{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D8","name":"Code Coverage","shortDescription":{"text":"Code Coverage"},"helpUri":"https://codehealth.canine.dev/dimensions/D8"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D10","name":"Test Quality","shortDescription":{"text":"Test Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D10"},{"id":"D12","name":"Dependency Hygiene","shortDescription":{"text":"Dependency Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/D12"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D14","name":"License Compliance","shortDescription":{"text":"License Compliance"},"helpUri":"https://codehealth.canine.dev/dimensions/D14"},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D18","name":"Solution Shape","shortDescription":{"text":"Solution Shape"},"helpUri":"https://codehealth.canine.dev/dimensions/D18"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D23","name":"Boundary Type-Coupling","shortDescription":{"text":"Boundary Type-Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D23"},{"id":"D24","name":"Comment Value","shortDescription":{"text":"Comment Value"},"helpUri":"https://codehealth.canine.dev/dimensions/D24"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D27","name":"Navigability","shortDescription":{"text":"Navigability"},"helpUri":"https://codehealth.canine.dev/dimensions/D27"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX4","name":"Dependency direction","shortDescription":{"text":"Dependency direction"},"helpUri":"https://codehealth.canine.dev/dimensions/AX4"},{"id":"AX5","name":"Architecture \u0026 structure","shortDescription":{"text":"Architecture \u0026 structure"},"helpUri":"https://codehealth.canine.dev/dimensions/AX5"},{"id":"AX6","name":"Interface segregation","shortDescription":{"text":"Interface segregation"},"helpUri":"https://codehealth.canine.dev/dimensions/AX6"},{"id":"AX8","name":"Test isolation","shortDescription":{"text":"Test isolation"},"helpUri":"https://codehealth.canine.dev/dimensions/AX8"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"DM12","name":"Ambient inputs in the domain","shortDescription":{"text":"Ambient inputs in the domain"},"helpUri":"https://codehealth.canine.dev/dimensions/DM12"},{"id":"ED5","name":"Idempotency","shortDescription":{"text":"Idempotency"},"helpUri":"https://codehealth.canine.dev/dimensions/ED5"},{"id":"GD1","name":"Unfinished \u0026 placeholder code","shortDescription":{"text":"Unfinished \u0026 placeholder code"},"helpUri":"https://codehealth.canine.dev/dimensions/GD1"},{"id":"IC1","name":"Incompleteness \u0026 stubs","shortDescription":{"text":"Incompleteness \u0026 stubs"},"helpUri":"https://codehealth.canine.dev/dimensions/IC1"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"SC1","name":"Supply-chain hygiene","shortDescription":{"text":"Supply-chain hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/SC1"},{"id":"X1","name":"Async correctness","shortDescription":{"text":"Async correctness"},"helpUri":"https://codehealth.canine.dev/dimensions/X1"},{"id":"X10","name":"Duplicated predicate","shortDescription":{"text":"Duplicated predicate"},"helpUri":"https://codehealth.canine.dev/dimensions/X10"},{"id":"X12","name":"Unreachable branch","shortDescription":{"text":"Unreachable branch"},"helpUri":"https://codehealth.canine.dev/dimensions/X12"},{"id":"X13","name":"Undrained process stream","shortDescription":{"text":"Undrained process stream"},"helpUri":"https://codehealth.canine.dev/dimensions/X13"},{"id":"X14","name":"Bypassable address classification","shortDescription":{"text":"Bypassable address classification"},"helpUri":"https://codehealth.canine.dev/dimensions/X14"},{"id":"X15","name":"Unvalidated length from an untrusted reader","shortDescription":{"text":"Unvalidated length from an untrusted reader"},"helpUri":"https://codehealth.canine.dev/dimensions/X15"},{"id":"X16","name":"Unfloored truncation loop","shortDescription":{"text":"Unfloored truncation loop"},"helpUri":"https://codehealth.canine.dev/dimensions/X16"},{"id":"X17","name":"Uncapped recursion over a caller-supplied document","shortDescription":{"text":"Uncapped recursion over a caller-supplied document"},"helpUri":"https://codehealth.canine.dev/dimensions/X17"},{"id":"X18","name":"Disposal-pattern correctness","shortDescription":{"text":"Disposal-pattern correctness"},"helpUri":"https://codehealth.canine.dev/dimensions/X18"},{"id":"X19","name":"Unrestored process-global state","shortDescription":{"text":"Unrestored process-global state"},"helpUri":"https://codehealth.canine.dev/dimensions/X19"},{"id":"X20","name":"Mistyped argument guard","shortDescription":{"text":"Mistyped argument guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X20"},{"id":"X21","name":"Side-effecting pattern guard","shortDescription":{"text":"Side-effecting pattern guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X21"},{"id":"X22","name":"Contradicted release guard","shortDescription":{"text":"Contradicted release guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X22"},{"id":"X23","name":"Unguarded diagnostic materialisation","shortDescription":{"text":"Unguarded diagnostic materialisation"},"helpUri":"https://codehealth.canine.dev/dimensions/X23"},{"id":"X24","name":"Document value interpolated into markup unescaped","shortDescription":{"text":"Document value interpolated into markup unescaped"},"helpUri":"https://codehealth.canine.dev/dimensions/X24"},{"id":"X25","name":"Inert configuration knob","shortDescription":{"text":"Inert configuration knob"},"helpUri":"https://codehealth.canine.dev/dimensions/X25"},{"id":"X26","name":"Unsynchronised callback handoff","shortDescription":{"text":"Unsynchronised callback handoff"},"helpUri":"https://codehealth.canine.dev/dimensions/X26"},{"id":"X27","name":"Collection changed while being enumerated","shortDescription":{"text":"Collection changed while being enumerated"},"helpUri":"https://codehealth.canine.dev/dimensions/X27"},{"id":"X28","name":"Index access outside its own emptiness guard","shortDescription":{"text":"Index access outside its own emptiness guard"},"helpUri":"https://codehealth.canine.dev/dimensions/X28"},{"id":"X29","name":"Per-element action decided by a fixed element","shortDescription":{"text":"Per-element action decided by a fixed element"},"helpUri":"https://codehealth.canine.dev/dimensions/X29"},{"id":"X3","name":"Exception handling","shortDescription":{"text":"Exception handling"},"helpUri":"https://codehealth.canine.dev/dimensions/X3"},{"id":"X30","name":"Support guard that admits what it rejects","shortDescription":{"text":"Support guard that admits what it rejects"},"helpUri":"https://codehealth.canine.dev/dimensions/X30"},{"id":"X32","name":"Type resolved by simple name across every loaded assembly","shortDescription":{"text":"Type resolved by simple name across every loaded assembly"},"helpUri":"https://codehealth.canine.dev/dimensions/X32"},{"id":"X4","name":"Structured logging","shortDescription":{"text":"Structured logging"},"helpUri":"https://codehealth.canine.dev/dimensions/X4"},{"id":"X5","name":"Nullable reference types","shortDescription":{"text":"Nullable reference types"},"helpUri":"https://codehealth.canine.dev/dimensions/X5"},{"id":"X6","name":"Hand-rolled structured-format parsing","shortDescription":{"text":"Hand-rolled structured-format parsing"},"helpUri":"https://codehealth.canine.dev/dimensions/X6"},{"id":"X7","name":"Silent fallback defaults","shortDescription":{"text":"Silent fallback defaults"},"helpUri":"https://codehealth.canine.dev/dimensions/X7"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (25\u201329 lines \u00D7 2): KalanMoney/KalanMoney.Persistence.CosmosDB/Repositories/AccountQueriesRepository.cs:25-49 | KalanMoney/KalanMoney.Persistence.CosmosDB/Repositories/AccountQueriesRepository.cs:52-80 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.Persistence.CosmosDB/Repositories/AccountQueriesRepository.cs"},"region":{"startLine":25}}}],"partialFingerprints":{"codehealthFindingId/v1":"3eed364cd8f3c343834e8c2ba0342dc1f516e6172e83e290794b66c1aa0bee70"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): KalanMoney/KalanMoney.Domain.UseCases/AddIncomeTransaction/AddIncomeTransaction.cs:31-38 | KalanMoney/KalanMoney.Domain.UseCases/AddOutcomeTransaction/AddOutcomeTransaction.cs:26-33 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice. Read the line range as the matched WINDOW rather than a finished unit: at \u0060KalanMoney/KalanMoney.Domain.UseCases/AddIncomeTransaction/AddIncomeTransaction.cs:31\u0060 it runs out through the closing brace of the declaration holding it \u2014 the window is that declaration\u0027s tail, not a fragment that begins part-way through something, so those exact lines cannot be lifted as they stand \u2014 widen the region to the smallest complete statement or declaration that contains it, and extract that. Note first that the copies are not typed on the same thing: the declarations holding them bind \u0060output\u0060 to \u0060IAddIncomeTransactionOutput\u0060 in one and \u0060IAddOutcomeTransactionOutput\u0060 in another, and the duplicated lines use it. The extracted unit therefore needs a parameter type that fits BOTH \u2014 their common supertype where they have one, or a new abstraction over them where they do not \u2014 and settling that is the step that comes BEFORE the extraction above. Where the two types are deliberately unrelated, the duplication is the price of that separation and the honest resolution is to record the decision rather than to extract."