{"$schema":"https://json.schemastore.org/sarif-2.1.0.json","version":"2.1.0","runs":[{"tool":{"driver":{"name":"codehealth","informationUri":"https://codehealth.canine.dev","rules":[{"id":"D1","name":"Cyclomatic Complexity","shortDescription":{"text":"Cyclomatic Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D1"},{"id":"D2","name":"Cognitive Complexity","shortDescription":{"text":"Cognitive Complexity"},"helpUri":"https://codehealth.canine.dev/dimensions/D2"},{"id":"D3","name":"God Classes","shortDescription":{"text":"God Classes"},"helpUri":"https://codehealth.canine.dev/dimensions/D3"},{"id":"D4","name":"Code Duplication","shortDescription":{"text":"Code Duplication"},"helpUri":"https://codehealth.canine.dev/dimensions/D4"},{"id":"D5","name":"Coupling","shortDescription":{"text":"Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D5"},{"id":"D6","name":"Cohesion (LCOM4)","shortDescription":{"text":"Cohesion (LCOM4)"},"helpUri":"https://codehealth.canine.dev/dimensions/D6"},{"id":"D9","name":"Test Distribution","shortDescription":{"text":"Test Distribution"},"helpUri":"https://codehealth.canine.dev/dimensions/D9"},{"id":"D13","name":"Secret Scanning","shortDescription":{"text":"Secret Scanning"},"helpUri":"https://codehealth.canine.dev/dimensions/D13","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D15","name":"Churn \u00D7 Complexity Hotspots","shortDescription":{"text":"Churn \u00D7 Complexity Hotspots"},"helpUri":"https://codehealth.canine.dev/dimensions/D15"},{"id":"D16","name":"Bus Factor","shortDescription":{"text":"Bus Factor"},"helpUri":"https://codehealth.canine.dev/dimensions/D16"},{"id":"D17","name":"Explicit Debt","shortDescription":{"text":"Explicit Debt"},"helpUri":"https://codehealth.canine.dev/dimensions/D17"},{"id":"D19","name":"Documentation Quality","shortDescription":{"text":"Documentation Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D19"},{"id":"D20","name":"ADR Quality","shortDescription":{"text":"ADR Quality"},"helpUri":"https://codehealth.canine.dev/dimensions/D20"},{"id":"D21","name":"Naming Consistency","shortDescription":{"text":"Naming Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D21"},{"id":"D22","name":"Internal API Consistency","shortDescription":{"text":"Internal API Consistency"},"helpUri":"https://codehealth.canine.dev/dimensions/D22"},{"id":"D26","name":"Project Cohesion","shortDescription":{"text":"Project Cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/D26"},{"id":"D28","name":"Secrets (history)","shortDescription":{"text":"Secrets (history)"},"helpUri":"https://codehealth.canine.dev/dimensions/D28","relationships":[{"target":{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-798","CWE-259"]}},{"id":"D29","name":"Static Analysis (SAST)","shortDescription":{"text":"Static Analysis (SAST)"},"helpUri":"https://codehealth.canine.dev/dimensions/D29","relationships":[{"target":{"id":"CWE-79","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-89","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-94","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-77","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-79","CWE-89","CWE-78","CWE-94","CWE-77"]}},{"id":"D30","name":"Dependency Vulnerabilities","shortDescription":{"text":"Dependency Vulnerabilities"},"helpUri":"https://codehealth.canine.dev/dimensions/D30","relationships":[{"target":{"id":"CWE-1395","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-937","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1395","CWE-937"]}},{"id":"D31","name":"IaC \u0026 Container Security","shortDescription":{"text":"IaC \u0026 Container Security"},"helpUri":"https://codehealth.canine.dev/dimensions/D31","relationships":[{"target":{"id":"CWE-1032","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-16","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1032","CWE-732","CWE-16"]}},{"id":"D34","name":"Knowledge Freshness","shortDescription":{"text":"Knowledge Freshness"},"helpUri":"https://codehealth.canine.dev/dimensions/D34"},{"id":"D35","name":"Change Coupling","shortDescription":{"text":"Change Coupling"},"helpUri":"https://codehealth.canine.dev/dimensions/D35"},{"id":"D36","name":"Supply-chain Provenance \u0026 Signing","shortDescription":{"text":"Supply-chain Provenance \u0026 Signing"},"helpUri":"https://codehealth.canine.dev/dimensions/D36","relationships":[{"target":{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]},{"target":{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1357","CWE-494"]}},{"id":"D37","name":"Vulnerability-disclosure Policy","shortDescription":{"text":"Vulnerability-disclosure Policy"},"helpUri":"https://codehealth.canine.dev/dimensions/D37","relationships":[{"target":{"id":"CWE-1059","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-1059"]}},{"id":"D40","name":"Network Egress Confinement","shortDescription":{"text":"Network Egress Confinement"},"helpUri":"https://codehealth.canine.dev/dimensions/D40"},{"id":"D41","name":"Kernel \u0026 Syscall Confinement","shortDescription":{"text":"Kernel \u0026 Syscall Confinement"},"helpUri":"https://codehealth.canine.dev/dimensions/D41"},{"id":"D42","name":"Runtime Threat Enforcement","shortDescription":{"text":"Runtime Threat Enforcement"},"helpUri":"https://codehealth.canine.dev/dimensions/D42"},{"id":"D43","name":"Malicious Dependencies","shortDescription":{"text":"Malicious Dependencies"},"helpUri":"https://codehealth.canine.dev/dimensions/D43","relationships":[{"target":{"id":"CWE-506","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},"kinds":["relevant"]}],"properties":{"cwe":["CWE-506"]}},{"id":"D44","name":"Platform End-of-Life","shortDescription":{"text":"Platform End-of-Life"},"helpUri":"https://codehealth.canine.dev/dimensions/D44"},{"id":"AX10","name":"Code composition","shortDescription":{"text":"Code composition"},"helpUri":"https://codehealth.canine.dev/dimensions/AX10"},{"id":"AX3","name":"Project dependency cycles","shortDescription":{"text":"Project dependency cycles"},"helpUri":"https://codehealth.canine.dev/dimensions/AX3"},{"id":"AX5","name":"Architecture \u0026 structure","shortDescription":{"text":"Architecture \u0026 structure"},"helpUri":"https://codehealth.canine.dev/dimensions/AX5"},{"id":"AX7","name":"Slice cohesion","shortDescription":{"text":"Slice cohesion"},"helpUri":"https://codehealth.canine.dev/dimensions/AX7"},{"id":"AX8","name":"Test isolation","shortDescription":{"text":"Test isolation"},"helpUri":"https://codehealth.canine.dev/dimensions/AX8"},{"id":"AX9","name":"CQS / query purity","shortDescription":{"text":"CQS / query purity"},"helpUri":"https://codehealth.canine.dev/dimensions/AX9"},{"id":"AXB2","name":"Runtime readiness","shortDescription":{"text":"Runtime readiness"},"helpUri":"https://codehealth.canine.dev/dimensions/AXB2"},{"id":"M1","name":"Documentation (README)","shortDescription":{"text":"Documentation (README)"},"helpUri":"https://codehealth.canine.dev/dimensions/M1"},{"id":"M2","name":"Architecture documentation","shortDescription":{"text":"Architecture documentation"},"helpUri":"https://codehealth.canine.dev/dimensions/M2"},{"id":"M3","name":"Folder \u0026 project structure","shortDescription":{"text":"Folder \u0026 project structure"},"helpUri":"https://codehealth.canine.dev/dimensions/M3"},{"id":"M4","name":"Documentation accuracy","shortDescription":{"text":"Documentation accuracy"},"helpUri":"https://codehealth.canine.dev/dimensions/M4"},{"id":"P1","name":"CI/CD gates","shortDescription":{"text":"CI/CD gates"},"helpUri":"https://codehealth.canine.dev/dimensions/P1"},{"id":"P12","name":"CI test-gate honesty","shortDescription":{"text":"CI test-gate honesty"},"helpUri":"https://codehealth.canine.dev/dimensions/P12"},{"id":"P2","name":"Observability","shortDescription":{"text":"Observability"},"helpUri":"https://codehealth.canine.dev/dimensions/P2"},{"id":"P3","name":"Security \u0026 performance tooling","shortDescription":{"text":"Security \u0026 performance tooling"},"helpUri":"https://codehealth.canine.dev/dimensions/P3"},{"id":"P4","name":"Deployment \u0026 Rollback","shortDescription":{"text":"Deployment \u0026 Rollback"},"helpUri":"https://codehealth.canine.dev/dimensions/P4"},{"id":"P6","name":"Release Hygiene","shortDescription":{"text":"Release Hygiene"},"helpUri":"https://codehealth.canine.dev/dimensions/P6"},{"id":"X9","name":"Subsumed condition operand","shortDescription":{"text":"Subsumed condition operand"},"helpUri":"https://codehealth.canine.dev/dimensions/X9"}]}},"results":[{"ruleId":"D1","level":"warning","message":{"text":"libcontainer::rootfs::utils::parse_mount (cyclomatic 47): libcontainer::rootfs::utils::parse_mount has cyclomatic complexity 47 