depth added 2). To reduce it, split the body: this score is breadth rather than depth \u2014 many checks laid out side by side rather than nested inside one another, so inverting conditions into early returns has nothing left to flatten. Group the statements between the checks into named steps and move each step into its own function, so the body reads as a short sequence of named stages."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-kubernetes/src/server/handlers.rs"},"region":{"startLine":488}}}],"partialFingerprints":{"codehealthFindingId/v1":"06fa26b34fa1e59f760995d6f439acd3617506b6529604cadfa4c48fe6972f0e"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: ServerSession: ClassTooLong \u2014 1670 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 68 methods, 4 blocks, lines 129-2720. The bar is 400 significant lines; this is 1270 over it, 4.18\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/session.rs"},"region":{"startLine":129}}}],"partialFingerprints":{"codehealthFindingId/v1":"2c31dc1952f09ac3a522b53ed5d884c1ba9392d5ba4153bb562b68aaf9d5c8be"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: AuditEvent.emit: MethodTooLong \u2014 emit runs 397 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 297 over it, 3.97\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-common/src/audit.rs"},"region":{"startLine":216}}}],"partialFingerprints":{"codehealthFindingId/v1":"684cc2a7da576d54b1a8fe57135c6c9bbc53949f6dfa50fef8832d3efcce6989"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: server/session.rs: FileTooLong \u2014 1796 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), about 93% of them inside a single declaration: ServerSession (4 blocks, 129-2720). The bar is 500 significant lines; this is 1296 over it, 3.59\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/session.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e755bae65406eaed9c5b4ce112bc9e4ee3d5159a2983d37857f50cdf496fd6e0"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: warpgate::commands::setup::command: FunctionTooLong \u2014 warpgate::commands::setup::command runs 318 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 218 over it, 3.18\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate/src/commands/setup.rs"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"cef5b887c194b470c30bc1ae9eb6da5314c9983ccb5d2b2977d83f02eba902a9"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: ServerSession: TooManyMethods \u2014 68 methods. The bar is 30 methods; this is 38 over it, 2.27\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/session.rs"},"region":{"startLine":129}}}],"partialFingerprints":{"codehealthFindingId/v1":"3c31bc2c5e5039844b3114769be210ceae38de42ca890becb316d98c5886b992"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFields: Model: TooManyFields \u2014 61 stored fields beside 7 methods. The bar is 30 stored fields; this is 31 over it, 2.03\u00D7 the bar. This is width in DATA, not behaviour: every reader that takes the whole type couples to all of its fields, so a change to any one of them is a change every reader has to be checked against. To reduce it, group the fields that are read together by the same callers into a smaller type of their own, and have this one hold that type as a single member \u2014 each reader then names only the group it uses."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-entities/src/Parameters.rs"},"region":{"startLine":185}}}],"partialFingerprints":{"codehealthFindingId/v1":"112ae297f09b8c4db5cc77e3a4583be0d7f6cea70006fb8c32891c974f4d91d8"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: Api.api_get_info: MethodTooLong \u2014 api_get_info runs 190 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 90 over it, 1.90\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/api/info.rs"},"region":{"startLine":164}}}],"partialFingerprints":{"codehealthFindingId/v1":"d77c918bf261c2c3e711f3eefeacf7db95d3577ec947ed5868f568e550f20784"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: HTTPProtocolServer.bind: MethodTooLong \u2014 bind runs 179 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 79 over it, 1.79\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/lib.rs"},"region":{"startLine":106}}}],"partialFingerprints":{"codehealthFindingId/v1":"bd28d4d4d788deb297d31c357c1e03100a8a1d2d194ea114d11c3cc246ee429d"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: client/mod.rs: FileTooLong \u2014 888 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 388 over it, 1.78\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/client/mod.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"84ab8344d467011e284d799577fcb431aaa9f0b5c83e79937c841b218904f9ab"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: warpgate_protocol_rdp::server::control_loop: FunctionTooLong \u2014 warpgate_protocol_rdp::server::control_loop runs 174 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 74 over it, 1.74\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-rdp/src/server/mod.rs"},"region":{"startLine":209}}}],"partialFingerprints":{"codehealthFindingId/v1":"65c6b6f015ab6fb49bf1286ba4ea48f4ad54f02a7b30c8fdff2478ae54e0b443"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: ServerSession.handle_remote_event: MethodTooLong \u2014 handle_remote_event runs 170 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 70 over it, 1.70\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/session.rs"},"region":{"startLine":1260}}}],"partialFingerprints":{"codehealthFindingId/v1":"48bc5c517d0d697df353e1d0713ec5e2b304ccfeb1ff88ca2a8a0e98cd291dc9"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: warpgate::commands::run::command: FunctionTooLong \u2014 warpgate::commands::run::command runs 164 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 64 over it, 1.64\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate/src/commands/run.rs"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7d3cce642c502b167a168b28206e98069b8bd2e63de22a6b31904d4df863590"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: DatabaseConfigProvider: ClassTooLong \u2014 630 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 3 methods, 3 blocks, lines 28-1016. The bar is 400 significant lines; this is 230 over it, 1.58\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/config_providers/db.rs"},"region":{"startLine":28}}}],"partialFingerprints":{"codehealthFindingId/v1":"a04524c3228cd93ef5ead78c317db50362b85f6ef08059f4f5d0d82eb82d7919"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFields: ParameterValues: TooManyFields \u2014 46 stored fields. The bar is 30 stored fields; this is 16 over it, 1.53\u00D7 the bar. This is width in DATA, not behaviour: every reader that takes the whole type couples to all of its fields, so a change to any one of them is a change every reader has to be checked against. To reduce it, group the fields that are read together by the same callers into a smaller type of their own, and have this one hold that type as a single member \u2014 each reader then names only the group it uses."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-admin/src/api/parameters.rs"},"region":{"startLine":61}}}],"partialFingerprints":{"codehealthFindingId/v1":"56247010e9fb7cfbeeb2675038047761a5c0cfd6e84d284b04f332fcbe93faaf"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyFields: ParameterUpdate: TooManyFields \u2014 46 stored fields. The bar is 30 stored fields; this is 16 over it, 1.53\u00D7 the bar. This is width in DATA, not behaviour: every reader that takes the whole type couples to all of its fields, so a change to any one of them is a change every reader has to be checked against. To reduce it, group the fields that are read together by the same callers into a smaller type of their own, and have this one hold that type as a single member \u2014 each reader then names only the group it uses."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-admin/src/api/parameters.rs"},"region":{"startLine":112}}}],"partialFingerprints":{"codehealthFindingId/v1":"202bc9a276172183a49d3bbdda667b83b61e80cf06bf28f4d5236212914328e3"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: config_providers/db.rs: FileTooLong \u2014 717 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), about 88% of them inside a single declaration: DatabaseConfigProvider (3 blocks, 28-1016). The bar is 500 significant lines; this is 217 over it, 1.43\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/config_providers/db.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"73e1f342199628a46da6d1a17de7c4c1ed89fd2a2264e261466572d1ad624907"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: Migration.up: MethodTooLong \u2014 up runs 143 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 43 over it, 1.43\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00044_ticket_requests.rs"},"region":{"startLine":87}}}],"partialFingerprints":{"codehealthFindingId/v1":"0c7149406b2626f9ed5e8ef6974c948d9f36845a5529b47cb14494a765f91e35"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: warpgate_protocol_kubernetes::server::handlers::_handle_normal_request_inner: FunctionTooLong \u2014 warpgate_protocol_kubernetes::server::handlers::_handle_normal_request_inner runs 135 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 35 over it, 1.35\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-kubernetes/src/server/handlers.rs"},"region":{"startLine":229}}}],"partialFingerprints":{"codehealthFindingId/v1":"53ac2c0edbbff7a010590789a7794d51c7ccc40c87a6ad4c87bfffe51b9373e8"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: AuditEvent: ClassTooLong \u2014 530 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 1 methods, 2 blocks, lines 35-662. The bar is 400 significant lines; this is 130 over it, 1.33\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-common/src/audit.rs"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"608243d5f41ca8272ae797549cbed0b0112c7ca56815d7e51c7c8cf93ee78eff"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: warpgate_core::db_auth::authorize_user: FunctionTooLong \u2014 warpgate_core::db_auth::authorize_user runs 125 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 25 over it, 1.25\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/db_auth.rs"},"region":{"startLine":189}}}],"partialFingerprints":{"codehealthFindingId/v1":"21bb20bb30979684d336477fdaab879ad8dd600b10fb1bc4088b63dbd487df84"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: MySqlClient.connect: MethodTooLong \u2014 connect runs 125 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 25 over it, 1.25\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-mysql/src/client.rs"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"445ae277ce6e6e2bf506d184d8f5362a74d7c87a3bdc3461445836a13f068c33"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: ServerSession.handle_server_handler_event: MethodTooLong \u2014 handle_server_handler_event runs 124 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 24 over it, 1.24\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/session.rs"},"region":{"startLine":1050}}}],"partialFingerprints":{"codehealthFindingId/v1":"b8339c350f16b440154a1e020a45b7b9575056c6d94511dd428df74a9c4285a3"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: api/users.rs: FileTooLong \u2014 619 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 119 over it, 1.24\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-admin/src/api/users.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"2c39b589fa40af3bce407800e09b479894156bdade3617285b37b39da9215040"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: config/mod.rs: FileTooLong \u2014 599 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 99 over it, 1.20\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-common/src/config/mod.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"f73d9250d36e6ad3711d9e41d1bc6950f3284ff5e2d8307fc1ffbd890017d83a"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: warpgate_protocol_vnc::server::negotiate_and_authorize: FunctionTooLong \u2014 warpgate_protocol_vnc::server::negotiate_and_authorize runs 119 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 19 over it, 1.19\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-vnc/src/server/mod.rs"},"region":{"startLine":163}}}],"partialFingerprints":{"codehealthFindingId/v1":"716164628f5c77dca2132b5674aeacd2fae043fa8df1dff77936eefa0585e233"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: Connector.authenticate_session: MethodTooLong \u2014 authenticate_session runs 117 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 17 over it, 1.17\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/client/mod.rs"},"region":{"startLine":872}}}],"partialFingerprints":{"codehealthFindingId/v1":"77c7d197634447a92af9a2ffb5cc46a4f951749abe76714202e4d5125663bac1"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: warpgate_core::ticket_requests::create_ticket_request: FunctionTooLong \u2014 warpgate_core::ticket_requests::create_ticket_request runs 116 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 16 over it, 1.16\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/ticket_requests.rs"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"d26e24ea0418ac84697e39ba5d261e096adacaeca0abf6d89b34644710112bfa"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: Api.api_return_to_sso_get_common: MethodTooLong \u2014 api_return_to_sso_get_common runs 115 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 15 over it, 1.15\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/api/sso_provider_list.rs"},"region":{"startLine":241}}}],"partialFingerprints":{"codehealthFindingId/v1":"0f864e17307c150dc2f3c1fb9a44c6c1156bbd96afa04b5a919e71957bb20b26"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: api/auth.rs: FileTooLong \u2014 570 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 70 over it, 1.14\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/api/auth.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b896d6c4d1907dad756e71a28449a20cda4f1a1c7e59120380f2489ae975e180"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/audit.rs: FileTooLong \u2014 551 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), about 96% of them inside a single declaration: AuditEvent (2 blocks, 35-662). The bar is 500 significant lines; this is 51 over it, 1.10\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-common/src/audit.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b8000253224c72226c6fc792b1e5d64ab5b1afb0ffeec011a7f99581b9876d88"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: Migration.up: MethodTooLong \u2014 up runs 109 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 9 over it, 1.09\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00035_ticket_user_target_id.rs"},"region":{"startLine":86}}}],"partialFingerprints":{"codehealthFindingId/v1":"f35c43c5f0014fdc5f731eae7eb64397c08a3d59a88ed472103e8f16ebdfe64b"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: PostgresClient.connect: MethodTooLong \u2014 connect runs 108 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 8 over it, 1.08\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-postgres/src/client.rs"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"a0b9164bb6328f260985dcde070b4a0b34a151a55f0b1b530f32fb502974e7af"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: api/credentials.rs: FileTooLong \u2014 528 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), about 66% of them inside a single declaration: Api (248-719). The bar is 500 significant lines; this is 28 over it, 1.06\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/api/credentials.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"5889895a1e0d99aba9d18da613e6c1ba21928db351410211e2cab594f11c9f9f"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: warpgate_protocol_kubernetes::server::handlers::_handle_websocket_request_inner: FunctionTooLong \u2014 warpgate_protocol_kubernetes::server::handlers::_handle_websocket_request_inner runs 104 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 4 over it, 1.04\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-kubernetes/src/server/handlers.rs"},"region":{"startLine":488}}}],"partialFingerprints":{"codehealthFindingId/v1":"5727cdddea4452f11611807c0352eb545f6f60e5630d3b79331313e21c5c5dd7"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: warpgate_protocol_vnc::server::protocol::read_client_messages: FunctionTooLong \u2014 warpgate_protocol_vnc::server::protocol::read_client_messages runs 104 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 4 over it, 1.04\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-vnc/src/server/protocol.rs"},"region":{"startLine":266}}}],"partialFingerprints":{"codehealthFindingId/v1":"752c47d550bc7eb3c629f19bc3605f0fdc969d9ff1fa920325db3ec90fb28c8c"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: client/mod.rs: FileTooLong \u2014 510 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 10 over it, 1.02\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-rdp/src/client/mod.