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.Domain.UseCases/AddIncomeTransaction/AddIncomeTransaction.cs"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"b868f85072f941a834503fa7919d323e62338a9f4e523aec81b3c23b15ca95a9"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: KalanMoney.Domain.Entities: KalanMoney.Domain.Entities: abstractness 0.09, instability 0.00, distance 0.91 \u2014 zone of pain \u2014 concrete and depended on by 3 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"215321821a34d1dae8cfe5838a67643f92c65a2687673b343309268cf9c53266"}},{"ruleId":"D8","level":"warning","message":{"text":"Coverage not measured \u2014 no coverage collector is wired up: Coverage NOT MEASURED: \u0060--collect:\u0022XPlat Code Coverage\u0022\u0060 names a data collector that ships in the \u0060coverlet.collector\u0060 package, and this repository wires up none \u2014 no test project references it and no runsettings declares one. The absence of coverage here is therefore not evidence about the suite or about our analyzer environment: without a collector, \u0060--collect\u0060 produces nothing even from a suite that builds and passes. Add a \u0060coverlet.collector\u0060 PackageReference to the test project(s) (or commit the Cobertura/OpenCover/lcov report your CI produces) and real coverage will be measured. It is excluded from the score rather than counted as a near-zero defect."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"62e63e619c28f057e129f2997c965d32a457366a9ce18ca019ffb6bdfba85c99"}},{"ruleId":"D17","level":"warning","message":{"text":"BareSuppressMessage: SuppressMessage \u2014 the suppression records no reason: either it carries no justification argument at all, or one that states nothing a reader can weigh (\u0022OK\u0022, \u0022By design\u0022). A suppression is a decision somebody made, and without the reason the next reader cannot tell a considered exception from an unexamined one, so it is never revisited. Write what makes this site legitimately different \u2014 the invariant that holds, the framework contract that forces the shape \u2014 or remove the suppression and fix what it hides."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.API.Functions.Tests/AccountDashboardTests/AccountDashboardFunctionTest.cs"},"region":{"startLine":52}}}],"partialFingerprints":{"codehealthFindingId/v1":"5f2cc753b9c6b59c387fbdf3e233b574b6cf8ff33d138763589f42dba5ee9130"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: * Todo: \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.Domain.UseCases.Tests/GetCategoriesByAccountTests/GetCategoriesByAccountUseCaseTest.cs"},"region":{"startLine":156}}}],"partialFingerprints":{"codehealthFindingId/v1":"4658e2f629112b2800010769c6800ab36f9765c3e402914d9961e3769281330d"}},{"ruleId":"D17","level":"warning","message":{"text":"Dead code: CreateHttpRequestWithoutNoBody: Method CreateHttpRequestWithoutNoBody \u2014 Roslyn\u0027s SymbolFinder walked every project the solution loads, including KalanMoney.API.Functions.Tests, and found no reference to it. That walk cannot see three kinds of caller, so check them before removing it: code outside the solution file (a solution is a curated list, not the repository \u2014 a sibling test tree with its own .sln is invisible), a call resolved by reflection or dependency injection from the symbol\u0027s name, and any project the workspace could not load. This is \u0027no caller found by this walk\u0027, not a verdict that the symbol is unused."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.API.Functions.Tests/AddIncomeTransactionTests/AddIncomeTransactionFunctionTest.cs"},"region":{"startLine":84}}}],"partialFingerprints":{"codehealthFindingId/v1":"6d8e0c6b40f179194079045aadffafb8d1c2206095f83fa0d34570a46dc55bdc"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no installation or build instructions: No setup/build/run instructions anywhere in the document. Add a short install/nuget/project.json or build snippet."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1fa6bfcd5c6ae231d1b8ee99bced50b832d1f61cde9da6cbb533467b879a57db"}},{"ruleId":"D19","level":"note","message":{"text":"Documentation: no usage examples: The README mentions TDD and design confirmation but provides no runnable example of how to run the app or use its features. Write a one-line \u0027how to run it\u0027 command with an optional short usage example."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"README.md"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"1355eb4e127a4bc9236772ce1c46f09510aa9286e7a06d1e47f308229df19049"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: KalanMoney.Domain.Entities: KalanMoney.Domain.Entities: 11 % XML-doc coverage (5/44)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.Domain.Entities/KalanMoney.Domain.Entities.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"6c9e3599c24e4f5e6d3850f93eaf86e22fe9c4f97826064a4fc72d43dd7190f0"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: KalanMoney.Domain.UseCases: KalanMoney.Domain.UseCases: 4 % XML-doc coverage (3/78)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.Domain.UseCases/KalanMoney.Domain.UseCases.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"4d41db5eb1ca4d1035895c4b0a1bb32451796f1a6124dff6d8175fcb69de27da"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: KalanMoney.Persistence.MemoryDatabase: KalanMoney.Persistence.MemoryDatabase: 0 % XML-doc coverage (0/27)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.Persistence.MemoryDatabase/KalanMoney.Persistence.MemoryDatabase.