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/rootfs/utils.rs"},"region":{"startLine":92}}}],"partialFingerprints":{"codehealthFindingId/v1":"e96b7b52a167383d273d21a31858e0f0b51db03b2e0703a8628c04ab1c4bb5ab"}},{"ruleId":"D1","level":"warning","message":{"text":"libcontainer::process::init::process::container_init_process (cyclomatic 45): libcontainer::process::init::process::container_init_process has cyclomatic complexity 45 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/init/process.rs"},"region":{"startLine":43}}}],"partialFingerprints":{"codehealthFindingId/v1":"74fa2e9355623303e53fe00dc282e9a466687bf019ac28c0cdcf27225d5600fc"}},{"ruleId":"D1","level":"warning","message":{"text":"libcontainer::process::container_intermediate_process::container_intermediate_process (cyclomatic 23): libcontainer::process::container_intermediate_process::container_intermediate_process has cyclomatic complexity 23 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/container_intermediate_process.rs"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"cfdd8e269cc3185a7be16cc24dc71deec05ea862a9f6198ea89618a664def850"}},{"ruleId":"D1","level":"warning","message":{"text":"youki::main (cyclomatic 23): youki::main has cyclomatic complexity 23 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/youki/src/main.rs"},"region":{"startLine":65}}}],"partialFingerprints":{"codehealthFindingId/v1":"23b6c1c5732a003da870ccfac32847cbcb2ea9de05440417bd76fe1e4287bdd6"}},{"ruleId":"D1","level":"warning","message":{"text":"libcontainer::process::memory_policy::validate_memory_policy (cyclomatic 21): libcontainer::process::memory_policy::validate_memory_policy has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/memory_policy.rs"},"region":{"startLine":94}}}],"partialFingerprints":{"codehealthFindingId/v1":"452da7e176d8d079ca4d66c197bdcdd6fb32872f1b077e6531812876d690fb10"}},{"ruleId":"D1","level":"warning","message":{"text":"SeccompProgramPlan::try_from (cyclomatic 21): SeccompProgramPlan::try_from has cyclomatic complexity 21 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/seccomp/src/seccomp.rs"},"region":{"startLine":355}}}],"partialFingerprints":{"codehealthFindingId/v1":"560a23353118de4a5cdde2c1b6cd7eb178b25d343c9b5e2abba52e0410672ce2"}},{"ruleId":"D1","level":"warning","message":{"text":"Unified::apply (cyclomatic 20): Unified::apply has cyclomatic complexity 20 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/systemd/unified.rs"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"9be3ed88bfc3659992313745665c0682756acdacfeaca15f044a49bc08af4403"}},{"ruleId":"D1","level":"warning","message":{"text":"Validator::validate_spec_for_sysctl (cyclomatic 19): Validator::validate_spec_for_sysctl has cyclomatic complexity 19 (threshold 15). Of this number, 18 points are the body\u0027s own statements and 1 belongs to one function item inside it that branches. To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/validator.rs"},"region":{"startLine":211}}}],"partialFingerprints":{"codehealthFindingId/v1":"754dc90c3fc75d2101db9eb0fefd8e67bcb71bea03f9687f1aca3bf1f4c10cc0"}},{"ruleId":"D1","level":"warning","message":{"text":"libcontainer::seccomp::initialize_seccomp (cyclomatic 19): libcontainer::seccomp::initialize_seccomp has cyclomatic complexity 19 (threshold 15). To reduce it, separate the branches: extract each independent case into its own named function so the top-level body reads as a short sequence of named decisions. This is NOT this file\u0027s highest cyclomatic complexity: libcontainer::seccomp::translate_arch (cyclomatic 24) is higher and carries no row of its own \u2014 it was excluded as a flat dispatcher (a long switch/match over independent cases: many branches, almost no nesting), which this dimension does not treat as a refactor obligation. It is named here so the ranking you see in this file is not mistaken for the whole of it; the excluded function is counted neither in this dimension\u0027s figures nor in its score."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/seccomp/mod.rs"},"region":{"startLine":150}}}],"partialFingerprints":{"codehealthFindingId/v1":"ac8346222f02f0725d2883e3203092b7fca5ef1e949de9ffa024492dd34190ba"}},{"ruleId":"D1","level":"warning","message":{"text":"Header::parse (cyclomatic 18): Header::parse has cyclomatic complexity 18 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/systemd/dbus_native/message.rs"},"region":{"startLine":128}}}],"partialFingerprints":{"codehealthFindingId/v1":"01d57c463b563d6e4919a84604bb1c5c704512ec55a31e827179d5104b2665b2"}},{"ruleId":"D1","level":"warning","message":{"text":"Io::apply (cyclomatic 18): Io::apply has cyclomatic complexity 18 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v2/io.rs"},"region":{"startLine":126}}}],"partialFingerprints":{"codehealthFindingId/v1":"d55bcff83b1068cfb2104c90ffe97f0eb82f446a90b02a28d4f87c7ac74cd00d"}},{"ruleId":"D1","level":"warning","message":{"text":"Mount::mount_into_container (cyclomatic 17): Mount::mount_into_container has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/rootfs/mount.rs"},"region":{"startLine":571}}}],"partialFingerprints":{"codehealthFindingId/v1":"6197b0d31776d9eab0b647e0600c916ff410f9799baa3fdd33a88c988e4c2c09"}},{"ruleId":"D1","level":"warning","message":{"text":"libcontainer::process::container_main_process::container_main_process (cyclomatic 17): libcontainer::process::container_main_process::container_main_process has cyclomatic complexity 17 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/container_main_process.rs"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"8a05ff4e49aea6b4642b74ebd8ce04399f3989d131f9fc82aa676ded91124a41"}},{"ruleId":"D1","level":"warning","message":{"text":"libcontainer::process::init::process::setup_scheduler (cyclomatic 17): libcontainer::process::init::process::setup_scheduler has cyclomatic complexity 17 (threshold 15). To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Where every arm is uniform \u2014 the same kind of value, with no behaviour of its own \u2014 a table keyed by the case is the shorter form; wherever the arms carry different data or different behaviour, keep them as cases, because collapsing those trades an explicit, reviewable set of cases for nothing."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/init/process.rs"},"region":{"startLine":907}}}],"partialFingerprints":{"codehealthFindingId/v1":"fdf86d8e872cff969f8d3b697eecaec5398c63eb82ba27f99bef4bfc2fc3d834"}},{"ruleId":"D1","level":"warning","message":{"text":"libcontainer::hooks::run_hooks (cyclomatic 17): libcontainer::hooks::run_hooks has cyclomatic complexity 17 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/hooks.rs"},"region":{"startLine":36}}}],"partialFingerprints":{"codehealthFindingId/v1":"cce9184fb828d43bb36445280efd2e937cc912fafe613acecea38c870cc899b1"}},{"ruleId":"D1","level":"warning","message":{"text":"Container::checkpoint (cyclomatic 16): Container::checkpoint has cyclomatic complexity 16 (threshold 15). To reduce it, separate the cases: extract each independent branch into its own named function, and where the body has guards that only reject input, fold those into early returns at the top."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/container/container_checkpoint.rs"},"region":{"startLine":29}}}],"partialFingerprints":{"codehealthFindingId/v1":"1322d2596064e20545eda855e166413ca26a119201124529e736e28cf2fd1fc1"}},{"ruleId":"D2","level":"warning","message":{"text":"libcontainer::process::init::process::container_init_process (cognitive 66): libcontainer::process::init::process::container_init_process has cognitive complexity 66 (threshold 15). Drivers by points: if/else 34 (49 pts), match/switch 6 (11 pts), boolean chains 3, loops 1 (3 pts) (nesting depth added 22). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/init/process.rs"},"region":{"startLine":43}}}],"partialFingerprints":{"codehealthFindingId/v1":"8af0816f3782e9e41334eb5bea2c75a5528a8af0dd1b72153c7f25aa63015960"}},{"ruleId":"D2","level":"warning","message":{"text":"Validator::validate_spec_for_sysctl (cognitive 63): Validator::validate_spec_for_sysctl has cognitive complexity 63 (threshold 15). Drivers by points: if/else 11 (40 pts), match/switch 3 (18 pts), loops 1 (3 pts), boolean chains 2 (nesting depth added 46). Of this number, 62 points are the body\u0027s own statements and 1 belongs to one function item inside it that branches. To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/validator.rs"},"region":{"startLine":211}}}],"partialFingerprints":{"codehealthFindingId/v1":"0c4197378b80b39e409598a83cca8d463553fef03e658cd85359c9c1f143443d"}},{"ruleId":"D2","level":"warning","message":{"text":"libcontainer::seccomp::initialize_seccomp (cognitive 51): libcontainer::seccomp::initialize_seccomp has cognitive complexity 51 (threshold 15). Drivers by points: if/else 9 (20 pts), loops 6 (20 pts), match/switch 3 (11 pts) (nesting depth added 33). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/seccomp/mod.rs"},"region":{"startLine":150}}}],"partialFingerprints":{"codehealthFindingId/v1":"6d80955d099199b8a7f5e86483658a1722fbbac44ced2dc7fed5fe63e47e169f"}},{"ruleId":"D2","level":"warning","message":{"text":"SeccompProgramPlan::try_from (cognitive 50): SeccompProgramPlan::try_from has cognitive complexity 50 (threshold 15). Drivers by points: if/else 11 (26 pts), loops 5 (14 pts), match/switch 3 (10 pts) (nesting depth added 31). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/seccomp/src/seccomp.rs"},"region":{"startLine":355}}}],"partialFingerprints":{"codehealthFindingId/v1":"1742d89ba8f37b57b7484c3f023bff24f30921bc710e97e55d6451c871dbc5f1"}},{"ruleId":"D2","level":"warning","message":{"text":"libcontainer::rootfs::utils::parse_mount (cognitive 47): libcontainer::rootfs::utils::parse_mount has cognitive complexity 47 (threshold 15). Drivers by points: if/else 10 (31 pts), match/switch 4 (14 pts), loops 1 (2 pts) (nesting depth added 32). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/rootfs/utils.rs"},"region":{"startLine":92}}}],"partialFingerprints":{"codehealthFindingId/v1":"171b95a0a87457566ae9f90529989222fbdc2d06868334acd4e92c8467634a58"}},{"ruleId":"D2","level":"warning","message":{"text":"libcontainer::hooks::run_hooks (cognitive 43): libcontainer::hooks::run_hooks has cognitive complexity 43 (threshold 15). Drivers by points: if/else 13 (30 pts), match/switch 3 (11 pts), loops 1 (2 pts) (nesting depth added 26). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/hooks.rs"},"region":{"startLine":36}}}],"partialFingerprints":{"codehealthFindingId/v1":"4795e34e2b30b7cf637aeb3f788525cbac42ab086a81b8f32146b15757c17f3c"}},{"ruleId":"D2","level":"warning","message":{"text":"libcontainer::process::container_intermediate_process::container_intermediate_process (cognitive 34): libcontainer::process::container_intermediate_process::container_intermediate_process has cognitive complexity 34 (threshold 15). Drivers by points: if/else 19 (30 pts), loops 1 (2 pts), boolean chains 1, match/switch 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/container_intermediate_process.rs"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"ad3a96cb235befb8d89f4578e3ebc380185190ed81458f85fb47a7efd651a869"}},{"ruleId":"D2","level":"warning","message":{"text":"Mount::mount_into_container (cognitive 32): Mount::mount_into_container has cognitive complexity 32 (threshold 15). Drivers by points: if/else 15 (24 pts), match/switch 2 (5 pts), loops 1 (2 pts), boolean chains 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/rootfs/mount.rs"},"region":{"startLine":571}}}],"partialFingerprints":{"codehealthFindingId/v1":"553bd79e080dfb5e0b351f521b513d393d785d45301b277c0995e20d48522d9d"}},{"ruleId":"D2","level":"warning","message":{"text":"Io::apply (cognitive 31): Io::apply has cognitive complexity 31 (threshold 15). Drivers by points: if/else 13 (21 pts), loops 5 (10 pts) (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v2/io.rs"},"region":{"startLine":126}}}],"partialFingerprints":{"codehealthFindingId/v1":"941f8295fb6c460aa051859ade3f26c65c7f2039e9c171c1496a46bed0cbd8fe"}},{"ruleId":"D2","level":"warning","message":{"text":"Container::checkpoint (cognitive 30): Container::checkpoint has cognitive complexity 30 (threshold 15). Drivers by points: if/else 10 (19 pts), loops 3 (6 pts), match/switch 2 (5 pts) (nesting depth added 15). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/container/container_checkpoint.rs"},"region":{"startLine":29}}}],"partialFingerprints":{"codehealthFindingId/v1":"d43fe13617d020c7d6cb1009a578cac63461a1dd2259ffd4ac28b1ac76eef311"}},{"ruleId":"D2","level":"warning","message":{"text":"Validator::validate_spec_for_scheduler (cognitive 29): Validator::validate_spec_for_scheduler has cognitive complexity 29 (threshold 15). Drivers by points: if/else 8 (25 pts), boolean chains 4 (nesting depth added 17). To reduce it, flatten the nesting: this score is depth rather than breadth \u2014 most of its points come from checks stacked inside one another, so the work sits several levels in. Invert each enclosing check into an early exit (a return, or the language\u0027s equivalent) so the happy path stays at one level, and where a level cannot be exited early, lift the block it encloses into its own named function."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/validator.rs"},"region":{"startLine":317}}}],"partialFingerprints":{"codehealthFindingId/v1":"004fbc2cb77f318dc5cb162fe1281bf89fa6b649e820aae041a6a25592282ca5"}},{"ruleId":"D2","level":"warning","message":{"text":"libcontainer::process::memory_policy::validate_memory_policy (cognitive 27): libcontainer::process::memory_policy::validate_memory_policy has cognitive complexity 27 (threshold 15). Drivers by points: if/else 10 (19 pts), match/switch 4 (6 pts), boolean chains 2 (nesting depth added 11). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/memory_policy.rs"},"region":{"startLine":94}}}],"partialFingerprints":{"codehealthFindingId/v1":"881ddc78bfa7aff173acc3e506ecbde4e302789285b4234777f123be3d4a3a8c"}},{"ruleId":"D2","level":"warning","message":{"text":"Unified::apply (cognitive 24): Unified::apply has cognitive complexity 24 (threshold 15). Drivers by points: if/else 5 (13 pts), match/switch 3 (8 pts), boolean chains 2, loops 1 (nesting depth added 13). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/systemd/unified.rs"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"b44b8243bf905ad701f6cab9b1179a3dbf578bb6afe6dc2b76ea03be510bf795"}},{"ruleId":"D2","level":"warning","message":{"text":"Memory::apply (cognitive 22): Memory::apply has cognitive complexity 22 (threshold 15). Drivers by points: if/else 8 (17 pts), match/switch 2 (3 pts), boolean chains 2 (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v2/memory.rs"},"region":{"startLine":111}}}],"partialFingerprints":{"codehealthFindingId/v1":"fc287be8dc0f4cb3c68df186239d4a2de47b4e09ebe831c6ba6bbd855542583c"}},{"ruleId":"D2","level":"warning","message":{"text":"TenantContainerBuilder::adapt_spec_for_tenant (cognitive 20): TenantContainerBuilder::adapt_spec_for_tenant has cognitive complexity 20 (threshold 15). Drivers by points: if/else 13 (20 pts) (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/container/tenant_builder.rs"},"region":{"startLine":388}}}],"partialFingerprints":{"codehealthFindingId/v1":"1435add5274874bce43a1a1f9cdf92742e1411681b763d52c42a9b0722b03d4c"}},{"ruleId":"D2","level":"warning","message":{"text":"Mount::check_proc_mount (cognitive 20): Mount::check_proc_mount has cognitive complexity 20 (threshold 15). Drivers by points: if/else 7 (19 pts), match/switch 1 (nesting depth added 12). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/rootfs/mount.rs"},"region":{"startLine":959}}}],"partialFingerprints":{"codehealthFindingId/v1":"39eb93a45f8da04aad90b1ee7f9db12176c585c83fb46b87768605b26cd66847"}},{"ruleId":"D2","level":"warning","message":{"text":"Blkio::apply (cognitive 19): Blkio::apply has cognitive complexity 19 (threshold 15). Drivers by points: if/else 8 (11 pts), loops 4 (8 pts) (nesting depth added 7). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v1/blkio.rs"},"region":{"startLine":123}}}],"partialFingerprints":{"codehealthFindingId/v1":"ab67239b69626523d533767e15da2d615a6db7441d880a7659a89a154995e202"}},{"ruleId":"D2","level":"warning","message":{"text":"youki::commands::ps::ps (cognitive 19): youki::commands::ps::ps has cognitive complexity 19 (threshold 15). Drivers by points: if/else 8 (16 pts), loops 1 (3 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/youki/src/commands/ps.rs"},"region":{"startLine":10}}}],"partialFingerprints":{"codehealthFindingId/v1":"3107212f8dd6650d7eddd11ac8fc11d37bfcaf23938f9e7798c801a358d19a04"}},{"ruleId":"D2","level":"warning","message":{"text":"SELinux::get_config_key (cognitive 19): SELinux::get_config_key has cognitive complexity 19 (threshold 15). Drivers by points: if/else 5 (15 pts), loops 1 (3 pts), boolean chains 1 (nesting depth added 12). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/selinux/src/selinux.rs"},"region":{"startLine":161}}}],"partialFingerprints":{"codehealthFindingId/v1":"ac96eb12cfc52c923cba98e834fdcb12f8b4abd3a9f167149c5b0c020bc933d7"}},{"ruleId":"D2","level":"warning","message":{"text":"Freezer::apply (cognitive 18): Freezer::apply has cognitive complexity 18 (threshold 15). Drivers by points: if/else 4 (12 pts), match/switch 2 (4 pts), loops 1 (2 pts) (nesting depth added 11). The drivers above price the dispatch low by construction \u2014 a dispatch is charged once however many cases it lists, while each branch inside an arm is charged in full \u2014 so most of this count is what the case bodies hold, and the arms are where it can be reduced. To reduce it, keep the dispatch but shrink the arms: move each non-trivial case body into its own named function (or onto the value being matched) so the dispatch reads one line per case, and group related cases into a sub-dispatch. Keep every case explicit, and make the behaviour for cases you do not list a deliberate choice rather than an accident."