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"16764eacc1d61812c02c269864993e3ca42e00b14f208d774f1e7b823859d38d"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: warpgate_desktop_auth::authenticate: FunctionTooLong \u2014 warpgate_desktop_auth::authenticate runs 102 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 2 over it, 1.02\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-desktop-auth/src/lib.rs"},"region":{"startLine":72}}}],"partialFingerprints":{"codehealthFindingId/v1":"a63cb041b5e1f2b8b2ee72dbb2d859a1e0fb566543565ad41b5febb8727e2b2a"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: ServerHandler: ClassTooLong \u2014 406 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 1 methods, 5 blocks, lines 103-619. The bar is 400 significant lines; this is 6 over it, 1.02\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/russh_handler.rs"},"region":{"startLine":103}}}],"partialFingerprints":{"codehealthFindingId/v1":"39e3d2fb7737e74cb8c0a81385c727bae15d90cb9e0aa2417dd4fe7cc6e83e3e"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: warpgate_protocol_http::proxy::proxy_ws_inner: FunctionTooLong \u2014 warpgate_protocol_http::proxy::proxy_ws_inner runs 101 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 1 over it, 1.01\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/proxy.rs"},"region":{"startLine":516}}}],"partialFingerprints":{"codehealthFindingId/v1":"8fe0372d0f5c7c548974b609bb1007e208964e68594d8b30fc239420ad66de1e"}},{"ruleId":"D4","level":"warning","message":{"text":"Near-duplicate member pair (50 shared lines): warpgate-db-migrations/src/m00078_assignment_composite_pks.rs:24-134 | warpgate-db-migrations/src/m00078_assignment_composite_pks.rs:136-240 \u2014 These two members are variants of one another: 50 of their lines are already reported as duplicated blocks below, spread through both bodies rather than gathered into one. Read them as a single construct written twice. The repair is at the members\u0027 grain \u2014 factor the shared pipeline into one implementation the two call with their differences as parameters or as an injected step, or, where the difference is systematic (sync against async, one transport against another), generate one from the other. Extracting the individual blocks below is not the same fix: it leaves the two bodies in place and the next edit still has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00078_assignment_composite_pks.rs"},"region":{"startLine":24}}}],"partialFingerprints":{"codehealthFindingId/v1":"fb1a5996160f5ee477bdd6e390ce10a1d75967b7bc117f7a529cfb23ffc3af1c"}},{"ruleId":"D4","level":"warning","message":{"text":"Members sharing a duplicated core (4 members, 50\u002B identical tokens): warpgate-common/src/auth/state.rs:463-476 | warpgate-core/src/approvals/subject.rs:61-74 | warpgate-core/src/approvals/subject.rs:76-89 | warpgate-core/src/approvals/subject.rs:91-104 \u2014 These 4 members share a duplicated core: a run of at least 50 identical tokens appears in every one of them. That run is NOT broken out as duplicated-block rows below \u2014 it is what admitted this row, and the blocks below cover only the part of it that clears the block floor, so they understate the correspondence. Read the members as one construct written 4 times. The repair is at the members\u0027 grain \u2014 factor the shared implementation out once and have all of them call it with their differences as parameters or as an injected step, or, where the difference is systematic, generate them from one template. Extracting the individual blocks below is not the same fix: it leaves every body in place and the next edit still has to be made 4 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-common/src/auth/state.rs"},"region":{"startLine":463}}}],"partialFingerprints":{"codehealthFindingId/v1":"2066c4047721ffc7ce12425e92ef5fbf56c14550c7b3117faf04f3e219d3c04d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (27 lines \u00D7 2): warpgate-db-migrations/src/m00073_redact_session_target_snapshots.rs:48-74 | warpgate-db-migrations/src/m00087_drop_null_target_options.rs:95-121 \u2014 before extracting anything, compare \u0060warpgate-db-migrations/src/m00073_redact_session_target_snapshots.rs\u0060 and \u0060warpgate-db-migrations/src/m00087_drop_null_target_options.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 39 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00073_redact_session_target_snapshots.rs"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"7a65611e7b907b9f3ec73cd8cd8d4e0b0126e5a7e6e08d6f51cdbf01e878ffd6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (18\u201320 lines \u00D7 2): warpgate-core/src/logging/json_console.rs:37-56 | warpgate-core/src/logging/layer.rs:50-67 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/logging/json_console.rs"},"region":{"startLine":37}}}],"partialFingerprints":{"codehealthFindingId/v1":"a851e168d5efaf3d202bdfeb5a59857e87ac25eaca0cc0807d064f0b14cea5ae"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16\u201318 lines \u00D7 2): warpgate-web-desktop/src/api.rs:29-44 | warpgate-web-ssh/src/api.rs:31-48 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web-desktop/src/api.rs"},"region":{"startLine":29}}}],"partialFingerprints":{"codehealthFindingId/v1":"b889a0c6ad55f5234edbe8b466c553c05070f9d018437395929fc1917493ff23"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): warpgate-protocol-rdp/src/server/mod.rs:140-154 | warpgate-protocol-vnc/src/server/mod.rs:100-113 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-rdp/src/server/mod.rs"},"region":{"startLine":140}}}],"partialFingerprints":{"codehealthFindingId/v1":"6617c535119e5f152348e84687a1289d6d7e1d7e3933ab4632e15eb2744aa9a5"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): warpgate-admin/src/api/otp_credentials.rs:149-161 | warpgate-admin/src/api/password_credentials.rs:159-171 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-admin/src/api/otp_credentials.rs"},"region":{"startLine":149}}}],"partialFingerprints":{"codehealthFindingId/v1":"3e1607c74bfa0ce9e484d36f0dcd59b8970018c46cb4c4d6a7e88b87503b506d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9\u201313 lines \u00D7 2): warpgate-db-migrations/src/m00072_session_node_id_not_null.rs:19-31 | warpgate-db-migrations/src/m00080_user_and_target_sessions.rs:232-240 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00072_session_node_id_not_null.rs"},"region":{"startLine":19}}}],"partialFingerprints":{"codehealthFindingId/v1":"9544d52ad61ebaa149d43446546963d47662e11117185a62a5bbf6101326976a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): warpgate-protocol-mysql/src/client.rs:98-110 | warpgate-protocol-postgres/src/client.rs:130-142 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-mysql/src/client.rs"},"region":{"startLine":98}}}],"partialFingerprints":{"codehealthFindingId/v1":"acb39287de06130aefae174e47dc90200edefc316f22ace9bfb9837459ca300b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): warpgate-protocol-ssh/src/server/session.rs:805-817 | warpgate-protocol-ssh/src/server/session.rs:2539-2552 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/session.rs"},"region":{"startLine":805}}}],"partialFingerprints":{"codehealthFindingId/v1":"d9ed80375772c4029f0cbcd9956b0b0e564af26a63afc86e97641fd741f02ba0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): warpgate-protocol-ssh/src/server/session.rs:2121-2133 | warpgate-protocol-ssh/src/server/session.rs:2159-2171 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/session.rs"},"region":{"startLine":2121}}}],"partialFingerprints":{"codehealthFindingId/v1":"9578b83414f86c24b65317032b746ba4e62ac1930c840a725249d50059362a21"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): warpgate-admin/src/api/certificate_credentials.rs:142-153 | warpgate-protocol-http/src/api/credentials.rs:638-649 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-admin/src/api/certificate_credentials.rs"},"region":{"startLine":142}}}],"partialFingerprints":{"codehealthFindingId/v1":"2a99249ab259c0c150c6501c1737271b637fca9ad80c53a63baf5dc415f46fd7"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8\u201312 lines \u00D7 2): warpgate-protocol-mysql/src/lib.rs:49-56 | warpgate-protocol-postgres/src/lib.rs:50-61 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-mysql/src/lib.rs"},"region":{"startLine":49}}}],"partialFingerprints":{"codehealthFindingId/v1":"05d4db166d806a599d940f666ccf414b16233b3c929b5a0850bcf7d9976b3317"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): warpgate-core/src/config_providers/db.rs:407-417 | warpgate-core/src/config_providers/db.rs:581-591 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/config_providers/db.rs"},"region":{"startLine":407}}}],"partialFingerprints":{"codehealthFindingId/v1":"41281f750267455b916666d7c9eacb16ed1531090ef2387427999c454ef2b59f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): warpgate-protocol-http/src/api/ticket_requests.rs:252-262 | warpgate-protocol-http/src/api/ticket_requests.rs:383-393 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/api/ticket_requests.rs"},"region":{"startLine":252}}}],"partialFingerprints":{"codehealthFindingId/v1":"d9d6cdbfcba3e9ed35226679718d574f263e74ecdbca11a9936ec2cbc99b9b83"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): warpgate-common/src/eventhub.rs:56-65 | warpgate-common/src/eventhub.rs:72-81 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-common/src/eventhub.rs"},"region":{"startLine":56}}}],"partialFingerprints":{"codehealthFindingId/v1":"7622f20b0951941318270a2dac84b446b62f067eebd40b3f577861c8daf402d4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): warpgate-core/src/config_providers/db.rs:823-832 | warpgate-core/src/config_providers/db.rs:884-893 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/config_providers/db.rs"},"region":{"startLine":823}}}],"partialFingerprints":{"codehealthFindingId/v1":"b2f2d590e52154dd7f3e46b2fe05e1693856c769e51e22220999cd7415df4414"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): warpgate-db-migrations/src/m00037_database_target_auth.rs:105-114 | warpgate-db-migrations/src/m00038_fix_target_auth_tags.rs:106-115 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00037_database_target_auth.rs"},"region":{"startLine":105}}}],"partialFingerprints":{"codehealthFindingId/v1":"ba065fe1d93af1ca3bc40cf24d7e2189e7b45051d59aba5da6d2125784ce1983"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): warpgate-protocol-http/src/api/auth.rs:449-458 | warpgate-protocol-http/src/api/auth.rs:601-610 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/api/auth.rs"},"region":{"startLine":449}}}],"partialFingerprints":{"codehealthFindingId/v1":"84727c564083c52e832dc7ef17832d12353927eff780feaddf92a2edc54806e1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): warpgate-protocol-ssh/src/server/session.rs:1442-1451 | warpgate-protocol-ssh/src/server/session.rs:1473-1482 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/session.rs"},"region":{"startLine":1442}}}],"partialFingerprints":{"codehealthFindingId/v1":"ca87fad793a90d78630d5ddb7e6e2a19560dbdc1319d0a66385038abdad97c72"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8\u20139 lines \u00D7 2): warpgate-admin/src/api/certificate_credentials.rs:194-201 | warpgate-admin/src/api/certificate_credentials.rs:226-234 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-admin/src/api/certificate_credentials.rs"},"region":{"startLine":194}}}],"partialFingerprints":{"codehealthFindingId/v1":"9fe8acf9cef3fb1b7ae6f8507c23f930885d2677e4f02354805cfa95bbea9fd9"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): warpgate-common/src/audit.rs:517-525 | warpgate-common/src/audit.rs:542-550 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-common/src/audit.rs"},"region":{"startLine":517}}}],"partialFingerprints":{"codehealthFindingId/v1":"b8de8ae6fc48f680e4219755f145f01e22ca0c947bf3583db846bb762eca5869"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): warpgate-common/src/audit.rs:586-594 | warpgate-common/src/audit.rs:613-621 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-common/src/audit.rs"},"region":{"startLine":586}}}],"partialFingerprints":{"codehealthFindingId/v1":"9331e9e5b4edd2a4be80faa1df40e89bb991fb1a0f3046041e784606e4721f02"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): warpgate-protocol-http/src/api/credentials.rs:439-447 | warpgate-protocol-http/src/api/credentials.rs:554-562 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/api/credentials.rs"},"region":{"startLine":439}}}],"partialFingerprints":{"codehealthFindingId/v1":"35c0739e9ad8aaf04352f090a1c37b72e7d71c76da0c65effc52da3894a2a2c1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 6): warpgate-common/src/audit.rs:516-523 | warpgate-common/src/audit.rs:541-548 | warpgate-common/src/audit.rs:563-570 | warpgate-common/src/audit.rs:585-592 | warpgate-common/src/audit.rs:612-619 | warpgate-common/src/audit.rs:643-650 \u2014 all 6 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-common/src/audit.rs"},"region":{"startLine":516}}}],"partialFingerprints":{"codehealthFindingId/v1":"c5990c183e5874bf6316e74b31653c0c6b65217234c71e5518f20621a8a6e0ed"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 3): warpgate-protocol-mysql/src/lib.rs:49-56 | warpgate-protocol-postgres/src/lib.rs:50-57 | warpgate-protocol-vnc/src/server/mod.rs:49-56 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 3 call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made 3 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-mysql/src/lib.rs"},"region":{"startLine":49}}}],"partialFingerprints":{"codehealthFindingId/v1":"157adcb0372c9c29ddbfc0544cfbda2e3423a54f7efe6ea3c6b0379246076c24"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): warpgate-admin/src/api/ldap_servers.rs:347-354 | warpgate-admin/src/api/ldap_servers.rs:413-420 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-admin/src/api/ldap_servers.rs"},"region":{"startLine":347}}}],"partialFingerprints":{"codehealthFindingId/v1":"83ee175f302b67ce77562c7db671bf7d82168d6be9178e956211bf0fd6b7b14d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): warpgate-admin/src/api/users.rs:669-676 | warpgate-admin/src/api/users.rs:723-730 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-admin/src/api/users.rs"},"region":{"startLine":669}}}],"partialFingerprints":{"codehealthFindingId/v1":"463a9a71f0c58a230b4e8257bf8b62a9e2fa184b128858eff81cae98adabfa2c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): warpgate-admin/src/api/users.rs:705-712 | warpgate-admin/src/api/users.rs:753-760 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-admin/src/api/users.rs"},"region":{"startLine":705}}}],"partialFingerprints":{"codehealthFindingId/v1":"f13abccc08afc2fff0665189f3cc7fb3b22a93c9a8c09910e66494d7ee2141e6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): warpgate-admin/src/api/users.rs:846-853 | warpgate-admin/src/api/users.rs:896-903 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-admin/src/api/users.rs"},"region":{"startLine":846}}}],"partialFingerprints":{"codehealthFindingId/v1":"639556a9bf43cdff0e20ee1d703e88180b49c4df1e472fd5da6a498c9f1dbeb8"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 4): warpgate-common/src/auth/state.rs:467-473 | warpgate-core/src/approvals/subject.rs:65-71 | warpgate-core/src/approvals/subject.rs:80-86 | warpgate-core/src/approvals/subject.rs:95-101 \u2014 there are 4 copies across 2 file(s) \u2014 more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 4 sites; resolving a subset leaves the remainder to drift apart."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-common/src/auth/state.rs"},"region":{"startLine":467}}}],"partialFingerprints":{"codehealthFindingId/v1":"bf6f10e4a19ad98995f5089ae82989f7307b40c9e720a16208b5c5d9b44c90e5"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): warpgate-core/src/ticket_requests.rs:173-179 | warpgate-core/src/ticket_requests.rs:202-208 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/ticket_requests.rs"},"region":{"startLine":173}}}],"partialFingerprints":{"codehealthFindingId/v1":"d7c825787bd227c09fc465f9204de431afd4188294c02c53b77b268ad61ccdec"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): warpgate-db-migrations/src/m00075_hash_ticket_and_api_token_secrets.rs:36-42 | warpgate-db-migrations/src/m00081_http_session_user_session_id.rs:104-110 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00075_hash_ticket_and_api_token_secrets.rs"},"region":{"startLine":36}}}],"partialFingerprints":{"codehealthFindingId/v1":"d5cd33859db917e3e3a5d50c5ae1527a67ed4e10c2d629815af84ec3e3bc1804"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): warpgate-protocol-vnc/src/server/protocol.rs:375-381 | warpgate-protocol-vnc/src/server/protocol.rs:390-397 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-vnc/src/server/protocol.rs"},"region":{"startLine":375}}}],"partialFingerprints":{"codehealthFindingId/v1":"cb1a8860f3eca540946644b6196843c07895cd55f16719e7c8401b8a64406127"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 3): warpgate-db-migrations/src/m00073_redact_session_target_snapshots.rs:53-58 | warpgate-db-migrations/src/m00080_user_and_target_sessions.rs:64-69 | warpgate-db-migrations/src/m00087_drop_null_target_options.rs:100-105 \u2014 before extracting anything, compare \u0060warpgate-db-migrations/src/m00073_redact_session_target_snapshots.rs\u0060 and \u0060warpgate-db-migrations/src/m00087_drop_null_target_options.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 39 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00073_redact_session_target_snapshots.rs"},"region":{"startLine":53}}}],"partialFingerprints":{"codehealthFindingId/v1":"5ce6cfd356bfa7ef68393aa12e2dcf5a832ecc3cf8e57dd7fc1c9b58f6912794"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 3): warpgate-db-migrations/src/m00073_redact_session_target_snapshots.rs:62-67 | warpgate-db-migrations/src/m00080_user_and_target_sessions.rs:74-79 | warpgate-db-migrations/src/m00087_drop_null_target_options.rs:109-114 \u2014 before extracting anything, compare \u0060warpgate-db-migrations/src/m00073_redact_session_target_snapshots.rs\u0060 and \u0060warpgate-db-migrations/src/m00087_drop_null_target_options.