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"5af4f66801caaf04192b3bf70fc53d7f96c06a8713857e84090104fb5a210c1c"}},{"ruleId":"D19","level":"warning","message":{"text":"Low XML-doc coverage: KalanMoney.Persistence.CosmosDB: KalanMoney.Persistence.CosmosDB: 0 % XML-doc coverage (0/31)."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.Persistence.CosmosDB/KalanMoney.Persistence.CosmosDB.csproj"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"61c7df09a2774ae04168e5b2dde7ac7f168e043cc442dbbf06cde74c74261a93"}},{"ruleId":"D21","level":"note","message":{"text":"Spelling errors in test method names: \u0027moth\u0027 instead of \u0027month\u0027 and \u0027to\u0027 instead of \u0027too\u0027.: Correct spelling to \u0027last_month\u0027 and \u0027too_long\u0027 respectively. (symbols: KalanMoney.Domain.UseCases.Tests.TransactionFilterTests.TransactionFilterTest.Create_transaction_filter_for_last_moth_range_utc_time_successfully, KalanMoney.Domain.UseCases.Tests.OpenAccountTests.OpenAccountUseCaseTest.Try_to_open_an_account_but_the_name_is_to_long)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"edc861f3f54db0e838990e75e56017c408b455f79b732ff12ef1beefee90531e"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent article usage in test names: \u0027a_income\u0027 vs \u0027a_new_outcome\u0027. \u0027a_income\u0027 is grammatically incorrect (should be \u0027an\u0027), and \u0027a_new\u0027 adds an adjective not present in the other.: Standardize to \u0027Add_an_income_transaction...\u0027 and \u0027Add_a_new_outcome_transaction...\u0027 or remove \u0027new\u0027 from the latter for consistency. (symbols: KalanMoney.Domain.UseCases.Tests.AddIncomeTransactionTests.AddIncomeTransactionUseCaseTest.Add_a_income_transaction_to_an_existing_account_successfully, KalanMoney.Domain.UseCases.Tests.AddOutcomeTransactionTests.AddOutcomeTransactionTest.Add_a_new_outcome_transaction_successfully)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7d64c1b0bb2505f7f03655394334220c4b02ba9cb7319a86fc2a5e11eb7bfaa1"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent phrasing in test names: \u0027Add_a_income_transaction...\u0027 vs \u0027Try_to_add_an_outcome_transaction...\u0027. One uses a direct statement, the other uses \u0027Try_to_\u0027.: Standardize test naming convention to either direct statements (\u0027Add_income_transaction...\u0027) or attempt descriptions (\u0027Try_to_add_income_transaction...\u0027). (symbols: KalanMoney.Domain.UseCases.Tests.AddIncomeTransactionTests.AddIncomeTransactionUseCaseTest.Add_a_income_transaction_to_an_existing_account_successfully, KalanMoney.Domain.UseCases.Tests.AddOutcomeTransactionTests.AddOutcomeTransactionTest.Try_to_add_an_outcome_transaction_to_unexciting_account)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0dcea50db5bba37eefe4b42f0da4fecb668cfc533d94686c2836944ada90f409"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent suffix usage: one test ends with \u0027to_an_existing_account_successfully\u0027 while the other ends with \u0027successfully\u0027.: Standardize suffixes, e.g., always include the context (\u0027to_an_existing_account\u0027) or always omit it if implied. (symbols: KalanMoney.Domain.UseCases.Tests.AddIncomeTransactionTests.AddIncomeTransactionUseCaseTest.Add_a_income_transaction_to_an_existing_account_successfully, KalanMoney.Domain.UseCases.Tests.AddOutcomeTransactionTests.AddOutcomeTransactionTest.Add_a_new_outcome_transaction_successfully)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"70d4e090b879226133a012ee13619138510d8f24eb51d74c49effc40307792a4"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent return/result description in test names: one specifies \u0027return_bad_request\u0027, the other describes the condition \u0027but_the_name_is_to_long\u0027 without specifying the HTTP result.: Standardize to either always include the HTTP result (e.g., \u0027return_bad_request\u0027) or always describe the specific validation failure condition. (symbols: KalanMoney.Domain.UseCases.Tests.OpenAccountTests.OpenAccountUseCaseTest.Try_to_open_an_account_with_an_invalid_name_return_bad_request, KalanMoney.Domain.UseCases.Tests.OpenAccountTests.OpenAccountUseCaseTest.Try_to_open_an_account_but_the_name_is_to_long)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0d343270d11b1a7849c5ce944338d536a0d698bd88c616502dca7b39d8adb129"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent use of the term \u0027unexciting_account\u0027 vs \u0027existing_account\u0027. \u0027Unexciting\u0027 appears to be a specific test fixture name or state, while \u0027existing\u0027 is a general state. If \u0027unexciting\u0027 is a specific mock state, it should be consistent across all tests using that state.: Clarify if \u0027unexciting\u0027 is a standard test fixture name. If so, use it consistently. If not, use \u0027existing\u0027 or \u0027empty\u0027 consistently. (symbols: KalanMoney.Domain.UseCases.Tests.GetCategoriesByAccount.GetCategoriesByAccountTest.Try_to_get_categories_from_unexciting_account, KalanMoney.Domain.UseCases.Tests.AddIncomeTransactionTests.AddIncomeTransactionUseCaseTest.Add_a_income_transaction_to_an_existing_account_successfully)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"95040e2de980aae3ac14b530ab82e7b35d5dc7c79795282041554a1e05e24972"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent verb tense/mood: \u0027Open_an_account...