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v1/freezer.rs"},"region":{"startLine":47}}}],"partialFingerprints":{"codehealthFindingId/v1":"693b5066529a42e8ff05a4f977e30ac42c538332591e2c60201e12c2863fc725"}},{"ruleId":"D2","level":"warning","message":{"text":"Cpu::apply (cognitive 17): Cpu::apply has cognitive complexity 17 (threshold 15). Drivers by points: if/else 12 (17 pts) (nesting depth added 5). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v1/cpu.rs"},"region":{"startLine":90}}}],"partialFingerprints":{"codehealthFindingId/v1":"aaaf967475b406295a7d2beaa9d23d1f46943dc2178fce7714d89413042f2fa2"}},{"ruleId":"D2","level":"warning","message":{"text":"libcontainer::user_ns::validate_mounts_for_new_user_ns (cognitive 16): libcontainer::user_ns::validate_mounts_for_new_user_ns has cognitive complexity 16 (threshold 15). Drivers by points: if/else 3 (10 pts), loops 2 (4 pts), boolean chains 2 (nesting depth added 9). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/user_ns.rs"},"region":{"startLine":319}}}],"partialFingerprints":{"codehealthFindingId/v1":"b9a5053434bba7db397c93d82356636961072d4f1bdfa780e741678d59b6f36a"}},{"ruleId":"D2","level":"warning","message":{"text":"libcontainer::seccomp::check_seccomp (cognitive 16): libcontainer::seccomp::check_seccomp has cognitive complexity 16 (threshold 15). Drivers by points: if/else 4 (10 pts), loops 2 (6 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/seccomp/mod.rs"},"region":{"startLine":119}}}],"partialFingerprints":{"codehealthFindingId/v1":"706e2760e299dbd17afc43618b1c26bcf51680f38efe8715c649f8a347a9d35d"}},{"ruleId":"D2","level":"warning","message":{"text":"seccomp::seccomp::check_seccomp (cognitive 16): seccomp::seccomp::check_seccomp has cognitive complexity 16 (threshold 15). Drivers by points: if/else 4 (10 pts), loops 2 (6 pts) (nesting depth added 10). To reduce it, split the body into named stages: move each independent step or branch into its own named function so the body reads as a short sequence of named calls rather than one long body."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/seccomp/src/seccomp.rs"},"region":{"startLine":269}}}],"partialFingerprints":{"codehealthFindingId/v1":"d24d702c1f06c0017062b3b0058a5cc0f6462ca8eb821d966bd1038cb87eb740"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: libcontainer::process::init::process::container_init_process: FunctionTooLong \u2014 libcontainer::process::init::process::container_init_process runs 290 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 190 over it, 2.90\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/init/process.rs"},"region":{"startLine":43}}}],"partialFingerprints":{"codehealthFindingId/v1":"986b3b5d775081c69e379e55a975f9d64f4134201e995f50107305b6c528ec66"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: Mount.mount_into_container: MethodTooLong \u2014 mount_into_container runs 185 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 85 over it, 1.85\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/rootfs/mount.rs"},"region":{"startLine":571}}}],"partialFingerprints":{"codehealthFindingId/v1":"1ddc4432f7f07a96e59ff1bcb43eef118c0990e331087f29831ff3336eb8f3b0"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: Mount: ClassTooLong \u2014 653 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 13 methods, 3 blocks, lines 115-1044. The bar is 400 significant lines; this is 253 over it, 1.63\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/rootfs/mount.rs"},"region":{"startLine":115}}}],"partialFingerprints":{"codehealthFindingId/v1":"1fc345e06d065598fc450f2099c782e50806ddd6a67e986e9e20e033e7aa8971"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: libcontainer::process::container_main_process::container_main_process: FunctionTooLong \u2014 libcontainer::process::container_main_process::container_main_process runs 154 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 54 over it, 1.54\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/container_main_process.rs"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"4baa1423346319d3322c28d7d84880b4c47201fae5995c49f4e41d08d582a0e1"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: rootfs/mount.rs: FileTooLong \u2014 753 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), about 87% of them inside a single declaration: Mount (3 blocks, 115-1044). The bar is 500 significant lines; this is 253 over it, 1.51\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/rootfs/mount.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"c9cbe4c62664439745b12ecce2e18eae721014d2c15fe2002aaaa962adad3e6f"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: SELinux: TooManyMethods \u2014 43 methods, declared across 2 files: src/selinux_label.rs (23), src/selinux.rs (20). The bar is 30 methods; this is 13 over it, 1.43\u00D7 the bar. That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/selinux/src/selinux.rs"},"region":{"startLine":96}}}],"partialFingerprints":{"codehealthFindingId/v1":"4eca4e5870090443bc0a9faa7abfeb42fe2080c2529ccdf5f528abfca6231736"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: Rule.build_instruction_with_args: MethodTooLong \u2014 build_instruction_with_args runs 140 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 40 over it, 1.40\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/seccomp/src/seccomp.rs"},"region":{"startLine":506}}}],"partialFingerprints":{"codehealthFindingId/v1":"12feab65d8e04cf74e9f76dd3145891fae70662b1533cc0098d7c77b15fb55d6"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: init/process.rs: FileTooLong \u2014 699 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 199 over it, 1.40\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/init/process.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"02d654968cc1e527b7c895d537143f2440276696398879920080b33e51e95f81"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: syscall/linux.rs: FileTooLong \u2014 686 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), about 65% of them inside a single declaration: LinuxSyscall (2 blocks, 313-1019). The bar is 500 significant lines; this is 186 over it, 1.37\u00D7 the bar. Moving the declarations that sit BESIDE it into sibling files will not shorten this file. Extract from INSIDE that declaration instead: lift each cohesive group of its body \u2014 the parts that share the same inputs and are named together \u2014 into its own unit in a sibling file, and have the original call them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/syscall/linux.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"30b0cf0bbafe00bf2b3ba1c96a917a8aba7a5f6a91c9f592cd450243a1dd19ba"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: Container: TooManyMethods \u2014 40 methods, declared across 8 files: container/container.rs (30), container/container_kill.rs (4), container/container_checkpoint.rs (1), container/container_delete.rs (1), \u002B4 more file(s). The bar is 30 methods; this is 10 over it, 1.33\u00D7 the bar. That list is where to read them, not a suggestion to split the file: the members belong to the type wherever they are declared, so moving them between files leaves the count unchanged. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/container/container.rs"},"region":{"startLine":17}}}],"partialFingerprints":{"codehealthFindingId/v1":"0af5df056aa1859ad04acb59e20505ea7dedb1ea60a97824598055adee158671"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: libcontainer::process::container_intermediate_process::container_intermediate_process: FunctionTooLong \u2014 libcontainer::process::container_intermediate_process::container_intermediate_process runs 127 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 27 over it, 1.27\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/container_intermediate_process.rs"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"08d6096ad3e98f192fe3a750a650bbb7f1b69398ca38ccabdfee387b72b52d07"}},{"ruleId":"D3","level":"warning","message":{"text":"ClassTooLong: LinuxSyscall: ClassTooLong \u2014 449 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted), 4 methods, 2 blocks, lines 313-1019. The bar is 400 significant lines; this is 49 over it, 1.12\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/syscall/linux.rs"},"region":{"startLine":311}}}],"partialFingerprints":{"codehealthFindingId/v1":"40546f05b34557463432535f2b0d4fd102a6d3c95d18c5f75a70b003f0ee86e7"}},{"ruleId":"D3","level":"warning","message":{"text":"MethodTooLong: Container.checkpoint: MethodTooLong \u2014 checkpoint runs 111 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 11 over it, 1.11\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/container/container_checkpoint.rs"},"region":{"startLine":29}}}],"partialFingerprints":{"codehealthFindingId/v1":"d0b1b6a057e57bc2cd2fb87479d279196ffd992c4a5ae01efeadb36a944978d0"}},{"ruleId":"D3","level":"warning","message":{"text":"TooManyMethods: TenantContainerBuilder: TooManyMethods \u2014 33 methods. The bar is 30 methods; this is 3 over it, 1.10\u00D7 the bar. To reduce it, group the members that share the same data into a smaller type of their own and delegate to it, so no single type carries every responsibility."