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 39 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00073_redact_session_target_snapshots.rs"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"5390d0f33a835cfaaf10b0af05aacb525ca5fa28ead6f96114f87f053dd5bda1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): warpgate-protocol-http/src/api/web_desktop.rs:146-151 | warpgate-protocol-http/src/api/web_desktop.rs:178-183 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/api/web_desktop.rs"},"region":{"startLine":146}}}],"partialFingerprints":{"codehealthFindingId/v1":"04795c89a2fada3d8a5bd975d2ac4d1cd5fe1268000271ac5098bf638b04146b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): warpgate-core/src/recordings/traffic.rs:186-190 | warpgate-core/src/recordings/traffic.rs:198-202 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/recordings/traffic.rs"},"region":{"startLine":186}}}],"partialFingerprints":{"codehealthFindingId/v1":"a936a5eae6481ea19ebacc87a69f4c584139f65a71d2f69682692be3dcfbc20a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 4): warpgate-protocol-mysql/src/session_handle.rs:9-18 | warpgate-protocol-postgres/src/session_handle.rs:9-18 | warpgate-protocol-rdp/src/session_handle.rs:9-18 | warpgate-protocol-vnc/src/server/session_handle.rs:9-18 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 4 call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made 4 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-mysql/src/session_handle.rs"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"a87f23513c7f83fe814dd4550f1942ff22e34078c15d8874e11c49d6f15e711f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): warpgate-common/src/helpers/serde_base64.rs:13-19 | warpgate-db-migrations/src/m00009_credential_models.rs:174-180 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-common/src/helpers/serde_base64.rs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"e07f4c85daa7951af0a2586c5e18cfb7f670738b28f7bdd21139b6cbd2793b59"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): warpgate-core/src/recordings/desktop.rs:238-243 | warpgate-core/src/recordings/terminal.rs:99-104 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/recordings/desktop.rs"},"region":{"startLine":238}}}],"partialFingerprints":{"codehealthFindingId/v1":"170c687214a4a575af5426f575511bb2022218673fd420baae501bc46f4a378d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 8): warpgate-db-entities/src/ApiToken.rs:25-33 | warpgate-db-entities/src/CertificateCredential.rs:28-36 | warpgate-db-entities/src/OtpCredential.rs:23-31 | warpgate-db-entities/src/PasswordCredential.rs:23-31 | warpgate-db-entities/src/PublicKeyCredential.rs:28-36 | warpgate-db-entities/src/SsoCredential.rs:24-32 | warpgate-db-migrations/src/m00014_api_tokens.rs:31-39 | warpgate-db-migrations/src/m00028_certificate_credentials.rs:33-41 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere all 8 call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made 8 times."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-entities/src/ApiToken.rs"},"region":{"startLine":25}}}],"partialFingerprints":{"codehealthFindingId/v1":"fdbf59a082346a72895fd3f7a006a43dbc0437883d5333ebcc4a11fdbad039eb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): warpgate-db-migrations/src/m00058_analytics.rs:10-19 | warpgate-db-migrations/src/m00063_recordings_storage.rs:13-22 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00058_analytics.rs"},"region":{"startLine":10}}}],"partialFingerprints":{"codehealthFindingId/v1":"b182934d7379cdb043da0dbfbc558f56605783575f3827a604a0627e7e372b6b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): warpgate-db-migrations/src/m00058_analytics.rs:21-30 | warpgate-db-migrations/src/m00063_recordings_storage.rs:24-33 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00058_analytics.rs"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"b14eef5340939fccc382b4739814708a74a62743a92a4368059c52b21ffaa3d4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): warpgate-protocol-http/src/api/web_desktop.rs:197-203 | warpgate-protocol-http/src/api/web_ssh.rs:178-184 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/api/web_desktop.rs"},"region":{"startLine":197}}}],"partialFingerprints":{"codehealthFindingId/v1":"6fb1864c1753bead50e4fa7f764cd1554aac0c65806b9d9f533d8587ea58778b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): warpgate-protocol-http/src/api/web_desktop.rs:207-214 | warpgate-protocol-http/src/api/web_ssh.rs:188-195 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/api/web_desktop.rs"},"region":{"startLine":207}}}],"partialFingerprints":{"codehealthFindingId/v1":"a8c83bc09dc2038f5a334db64b16a7e07029f1362b86bd730c5f21bc7003a574"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): warpgate-protocol-mysql/src/stream.rs:95-103 | warpgate-protocol-postgres/src/stream.rs:158-165 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-mysql/src/stream.rs"},"region":{"startLine":95}}}],"partialFingerprints":{"codehealthFindingId/v1":"2d435aa7ec59c847303928a1892c87c959531fe457bd5a9987b673ee196c077a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): warpgate-admin/src/api/admin_scheme.rs:162-168 | warpgate-protocol-http/src/api/auth_scheme.rs:55-61 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-admin/src/api/admin_scheme.rs"},"region":{"startLine":162}}}],"partialFingerprints":{"codehealthFindingId/v1":"19d6cafea064c7355901405cb61a732b04a5300d178faa4e14a4595756bbb6d1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): warpgate-db-migrations/src/m00010_parameters.rs:32-39 | warpgate-db-migrations/src/m00020_ldap_server.rs:45-52 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00010_parameters.rs"},"region":{"startLine":32}}}],"partialFingerprints":{"codehealthFindingId/v1":"7cfdb7fa64b0fb00a87e08627d3a50091059c9d8cbf1e35dc6d05f8a84fbb27f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 2): warpgate-db-migrations/src/m00010_parameters.rs:41-46 | warpgate-db-migrations/src/m00020_ldap_server.rs:54-59 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00010_parameters.rs"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"c4e253b128a13fda542f532b2c85720dcc35f4b98c2910d710eccd0a315762b1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): warpgate-db-migrations/src/m00078_assignment_composite_pks.rs:47-74 | warpgate-db-migrations/src/m00078_assignment_composite_pks.rs:153-169 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00078_assignment_composite_pks.rs"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"2dc1b7f527b7d5e37172db1b45addb9ee60c848b9c4d18e06935e95e817ce818"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (20 lines \u00D7 2): warpgate-db-migrations/src/m00078_assignment_composite_pks.rs:88-108 | warpgate-db-migrations/src/m00078_assignment_composite_pks.rs:179-198 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00078_assignment_composite_pks.rs"},"region":{"startLine":88}}}],"partialFingerprints":{"codehealthFindingId/v1":"9696346c7ec06deba3da2512823992a6a89135e86dbc4b6ec20cfb88283849d7"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): warpgate-db-migrations/src/m00025_ssh_client_auth.rs:28-42 | warpgate-db-migrations/src/m00044_ticket_requests.rs:135-151 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00025_ssh_client_auth.rs"},"region":{"startLine":28}}}],"partialFingerprints":{"codehealthFindingId/v1":"41e3adff5ecf2d9d154f9c9505f63fec0f8eba1da0a47a0946bef4446ec574d0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): warpgate-db-migrations/src/m00034_add_log_related_fields.rs:25-41 | warpgate-db-migrations/src/m00034_add_log_related_fields.rs:48-64 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00034_add_log_related_fields.rs"},"region":{"startLine":25}}}],"partialFingerprints":{"codehealthFindingId/v1":"d54685da28f70f8c929c7df9519cb781e75e75e10fff78e791e9b98dc83e7294"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 4): warpgate-db-migrations/src/m00044_ticket_requests.rs:121-137 | warpgate-db-migrations/src/m00044_ticket_requests.rs:176-192 | warpgate-db-migrations/src/m00050_password_policy.rs:23-39 | warpgate-db-migrations/src/m00050_password_policy.rs:51-67 \u2014 there are 4 copies across 2 file(s) \u2014 more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 4 sites; resolving a subset leaves the remainder to drift apart."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00044_ticket_requests.rs"},"region":{"startLine":121}}}],"partialFingerprints":{"codehealthFindingId/v1":"f782a6f42c4cd9742f0891ee376e643cae6fe3fc989b82887334220f08d9d6af"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): warpgate-db-migrations/src/m00025_ssh_client_auth.rs:66-79 | warpgate-db-migrations/src/m00086_jit_session_approval.rs:162-177 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00025_ssh_client_auth.rs"},"region":{"startLine":66}}}],"partialFingerprints":{"codehealthFindingId/v1":"41dc7b543bfcfd2b156f0f03b23c2ae3bf089842cde61aec776b23d77ec06577"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): warpgate-db-migrations/src/m00019_rate_limits.rs:38-52 | warpgate-db-migrations/src/m00044_ticket_requests.rs:201-216 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00019_rate_limits.rs"},"region":{"startLine":38}}}],"partialFingerprints":{"codehealthFindingId/v1":"eb8662f5eb5f1e779b1b39983646614bff71bd5d2c464962db0298e46d5659fc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): warpgate-db-migrations/src/m00044_ticket_requests.rs:219-234 | warpgate-db-migrations/src/m00086_jit_session_approval.rs:66-81 \u2014 before extracting anything, compare \u0060warpgate-db-migrations/src/m00044_ticket_requests.rs\u0060 and \u0060warpgate-db-migrations/src/m00086_jit_session_approval.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 46 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00044_ticket_requests.rs"},"region":{"startLine":219}}}],"partialFingerprints":{"codehealthFindingId/v1":"1f94150d46b4a1f92513611ce64baee91b3eeb6801ad5c628f65707d74f8f54b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): warpgate-db-migrations/src/m00044_ticket_requests.rs:106-121 | warpgate-db-migrations/src/m00086_jit_session_approval.rs:100-115 \u2014 before extracting anything, compare \u0060warpgate-db-migrations/src/m00044_ticket_requests.rs\u0060 and \u0060warpgate-db-migrations/src/m00086_jit_session_approval.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 46 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00044_ticket_requests.rs"},"region":{"startLine":106}}}],"partialFingerprints":{"codehealthFindingId/v1":"af431e177dfb9412f9e7f6316fa9e9e07785233f948b562827be659bfa003a52"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2): warpgate-common/src/audit.rs:219-234 | warpgate-common/src/audit.rs:252-267 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-common/src/audit.rs"},"region":{"startLine":219}}}],"partialFingerprints":{"codehealthFindingId/v1":"bbf2cde50c3508626552ae323cb2a98ebdc9b8f843c6cfdc2e4cf4b67a27e1eb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 4): warpgate-db-migrations/src/m00025_ssh_client_auth.rs:42-56 | warpgate-db-migrations/src/m00037_show_session_menu.rs:16-30 | warpgate-db-migrations/src/m00047_record_scp.rs:11-25 | warpgate-db-migrations/src/m00083_record_desktop_keyboard_input.rs:11-25 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from all 4 call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00025_ssh_client_auth.rs"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"97aaef4772cc423ec120e16a55c6355551b693ff8bf171ca4bb9fe2796969eb4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 5): warpgate-db-migrations/src/m00044_ticket_requests.rs:120-134 | warpgate-db-migrations/src/m00044_ticket_requests.rs:175-189 | warpgate-db-migrations/src/m00050_password_policy.rs:22-36 | warpgate-db-migrations/src/m00050_password_policy.rs:50-64 | warpgate-db-migrations/src/m00084_mfa_enforcement.rs:22-35 \u2014 there are 5 copies across 3 file(s) \u2014 more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 5 sites; resolving a subset leaves the remainder to drift apart."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00044_ticket_requests.rs"},"region":{"startLine":120}}}],"partialFingerprints":{"codehealthFindingId/v1":"24886dfe184f94e144cb8f9b719cfcf7dfde4fa16cba914a1f2115f062a28aa7"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): warpgate-db-migrations/src/m00078_assignment_composite_pks.rs:116-130 | warpgate-db-migrations/src/m00078_assignment_composite_pks.rs:203-215 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00078_assignment_composite_pks.rs"},"region":{"startLine":116}}}],"partialFingerprints":{"codehealthFindingId/v1":"bcaef65c0bfc590130ebaa7b889427418fc7b2777b982b0da4cbdbeaf93098fd"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2): warpgate-db-migrations/src/m00031_minimize_password_login.rs:16-30 | warpgate-db-migrations/src/m00050_password_policy.rs:67-81 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00031_minimize_password_login.rs"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"152e55f3e82782117b5c1efc605b641a02254fa5b7be2c0565c998abf4a52a89"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 4): warpgate-common/src/audit.rs:314-327 | warpgate-common/src/audit.rs:334-347 | warpgate-common/src/audit.rs:354-367 | warpgate-common/src/audit.rs:374-387 \u2014 all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-common/src/audit.rs"},"region":{"startLine":314}}}],"partialFingerprints":{"codehealthFindingId/v1":"c2b0dc6f3f0503f9953159b264ba15fc0d0c0763f6225c1b7cb17b63a999eeae"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 3): warpgate-db-migrations/src/m00044_ticket_requests.rs:221-234 | warpgate-db-migrations/src/m00044_ticket_requests.rs:235-248 | warpgate-db-migrations/src/m00086_jit_session_approval.rs:68-81 \u2014 before extracting anything, compare \u0060warpgate-db-migrations/src/m00044_ticket_requests.rs\u0060 and \u0060warpgate-db-migrations/src/m00086_jit_session_approval.rs\u0060 as WHOLE FILES: this scan already matched 3 separate duplicated blocks between them, totalling at least 46 lines, which is the signature of one file having been copied from the other rather than of a helper waiting to be extracted. If that is what happened, the fix is to keep one copy and have the other call it (or delete it), which resolves this row and its siblings together \u2014 extracting one helper per block leaves the fork in place."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00044_ticket_requests.rs"},"region":{"startLine":221}}}],"partialFingerprints":{"codehealthFindingId/v1":"dfe9698d31ca1af3a8a2b6df070b459e08d18de274795ecb091752afab4cf949"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): warpgate-db-migrations/src/m00041_fix_user_role_assignment_dates.rs:21-34 | warpgate-db-migrations/src/m00041_fix_user_role_assignment_dates.rs:35-48 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00041_fix_user_role_assignment_dates.rs"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"909073fc5e3eb68d5da03fd5ccab933cea10f3a3023617fa729c8a6bde494a3d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): warpgate-common/src/audit.rs:394-407 | warpgate-common/src/audit.rs:413-426 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-common/src/audit.rs"},"region":{"startLine":394}}}],"partialFingerprints":{"codehealthFindingId/v1":"502c30b8d217fb42c39bcaf565df0f5b08cad5420d0e75d123a8414a7f6eab7b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): warpgate-db-migrations/src/m00017_descriptions.rs:96-109 | warpgate-db-migrations/src/m00019_rate_limits.rs:64-77 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00017_descriptions.rs"},"region":{"startLine":96}}}],"partialFingerprints":{"codehealthFindingId/v1":"7e832981312f78e9816e4dc6ff06cda8023e3cc9d1e9ba50d9913321f2e638e5"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 3): warpgate-db-migrations/src/m00025_ssh_client_auth.rs:60-71 | warpgate-db-migrations/src/m00027_ca.rs:97-109 | warpgate-db-migrations/src/m00084_mfa_enforcement.rs:40-51 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from all 3 call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00025_ssh_client_auth.rs"},"region":{"startLine":60}}}],"partialFingerprints":{"codehealthFindingId/v1":"945a74039597f0bb30ecc63ae72a27bde554b49d9e8fe8ebeed413f46dadf00a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): warpgate-web-desktop/src/manager.rs:76-88 | warpgate-web-ssh/src/manager.rs:68-80 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web-desktop/src/manager.rs"},"region":{"startLine":76}}}],"partialFingerprints":{"codehealthFindingId/v1":"403fbf4bc4cc9bbf31465b5ee29bb9d7b9513d64c7288a75a5515717cf7ac51c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): warpgate-db-migrations/src/m00027_ca.rs:40-52 | warpgate-db-migrations/src/m00027_ca.rs:53-65 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00027_ca.rs"},"region":{"startLine":40}}}],"partialFingerprints":{"codehealthFindingId/v1":"3026acbf89dfab367f455e453d599c302ae8510719d46b4bc860d7b97df8503f"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): warpgate-db-migrations/src/m00080_user_and_target_sessions.rs:166-178 | warpgate-db-migrations/src/m00082_target_session_columns.rs:112-121 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00080_user_and_target_sessions.rs"},"region":{"startLine":166}}}],"partialFingerprints":{"codehealthFindingId/v1":"dc330c83a7cfade61f8f98ed7891bd5b80451b4576c985365700c1d14a8f5ea7"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 2): warpgate-db-migrations/src/m00057_password_login_mode.rs:35-47 | warpgate-db-migrations/src/m00057_password_login_mode.rs:71-83 