\u0027 (imperative/statement) vs \u0027Try_to_open_an_account...\u0027 (attempt).: Standardize to either \u0027Open_an_account...\u0027 or \u0027Try_to_open_an_account...\u0027. (symbols: KalanMoney.Domain.UseCases.Tests.OpenAccountTests.OpenAccountUseCaseTest.Open_an_account_with_account_name_successfully, KalanMoney.Domain.UseCases.Tests.OpenAccountTests.OpenAccountUseCaseTest.Try_to_open_an_account_but_the_name_is_to_long)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ae81a5c6e1224c5218620787d73a1f8b17fb69446bee687c8ae24461659ca0b4"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent article usage: \u0027a_income\u0027 (incorrect) vs \u0027an_outcome\u0027 (correct).: Correct \u0027a_income\u0027 to \u0027an_income\u0027. (symbols: KalanMoney.Domain.UseCases.Tests.AddIncomeTransactionTests.AddIncomeTransactionUseCaseTest.Add_a_income_transaction_to_an_existing_account_successfully, KalanMoney.Domain.UseCases.Tests.AddOutcomeTransactionTests.AddOutcomeTransactionTest.Try_to_add_an_outcome_transaction_to_unexciting_account)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"21d345917beb8eeb8af9acc8101d422c7bfa651203a632620d22757b5a188426"}},{"ruleId":"D21","level":"note","message":{"text":"Inconsistent structure: one test name includes the expected result (\u0027return_bad_request\u0027), the other does not.: Include the expected result in all test names, e.g., \u0027Try_to_open_an_account_with_name_too_long_return_bad_request\u0027. (symbols: KalanMoney.Domain.UseCases.Tests.OpenAccountTests.OpenAccountUseCaseTest.Try_to_open_an_account_with_an_invalid_name_return_bad_request, KalanMoney.Domain.UseCases.Tests.OpenAccountTests.OpenAccountUseCaseTest.Try_to_open_an_account_but_the_name_is_to_long)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"f97568a381fb3e89068ac92c67a6b1bbf5b34f9e026d49b5e575ab04b6c19d8e"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3717130fb5bb0285f61a2a4c7476f255759f3dc4bed93f9fa857e6382c57109d"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5d30d3211d57d9589d8f226423454c62b64762ae5fbe016970b064c251c6698b"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"58c61fd9b239c2505b291f9f0b42d311bc1fbae0ccfea9c8d6841fe9eba0ba49"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"144ba3d64b2f88552ffc19d754e40bd2451972fd866ceb13b6e402c8039c1886"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7cf85abffe732f2645ef95a624d6badc26f0263616284d6a4cc46ca8e983031d"}},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b96b7173c4377d5bea4d6fd7b52323631c631c44172b743bec6f266c10a4e538"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6bf05b8d5cd947944c79e6235483d91a7c84d4f82421dc72e06586ecfda688c0"}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b38a2dc0eb0173117d221cb78ed172bf0593b28c52750693afcc0fa20a40e421"}},{"ruleId":"D34","level":"note","message":{"text":"Orphaned files with no living knowledge: 4 of 4 analysed file(s) have no living knowledge left \u2014 their last meaningful change has decayed away, so if one breaks, no one currently understands it (counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 4 of the 73 production source files in this repository met that bar). None is large enough to earn a read-through of its own, so this row stands in for the per-file rows rather than raising one each \u2014 most significant first: KalanMoney/KalanMoney.Persistence.CosmosDB/Repositories/AccountQueriesRepository.cs, KalanMoney/KalanMoney.Persistence.MemoryDatabase/AccountsMemoryRepository.cs, KalanMoney/KalanMoney.Startup/AccountUseCaseServiceRegistration.cs, KalanMoney/KalanMoney.API.Functions/GetMonthlyTransactions/GetMonthlyTransactionsFunction.cs. Attach the read to the next change that touches one of them: have a second person review that change, and leave behind a short comment or test recording what the file is for, so the knowledge comes back at the cost of a change you were making anyway."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ce861fd78f6935114d3a342cb90ad25870f984e1042954fcbbe27c0e23be3658"}},{"ruleId":"D44","level":"warning","message":{"text":"End-of-life runtime: .NET net6.0: KalanMoney/KalanMoney.Startup/KalanMoney.Startup.csproj declares .NET net6.0 as this project\u0027s target framework, and .NET 6 LTS, support ended 2024-11-12. An unsupported runtime receives no security patches, so every vulnerability disclosed in it since 2024-11-12 is present and unfixable without moving off it. This is a migration rather than an upgrade: there is no newer release of a runtime that has ended."