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/container/tenant_builder.rs"},"region":{"startLine":40}}}],"partialFingerprints":{"codehealthFindingId/v1":"0e33dcb9b4e7619dd05a326c76d48ed4e73548d142ec9a52edaf181d3b37926d"}},{"ruleId":"D3","level":"warning","message":{"text":"FileTooLong: src/common.rs: FileTooLong \u2014 520 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted). The bar is 500 significant lines; this is 20 over it, 1.04\u00D7 the bar. To reduce it, split the file along the responsibilities already in it: move each cohesive group of declarations into its own sibling file in the same module or package, so no one file has to be read whole to change one of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/common.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"d997f821b8ae16382656a5a1018b597449432fc38d37a41d60c1ed79157bc435"}},{"ruleId":"D3","level":"warning","message":{"text":"FunctionTooLong: libcontainer::seccomp::initialize_seccomp: FunctionTooLong \u2014 libcontainer::seccomp::initialize_seccomp runs 104 significant lines (blank, comment-only and punctuation-only lines excluded, and inline test code \u2014 #[cfg(test)] modules and bare #[test] functions \u2014 not counted) in one body. The bar is 100 significant lines; this is 4 over it, 1.04\u00D7 the bar. This is length, not branching: a long straight-line body scores low on complexity and is still read whole to change any part of it, so the complexity numbers beside this row neither confirm nor excuse it. To reduce it, extract each cohesive step of the body \u2014 the runs of statements that work on the same values and would earn the same name \u2014 into its own named unit, and have this one call them in order."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/seccomp/mod.rs"},"region":{"startLine":150}}}],"partialFingerprints":{"codehealthFindingId/v1":"8bb87b4ff89cbb15f294291eea13db87cfda889a9f5c92bf0b5b98971fa48fd0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (51 lines \u00D7 2): crates/libcgroups/src/common.rs:580-630 | crates/libcontainer/src/rootfs/utils.rs:31-81 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/common.rs"},"region":{"startLine":580}}}],"partialFingerprints":{"codehealthFindingId/v1":"99264ef9eaf8504adf4fad9100d0d7b2731ef62765be42bd33c910b72d2bc80c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (45 lines \u00D7 2): crates/libcontainer/src/rootfs/mount.rs:656-700 | crates/libcontainer/src/rootfs/mount.rs:745-789 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/rootfs/mount.rs"},"region":{"startLine":656}}}],"partialFingerprints":{"codehealthFindingId/v1":"a83b67ef80cad945a31e51c8983d971445ebb23d35c805c7c198da10830552c5"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (21 lines \u00D7 2): experiment/seccomp/src/seccomp.rs:515-535 | experiment/seccomp/src/seccomp.rs:595-615 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/seccomp/src/seccomp.rs"},"region":{"startLine":515}}}],"partialFingerprints":{"codehealthFindingId/v1":"37f83962d05c19de6d1c09732df07cf518011fe8fc87c821f49084e96dfd144a"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): crates/libcgroups/src/v1/memory.rs:231-247 | crates/libcgroups/src/v1/memory.rs:260-276 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v1/memory.rs"},"region":{"startLine":231}}}],"partialFingerprints":{"codehealthFindingId/v1":"eedf459e4e3ed47593548790b55c063265b8cd36da8463a0232a1f0d82ed9106"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): experiment/seccomp/src/seccomp.rs:538-554 | experiment/seccomp/src/seccomp.rs:566-582 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/seccomp/src/seccomp.rs"},"region":{"startLine":538}}}],"partialFingerprints":{"codehealthFindingId/v1":"3c8719d0d988b3e1074c3cc9e925480ef0434eae3e1d21ff21afda4875e3bbe5"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (17 lines \u00D7 2): experiment/seccomp/src/seccomp.rs:618-634 | experiment/seccomp/src/seccomp.rs:647-663 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/seccomp/src/seccomp.rs"},"region":{"startLine":618}}}],"partialFingerprints":{"codehealthFindingId/v1":"4a3eaa7818de0f103b153564f892d222451124a53f79e48accaa4451aaecff60"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (15\u201316 lines \u00D7 2): crates/libcgroups/src/common.rs:539-554 | crates/libcgroups/src/common.rs:556-570 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/common.rs"},"region":{"startLine":539}}}],"partialFingerprints":{"codehealthFindingId/v1":"3842605c7e867687dc4def7af62f0ad540cadca0d1fb41ce790d1b2895285ef2"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 3): experiment/seccomp/src/seccomp.rs:551-564 | experiment/seccomp/src/seccomp.rs:631-644 | experiment/seccomp/src/seccomp.rs:660-673 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/seccomp/src/seccomp.rs"},"region":{"startLine":551}}}],"partialFingerprints":{"codehealthFindingId/v1":"5bc5446ed186cf9f578bc8630f3735649e6de4aee365d4f59398dd2ac7a80881"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12\u201314 lines \u00D7 2): crates/libcgroups/src/v1/controller_type.rs:22-33 | crates/libcgroups/src/v1/controller_type.rs:42-55 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v1/controller_type.rs"},"region":{"startLine":22}}}],"partialFingerprints":{"codehealthFindingId/v1":"95c496845262aaefdb739392d5130aa210ba1722772db364af8653a1534d8612"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (14 lines \u00D7 2): crates/libcontainer/src/container/init_builder.rs:214-227 | crates/libcontainer/src/container/tenant_builder.rs:357-370 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/container/init_builder.rs"},"region":{"startLine":214}}}],"partialFingerprints":{"codehealthFindingId/v1":"4473f7d9e5d96fa88749506d47a8d3a33e466c56dad7d2ff4a74079a478ed8ac"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 3): crates/libcgroups/src/v1/memory.rs:229-240 | crates/libcgroups/src/v1/memory.rs:258-269 | crates/libcgroups/src/v1/memory.rs:287-298 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v1/memory.rs"},"region":{"startLine":229}}}],"partialFingerprints":{"codehealthFindingId/v1":"713ad5b18210a64790f0c7163c86c2ed53e0575cd669567b476953f4b30ec2db"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/libcgroups/src/v1/util.rs:28-39 | crates/libcgroups/src/v1/util.rs:66-77 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v1/util.rs"},"region":{"startLine":28}}}],"partialFingerprints":{"codehealthFindingId/v1":"43d76bed73d464c7314ae44aac6c7a0f2e9deea3a650da2ee352369807063440"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (12 lines \u00D7 2): crates/youki/src/workload/wasmer.rs:35-46 | crates/youki/src/workload/wasmtime.rs:26-37 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/youki/src/workload/wasmer.rs"},"region":{"startLine":35}}}],"partialFingerprints":{"codehealthFindingId/v1":"8f1c234cc9fe61f7a431f555868248556a4386a8a2d59399a0ad6edc33a100c1"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/libcgroups/src/systemd/dbus_native/message.rs:205-215 | crates/libcgroups/src/systemd/dbus_native/message.rs:219-229 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/systemd/dbus_native/message.rs"},"region":{"startLine":205}}}],"partialFingerprints":{"codehealthFindingId/v1":"59c416623e28ceb30fdd0fe1cb6d4cb2fa2bbb8494829cb12c9b1b27fe286ac0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/libcontainer/src/process/container_intermediate_process.rs:62-72 | crates/libcontainer/src/process/container_intermediate_process.rs:92-102 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/container_intermediate_process.rs"},"region":{"startLine":62}}}],"partialFingerprints":{"codehealthFindingId/v1":"8fd04f53a5ed295e8574d96be5c601f07592e52f8574ab66cd44cd917ac257b6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (11 lines \u00D7 2): crates/libcontainer/src/process/init/process.rs:370-380 | crates/libcontainer/src/process/init/process.rs:417-427 