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00057_password_login_mode.rs"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"9f46825b42dd2c62ee45b4943a0f30deb48702bdcf9d58d617ba0581af258881"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): warpgate-admin/src/api/certificate_credentials.rs:253-263 | warpgate-admin/src/api/public_key_credentials.rs:282-292 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-admin/src/api/certificate_credentials.rs"},"region":{"startLine":253}}}],"partialFingerprints":{"codehealthFindingId/v1":"1dbda67773b1d30eccfbbe3d19f86b4d1f378287fabd56b1db972c57518361c6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): warpgate-protocol-http/src/api/credentials.rs:408-417 | warpgate-protocol-http/src/api/credentials.rs:642-651 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/api/credentials.rs"},"region":{"startLine":408}}}],"partialFingerprints":{"codehealthFindingId/v1":"1201c21ed4bc6e5441774a9d3b261532d8e3c99e9feeae35fbb14f2612da32cc"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): warpgate-protocol-http/src/api/credentials.rs:462-471 | warpgate-protocol-http/src/api/credentials.rs:593-602 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/api/credentials.rs"},"region":{"startLine":462}}}],"partialFingerprints":{"codehealthFindingId/v1":"7267077b3d981e94b50d14c7c5a90caa2749e457a9735ca743eaaa810779c886"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): warpgate-aws/src/region.rs:14-23 | warpgate-aws/src/region.rs:34-43 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-aws/src/region.rs"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"db39f165daff2c358cb20e30af3b87d63b0433814168b5538f2abaf0cbdfeb8e"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): warpgate-admin/src/api/certificate_credentials.rs:146-155 | warpgate-admin/src/api/public_key_credentials.rs:164-173 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-admin/src/api/certificate_credentials.rs"},"region":{"startLine":146}}}],"partialFingerprints":{"codehealthFindingId/v1":"69bf79eba9a4f14ef7da823da2b91c363a177964975f03f3a752c94c4e648cca"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): warpgate-protocol-ssh/src/server/session.rs:2036-2045 | warpgate-protocol-ssh/src/server/session.rs:2085-2094 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/session.rs"},"region":{"startLine":2036}}}],"partialFingerprints":{"codehealthFindingId/v1":"d59d999dac92f965818d3a21ad85530790c00e5adea439ed802d2e8e5b466ce4"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): warpgate-db-migrations/src/m00041_fix_user_role_assignment_dates.rs:70-78 | warpgate-db-migrations/src/m00041_fix_user_role_assignment_dates.rs:79-87 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00041_fix_user_role_assignment_dates.rs"},"region":{"startLine":70}}}],"partialFingerprints":{"codehealthFindingId/v1":"41650aec6fb5305892bba4eb0b0026f8b35ce23a52cc7d2a5b729fe7040e290b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): warpgate-db-migrations/src/m00036_user_role_expiry_history.rs:13-21 | warpgate-db-migrations/src/m00036_user_role_expiry_history.rs:22-30 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-db-migrations/src/m00036_user_role_expiry_history.rs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"4c2310fca23f0f3231c166a627ecd3ad175d9f22f37979bcb6c25e69d805a07b"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): warpgate-protocol-ssh/src/server/session.rs:1086-1092 | warpgate-protocol-ssh/src/server/session.rs:1694-1700 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/session.rs"},"region":{"startLine":1086}}}],"partialFingerprints":{"codehealthFindingId/v1":"168dbd5162d72219643a3f9e02d0e609a5ea9d290e92c3d12f3218c1fa2aef94"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): warpgate-admin/src/api/recordings_detail.rs:106-110 | warpgate-admin/src/api/recordings_detail.rs:123-127 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-admin/src/api/recordings_detail.rs"},"region":{"startLine":106}}}],"partialFingerprints":{"codehealthFindingId/v1":"0c621235dcd0868bd30bdd4f45b4cbdc43c035115660115dc9600cf620eaff32"}},{"ruleId":"D5","level":"warning","message":{"text":"Unstable project warpgate-web-desktop: warpgate-web-desktop has instability 0.88 with 1 dependents."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"21748809ece731fbdb0b063298cfb3779dc26fd32dc5782ac7a53f14149db03e"}},{"ruleId":"D5","level":"warning","message":{"text":"Unstable project warpgate-web-ssh: warpgate-web-ssh has instability 0.86 with 1 dependents."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"08ea3957dda480d507def8fd3152523a44494fa55912bc05fc44ead0e513eacd"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: warpgate-aws: warpgate-aws: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and depended on by 8 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"604865142f0039263e94387cb3c30ebacb17cea526d13015b959c90721006552"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: warpgate-ca: warpgate-ca: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and depended on by 7 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"86d329f6d7eedc2afe945bb51d20fcd3867b81746dbe00ff2cef611e6f870ec3"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: warpgate-sso: warpgate-sso: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and depended on by 4 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f840fff5c13500d12e7bb97fa07587e2d99a8fdc7d551c1dee968ad01dfc7605"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: warpgate-admin: warpgate-admin: abstractness 0.08, instability 0.00, distance 0.92 \u2014 an application entry point, so it is concrete by design \u2014 the distance is expected; what is worth checking is that other projects depend on it at all, since a host should be a leaf of the graph."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7d0073a833698144165162c6b74451a243f027f44719f16d0b855615f13d13f4"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: warpgate-db-entities: warpgate-db-entities: abstractness 0.00, instability 0.24, distance 0.76 \u2014 zone of pain \u2014 concrete and depended on by 13 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"76f60ce03ccb0c020ce69f3a0d7e7bf144e09b2f4b848f262281cfe59c073304"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: warpgate-common-http: warpgate-common-http: abstractness 0.00, instability 0.25, distance 0.75 \u2014 the shape a shared-kernel / building-block library has BY DESIGN \u2014 concrete and widely depended-on is what makes it useful, and this dimension does not penalise it (the distance is reported for completeness, not as a defect). Worth a look only if it has grown past one coherent kernel into an everything-bucket."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"fb3d8beef7ccde39925d5cf13e0b1472b47d7142fac770203b9b51374447ea6a"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: warpgate-database-protocols: warpgate-database-protocols: abstractness 0.25, instability 0.00, distance 0.75 \u2014 zone of pain \u2014 concrete and depended on by 1 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e316c31d06b6c33910058f881c1ff14980dd92e9575b909b7fcad5d48f528c9c"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: warpgate-desktop-ui: warpgate-desktop-ui: abstractness 0.00, instability 0.25, distance 0.75 \u2014 zone of pain \u2014 concrete and depended on by 3 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f13cbb97c599775fddc397da9bb158e98b43181d5e92239e2308f5a32275a2de"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: warpgate-ldap: warpgate-ldap: abstractness 0.00, instability 0.25, distance 0.75 \u2014 zone of pain \u2014 concrete and depended on by 3 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3524a4cea3be87c4ae92a80ce9f39e4e0572697da6ec3c234dcdc8d0878a134e"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: warpgate-tls: warpgate-tls: abstractness 0.18, instability 0.08, distance 0.74 \u2014 zone of pain \u2014 concrete and depended on by 12 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"8c59a981fa21e4f8ef9cd254e647b7ba27eb966eb51a244500267fa0a1e6f993"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: warpgate-common: warpgate-common: abstractness 0.07, instability 0.22, distance 0.71 \u2014 the shape a shared-kernel / building-block library has BY DESIGN \u2014 concrete and widely depended-on is what makes it useful, and this dimension does not penalise it (the distance is reported for completeness, not as a defect). Worth a look only if it has grown past one coherent kernel into an everything-bucket."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6c413298450c312953dee9a48560523efc89be068891256ae459317218f7aa51"}},{"ruleId":"D13","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"632a847ae41fd6ed053fcf2343be0f804cb2f757a3352d1f35fd607aab47f309"},"taxa":[{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: warpgate-protocol-ssh/src/server/session.rs: warpgate-protocol-ssh/src/server/session.rs changed 34 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 47 in ServerSession::handle_remote_event at line 1260. 17 of those changes were fix/bug commits, and the other 17 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-protocol-ssh/src/server/session.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/session.rs"},"region":{"startLine":1260}}}],"partialFingerprints":{"codehealthFindingId/v1":"39a90e163098fb0a4107f3a3cd1b7ca5b5cc7d10b0ef9ef4a505137b0435fd5d"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: warpgate-protocol-rdp/src/server/mod.rs: warpgate-protocol-rdp/src/server/mod.rs changed 14 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 34 in warpgate_protocol_rdp::server::control_loop at line 209. 6 of those changes were fix/bug commits, and the other 8 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-protocol-rdp/src/server/mod.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-rdp/src/server/mod.rs"},"region":{"startLine":209}}}],"partialFingerprints":{"codehealthFindingId/v1":"ebc51ee445f2f8e00a872d627315eb5d23e959327a5046720d606f5dc3a0cbd0"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: warpgate/src/commands/setup.rs: warpgate/src/commands/setup.rs changed 9 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 49 in warpgate::commands::setup::command at line 52. 3 of those changes were fix/bug commits, and the other 6 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate/src/commands/setup.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate/src/commands/setup.rs"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"a39525239aa3e16abfa2ae661cb76edf6c89190f6a974ec1d2737382c4ae8a9a"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: warpgate/src/commands/run.rs: warpgate/src/commands/run.rs changed 15 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 23 in warpgate::commands::run::command at line 62. 2 of those changes were fix/bug commits, and the other 13 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate/src/commands/run.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate/src/commands/run.rs"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"a4c4e23512cb27925a0aee08dc5697cbfab420a7c7b8d2b0ddd31ab177dac74a"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: warpgate-protocol-rdp/src/client/mod.rs: warpgate-protocol-rdp/src/client/mod.rs changed 15 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 22 in warpgate_protocol_rdp::client::active_loop at line 153. 6 of those changes were fix/bug commits, and the other 9 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-protocol-rdp/src/client/mod.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-rdp/src/client/mod.rs"},"region":{"startLine":153}}}],"partialFingerprints":{"codehealthFindingId/v1":"26211a73bbc5b3de2676a67c6b85c7a04c4ee009d398d17b1e57b6c45d08fddb"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: warpgate-protocol-http/src/api/info.rs: warpgate-protocol-http/src/api/info.rs changed 16 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 19 in Api::api_get_info at line 164. 6 of those changes were fix/bug commits, and the other 10 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-protocol-http/src/api/info.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/api/info.rs"},"region":{"startLine":164}}}],"partialFingerprints":{"codehealthFindingId/v1":"f1339c48dd1ddffb6503bb95d83814b70a435c3b5c9d978449bd1a98d8096152"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: warpgate-protocol-kubernetes/src/server/handlers.rs: warpgate-protocol-kubernetes/src/server/handlers.rs changed 10 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 24 in warpgate_protocol_kubernetes::server::handlers::_handle_normal_request_inner at line 229. 1 of those changes was a fix/bug commit, and the other 9 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-protocol-kubernetes/src/server/handlers.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-kubernetes/src/server/handlers.rs"},"region":{"startLine":229}}}],"partialFingerprints":{"codehealthFindingId/v1":"c8adac7104a71020917ae833b83725db4b7f5183ee253a0f2ffb005d4e977243"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: warpgate-protocol-rdp/src/server/hold_screen.rs: warpgate-protocol-rdp/src/server/hold_screen.rs changed 11 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 16 in warpgate_protocol_rdp::server::hold_screen::scancode_otp_action at line 277. 3 of those changes were fix/bug commits, and the other 8 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-protocol-rdp/src/server/hold_screen.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-rdp/src/server/hold_screen.rs"},"region":{"startLine":277}}}],"partialFingerprints":{"codehealthFindingId/v1":"00e4f1d85e1c9f4b04e054287015ecb7f0372bb90a1a1181294edcb216863674"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: warpgate-web-ssh/src/manager.rs: warpgate-web-ssh/src/manager.rs changed 10 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 15 in warpgate_web_ssh::manager::spawn_event_loop at line 134. 4 of those changes were fix/bug commits, and the other 6 changed it for other reasons \u2014 this file is under both repair and feature pressure. Before the next change lands here, make sure the area it touches is under test, then split that area out of the file so the following change is smaller than this one \u2014 a file this often edited pays the complexity back every time. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-web-ssh/src/manager.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web-ssh/src/manager.rs"},"region":{"startLine":134}}}],"partialFingerprints":{"codehealthFindingId/v1":"2a4d90cf2abe8fa5b5702f7ebef3ce6b348b2bc064a896ee579348348c4a76ac"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: warpgate-common/src/error.rs: warpgate-common/src/error.rs changed 7 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 21 in WarpgateError::user_facing_reason at line 104. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-common/src/error.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-common/src/error.rs"},"region":{"startLine":104}}}],"partialFingerprints":{"codehealthFindingId/v1":"517fe4995998556a9d64717ef3193287db472a49b23176f80cb7926d375822e6"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: warpgate-protocol-mysql/src/client.rs: warpgate-protocol-mysql/src/client.rs changed 7 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 19 in MySqlClient::connect at line 41. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-protocol-mysql/src/client.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-mysql/src/client.rs"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"7aeac00eac0b2764ef22e90875876c80613aaa61820e3ff3349172ac0e3f1002"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: warpgate-web-desktop/src/api.rs: warpgate-web-desktop/src/api.rs changed 6 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 21 in warpgate_web_desktop::api::ws_handler at line 19. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-web-desktop/src/api.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web-desktop/src/api.rs"},"region":{"startLine":19}}}],"partialFingerprints":{"codehealthFindingId/v1":"f6d806adb6efad2a219f538eedd22881aad3eeb688b38c68d4dbe7bf8701dbe4"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: warpgate-web-ssh/src/api.rs: warpgate-web-ssh/src/api.rs changed 7 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 18 in warpgate_web_ssh::api::ws_handler at line 20. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-web-ssh/src/api.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web-ssh/src/api.rs"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"75098da5087e0e742ada9317e8cf20869abdff61b085f09fe39bcd801c4ca072"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: warpgate-core/src/ticket_requests.rs: warpgate-core/src/ticket_requests.rs changed 6 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 17 in warpgate_core::ticket_requests::create_ticket_request at line 57. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-core/src/ticket_requests.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/ticket_requests.rs"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"3c476dc18351154d0430eec47f207aa50241675c8e3293645746e8964f798ba4"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: warpgate-protocol-postgres/src/client.rs: warpgate-protocol-postgres/src/client.rs changed 5 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 18 in PostgresClient::connect at line 59. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-protocol-postgres/src/client.