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"833052aef8fed8fff4f2fedf55a392e3e58dc048b7b988c82a469d1d41453aa6"}},{"ruleId":"AX8","level":"error","message":{"text":"Production project references a test project: KalanMoney.Startup \u2192 KalanMoney.Domain.UseCases.Tests: \u0060KalanMoney.Startup\u0060 (production) references the test project \u0060KalanMoney.Domain.UseCases.Tests\u0060. Production must never depend on test code \u2014 it pulls a unit-test framework and test fixtures into the shipped product and inverts the only correct direction (tests depend on production, never the reverse). Move any shared helper into a production support library, or invert the reference."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"63670123b31e7eef1217e547772f8c79132e121ee31d871d5d89813212097885"}},{"ruleId":"DM12","level":"warning","message":{"text":"Domain type reads the wall clock: DateRangeFilter: \u0060DateRangeFilter\u0060 reads \u0060DateTime.UtcNow\u0060 inside \u0060CreateMonthRangeFromUtcNow\u0060. The rule this feeds is not a function of its inputs: it cannot be tested at the instant that matters without moving the machine clock, and two reads inside one operation can observe different times. Pass the instant in as a parameter, or inject \u0060TimeProvider\u0060."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.Domain.UseCases/Repositories/Models/DateRangeFilter.cs"},"region":{"startLine":5}}}],"partialFingerprints":{"codehealthFindingId/v1":"b6611b3c61db40a172b47043c17d0a757cec514476c0827e1394147397aa759a"}},{"ruleId":"DM12","level":"warning","message":{"text":"Domain type reads the wall clock: TimeStamp: \u0060TimeStamp\u0060 reads \u0060DateTimeOffset.UtcNow\u0060 inside \u0060CreateNow\u0060. The rule this feeds is not a function of its inputs: it cannot be tested at the instant that matters without moving the machine clock, and two reads inside one operation can observe different times. Pass the instant in as a parameter, or inject \u0060TimeProvider\u0060."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.Domain.Entities/ValueObjects/TimeStamp.cs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"a1d41f82790bbacd29d08f242c89e9e976889581fcca0dbc92ef4bebab1a47d5"}},{"ruleId":"GD1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: A shipped member still throws NotImplementedException \u2014 generated scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.Persistence.MemoryDatabase/AccountsMemoryRepository.cs"},"region":{"startLine":70}}}],"partialFingerprints":{"codehealthFindingId/v1":"f8c3c7cdeeb6a1497786fd7473ede6499de304d68e57cc1daf96ce606c535f24"}},{"ruleId":"IC1","level":"warning","message":{"text":"Unfinished stub \u2014 throws NotImplementedException: \u0060GetCategoriesByAccount\u0060 is a shipped member whose whole body throws NotImplementedException \u2014 scaffolding that was never completed. Implement it or remove the dead surface."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.Persistence.MemoryDatabase/AccountsMemoryRepository.cs"},"region":{"startLine":70}}}],"partialFingerprints":{"codehealthFindingId/v1":"d0bc946c407811ee5789da0a50175a71c65c38ec3c1d41dd1d4cbbb2611e0f08"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"M3","level":"note","message":{"text":"No tests/ separation: Tests aren\u0027t grouped in a dedicated test folder \u2014 the test surface isn\u0027t separable from production code at a glance."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"999e0c784909c76b6346a705ee63961fe363ed1cd6a94e3f80e2ebe7820ccd5d"}},{"ruleId":"P1","level":"warning","message":{"text":"No CI pipeline: No CI workflow found (.github/workflows, azure-pipelines.yml, .gitlab-ci.yml, \u2026) \u2014 changes aren\u0027t gated by an automated build/test."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"44f01af96e50474fba2df84d95ddf4f7e1d34c29c307830b9efc9057daa6b670"}},{"ruleId":"P3","level":"note","message":{"text":"No SAST: No static application security testing detected. For this repository\u0027s stack, add CodeQL\u0027s csharp pack, or a .NET security analyzer package (or \u0060semgrep --config=auto\u0060, which runs on any language) \u2014 this repository has no CI pipeline yet, so run it locally to clear the existing findings, then make it a step of the first workflow you add so a regression fails the build. What was searched, so you can tell an absence from a miss: the 0 CI workflow file(s) in this repository, and the scanner and linter configuration checked in beside them. A scan that runs outside CI, one configured in your forge\u0027s web UI rather than in a committed file, or a tool whose name is none of those this check carries, is not seen \u2014 if that is your case the row is wrong, and saying so is more useful than adding a second scanner."