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/init/process.rs"},"region":{"startLine":370}}}],"partialFingerprints":{"codehealthFindingId/v1":"ffc12948a24c7b97d1786b7a720ff2347549d808482ecf3897542dfbe975d311"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 6): experiment/seccomp/src/seccomp.rs:520-529 | experiment/seccomp/src/seccomp.rs:549-558 | experiment/seccomp/src/seccomp.rs:577-586 | experiment/seccomp/src/seccomp.rs:600-609 | experiment/seccomp/src/seccomp.rs:629-638 | experiment/seccomp/src/seccomp.rs:658-667 \u2014 all 6 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/seccomp/src/seccomp.rs"},"region":{"startLine":520}}}],"partialFingerprints":{"codehealthFindingId/v1":"9f06716b4ee4556ee8b1816d141ecb1dafc59591e543f9231a05b46795446669"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/libcgroups/src/common.rs:216-225 | crates/libcgroups/src/common.rs:243-252 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/common.rs"},"region":{"startLine":216}}}],"partialFingerprints":{"codehealthFindingId/v1":"079488ed3d7080cd9cd2835e4c995e1e97ae48fa8007f3d96d9dd59020b3bbbf"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/libcgroups/src/v1/cpuset.rs:70-79 | crates/libcgroups/src/v2/cpuset.rs:27-36 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v1/cpuset.rs"},"region":{"startLine":70}}}],"partialFingerprints":{"codehealthFindingId/v1":"d2da2a218d460b2b6412422f7385ef3c8b051974ee4e2a9d2a9f84e807cae0ad"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/libcontainer/src/network/address.rs:60-68 | crates/libcontainer/src/network/link.rs:35-43 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/network/address.rs"},"region":{"startLine":60}}}],"partialFingerprints":{"codehealthFindingId/v1":"8548445e2fe1fa6941f3078769dbf5f7a475620a3c2814ab3b2c6f58f7e96c73"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 2): crates/libcontainer/src/network/link.rs:96-104 | crates/libcontainer/src/network/link.rs:127-135 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/network/link.rs"},"region":{"startLine":96}}}],"partialFingerprints":{"codehealthFindingId/v1":"f039373f0ac4321b96917830ab97cb8f6bd99d37bd06cdcfe2c90ed360a35edb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5\u20138 lines \u00D7 4): crates/libcgroups/src/v1/blkio.rs:141-148 | crates/libcgroups/src/v1/blkio.rs:150-157 | crates/libcgroups/src/v1/blkio.rs:159-166 | crates/libcgroups/src/v1/blkio.rs:167-171 \u2014 all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v1/blkio.rs"},"region":{"startLine":141}}}],"partialFingerprints":{"codehealthFindingId/v1":"312af67a9b80510c40731038ef28cbefaa926b35ac7d17201abfb8ceacdeefdb"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/libcgroups/src/v1/hugetlb.rs:88-95 | crates/libcgroups/src/v2/hugetlb.rs:79-86 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v1/hugetlb.rs"},"region":{"startLine":88}}}],"partialFingerprints":{"codehealthFindingId/v1":"b7c6fd4ce8cfb516f56d3dab6df05400b821cc580335dc954bf68318d5b7a136"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 7): experiment/seccomp/src/seccomp.rs:515-521 | experiment/seccomp/src/seccomp.rs:538-544 | experiment/seccomp/src/seccomp.rs:566-572 | experiment/seccomp/src/seccomp.rs:595-601 | experiment/seccomp/src/seccomp.rs:618-624 | experiment/seccomp/src/seccomp.rs:647-653 | experiment/seccomp/src/seccomp.rs:676-683 \u2014 all 7 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/seccomp/src/seccomp.rs"},"region":{"startLine":515}}}],"partialFingerprints":{"codehealthFindingId/v1":"3f08d9440c7e0a9a75a82d6885ee56f0b6ec8b1e3bbb97645cef7296a36a71ef"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/libcgroups/src/v1/manager.rs:229-235 | crates/libcgroups/src/v2/manager.rs:252-258 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v1/manager.rs"},"region":{"startLine":229}}}],"partialFingerprints":{"codehealthFindingId/v1":"a2ed74cc4b2713943f8866c18cbf224a92574240e3fa8e699e1e2a9c40f31dad"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (4\u20136 lines \u00D7 4): crates/libcontainer/src/container/tenant_builder.rs:83-88 | crates/libcontainer/src/container/tenant_builder.rs:89-94 | crates/libcontainer/src/container/tenant_builder.rs:95-104 | crates/libcontainer/src/container/tenant_builder.rs:105-108 \u2014 all 4 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/container/tenant_builder.rs"},"region":{"startLine":83}}}],"partialFingerprints":{"codehealthFindingId/v1":"909e83c91182756a9bbdb0c71955597c9d1eb320b9ebce3c2e531ecbc1b9df86"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): crates/youki/src/commands/foreground.rs:124-128 | crates/youki/src/commands/foreground.rs:155-159 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/youki/src/commands/foreground.rs"},"region":{"startLine":124}}}],"partialFingerprints":{"codehealthFindingId/v1":"a6bc5ef2f0cf5580b0b1748642afbfcdd9d39da1ade075e2e9a071393801a711"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 2): crates/libcgroups/src/v2/cpu.rs:33-39 | crates/libcgroups/src/v2/memory.rs:36-42 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from both call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v2/cpu.rs"},"region":{"startLine":33}}}],"partialFingerprints":{"codehealthFindingId/v1":"6c9af50f83a83066f1fb04035ef9b5dfc98da796257fc0cd42d2fe0d2164a29d"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (13 lines \u00D7 3): crates/youki/src/workload/wasmedge.rs:79-91 | crates/youki/src/workload/wasmer.rs:121-133 | crates/youki/src/workload/wasmtime.rs:112-124 \u2014 the copies sit in sibling files of one directory, so a shared home is within easy reach: extract the block into a single shared function the call sites can all reach \u2014 a file they already depend on, or a new one alongside them \u2014 and call it from all 3 call sites, so a change lands once."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/youki/src/workload/wasmedge.rs"},"region":{"startLine":79}}}],"partialFingerprints":{"codehealthFindingId/v1":"bb152b180ddd8339ef4ac84ea1bea83716dc9529344aecebfce605874b29b430"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (10 lines \u00D7 2): crates/libcgroups/src/v1/hugetlb.rs:111-123 | crates/libcgroups/src/v2/hugetlb.rs:102-111 \u2014 the copies span different directories, so extracting a shared function means choosing where it lives: put it somewhere both call sites can already reach \u2014 a location they all depend on today, or a new shared one if there is none \u2014 and call it from each site; until then, every change has to be made twice."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v1/hugetlb.rs"},"region":{"startLine":111}}}],"partialFingerprints":{"codehealthFindingId/v1":"929d8090104634c3e3467ebfb0661fb5d1590928d1b960a852f070cde8b34224"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (7 lines \u00D7 3): crates/libcgroups/src/systemd/dbus_native/message.rs:207-213 | crates/libcgroups/src/systemd/dbus_native/message.rs:221-227 | crates/libcgroups/src/systemd/dbus_native/serialize.rs:474-482 \u2014 there are 3 copies across 2 file(s) \u2014 more copies than files, so at least one file holds the block twice. Extract it once into a single shared function every call site can reach and call it from all 3 sites; resolving a subset leaves the remainder to drift apart."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/systemd/dbus_native/message.rs"},"region":{"startLine":207}}}],"partialFingerprints":{"codehealthFindingId/v1":"45434392f8589195ed82f27d39e2c9bd5456c44a9547277bc683020f1b445cd0"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (9 lines \u00D7 3): crates/libcgroups/src/v2/io.rs:163-171 | crates/libcgroups/src/v2/io.rs:172-180 | crates/libcgroups/src/v2/io.rs:181-189 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v2/io.rs"},"region":{"startLine":163}}}],"partialFingerprints":{"codehealthFindingId/v1":"949912849e0ffdbc9e64d54b729cf9a06818c5014e4e79584c6b2482d8fe5bb6"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (8 lines \u00D7 2): crates/libcgroups/src/systemd/dbus_native/message.rs:437-444 | crates/libcgroups/src/systemd/dbus_native/message.rs:447-455 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/systemd/dbus_native/message.rs"},"region":{"startLine":437}}}],"partialFingerprints":{"codehealthFindingId/v1":"c72568a280e7358992b89c7a570cb3a4511721fe4e51f3fc46aa47a299f69e8c"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 3): crates/libcgroups/src/systemd/dbus_native/message.rs:429-435 | crates/libcgroups/src/systemd/dbus_native/message.rs:439-444 | crates/libcgroups/src/systemd/dbus_native/message.rs:449-455 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/systemd/dbus_native/message.rs"},"region":{"startLine":429}}}],"partialFingerprints":{"codehealthFindingId/v1":"5315f93a850edf815d663b19d30a89468ae4d7864a0fc3fd1a4fd5a4a4a3b7df"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (6 lines \u00D7 3): crates/libcgroups/src/systemd/dbus_native/message.rs:199-204 | crates/libcgroups/src/systemd/dbus_native/message.rs:430-436 | crates/libcgroups/src/systemd/dbus_native/message.rs:450-456 \u2014 all 3 copies are in the same file, so extract the block into one function there and call it from every one of those sites \u2014 resolving only two of them leaves the rest to drift apart the first time one is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/systemd/dbus_native/message.rs"},"region":{"startLine":199}}}],"partialFingerprints":{"codehealthFindingId/v1":"8145d98605c16ebb8c65bf5ac395527aac35e0b2d5dc111d9a21d1b6942d4c90"}},{"ruleId":"D4","level":"warning","message":{"text":"Duplicated block (5 lines \u00D7 2): crates/libcgroups/src/systemd/io.rs:81-85 | crates/libcgroups/src/systemd/io.rs:89-93 \u2014 both copies are in the same file, so extract the block into one function there and call it from each site \u2014 the copies drift apart the first time only one of them is edited."