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-postgres/src/client.rs"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"0b8453d95531acc268f3ac936097710986de12b16811bd550f40f152684b3608"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: warpgate-protocol-http/src/catchall.rs: warpgate-protocol-http/src/catchall.rs changed 6 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 15 in warpgate_protocol_http::catchall::get_target_for_request at line 128. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-protocol-http/src/catchall.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-http/src/catchall.rs"},"region":{"startLine":128}}}],"partialFingerprints":{"codehealthFindingId/v1":"613df1534c747bb0010c30e4564aec9aaba810c963a638176ad4eb4eab4eeebb"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: warpgate-common/src/audit.rs: warpgate-common/src/audit.rs changed 4 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 22 in AuditEvent::emit at line 216. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-common/src/audit.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-common/src/audit.rs"},"region":{"startLine":216}}}],"partialFingerprints":{"codehealthFindingId/v1":"e99113a02ddadcefbebd0446daf4b06552524f3fe1b33e8194b7276d7ed175a5"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: warpgate-protocol-vnc/src/server/bridge.rs: warpgate-protocol-vnc/src/server/bridge.rs changed 4 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 20 in warpgate_protocol_vnc::server::bridge::run_proxy_session at line 108. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-protocol-vnc/src/server/bridge.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-vnc/src/server/bridge.rs"},"region":{"startLine":108}}}],"partialFingerprints":{"codehealthFindingId/v1":"b797b9acbcbf255a4f91f1bef4a832418d2a5ef2f0160d81ed4f32c927dd5f48"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: warpgate-core/src/db_auth.rs: warpgate-core/src/db_auth.rs changed 4 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 19 in warpgate_core::db_auth::authorize_user at line 189. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-core/src/db_auth.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/db_auth.rs"},"region":{"startLine":189}}}],"partialFingerprints":{"codehealthFindingId/v1":"c43e9055a41359547ac739099ad665cc1f9ac48ec3a03ce9a679fca5a5ce111f"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: warpgate-core/src/credential_encryption.rs: warpgate-core/src/credential_encryption.rs changed 2 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 16 in warpgate_core::credential_encryption::rewrite_all at line 230. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-core/src/credential_encryption.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/credential_encryption.rs"},"region":{"startLine":230}}}],"partialFingerprints":{"codehealthFindingId/v1":"392852549b1e67a23ccadcbc285edfb3fb9d4fbd2e5abb21b59015eb87abaf43"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: warpgate-web/src/admin/config/Parameters.svelte: warpgate-web/src/admin/config/Parameters.svelte changed 24 times in last 90 days and 13 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 11 (its worst body is save at line 114), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfixed #2556 - default auth policy (#2557)\u201D; \u201Cfixed #2536 - do not record keypresses during interactive RDP logon, add disable keyboard recording option (#2537)\u201D; \u201Cfixed #2422 - validate numeric parameter fields in the API\u201D; \u201Cfixed #2487 - RDP - handle unstable bitmap parse order in Chromium (#2491)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-web/src/admin/config/Parameters.svelte\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/config/Parameters.svelte"},"region":{"startLine":114}}}],"partialFingerprints":{"codehealthFindingId/v1":"7dcd9b9eb41a339307bd6c7047d837256b331e15272f8d310e45ff23728f2b11"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: warpgate-admin/src/api/parameters.rs: warpgate-admin/src/api/parameters.rs changed 22 times in last 90 days and 12 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 4 (its worst body is Api::api_update_parameters at line 302), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfixed #2556 - default auth policy (#2557)\u201D; \u201Cfixed #2536 - do not record keypresses during interactive RDP logon, add disable keyboard recording option (#2537)\u201D; \u201Cfixed #2422 - validate numeric parameter fields in the API\u201D; \u201Cfixed #2449 - cannot unset nullable parameters via API\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-admin/src/api/parameters.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-admin/src/api/parameters.rs"},"region":{"startLine":302}}}],"partialFingerprints":{"codehealthFindingId/v1":"165425fd97bd4a0e5eceddcd72cf83acdf33a7d8391c430f9ba988d48899081e"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: warpgate-core/src/protocols/desktop.rs: warpgate-core/src/protocols/desktop.rs changed 5 times in last 90 days and 4 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 4 (its worst body is warpgate_core::protocols::desktop::truncate_clipboard_contents at line 18), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfixed #2536 - do not record keypresses during interactive RDP logon, add disable keyboard recording option (#2537)\u201D; \u201Cfixed #2411 - support RDP clipboard redirection (#2447)\u201D; \u201Cfixed #2349 - keyboard layouts in RDP (#2364)\u201D; \u201Cfixed #2326 - dynamic resolution in RDP web client (#2329)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-core/src/protocols/desktop.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/protocols/desktop.rs"},"region":{"startLine":18}}}],"partialFingerprints":{"codehealthFindingId/v1":"b2a9217bb9e0b7444af7cf1211e691607744f2843e84b743bf056b0d2efb5f8f"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: warpgate/src/commands/create_user.rs: warpgate/src/commands/create_user.rs changed 5 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 6 (its worst body is warpgate::commands::create_user::command at line 13), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfixed #2556 - default auth policy (#2557)\u201D; \u201Cfixed #2453 - setup CLI recreates admin user every time\u201D; \u201Cfixed #2191 - allow concurrent DB access (#2192)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate/src/commands/create_user.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate/src/commands/create_user.rs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"fb69ffeb929de3eccbbeb7a3f9ca604aab41480a094ef6ddf947cb491ecb69e0"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: warpgate-web/src/embed/index.ts: warpgate-web/src/embed/index.ts changed 5 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 4 (its worst body is index.forceSecureWebSocketURLs at line 9), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfixed #1627 - support multiple SSH keys (#2277)\u201D; \u201Cfixed #2254 - novnc websockets not working\u201D; \u201Cfixed embedded menu\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-web/src/embed/index.ts\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/embed/index.ts"},"region":{"startLine":9}}}],"partialFingerprints":{"codehealthFindingId/v1":"3eaba56ec9b12cf8f1d34c2648948898fdf899fab42a051de50da67267a730a6"}},{"ruleId":"D15","level":"warning","message":{"text":"Repeated repair: warpgate-protocol-ssh/src/server/russh_handler.rs: warpgate-protocol-ssh/src/server/russh_handler.rs changed 5 times in last 90 days and 3 of those changes were fix/bug commits, so repair is the majority of this file\u0027s churn. Its max cyclomatic complexity is 2 (its worst body is ServerHandlerEvent::existing_channel at line 71), UNDER the 15 threshold, so this is deliberately not filed as a churn \u00D7 complexity hotspot \u2014 the difficulty here is in the behaviour the file has to get right, not in its control flow, and refactoring it for complexity would be the wrong move. The repairs counted were: \u201Cfixed #2328 - channel confirmation race (#2331)\u201D; \u201Cfixed #1459 - concurrent agent channel requests causing deadlock (#2135)\u201D; \u201Cfixed #2026 - custom SSH banner (#2125)\u201D. Each one is a case this code did not handle. Before the next change lands here, check that every one of them is pinned by a test that fails without its fix; where the same area keeps coming back, the durable fix is usually at the interface that keeps being misused rather than at the line that was last corrected. Counted over 2026-06-26..2026-09-24, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-06-26 17:13:34 \u002B02:00\u0027 --until=\u00272026-09-24 17:13:34 \u002B02:00\u0027 --full-history --no-merges -- warpgate-protocol-ssh/src/server/russh_handler.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/server/russh_handler.rs"},"region":{"startLine":71}}}],"partialFingerprints":{"codehealthFindingId/v1":"fe1267eb912c47c9534f3df296ae084b1603fb841e8b842c7541b42629fd2887"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found. No recognised ADR directory (\u0060docs/adr/\u0060, \u0060docs/decisions/\u0060, \u0060adr/\u0060, \u0060docs/rfcs/\u0060, an \u0060ADR0001/\u0060 folder, or their siblings) exists anywhere in this tree. What was searched, so you can tell an empty log from a search that missed one: every directory under the tree (build output, dependencies and VCS metadata excepted), for a document that is either any non-index page inside a recognised ADR directory, whatever its name and however deeply nested (\u0060docs/adr/use-postgres.md\u0060, \u0060docs/adr/2024/0001-x.md\u0060); or a file anywhere whose name is ADR-shaped (\u00600001-use-postgres.md\u0060, \u0060adr-012-caching.md\u0060); or, when neither turned anything up, a document carrying the decision-record signature (an \u0022Architecture Decision Record\u0022 heading, or Status / Context / Decision / Consequences as section headings). A decision log that clears none of these \u2014 unnumbered files outside any recognised directory, without those headings \u2014 is not seen by this check and this row is then wrong. If that is your case, say so rather than renaming anything; otherwise, consider recording architectural decisions in \u0060docs/adr/\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent abbreviation for the same concept. \u0027MembershipChgs\u0027 is used as a nested type name for specific SIDs, while \u0027MembershipChanges\u0027 is used as the property name for the collection. \u0027Chgs\u0027 is a non-standard abbreviation for \u0027Changes\u0027.: Use \u0027MembershipChanges\u0027 consistently for both the property and the nested type (e.g., rename \u0027MembershipChgs\u0027 to \u0027MembershipChanges\u0027). (symbols: Property: public AADJoin.Messages.JoinDeviceResponse.MembershipChgs.LocalSID, Property: public AADJoin.Messages.JoinDeviceResponse.MembershipChanges)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f99cb08e4e9f42f80d0d5355f59464fcb3dea49f9ec060428ee2971b6b1e57a2"}},{"ruleId":"D21","level":"note","message":{"text":"Typo in method name. \u0027DecryptCeritficate\u0027 contains a typo (\u0027Ceritficate\u0027 instead of \u0027Certificate\u0027). Other methods in the same class use correct spelling (\u0027PemCsrToFile\u0027, \u0027PemCrtToFile\u0027).: Rename \u0027DecryptCeritficate\u0027 to \u0027DecryptCertificate\u0027. (symbols: Method: public string AADJoin.Utils.CryptoUtils.DecryptCeritficate(byte[], byte[], string), Method: public string AADJoin.Utils.CryptoUtils.PemCsrToFile(string, string), Method: public string AADJoin.Utils.CryptoUtils.PemCrtToFile(string, string), Method: public string AADJoin.Utils.CryptoUtils.PemCrtToPfxFile(string, System.Security.Cryptography.RSA, string, string))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9a94448d85a67b763c11d4b234ef58b9c93977447f99e2683494075ffd2c43c8"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent casing for factory/parse methods. \u0027AuthResponse.fromString\u0027 uses lowercase \u0027f\u0027, while \u0027JoinDeviceResponse.FromString\u0027, \u0027TenantAuthResponse.FromString\u0027, and \u0027P2PCertificatesResponse.FromString\u0027 use PascalCase \u0027F\u0027.: Rename \u0027AuthResponse.fromString\u0027 to \u0027AuthResponse.FromString\u0027 to match the convention used by other message types. (symbols: Method: public AuthResponse AADJoin.Messages.AuthResponse.fromString(string), Method: public JoinDeviceResponse AADJoin.Messages.JoinDeviceResponse.FromString(string), Method: public TenantAuthResponse AADJoin.Messages.TenantAuthResponse.FromString(string), Method: public P2PCertificatesResponse AADJoin.Messages.P2PCertificatesResponse.FromString(string))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"55c76742df8418d82ceccc6b7e47e52f5986e00cbc8a8ea6d0c143c4466c93ad"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent abbreviation for \u0027User\u0027. The type and property are named \u0027Usr\u0027, while other credentials use \u0027User\u0027 (e.g., \u0027AADJoin.Creds.UserCreds\u0027, \u0027AADJoin.Messages.JoinDeviceRequest.User\u0027 is not present but \u0027UserCreds\u0027 is). \u0027Usr\u0027 is a non-standard abbreviation.: Rename \u0027Usr\u0027 to \u0027User\u0027 to align with standard naming conventions and other \u0027User\u0027 related types in the codebase. (symbols: Property: public AADJoin.Messages.JoinDeviceResponse.Usr, Property: public AADJoin.Messages.JoinDeviceResponse.Usr.Upn, Type: public AADJoin.Messages.JoinDeviceResponse.Usr)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"06d927a910afa97cb23d46e0d47e3c72fae70811f589fc0b9aa9351d59d7fd2c"}},{"ruleId":"D22","level":"warning","message":{"text":"Inconsistent naming for standard I/O operations. \u0060FramedRead\u0060 uses \u0060read\u0060 (standard Rust \u0060Read\u0060 trait name), while \u0060FramedWrite\u0060 uses \u0060write_all\u0060 (standard Rust \u0060Write\u0060 trait method for full buffer writes). This creates asymmetry in the API surface.: Rename \u0060FramedWrite.write_all\u0060 to \u0060FramedWrite.write\u0060 to match \u0060FramedRead.read\u0060, or rename \u0060FramedRead.read\u0060 to \u0060FramedRead.read_all\u0060 if partial reads are not supported. Given the context of framing, \u0060write\u0060 is likely the intended symmetric counterpart to \u0060read\u0060. (signatures: FramedRead.read(buf: BytesMut): ReadFut | FramedWrite.write_all(buf: \u0026[u8]): WriteAllFut)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"61c12dd068aecabbd30c29bbafbbadc73339276dbf3593cf402e853c20ada188"}},{"ruleId":"D22","level":"warning","message":{"text":"Inconsistent constructor patterns for wrapping streams. \u0060StreamWrapper\u0060 uses a static factory method \u0060from_inner\u0060, while \u0060Framed\u0060 uses \u0060new\u0060 and \u0060new_with_leftover\u0060. This forces users to remember different instantiation patterns for similar wrapper types.: Standardize on \u0060new\u0060 for constructors. Rename \u0060StreamWrapper.from_inner\u0060 to \u0060StreamWrapper.new\u0060 or provide a \u0060new\u0060 constructor that takes the inner stream. (signatures: StreamWrapper.from_inner(stream: InnerStream): Self | Framed.new(stream: InnerStream): Self | Framed.new_with_leftover(stream: InnerStream, leftover: BytesMut): Self)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"95f7187241023c339a69f2cd321fb780ad111eca2e5524dd0878003864257436"}},{"ruleId":"D22","level":"warning","message":{"text":"Inconsistent return types for \u0060into_inner\u0060. \u0060StreamWrapper.into_inner\u0060 returns the inner type directly, while \u0060Framed.into_inner\u0060 returns a tuple \u0060(InnerStream, BytesMut)\u0060. This breaks the expectation that \u0060into_inner\u0060 always returns the wrapped inner component in a consistent shape, forcing users to handle the tuple unpacking for \u0060Framed\u0060 specifically.: Align the return types. Either have \u0060StreamWrapper\u0060 return a tuple if it also holds state, or provide \u0060Framed.into_inner_stream()\u0060 that returns just the stream, keeping \u0060into_inner\u0060 for the full state extraction. Given \u0060into_inner_no_leftover\u0060 exists, \u0060into_inner\u0060 is ambiguous in intent (does it include leftover?). A clearer name like \u0060into_inner_with_leftover\u0060 for the tuple version would help, but the asymmetry with \u0060StreamWrapper\u0060 is the primary issue. (signatures: StreamWrapper.into_inner(): InnerStream | Framed.into_inner(): (InnerStream, BytesMut) | Framed.into_inner_no_leftover(): InnerStream)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3ba5dd8a2a059fdae49dc047cf3cf2f8043bdedc1f9289e9a7d6fa06a63961b6"}},{"ruleId":"D22","level":"warning","message":{"text":"Inconsistent return types for \u0060get_inner\u0060/\u0060get_inner_mut\u0060. \u0060StreamWrapper\u0060 returns the inner stream directly, while \u0060Framed\u0060 returns a tuple of references. This inconsistency requires different handling code depending on which wrapper type is being used.: Standardize the return type. If \u0060Framed\u0060 needs to expose both stream and leftover buffer, \u0060StreamWrapper\u0060 should likely do the same if it holds similar state, or \u0060Framed\u0060 should provide separate getters like \u0060get_stream()\u0060 and \u0060get_leftover()\u0060 to avoid the tuple asymmetry. (signatures: StreamWrapper.get_inner(): InnerStream | StreamWrapper.get_inner_mut(): InnerStream | Framed.get_inner(): (\u0026InnerStream, \u0026BytesMut) | Framed.get_inner_mut(): (\u0026mut InnerStream, \u0026mut BytesMut))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3d3b3754b9b43e61cb246e5f6dcfd4e148cdaaecab65ebbefdef67878d8ca71e"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d5b8f11381d61a58459ffc7c595fd52d09c03c711894a63a9578043d2338412b"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"17b8272c02aa7355e55d9f807b818ec47b49d90d881c07d075aea1c559fa5f08"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"42a3a078b7bd5c81dbd635f778bd11a64f3380c51296fde59c9edfa78b1a5b86"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"921bee2ad43557e23559ebfb80853a4889abf6d502ee16efa078e4cc4fd5bfe5"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8f177b03a37c3ab9978e4a819ef0a3bfd633f205db9f8d5e791297e027c6df34"},"taxa":[{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e9db7dd925ec080a68d76340f471a970050339425d2c1b18bf26bd434da931fc"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9c6a5e12cec029eae773d25308515286a1f05b05a7ce81cbfe720804857f4b82"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0640121db59cf7d5d09d2c396e1a9b6bedc8524ff096d584f974d25166f0e2d5"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f96d69481872be3d56a6d6af1deb9aff31097bcae62f9d0524fe7029534a0388"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f2fb74dc2af5390b56241a51badc1f32630ae5bd78faba2ef67022943038e7c3"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ab8ce016c05617d2bea946f803bbeb3700de85a9611a8808cd4bc113313a14a3"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"260085588e116aa476cafef8a6c41eca3243e343c428ab11040382474a60231d"},"taxa":[{"id":"CWE-214","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2ca69c839a165a4e214869678bbf27dd51d5551b38d5c1cb78d29c86aadfe6ec"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-552","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ade839f4658fd8cefd1882e50ace4960429350df6578977cbeae5d5e746ffa0d"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e526829c79252f049284c29171c39704c25bafa246cebf1a6dbe1bda251f2c85"},"properties":{"dependency":{"package":"crypto-js","version":"3.3.