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6e54424179c892f03ef2fd003130ac4bd43f39bbf3b1ca0a0143e25acb80ec87"}},{"ruleId":"SC1","level":"warning","message":{"text":"NuGet dependencies are not locked: No packages.lock.json and no central package management \u2014 restores aren\u0027t reproducible or pinned (SSDF PW.4.4). Enable \u003CRestorePackagesWithLockFile\u003Etrue\u003C/RestorePackagesWithLockFile\u003E (commit the lockfile) or adopt Directory.Packages.props. Advisory \u2014 never scored."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0a97b4f69ccac509400ece7eedefb06d3ede0522cd4d8bcb5c068bea719545a6"}},{"ruleId":"X1","level":"warning","message":{"text":"Sync-over-async (deadlock risk): Blocking on a Task with \u0060.Wait()\u0060/\u0060.GetAwaiter().GetResult()\u0060 can deadlock (and wastes a thread). Prefer awaiting it: make the caller \u0060async\u0060 and \u0060await\u0060 instead. Where a synchronous entry point must stay \u2014 a public sync API you cannot break, or a process entry point that must not return until the work finishes \u2014 the block belongs in ONE documented bridge and never inside code that is already async; and where it already is that bridge, give the wait a TIMEOUT so a hung task fails the call instead of hanging the process."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.Persistence.CosmosDB/Repositories/AccountCommandsRepository.cs"},"region":{"startLine":29}}}],"partialFingerprints":{"codehealthFindingId/v1":"f6449c82c20f5876179d80327932eb25c7a9fbaa50998ec1fa536fb2116a449b"}},{"ruleId":"X1","level":"warning","message":{"text":"Sync-over-async (deadlock risk): Blocking on a Task with \u0060.Wait()\u0060/\u0060.GetAwaiter().GetResult()\u0060 can deadlock (and wastes a thread). Prefer awaiting it: make the caller \u0060async\u0060 and \u0060await\u0060 instead. Where a synchronous entry point must stay \u2014 a public sync API you cannot break, or a process entry point that must not return until the work finishes \u2014 the block belongs in ONE documented bridge and never inside code that is already async; and where it already is that bridge, give the wait a TIMEOUT so a hung task fails the call instead of hanging the process."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.Persistence.CosmosDB/Repositories/AccountCommandsRepository.cs"},"region":{"startLine":43}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a889596cafe8361582684014c71202a5aeaf2c49ac94407e75b2adc03723329"}},{"ruleId":"X1","level":"warning","message":{"text":"Sync-over-async (deadlock risk): Blocking on a Task with \u0060.Wait()\u0060/\u0060.GetAwaiter().GetResult()\u0060 can deadlock (and wastes a thread). Prefer awaiting it: make the caller \u0060async\u0060 and \u0060await\u0060 instead. Where a synchronous entry point must stay \u2014 a public sync API you cannot break, or a process entry point that must not return until the work finishes \u2014 the block belongs in ONE documented bridge and never inside code that is already async; and where it already is that bridge, give the wait a TIMEOUT so a hung task fails the call instead of hanging the process."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.Persistence.CosmosDB/Repositories/AccountQueriesRepository.cs"},"region":{"startLine":41}}}],"partialFingerprints":{"codehealthFindingId/v1":"ac9da3be4d94e22073784045420833df52ce64372b24b88a3a901ce958a5f0a8"}},{"ruleId":"X1","level":"warning","message":{"text":"Sync-over-async (deadlock risk): Blocking on a Task with \u0060.Wait()\u0060/\u0060.GetAwaiter().GetResult()\u0060 can deadlock (and wastes a thread). Prefer awaiting it: make the caller \u0060async\u0060 and \u0060await\u0060 instead. Where a synchronous entry point must stay \u2014 a public sync API you cannot break, or a process entry point that must not return until the work finishes \u2014 the block belongs in ONE documented bridge and never inside code that is already async; and where it already is that bridge, give the wait a TIMEOUT so a hung task fails the call instead of hanging the process."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.Persistence.CosmosDB/Repositories/AccountQueriesRepository.cs"},"region":{"startLine":72}}}],"partialFingerprints":{"codehealthFindingId/v1":"cdf7b8cb93dbd0b8f0c00efc1c226b0750dd97e937a5af07c0f4328012dddb83"}},{"ruleId":"X1","level":"warning","message":{"text":"Sync-over-async (deadlock risk): Blocking on a Task with \u0060.Wait()\u0060/\u0060.GetAwaiter().GetResult()\u0060 can deadlock (and wastes a thread). Prefer awaiting it: make the caller \u0060async\u0060 and \u0060await\u0060 instead. Where a synchronous entry point must stay \u2014 a public sync API you cannot break, or a process entry point that must not return until the work finishes \u2014 the block belongs in ONE documented bridge and never inside code that is already async; and where it already is that bridge, give the wait a TIMEOUT so a hung task fails the call instead of hanging the process."