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/systemd/io.rs"},"region":{"startLine":81}}}],"partialFingerprints":{"codehealthFindingId/v1":"4441e4cc098317ae293446669bb0798c4f8962d5cb8d75bb19576e1fb9b59470"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: liboci-cli: liboci-cli: abstractness 0.00, instability 0.00, distance 1.00 \u2014 zone of pain \u2014 concrete and depended on by 1 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7dd4feb253f8fc7b06af0581a3ca581823ee03a7e4565309852c953be434d071"}},{"ruleId":"D5","level":"warning","message":{"text":"Off the main sequence: libcgroups: libcgroups: abstractness 0.13, instability 0.00, distance 0.87 \u2014 zone of pain \u2014 concrete and depended on by 2 project(s), so it\u0027s rigid to change."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"938ecd17a389b67ddeda658c6538d438047beb034edbdb684b2bb7e8ab034baa"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: SELinux (LCOM4 16): SELinux\u0027s methods fall into 16 groups that share no field and call none of each other, against a bar of more than 3 for this run (LCOM4, configurable \u2014 your repository\u0027s bar is the one quoted here). Each group is a set of methods reachable from one another through shared fields or direct calls, so 16 groups means the type has that many internally-connected clusters with nothing tying them together. Types whose shape makes a high count expected \u2014 and which would otherwise dominate this list \u2014 are excluded before this row is raised, so this is a genuine split candidate rather than a metric reading. It is still a shape, not a defect: confirm the groups match responsibilities you can name before splitting."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/selinux/src/selinux.rs"},"region":{"startLine":96}}}],"partialFingerprints":{"codehealthFindingId/v1":"ed28e3dec49ff14b468820d61338c693e14caf95d826cc19e38f693147e81bed"}},{"ruleId":"D6","level":"warning","message":{"text":"Low cohesion: ContainerBuilder (LCOM4 9): ContainerBuilder\u0027s methods fall into 9 groups that share no field and call none of each other, against a bar of more than 3 for this run (LCOM4, configurable \u2014 your repository\u0027s bar is the one quoted here). Each group is a set of methods reachable from one another through shared fields or direct calls, so 9 groups means the type has that many internally-connected clusters with nothing tying them together. Types whose shape makes a high count expected \u2014 and which would otherwise dominate this list \u2014 are excluded before this row is raised, so this is a genuine split candidate rather than a metric reading. It is still a shape, not a defect: confirm the groups match responsibilities you can name before splitting."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/container/builder.rs"},"region":{"startLine":13}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a54138fd3d915c01bc32a8561b4399f726af12f40671018eaa514ec81637c44"}},{"ruleId":"D13","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9c6bb77390408abff323d2b9f71e85ad584eb2b5b35ae38b0ce5207c4cd49414"},"taxa":[{"id":"CWE-259","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-798","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/libcontainer/src/process/init/process.rs: crates/libcontainer/src/process/init/process.rs changed 3 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 45 in libcontainer::process::init::process::container_init_process at line 43. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 12:46:19 \u002B09:00\u0027 --until=\u00272026-09-29 12:46:19 \u002B09:00\u0027 --full-history --no-merges -- crates/libcontainer/src/process/init/process.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/init/process.rs"},"region":{"startLine":43}}}],"partialFingerprints":{"codehealthFindingId/v1":"82267ec16c6a61ec66886e1fd267d8240e43be2e11726c62ab456643a7d0bcf0"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/libcontainer/src/process/container_main_process.rs: crates/libcontainer/src/process/container_main_process.rs changed 4 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 17 in libcontainer::process::container_main_process::container_main_process at line 50. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 12:46:19 \u002B09:00\u0027 --until=\u00272026-09-29 12:46:19 \u002B09:00\u0027 --full-history --no-merges -- crates/libcontainer/src/process/container_main_process.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/container_main_process.rs"},"region":{"startLine":50}}}],"partialFingerprints":{"codehealthFindingId/v1":"56e1017ce15566719695a71a28d580b889aa87446c369d4d1636a801e6fb8623"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/libcontainer/src/container/container_checkpoint.rs: crates/libcontainer/src/container/container_checkpoint.rs changed 4 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 16 in Container::checkpoint at line 29. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 12:46:19 \u002B09:00\u0027 --until=\u00272026-09-29 12:46:19 \u002B09:00\u0027 --full-history --no-merges -- crates/libcontainer/src/container/container_checkpoint.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/container/container_checkpoint.rs"},"region":{"startLine":29}}}],"partialFingerprints":{"codehealthFindingId/v1":"e3f695212d7a71d641e60f716e74ca32e8c138376bf62c636fedeb88dbae1ed6"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/libcontainer/src/process/container_intermediate_process.rs: crates/libcontainer/src/process/container_intermediate_process.rs changed 2 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 23 in libcontainer::process::container_intermediate_process::container_intermediate_process at line 42. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 12:46:19 \u002B09:00\u0027 --until=\u00272026-09-29 12:46:19 \u002B09:00\u0027 --full-history --no-merges -- crates/libcontainer/src/process/container_intermediate_process.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/container_intermediate_process.rs"},"region":{"startLine":42}}}],"partialFingerprints":{"codehealthFindingId/v1":"f9a24fd21f64f76a157a44f369cec301edc941f2f0126b1f8932fdb1c54a2830"}},{"ruleId":"D15","level":"warning","message":{"text":"Hotspot: crates/libcontainer/src/rootfs/mount.rs: crates/libcontainer/src/rootfs/mount.rs changed 2 times in last 90 days, and the most complex body those changes touched has cyclomatic complexity 17 in Mount::mount_into_container at line 571. Frequent change and high complexity in one file compound: schedule the next change to it to include carving out the part being edited, with the area under test before it moves. Counted over 2026-07-01..2026-09-29, the 90 days ending at the analysed commit. Reproduce with \u0060git log --since=\u00272026-07-01 12:46:19 \u002B09:00\u0027 --until=\u00272026-09-29 12:46:19 \u002B09:00\u0027 --full-history --no-merges -- crates/libcontainer/src/rootfs/mount.rs\u0060: merges are excluded because a merge re-states changes already counted at their own commits, and history is NOT path-simplified because a change that reached the file through a merged branch is still a change to it. That command counts raw commits and can read HIGHER than this row, which counts a cherry-picked re-land, and a revert together with the commit it undoes, once each \u2014 a difference of several commits on a file whose history was re-landed or reverted inside the window."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/rootfs/mount.rs"},"region":{"startLine":571}}}],"partialFingerprints":{"codehealthFindingId/v1":"43ecef2985e6d44973b536ad8bb97f4e43cc338d984ac31e61e2dfe92ca27a3f"}},{"ruleId":"D16","level":"note","message":{"text":"Off-boarding risk: anonymized user #1: If anonymized user #1 becomes unavailable, 1 significant file(s) lose their only recent owner: crates/libcgroups/src/v2/io.rs. Pair on, review, or document these before any departure."