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"144ba3d64b2f88552ffc19d754e40bd2451972fd866ceb13b6e402c8039c1886"},"properties":{"dependency":{"package":"Newtonsoft.Json","version":"9.0.1","advisory":"[GHSA redacted]","reachability":{"kind":"test-or-tooling","file":"vendor/sspi/tools/aadjoin/UnitTests/UnitTests.csproj"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7cf85abffe732f2645ef95a624d6badc26f0263616284d6a4cc46ca8e983031d"},"properties":{"dependency":{"package":"System.Net.Http","version":"4.3.0","advisory":"[GHSA redacted]","reachability":{"kind":"test-or-tooling","file":"vendor/sspi/tools/aadjoin/UnitTests/UnitTests.csproj"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b96b7173c4377d5bea4d6fd7b52323631c631c44172b743bec6f266c10a4e538"},"properties":{"dependency":{"package":"System.Text.RegularExpressions","version":"4.3.0","advisory":"[GHSA redacted]","reachability":{"kind":"test-or-tooling","file":"vendor/sspi/tools/aadjoin/UnitTests/UnitTests.csproj"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0d3d2c2346bccaaa14c1bd0f0713c18ae4de849fffdc7282dbd533ab105c9398"},"properties":{"dependency":{"package":"rustls-webpki","version":"0.101.7","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","RUSTSEC-2026-0098","RUSTSEC-2026-0099","RUSTSEC-2026-0104"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"87d8ea9cdfd1c88bab1777f1cc2e9aba259b17a119eab3d910b917ba4355374b"},"properties":{"dependency":{"package":"nanoid","version":"3.3.16","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"713d68fe58435a878597532d16837ae0e533aceae8d2dae6731e491dc39452e7"},"properties":{"dependency":{"package":"rsa","version":"0.10.0-rc.18","advisory":"RUSTSEC-2023-0071","aliases":["[CVE redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4bb282e6cc9a79b7047c6a5d1c6a0274b6f637b8703f75038c751facb38089a6"},"properties":{"dependency":{"package":"rsa","version":"0.9.10","advisory":"RUSTSEC-2023-0071","aliases":["[CVE redacted]","[GHSA redacted]","[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d16a195f2692c30c6739c7ce8896426c6177603bb31aa1a2f55c80769aaed29a"},"properties":{"dependency":{"package":"dotenv","version":"0.15.0","advisory":"RUSTSEC-2021-0141","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9d7e2f5e4e133844171b9412d83e460349b527553e21e4eb5d4f1e038ed6831f"},"properties":{"dependency":{"package":"atomic-polyfill","version":"1.0.3","advisory":"RUSTSEC-2023-0089","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f48cf8c9f415048128045caa118a1e03769d0b4fe18d7f036c2f3766e3e8d8fb"},"properties":{"dependency":{"package":"instant","version":"0.1.13","advisory":"RUSTSEC-2024-0384","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b5524f25221308ec94b7206b58afaa59996104c20abaa242285d451f5344e44b"},"properties":{"dependency":{"package":"rustls-pemfile","version":"2.2.0","advisory":"RUSTSEC-2025-0134","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d469c4cdd0b2892278c4ee90c01a5a8ea4872a98733c483777e04c904cfebdfc"},"properties":{"dependency":{"package":"proc-macro-error2","version":"2.0.1","advisory":"RUSTSEC-2026-0173","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"422864efbc32ee020d94634a443edac9d818b90faf02ac96d91c4d66ffa4da37"},"properties":{"dependency":{"package":"lru","version":"0.16.4","advisory":"RUSTSEC-2026-0253","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5585c48a8c4ed670247ebaa40a533d385248c4e49079fee700e7b93cbab137a9"},"properties":{"dependency":{"package":"quick-xml","version":"0.36.2","advisory":"RUSTSEC-2026-0194","aliases":["RUSTSEC-2026-0195"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"80b5c22beae306eb623d7a60ec13361ab89285e1cc30fcf5b8daa2e87ffb5c69"},"properties":{"dependency":{"package":"h2","version":"0.3.27","advisory":"RUSTSEC-2026-0258","aliases":["[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f4810f062ca4ecd90dcecad1f9d039cc72775899b526ffc0a1c21eefecaab25d"},"properties":{"dependency":{"package":"ip-address","version":"10.4.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[GHSA redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"87792e5d29062e878f075d6cab8df0cc889b5ad023d6067900e89facf5be29ba"},"properties":{"dependency":{"package":"devalue","version":"5.9.0","advisory":"[GHSA redacted]","aliases":["[CVE redacted]"],"reachability":{"kind":"not-imported"}}}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"434a2ada5006a15d805952c5a6b9aa1627dfd116cb9daee3bb50e7d8619ed6bc"},"taxa":[{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"97333efa9717b49907206dd0c5fefbc46fe42a9e41f48a501a831a60c27307b8"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a0142eef9f259476fb528c68f8e80989e186ba8e413fc2dfe465e70b5190c230"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"fa50f0921b1ccf8c231e4a1df009fe9bcdf6bd74d5fe1e67f6d13dab2420983a"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"96792bb31c95dac3b21775e410237a9316c7c20a7e6b01ea593608160ff11db7"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8515041ba43c31d4aa22a0f18534ddf156d816a7d8d50a70f49c561e79e38a21"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e8d40d39e62bc8222083e750fde2b02c0d64607c1c5e093d83535b6b080a81fa"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"97076146b48eeec7c18d760572d148622832996aba0c2ccd2424e4629cd6b5c3"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"92f3e1079b70e263993d27729651a63c07d1733816bcee607e94ff4302fc6300"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"78d45d7a3535cf86a9635402729863950c7ee4924864b2f953fc88737c77d6e6"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2952508820f8722ed53aedc07442253fa2bce8d3409f18a23d41ac08a8235efa"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a5787d39a1bc0562842c3df65fc8f901b4da50d8b1c2f2ef5b80bc773c6818f9"},"taxa":[{"id":"CWE-250","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6c912cf1f9f3609a0b69321326d79b72a48f350e04992de8949a8b8826726f39"},"taxa":[{"id":"CWE-250","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"39316cc8d3b58b22edd9315341b3f6051531778bfd322a7978b2c918ac47719c"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1004fdb052889788b290e4d6266ea841f8827e57393deabbb45534085e97f66f"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"35fa34dabe6931e81e133a186cb81762c4d7d35d5f2dcb93758caacc06e4fe83"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"01cd5002c3654ace16d148532aa3668de5f75db7dbc011bb4757ec571020e6c3"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6fb0c3a8bcb08f63512b53237874982d7f278b6c8e3ac973724e07d21b80793e"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"82083ac7c3ef3726928a7c4831790bae044068df921e6c518f228d4443a33e4e"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"867095b0a4865dc982df620ad09139efabe466894a595a8fed7527e59b092954"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"efac74860256a75f81ec05b4de53a5406eba0c0ff55deea4d39872ee8b4ee26c"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7336cc10223e39d0b4bc7e0f7672c6c902f00f287de3d25727829aee5fde87af"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e619b1af899bb1656ba2a70b45a2b0f871a46f855e572df209cb71c398e59fd1"}},{"ruleId":"D34","level":"note","message":{"text":"Orphaned files with no living knowledge: 5 of 270 analysed file(s) have no living knowledge left \u2014 their last meaningful change has decayed away, so if one breaks, no one currently understands it (counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 270 of the 496 production source files in this repository met that bar). None is large enough to earn a read-through of its own, so this row stands in for the per-file rows rather than raising one each \u2014 most significant first: warpgate-db-migrations/src/m00044_ticket_requests.rs, warpgate-sso/src/google_groups.rs, warpgate-db-migrations/src/m00050_password_policy.rs, warpgate-db-migrations/src/m00020_target_groups.rs, warpgate-db-migrations/src/m00025_ssh_client_auth.rs. Attach the read to the next change that touches one of them: have a second person review that change, and leave behind a short comment or test recording what the file is for, so the knowledge comes back at the cost of a change you were making anyway."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ce861fd78f6935114d3a342cb90ad25870f984e1042954fcbbe27c0e23be3658"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: parameters.rs \u2194 lib.rs: \u0060warpgate-admin/src/api/parameters.rs\u0060 (context warpgate-admin) and \u0060warpgate-db-migrations/src/lib.rs\u0060 (context warpgate-db-migrations) sit in DIFFERENT parts of the tree yet change together 86% of the time (18 of the 21 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see. You can check this without leaving the row: of the 18 shared commits counted here, the most recent 3 are \u0060aec66b7a\u0060 fixed #2556 - default auth policy (#2557); \u00603f36f133\u0060 fixed #2536 - do not record keypresses during interactive RDP logon, \u2026; \u00600b12eff8\u0060 Allow admin to configure new tab preference (#2396) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-admin/src/api/parameters.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"fab7c71b2aba876f9295eaad64b7ee73c17fa286c82aba27fc1656733622dd9a"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: lib.rs \u2194 lib.rs: \u0060warpgate-protocol-mysql/src/lib.rs\u0060 (context warpgate-protocol-mysql) and \u0060warpgate-protocol-postgres/src/lib.rs\u0060 (context warpgate-protocol-postgres) sit in DIFFERENT parts of the tree yet change together 77% of the time (10 of the 13 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see. You can check this without leaving the row: of the 10 shared commits counted here, the most recent 3 are \u00601b848915\u0060 Stop Kubernetes listener from becoming unavailable on incomplete TCP \u2026; \u0060bfcf2023\u0060 fixed #2379 - do not log LB health checks as failed sessions (#2390); \u006013478db2\u0060 Support TCP Proxy Protocol (#2174) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-mysql/src/lib.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"2f958a592ee61095f7e69c27e6bc45af363a35bee9acfc23d32a00cb8fc3183d"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: session.rs \u2194 session.rs: \u0060warpgate-protocol-mysql/src/session.rs\u0060 (context warpgate-protocol-mysql) and \u0060warpgate-protocol-ssh/src/server/session.rs\u0060 (context warpgate-protocol-ssh) sit in DIFFERENT parts of the tree yet change together 61% of the time (11 of the 18 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see. You can check this without leaving the row: of the 11 shared commits counted here, the most recent 3 are \u00600daf97d9\u0060 fixed #1981 - option to cache web approvals (#2175); \u00609ca14d10\u0060 record invalid usernames as login failures; \u0060a037b92d\u0060 perf: find target by name using a query instead of doing it in memory\u2026 \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-mysql/src/session.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"5cb62552c8caeb2153ffecef053addd6f982f8143f74dc82bd737a525b0f36b1"}},{"ruleId":"D35","level":"error","message":{"text":"Boundary-crossing change coupling: auth_state_store.rs \u2194 session.rs: \u0060warpgate-core/src/auth_state_store.rs\u0060 (context warpgate-core) and \u0060warpgate-protocol-ssh/src/server/session.rs\u0060 (context warpgate-protocol-ssh) sit in DIFFERENT parts of the tree yet change together 58% of the time (11 of the 19 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) \u2014 the bounded-context boundary may be in the wrong place, or one context is leaking into the other. This is the behavioural boundary violation a static scan can\u0027t see. You can check this without leaving the row: of the 11 shared commits counted here, the most recent 3 are \u00600daf97d9\u0060 fixed #1981 - option to cache web approvals (#2175); \u00609ca14d10\u0060 record invalid usernames as login failures; \u006082041787\u0060 fixed #2027 - case-insensitive username comparison for web approval (\u2026 \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-core/src/auth_state_store.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d1dd5a40bbb19d27ebab19f29379d4a1a88efe89aea080194dfdb2c60ea4b912"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: handler.rs \u2194 russh_handler.rs: \u0060warpgate-protocol-ssh/src/client/handler.rs\u0060 and \u0060warpgate-protocol-ssh/src/server/russh_handler.rs\u0060 change together 75% of the time (9 of the 12 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 9 shared commits counted here, the most recent 3 are \u00606c231ba6\u0060 fixed #1459 - concurrent agent channel requests causing deadlock (#2135); \u00609453879e\u0060 fmt; \u0060e2036886\u0060 Implement Agent Forwarding (#1249) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/client/handler.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"8e3ddde835292d0ac8039579d19a4a4b1853b6af9c8551f4d201d83fcd17e72e"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: handler.rs \u2194 session.rs: \u0060warpgate-protocol-ssh/src/client/handler.rs\u0060 and \u0060warpgate-protocol-ssh/src/server/session.rs\u0060 change together 58% of the time (7 of the 12 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 7 shared commits counted here, the most recent 3 are \u0060f66dee30\u0060 #1828 - option to disable host key checks (#2284); \u00606c231ba6\u0060 fixed #1459 - concurrent agent channel requests causing deadlock (#2135); \u0060e2036886\u0060 Implement Agent Forwarding (#1249) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-protocol-ssh/src/client/handler.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"dfc6941d104f232bee111d8905e922901b3cfe8ee4948e670a7eb4a2c671f4d7"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"90f83b4fa27db32740afe9540c905f3c0499caed87f61049a8a903ecc95b41c3"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7be964b311a6380af50ea81671ece9780d741f767dc79e47c2b108618722cf0c"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1ae293ce5d00c64f9fe36fad06531a59d9923eca1c6f5991b41ebe62d4e553d0"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c593d4dbd23724f337bfb8d2c1653812f143ae255bd9b59d4b3e9c37779fa6f4"}},{"ruleId":"D40","level":"note","message":{"text":"No network policy: No Kubernetes NetworkPolicy (or Cilium policy) found. Without one, every pod can talk to every other pod and reach out to the internet by default. Add a default-deny policy and open only the flows you need."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"295828650a2aaa1b03ae9b32ae6843a0c38011e5a70b1926442c4fa7187de5f0"}},{"ruleId":"D41","level":"note","message":{"text":"No seccomp profile: Workloads do not set a seccomp profile (RuntimeDefault or a Localhost profile). Seccomp blocks the syscalls a container never needs, shrinking the kernel attack surface a container escape would use."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3f418e9f76c3ac90484e0e94a454bfe9b08e914e1cdd218e1fc9e3b261a3bf6e"}},{"ruleId":"D41","level":"note","message":{"text":"No AppArmor/SELinux confinement: Workloads declare no AppArmor or SELinux profile. A mandatory-access-control profile confines what a compromised container can touch on the host, complementing seccomp\u0027s syscall filter."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e83fbc31033373d6c51983ed230eb4ba61f7775ed02afb30f5fc1840bde01d4f"}},{"ruleId":"D44","level":"warning","message":{"text":"End-of-life runtime: .NET net6.0: vendor/sspi/tools/aadjoin/UnitTests/UnitTests.csproj declares .NET net6.0 as this project\u0027s target framework, and .NET 6 LTS, support ended 2024-11-12. An unsupported runtime receives no security patches, so every vulnerability disclosed in it since 2024-11-12 is present and unfixable without moving off it. This is a migration rather than an upgrade: there is no newer release of a runtime that has ended."