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.Persistence.CosmosDB/Repositories/AccountQueriesRepository.cs"},"region":{"startLine":111}}}],"partialFingerprints":{"codehealthFindingId/v1":"8d2b6d53bff42fdcd55bb20af381a88b6a33288cb3c7404002c151710179a2a4"}},{"ruleId":"X1","level":"warning","message":{"text":"Sync-over-async (deadlock risk): Blocking on a Task with \u0060.Wait()\u0060/\u0060.GetAwaiter().GetResult()\u0060 can deadlock (and wastes a thread). Prefer awaiting it: make the caller \u0060async\u0060 and \u0060await\u0060 instead. Where a synchronous entry point must stay \u2014 a public sync API you cannot break, or a process entry point that must not return until the work finishes \u2014 the block belongs in ONE documented bridge and never inside code that is already async; and where it already is that bridge, give the wait a TIMEOUT so a hung task fails the call instead of hanging the process."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.Persistence.CosmosDB/Repositories/AccountQueriesRepository.cs"},"region":{"startLine":153}}}],"partialFingerprints":{"codehealthFindingId/v1":"b8e49521a2b11243f9fdfb896c20e6cde2613f82126e5b37c589224b1004ef8a"}},{"ruleId":"X20","level":"warning","message":{"text":"Argument guard throws the exception its own condition disproves: The guard on line 14 rejects \u0060category\u0060 and line 14 reports that rejection as \u0060ArgumentNullException\u0060 \u2014 but the condition\u0027s own test \u0060string.IsNullOrEmpty(category)\u0060 is true of a value that is NOT null: it is satisfied by an EMPTY \u0060category\u0060, and on that path \u0060category\u0060 was already proven non-null by the very expression that decided it (\u0060||\u0060 short-circuits, so the null test to its left had to be false to get here). So a caller who passes a valid empty argument is told a parameter was null. That is not a wording problem: the exception type is the contract. A caller catching \u0060ArgumentNullException\u0060 to handle a real null swallows the empty case with it, and whoever reads the stack trace later is told a failure the source disproves. .NET separates the two on purpose \u2014 \u0060ArgumentNullException.ThrowIfNull\u0060 and \u0060ArgumentException.ThrowIfNullOrEmpty\u0060 are two helpers because they are two failures. Throw \u0060ArgumentException\u0060 for the empty case, or split the guard and throw each on its own condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.Domain.Entities/ValueObjects/Category.cs"},"region":{"startLine":14}}}],"partialFingerprints":{"codehealthFindingId/v1":"e3386b157b3f94a071c58f7cce95e823f009a99655408696b17c04837ea015bc"}},{"ruleId":"X20","level":"warning","message":{"text":"Argument guard throws the exception its own condition disproves: The guard on line 17 rejects \u0060description\u0060 and line 18 reports that rejection as \u0060ArgumentNullException\u0060 \u2014 but the condition\u0027s own test \u0060string.IsNullOrEmpty(description)\u0060 is true of a value that is NOT null: it is satisfied by an EMPTY \u0060description\u0060, and on that path \u0060description\u0060 was already proven non-null by the very expression that decided it (\u0060||\u0060 short-circuits, so the null test to its left had to be false to get here). So a caller who passes a valid empty argument is told a parameter was null. That is not a wording problem: the exception type is the contract. A caller catching \u0060ArgumentNullException\u0060 to handle a real null swallows the empty case with it, and whoever reads the stack trace later is told a failure the source disproves. .NET separates the two on purpose \u2014 \u0060ArgumentNullException.ThrowIfNull\u0060 and \u0060ArgumentException.ThrowIfNullOrEmpty\u0060 are two helpers because they are two failures. Throw \u0060ArgumentException\u0060 for the empty case, or split the guard and throw each on its own condition."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"KalanMoney/KalanMoney.Domain.Entities/ValueObjects/Description.cs"},"region":{"startLine":18}}}],"partialFingerprints":{"codehealthFindingId/v1":"9a7164b69d0f2e29d84d33430e967763911a3580d3c34103d8ddbae321906bb9"}},{"ruleId":"X5","level":"note","message":{"text":"Null-forgiving operator (\u0060!\u0060) suppressions reduce the NRT score: ~0.4 \u0060!\u0060 suppressions per 1k syntax nodes \u2014 2 suppression(s) across the 5210 syntax node(s) in code where nullable warnings are ENABLED, which is the only code a \u0060!\u0060 can suppress anything in (a \u0060!\u0060 under \u0060#nullable disable\u0060 is inert and is not counted, and its file\u0027s nodes are not in the denominator). Each one tells the compiler to trust you about null, suppressing the very safety NRTs provide."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"93cfe05d4ad8c8c171267603b23dfe289b74842e38edd1b7bfed59cc32bda337"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":8,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}