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"833052aef8fed8fff4f2fedf55a392e3e58dc048b7b988c82a469d1d41453aa6"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"P12","level":"warning","message":{"text":"Coverage collected but not gated: CI collects a coverage report but no step enforces a minimum \u2014 coverage could halve and CI stays green. Add a step that fails the build when coverage drops below a floor (your coverage tool\u0027s minimum-threshold flag, or a coverage-gate action) so the number guards something. What was searched, so you can tell an absence from a miss: this repository\u0027s CI files AND its coverage configuration \u2014 the well-known coverage and test-runner config files, read at the repository root and inside workspace package directories two levels down, so a floor declared beside the tests rather than in the pipeline is credited \u2014 matched against the threshold settings this check knows by name. A floor set in your coverage service\u0027s web UI rather than in a committed file, or under a setting whose name is not one of those, is not seen here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7f63c06044cf998d9a0698692df30d8873e29bc9b0c98ee829255017c1193d33"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (28 lines \u00D7 2 locations): warpgate-web/src/gateway/WebDesktop.svelte:446 \u00B7 warpgate-web/src/gateway/WebSsh.svelte:258 \u2014 the 2 copies sit in sibling files in one directory, so check first whether one of them (or an existing module there) already owns this behaviour and the others should call it; otherwise extract it into one module in that directory and have each site call it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/gateway/WebDesktop.svelte"},"region":{"startLine":446}}}],"partialFingerprints":{"codehealthFindingId/v1":"8c67a5885c6d196abbeb9b3bf5cdffcdb3f537bf18dae7034ae62b9dcf9e1530"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (23 lines \u00D7 2 locations): warpgate-web/src/admin/config/AccessRoles.svelte:12 \u00B7 warpgate-web/src/admin/config/users/Users.svelte:21 \u2014 the 2 copies are spread across 2 directories, so the shared home is a decision rather than an obvious spot: check first whether one of them already owns this behaviour, and otherwise put the extracted module somewhere all of the sites already reach rather than making one of them depend on another."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/config/AccessRoles.svelte"},"region":{"startLine":12}}}],"partialFingerprints":{"codehealthFindingId/v1":"9dea150e6728db5102c6f9140ff082fbf6e9ad91266e3acb1ebb84d658ee3ae0"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block with local edits (19 matched lines \u00D7 2 locations): warpgate-web/src/admin/config/Parameters.svelte:80 \u00B7 warpgate-web/src/admin/config/Policies.svelte:16 \u2014 the two spans are one implementation copied and then locally edited \u2014 93 tokens are still identical, in the same order in both files, with only local edits between them. The copies have already begun to drift, which is this row\u0027s finding: an edit made to one and not the other changes behaviour silently. Diff the two spans first to learn what genuinely differs, then extract the shared core into one module both sites use, passing the differences in as parameters \u2014 or, if one copy exists only because the other could not be imported from its context, make one of them the single source the other is generated or re-exported from. If one copy is no longer reachable, delete it rather than letting it shadow the live one."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/config/Parameters.svelte"},"region":{"startLine":80}}}],"partialFingerprints":{"codehealthFindingId/v1":"d1c50199f015c998d9f7baa395ac4d71ffceef97ae56e2b33dc725665f18c010"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2 locations): warpgate-web/src/admin/player/DesktopRecordingPlayer.svelte:140 \u00B7 warpgate-web/src/admin/player/TerminalRecordingPlayer.svelte:202 \u2014 the 2 copies are spread across 2 files, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/player/DesktopRecordingPlayer.svelte"},"region":{"startLine":140}}}],"partialFingerprints":{"codehealthFindingId/v1":"890fffc08f0fee6106e62939b765ec6b85ff4851e066d3f71ff949baf00d6f25"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 3 locations): warpgate-web/src/admin/config/AccessRoles.svelte:19 \u00B7 warpgate-web/src/admin/config/target-groups/TargetGroups.svelte:12 \u00B7 warpgate-web/src/admin/config/users/Users.svelte:28 \u2014 the 3 copies are spread across 3 files, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/config/AccessRoles.svelte"},"region":{"startLine":19}}}],"partialFingerprints":{"codehealthFindingId/v1":"fefc5ba9c8c17f6482e49aa54a94bf8901943b4eaccdd7b0510cf53659cefe55"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (16 lines \u00D7 2 locations): warpgate-web/src/admin/config/ldap/CreateLdapServer.svelte:48 \u00B7 warpgate-web/src/admin/config/ldap/LdapServer.svelte:82 \u2014 the 2 copies sit in sibling files in one directory, so check first whether one of them (or an existing module there) already owns this behaviour and the others should call it; otherwise extract it into one module in that directory and have each site call it."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/config/ldap/CreateLdapServer.svelte"},"region":{"startLine":48}}}],"partialFingerprints":{"codehealthFindingId/v1":"0024cf14215a506297a4df70d771d9caa40b723fd2d572a6718e84261870ac90"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 2 locations): warpgate-web/src/admin/config/AccessRole.svelte:27 \u00B7 warpgate-web/src/admin/config/AccessRole.svelte:43 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/config/AccessRole.svelte"},"region":{"startLine":27}}}],"partialFingerprints":{"codehealthFindingId/v1":"c96faedefed55dff0c2781c3b0448563b5a24819661e4fbc4a27068d0f27c6c8"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (15 lines \u00D7 3 locations): warpgate-web/src/admin/config/AccessRole.svelte:62 \u00B7 warpgate-web/src/admin/config/AdminRole.svelte:127 \u00B7 warpgate-web/src/admin/config/targets/Target.svelte:81 \u2014 the 3 copies are spread across 3 files, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/config/AccessRole.svelte"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"a5383c32bc62fabb0c3ff1f889f8154e9ec53a8eaa7f81a4a1ea950fa19b8e56"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2 locations): warpgate-web/src/common/protocols.ts:203 \u00B7 warpgate-web/src/common/protocols.ts:224 \u2014 all 2 copies are in the same file, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/common/protocols.ts"},"region":{"startLine":203}}}],"partialFingerprints":{"codehealthFindingId/v1":"dab7f8bae4e9ccef35191bfde36cf3f057a90c659b30d7ee19e2e85601ab8096"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2 locations): warpgate-web/src/gateway/lib/certificateStore.ts:24 \u00B7 warpgate-web/src/gateway/lib/certificateStore.ts:48 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/gateway/lib/certificateStore.ts"},"region":{"startLine":24}}}],"partialFingerprints":{"codehealthFindingId/v1":"cfa51641d7d59a9c5916cff3a2194967ecf18c4095f9be8990fb92ba851b4d2f"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2 locations): warpgate-web/src/admin/lib/api.ts:8 \u00B7 warpgate-web/src/gateway/lib/api.ts:4 \u2014 the 2 copies are spread across 2 directories, so the shared home is a decision rather than an obvious spot: check first whether one of them already owns this behaviour, and otherwise put the extracted module somewhere all of the sites already reach rather than making one of them depend on another."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/lib/api.ts"},"region":{"startLine":8}}}],"partialFingerprints":{"codehealthFindingId/v1":"dca28ad34651ce848dd4c00bfd38fcea8c32766e4369463fb80f633a429f46cc"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2 locations): warpgate-web/src/admin/status/Session.svelte:64 \u00B7 warpgate-web/src/admin/status/Session.svelte:78 \u2014 all 2 copies are in the same file, and the CITED SPAN is not a self-contained block \u2014 it runs from inside one construct into the next (the tail of a branch plus the head of the following one, a run of switch arms, the end of a declaration plus the list that follows it) rather than covering a whole unit. So do not lift these lines literally: no call can be substituted for a half-open construct. Extract the enclosing repeated UNIT instead \u2014 the whole function, component or branch these lines sit in \u2014 and where the repetition IS the construct (a run of switch arms, a stack of near-identical declarations) replace it with one table or registry looked up by key rather than a helper each arm calls. The copies still drift apart the first time only one of them is edited, which is why this is reported."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/status/Session.svelte"},"region":{"startLine":64}}}],"partialFingerprints":{"codehealthFindingId/v1":"6b7d700af31b397ea586b4a178a939cad0d84f013d607df4d657dd14f8128de4"}},{"ruleId":"R10","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2 locations): warpgate-web/src/common/protocols.ts:100 \u00B7 warpgate-web/src/common/protocols.ts:126 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/common/protocols.ts"},"region":{"startLine":100}}}],"partialFingerprints":{"codehealthFindingId/v1":"ac2fb5f58b9330b23fad0dd95e167dced8d685ecfddfbe314524591e84e9201f"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function mfaEnforcedFactor (cyclomatic 14, cognitive 14): mfaEnforcedFactor has cyclomatic complexity 14 and cognitive complexity 14; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/config/users/AuthPolicyEditor.svelte"},"region":{"startLine":113}}}],"partialFingerprints":{"codehealthFindingId/v1":"007bcb40bde9603b2d166bfa67be36a9d43fb6a790756a8cd2a4bddc8425080e"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function parseHumantimeDuration (cyclomatic 13, cognitive 12): parseHumantimeDuration has cyclomatic complexity 13 and cognitive complexity 12; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/common/duration.ts"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"11cc9be8447269a38afd3a184ffc491e348fc3bfc8e852910f5f99c55819f839"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function getEffectivePossibleCredentials (cyclomatic 12, cognitive 18): getEffectivePossibleCredentials has cyclomatic complexity 12 and cognitive complexity 18; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/common/protocols.ts"},"region":{"startLine":331}}}],"partialFingerprints":{"codehealthFindingId/v1":"528889f7cafd33f273dda0082f924317586ad8be5c483dbc017a6d4990526d63"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function (anonymous) (cyclomatic 12, cognitive 11): (anonymous) has cyclomatic complexity 12 and cognitive complexity 11; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/player/DesktopRecordingPlayer.svelte"},"region":{"startLine":121}}}],"partialFingerprints":{"codehealthFindingId/v1":"9610a7ad0be94c5de5e14dadedf84de70281f106733ae53ab1258a6ce33dbeb3"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function reset (cyclomatic 12, cognitive 7): reset has cyclomatic complexity 12 and cognitive complexity 7; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/config/secret-backends/SecretBackendModal.svelte"},"region":{"startLine":46}}}],"partialFingerprints":{"codehealthFindingId/v1":"c60024d642beabfa163babcd427963afc67432e8a34f4e6766227263fd5ae836"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function onMessage (cyclomatic 12, cognitive 6): onMessage has cyclomatic complexity 12 and cognitive complexity 6; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/gateway/WebSsh.svelte"},"region":{"startLine":152}}}],"partialFingerprints":{"codehealthFindingId/v1":"fc05400ecca7dfc45066da5a7e9ca2d8d8d789bf01e24555e77939b97f1ce93e"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function recordingMetadataToFieldSet (cyclomatic 12, cognitive 5): recordingMetadataToFieldSet has cyclomatic complexity 12 and cognitive complexity 5; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/common/recordings.ts"},"region":{"startLine":63}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a723256ed12f4bd54f6c37748e08a0ae21629d1e7133a42406c40b557c8d9b7"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function updateActiveSectionFromScroll (cyclomatic 11, cognitive 18): updateActiveSectionFromScroll has cyclomatic complexity 11 and cognitive complexity 18; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/lib/SectionedForm.svelte"},"region":{"startLine":23}}}],"partialFingerprints":{"codehealthFindingId/v1":"7678426217e86c2bfd22656fa11953e529ac241813a245f0d9ce1a5191497339"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function onWsMessage (cyclomatic 11, cognitive 11): onWsMessage has cyclomatic complexity 11 and cognitive complexity 11; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive is at or above cyclomatic here, so the branching is nested or entangled rather than laid out side by side \u2014 extracting each decision into its own named function is the change that pays. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/gateway/WebDesktop.svelte"},"region":{"startLine":134}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a0231d51b61c941aeb335761e31e53232f62d229e2a0ff94b8ded2f80618f3b"}},{"ruleId":"R2","level":"warning","message":{"text":"Complex function save (cyclomatic 11, cognitive 10): save has cyclomatic complexity 11 and cognitive complexity 10; this row is raised above a cyclomatic bar of 10. The two numbers answer different questions and the gap between them is what decides whether to act: cyclomatic counts the independent arms through the body, cognitive counts what it costs to hold them in your head, so nesting and mixed boolean chains raise it while a flat run of independent arms does not. Cognitive sits below cyclomatic here, so much of the count is breadth \u2014 arms side by side rather than stacked \u2014 and splitting per arm would leave a function per arm; group the work between the checks into named steps instead. Measured by this repository\u0027s own parse of the file, so a body assembled at runtime, or generated, is counted as written rather than as it executes."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/config/Parameters.svelte"},"region":{"startLine":114}}}],"partialFingerprints":{"codehealthFindingId/v1":"bea1649d3fcb4ff76799e65a4dba789581cccf4f5beeaaf2cfefe8ded134af7c"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~500 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 2 in-repo import(s) from 2 other file(s) do name it (warpgate-web/src/admin/Log.svelte, warpgate-web/src/admin/status/Session.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/log-viewer/LogViewer.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"12c2da0818381f365e6aee5d2bc173a6cb50ebf108b0140d282005682d09c7ef"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~491 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 2 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/gateway/Root.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/gateway/WebDesktop.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"005d5403b3e235f640673bf80f3aa5bb9b46be85ab5529c0268a4a995b86c94f"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~372 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 4 in-repo import(s) from 4 other file(s) do name it (warpgate-web/src/admin/config/users/AuthPolicyEditor.svelte, warpgate-web/src/admin/config/users/CredentialEditor.svelte, warpgate-web/src/admin/status/Session.svelte and 1 more) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/common/protocols.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"51d2d5ec483a5f876ddc2f4dccfccaf88752d92be2bb3140d36d66dd46479755"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~331 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/gateway/WebSsh.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/gateway/WebSshTab.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0d69695bab5c0ddabd3a43c8e729dbcf6b19a95788fc77e03f9d149e690e7ccc"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~324 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 2 in-repo import(s) from 2 other file(s) do name it (warpgate-web/src/admin/player/DesktopRecordingPlayer.svelte, warpgate-web/src/gateway/WebDesktop.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/common/desktopInput.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"6ab45421f79b6b8410c1d8099f00767e5a598674c9d499400382e7a13a59eeba"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~322 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/admin/status/Recording.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/player/TerminalRecordingPlayer.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ce707e8689e51a6e885e47fc0ecaef0d497ba2c8699c6fa41cf2f116aeaedbd9"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~321 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/admin/config/Config.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/config/users/User.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"bd7e867f238ab92133a09f4ee6052698d74d7be6e96426ea858b394be4b517cd"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~308 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 2 in-repo import(s) from 2 other file(s) do name it (warpgate-web/src/admin/config/users/AuthPolicyEditor.svelte, warpgate-web/src/admin/config/users/User.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/config/users/CredentialEditor.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3eb840ed7f932075589350da9b4b67db02dd9e6c1d6b06ee28b30e42957e3fe3"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~304 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 2 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/gateway/Root.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/gateway/WebSsh.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"6acd0223c8dc5697ec399fe9f4dd01efeb2538488a8a92e2a35d209f16f0eb1a"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~297 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 2 in-repo import(s) from 2 other file(s) do name it (warpgate-web/src/admin/player/DesktopRecordingPlayer.svelte, warpgate-web/src/admin/player/TerminalRecordingPlayer.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/player/playbackController.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"735730ad6cdc4917422188e7dd90103face2b665f7be9af35475319a1574c6b7"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~242 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/admin/status/Recording.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/player/DesktopRecordingPlayer.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c0727fc19c37114129344739dcf46d61a11ced0769347bd1e4cab2015de25800"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~233 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 2 in-repo import(s) from 2 other file(s) do name it (warpgate-web/src/admin/player/DesktopRecordingPlayer.svelte, warpgate-web/src/gateway/WebDesktop.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/common/desktopCanvas.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e888a6474580645c86f9236006a00bed85188050976a6238a4ea54c337f4813f"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~221 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 7 in-repo import(s) from 7 other file(s) do name it (warpgate-web/src/admin/config/ClientKeyModal.svelte, warpgate-web/src/admin/config/SSHKeys.svelte, warpgate-web/src/admin/config/secret-backends/SecretBackends.svelte and 4 more) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/common/SecretRefInput.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"53633d2cc56e11f849242e1435dced9158da2225b70ca82ecaf67414d7918134"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~213 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 2 in-repo import(s) from 2 other file(s) do name it (warpgate-web/src/admin/config/Policies.svelte, warpgate-web/src/admin/config/users/CredentialEditor.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/config/users/AuthPolicyEditor.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1e9ca74afee220d116ae29d31ecb5bea532ba2039cf1a1cfea9959b1237dddac"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~206 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 5 in-repo import(s) from 5 other file(s) do name it (warpgate-web/src/admin/config/CreateTicket.svelte, warpgate-web/src/admin/config/targets/Target.svelte, warpgate-web/src/gateway/TargetList.svelte and 2 more) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/common/ConnectionInstructions.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"26623e8a921d7644b2d3f522757f7cb2f263c815ecf6b17d7cea5feed882ebcb"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~198 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/gateway/App.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/gateway/TicketRequests.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"cc0bf5267456439354e00fce508e0f8ee93b4d67504503cc5c6f3459e97ea221"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~196 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 13 in-repo import(s) from 13 other file(s) do name it (warpgate-web/src/admin/config/AccessRole.svelte, warpgate-web/src/admin/config/AccessRoles.svelte, warpgate-web/src/admin/config/AdminRole.svelte and 10 more) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/common/ItemList.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1fae80b1c61aeef450025d6405ae3cfde26d507d1f64fa8455758dff98f644cb"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~184 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/admin/config/targets/ProtocolDocs.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/config/targets/protocolInfo.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"4b43b2209af262a603c56d369cf6772a48d2718ba592210cb7159c97d443aafa"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~183 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/admin/status/Status.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/status/Requests.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"da7c2f1f2a0ecf61bd849eec3106b7bc30753f240e5dcbab1d5ca309f29a42e6"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~180 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/gateway/App.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/gateway/TargetList.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"00e32f4b4e30c1f624916b3f28b057f37f4b1b5dd9f3e0ad72d33146bed2055b"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~165 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/admin/config/Config.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/config/Parameters.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"70ad3fc2b46819022b69849b03e244f68c245e7cba66ec59a8fdf678bf94fa7a"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~160 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/admin/status/Session.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/common/recordings.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"394f7b433543e0dc4d44ca768e1b5f5de51bdee07803d5b7782c062472a21901"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~158 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 3 in-repo import(s) from 3 other file(s) do name it (warpgate-web/src/admin/config/users/CredentialEditor.svelte, warpgate-web/src/common/ConnectionInstructions.svelte, warpgate-web/src/gateway/CredentialManager.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/CertificateCredentialModal.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1f59ef7979770147728b61ba63ebd6751eaabdab356e6534eebc99256dace12e"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~158 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/admin/config/targets/ssh/Options.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/config/targets/ssh/KeyChecker.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"384bef56c6c61b6a299d43244b61d44157e1efb1e7c5c6e3f3a7ffcd32a18f21"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~147 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 29 in-repo import(s) from 29 other file(s) do name it (warpgate-web/src/admin/App.svelte, warpgate-web/src/admin/config/AccessRole.svelte, warpgate-web/src/admin/config/AccessRoles.svelte and 26 more) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/lib/store.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0882403c74306e3172392796e3df08e4ddf0a70169a66f489a078c8dd58f40c0"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~143 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/gateway/WebDesktop.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/common/desktopClipboard.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"43c472ef0cd9f0e9fce8f2bd043e106eaf9d821ac945f8085b3feb2618103650"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~142 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/admin/config/Config.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/config/AdminRole.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3e652ca10cf2576a5c56ca377bc6cdf4fbafe94e8f43b2b4ccbed1a01b653b8a"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~142 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/admin/config/Config.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/config/ldap/LdapServer.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b055d3227f1d09b62974436bae8544ac6201b858cecef9b0b19923c9ee944142"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~140 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/admin/config/Config.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/config/targets/CreateTarget.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b735901d9d7cf9a12bd8a1ab55b2e01cdc3518b2790c8500b61488b948c4b516"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~135 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 6 in-repo import(s) from 6 other file(s) do name it (warpgate-web/src/admin/config/Tickets.svelte, warpgate-web/src/admin/status/Requests.svelte, warpgate-web/src/common/DurationInput.svelte and 3 more) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/common/duration.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b5aa235c29f14c703441b2b6f2385fe7b8acdd9af1c23002c265d0d6c887eba3"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~133 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/gateway/Root.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/gateway/App.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"ab406e8063f6b715a9fcfb5e917a668eef4dbf834aad7114b1aad2d7ad166fa9"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~126 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/admin/config/Config.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/config/targets/Target.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"8ad00317471ab8e6eb0adbd5a4909cefd83aefe39949ed4135561a19f55e4d91"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~123 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 3 in-repo import(s) from 3 other file(s) do name it (warpgate-web/src/admin/config/Parameters.svelte, warpgate-web/src/admin/config/targets/Target.svelte, warpgate-web/src/admin/config/users/User.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/lib/SectionedForm.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"2dcf6c62a811c089756eb7cfa91dd9662978c1192b42e5f643d3cbb3b0970e75"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~119 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/gateway/ProfileCredentials.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/gateway/CredentialManager.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"8ed4e490ea1e15290ea69a854ef16663a8ad283abe687fee76424a669bcd6126"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~115 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 3 in-repo import(s) from 3 other file(s) do name it (warpgate-web/src/admin/config/Parameters.svelte, warpgate-web/src/admin/config/targets/Target.svelte, warpgate-web/src/admin/config/users/User.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/common/RateLimitInput.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3b5e431f720b913e4f73bb30bd1a31ed02914c786d89e3308f343416c1184708"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~114 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/admin/player/playbackController.ts) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/common/liveRecordingStream.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a2df60641f924ebcbc69c3369c9f1b8bd194b0bffa473ecb3e715c86ea05e23a"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~111 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 3 in-repo import(s) from 3 other file(s) do name it (warpgate-web/src/admin/config/users/CredentialEditor.svelte, warpgate-web/src/gateway/CredentialManager.svelte, warpgate-web/src/gateway/MfaSetup.svelte) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/CreateOtpModal.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"3ca55840f5c8266c24357308b1a935e9ae27818dfb7d53a9900c01b276b973d2"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~109 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 3 in-repo import(s) from 3 other file(s) do name it (warpgate-web/src/admin/player/DesktopRecordingPlayer.svelte, warpgate-web/src/admin/player/TerminalRecordingPlayer.svelte, warpgate-web/src/admin/player/playbackController.ts) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/player/rangeStream.ts"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a28b6ea6617bb4dbc077264b431e828863e16f8ad00ad6827f1d0c309a6e3990"}},{"ruleId":"R7","level":"warning","message":{"text":"Dead file (~105 LoC): no import path from any entry point (2 application, 4 tooling, 1 test roots considered), but 1 in-repo import(s) from 1 other file(s) do name it (warpgate-web/src/admin/index.ts) \u2014 every one of those referrers is itself unreachable, so this file is dead only as a member of that cluster: if any referrer is in fact alive, this row falls with it"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"warpgate-web/src/admin/App.svelte"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"e17e39e78168b97302f0eb94937d1943e9b2bb7c09b9047b6790fe0e63e518f1"}},{"ruleId":"R8","level":"warning","message":{"text":"Unused dependency \u0027@otplib/plugin-base32-enc-dec\u0027: Declared in warpgate-web/package.json but never imported anywhere in that package or its workspace members \u2014 no static import reaches it. Usually that is dead weight and attack surface, but two shapes are indistinguishable from source and are NOT dead: an optional or native peer that another dependency loads dynamically at runtime, and a package a build, docs or test step installs and invokes separately. Confirm which of the three this is before removing it."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6040d307e2b76bfca5670db8ad24beedf758d40c6bcb4eb8ec8aff1e58e86c14"}},{"ruleId":"R8","level":"warning","message":{"text":"Unused dependency \u0027@otplib/plugin-crypto-js\u0027: Declared in warpgate-web/package.json but never imported anywhere in that package or its workspace members \u2014 no static import reaches it. Usually that is dead weight and attack surface, but two shapes are indistinguishable from source and are NOT dead: an optional or native peer that another dependency loads dynamically at runtime, and a package a build, docs or test step installs and invokes separately. Confirm which of the three this is before removing it."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"cc4f7d8df0e4d803a4e6f23b09b6bfaefc2bc85618770d43e55b7e261d9bbd02"}},{"ruleId":"R8","level":"warning","message":{"text":"Unused dependency \u0027@otplib/preset-browser\u0027: Declared in warpgate-web/package.json but never imported anywhere in that package or its workspace members \u2014 no static import reaches it. Usually that is dead weight and attack surface, but two shapes are indistinguishable from source and are NOT dead: an optional or native peer that another dependency loads dynamically at runtime, and a package a build, docs or test step installs and invokes separately. Confirm which of the three this is before removing it."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"a2599aa61a763112e5a6bbb92b0770d6f7d15858092fda551de570bda4cc6fab"}},{"ruleId":"SC1","level":"warning","message":{"text":"NuGet dependencies are not locked: No packages.lock.json and no central package management \u2014 restores aren\u0027t reproducible or pinned (SSDF PW.4.4). Enable \u003CRestorePackagesWithLockFile\u003Etrue\u003C/RestorePackagesWithLockFile\u003E (commit the lockfile) or adopt Directory.Packages.props. Advisory \u2014 never scored."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0a97b4f69ccac509400ece7eedefb06d3ede0522cd4d8bcb5c068bea719545a6"}},{"ruleId":"X5","level":"note","message":{"text":"Nullable reference types not enabled everywhere: 0/1 NRT-eligible project(s) enable \u003CNullable\u003Eenable\u003C/Nullable\u003E (projects targeting a pre-C#-8 framework are excluded \u2014 NRTs aren\u0027t available there). NRTs catch a whole class of null-deref bugs at compile time."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"80b24de9378624a0ce4846d60457395befcaec8e109ea81d289a370c9f7bfd5d"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-1059","guid":"a2381a08-60f6-9554-a8b8-f3018cfaaca5","name":"Insufficient Technical Documentation","shortDescription":{"text":"Insufficient Technical Documentation"},"helpUri":"https://cwe.mitre.org/data/definitions/1059.html"},{"id":"CWE-1104","guid":"4c918cb5-b2a6-6c55-9963-a44ee464305e","name":"CWE-1104","shortDescription":{"text":"CWE-1104"},"helpUri":"https://cwe.mitre.org/data/definitions/1104.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-214","guid":"b10ad120-fb22-1351-9348-aa23b453e815","name":"CWE-214","shortDescription":{"text":"CWE-214"},"helpUri":"https://cwe.mitre.org/data/definitions/214.html"},{"id":"CWE-250","guid":"52ee12e8-390a-7351-b1e6-388afa694e54","name":"CWE-250","shortDescription":{"text":"CWE-250"},"helpUri":"https://cwe.mitre.org/data/definitions/250.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-522","guid":"71fb233e-ce6a-ae57-9419-ef8373540b09","name":"CWE-522","shortDescription":{"text":"CWE-522"},"helpUri":"https://cwe.mitre.org/data/definitions/522.html"},{"id":"CWE-552","guid":"3492436b-eca2-9c54-9ba3-5dade427c903","name":"CWE-552","shortDescription":{"text":"CWE-552"},"helpUri":"https://cwe.mitre.org/data/definitions/552.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-829","guid":"13c33925-97fb-5a5e-b40c-56d328b8a4d7","name":"CWE-829","shortDescription":{"text":"CWE-829"},"helpUri":"https://cwe.mitre.org/data/definitions/829.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":60,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}