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"9707a4d494aef395ab5dd3d6085eeec6464bcfadf0c60fea1efdd731fe85c38b"}},{"ruleId":"D16","level":"note","message":{"text":"Further sole-owners (lower concentration): 5 other contributor(s) are each the sole owner of a small amount of code below the off-boarding threshold \u2014 folded into the bus-factor score and metrics (6 single-owned of 111 analysed files in total, counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 111 of the 192 production source files in this repository met that bar). They are anonymized user #2 (1 file(s)), anonymized user #3 (1 file(s)), anonymized user #4 (1 file(s)), anonymized user #5 (1 file(s)), anonymized user #6 (1 file(s)) \u2014 spread or document their files in the same way, at lower priority than the named off-boarding risks above."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"6eac528f2429e724e1a97ed868f79eefbcf1888dab4af9a9e673429369bb5b2f"}},{"ruleId":"D17","level":"warning","message":{"text":"FixmeComment: // FIXME: should we use runc\u0027s implementation? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v2/devices/emulator.rs"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"73361032c525770ef9aa617467665e30863cf2b332e110107946aaf235ca64d6"}},{"ruleId":"D17","level":"warning","message":{"text":"FixmeComment: // FIXME: should we start as \u0022deny all\u0022? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v2/devices/controller.rs"},"region":{"startLine":54}}}],"partialFingerprints":{"codehealthFindingId/v1":"e5dcf47a31dcba50fb28e1126411eec23451e0ee6c45f21554963270dedc9ae1"}},{"ruleId":"D17","level":"warning","message":{"text":"FixmeComment: // FIXME: apply user-defined and default rules in which order? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v2/devices/controller.rs"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"57e6e59acd95fffa37e1a39378f511507079eeccc80fb45fbe3f2fb5e7afd388"}},{"ruleId":"D17","level":"warning","message":{"text":"FixmeComment: // FIXME: simple way to attach BPF program \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v2/devices/controller.rs"},"region":{"startLine":82}}}],"partialFingerprints":{"codehealthFindingId/v1":"a339f50a59985e8eb9af00e2ad1325f4ced95a55a8403624fb6e62ddc451c50c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: consider use of #[mockall_double] \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v2/devices/bpf.rs"},"region":{"startLine":30}}}],"partialFingerprints":{"codehealthFindingId/v1":"8b8da051fb8fc264007a384caeee7292068e0180490e8a4bd6229413a6ccb4c8"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: consider use of #[mockall_double] \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v2/devices/bpf.rs"},"region":{"startLine":36}}}],"partialFingerprints":{"codehealthFindingId/v1":"a0ef0268c09b976daa2c7f0937bf773cae2a1b1ad67a3137165af7d15a73ab27"}},{"ruleId":"D17","level":"warning","message":{"text":"FixmeComment: // FIXME: Rarely does it fail. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/tty.rs"},"region":{"startLine":438}}}],"partialFingerprints":{"codehealthFindingId/v1":"711c7294f4bfd0c4a41d2d8d67915b84f45fd8bb2701756135a13aa7ab9406cd"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Remove the following parameters. To comply with the OCI State, hooks should only depend on structures defined in oci-spec-rs. Cleaning these up ensures proper functional isolation. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/hooks.rs"},"region":{"startLine":39}}}],"partialFingerprints":{"codehealthFindingId/v1":"bf0702f4ae7633867d1b65a2c3f28353a2acbae54d255dc58c7c8a428370921b"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: remove this guard when idmapped mount support is implemented. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/container/mount_validation.rs"},"region":{"startLine":96}}}],"partialFingerprints":{"codehealthFindingId/v1":"bdf02561a9ef5384736c8b2e96e70d827adbf2bee8ae35f462a115a6308f9c46"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: youki does not support selinux yet \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/container/builder_impl.rs"},"region":{"startLine":66}}}],"partialFingerprints":{"codehealthFindingId/v1":"1214d96f4f66ff04b7b3f06187c4966d8dbecf39ec33574a0274512c4bf53482"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO when nix or libc support this function, replace nx crates. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/init/process.rs"},"region":{"startLine":946}}}],"partialFingerprints":{"codehealthFindingId/v1":"7bd3bb9c11b7931da19625dc85537b430fa85644b4e6b98f98c05f06b8298035"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Path for previous criu image file in pre-dump \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/liboci-cli/src/checkpoint.rs"},"region":{"startLine":16}}}],"partialFingerprints":{"codehealthFindingId/v1":"0a09cb1424b705a61853b2a7d536603069cbd16af80eaa9f3528dcfa27d721bc"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Use lazy migration mechanism \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/liboci-cli/src/checkpoint.rs"},"region":{"startLine":37}}}],"partialFingerprints":{"codehealthFindingId/v1":"594a7227082ad0ee043675fe19287e68a698399d280b65edc025f71ea9d8392a"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Pass a file descriptor fd to criu. Is u32 the right type? \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/liboci-cli/src/checkpoint.rs"},"region":{"startLine":40}}}],"partialFingerprints":{"codehealthFindingId/v1":"b684d9d0ff4c426c9e9e0862a0d4ac4d1786a482a3b063e22aded9cbe380a395"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Start a page server at the given URL \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/liboci-cli/src/checkpoint.rs"},"region":{"startLine":43}}}],"partialFingerprints":{"codehealthFindingId/v1":"7027b447a8f37e97de3cd9f0b1ec2dba770fd5d1a36f64a236a3ba91c4cc74a8"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Do a pre-dump \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/liboci-cli/src/checkpoint.rs"},"region":{"startLine":49}}}],"partialFingerprints":{"codehealthFindingId/v1":"10cecc274242ba9cc11194c8e3e0fa45e9b1298a488b6cce4bbfa0a09ea9bb3b"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Enable auto-deduplication \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/liboci-cli/src/checkpoint.rs"},"region":{"startLine":60}}}],"partialFingerprints":{"codehealthFindingId/v1":"2c64df5b7126018c96ebc89741fd7c0fd88bd02d099dbd99199d580504ae673a"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: consider making colors configurable \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/youki/src/observability.rs"},"region":{"startLine":111}}}],"partialFingerprints":{"codehealthFindingId/v1":"16965071d7bf2fd1d84542542bc4129b4088afdc98b1932c897876a982a9825c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Expose seccomp support information \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/youki/src/commands/features.rs"},"region":{"startLine":78}}}],"partialFingerprints":{"codehealthFindingId/v1":"3b47a4218407e88cd89ab48e8eb6eff4022f96d4bf8e8f1a674582573482f321"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Address the case where don\u0027t use seccomp notify. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/seccomp/src/seccomp.rs"},"region":{"startLine":67}}}],"partialFingerprints":{"codehealthFindingId/v1":"f0c95fee168ff528fce42d40035c0a842fd4a1180db946c960dd31ff95f691a7"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Rename \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/seccomp/src/seccomp.rs"},"region":{"startLine":126}}}],"partialFingerprints":{"codehealthFindingId/v1":"3f7f52c56ecd1ae490ef6fbe406d681fc650e7252bd7c96dd6bff66cc5f59d18"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // Todo: consider need to porting SeccompError \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/seccomp/src/seccomp.rs"},"region":{"startLine":281}}}],"partialFingerprints":{"codehealthFindingId/v1":"ae73712f07fdba3088d3460fcd77f2083140384550bd81c9c687c2a013eca98c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // Todo: consider support other Arch \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/seccomp/src/seccomp.rs"},"region":{"startLine":388}}}],"partialFingerprints":{"codehealthFindingId/v1":"ec1ac3f80655c53afd55fc3664b95f87071fbb71d296a027954429c2c278f63b"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: use addMcs \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/selinux/src/selinux_label.rs"},"region":{"startLine":242}}}],"partialFingerprints":{"codehealthFindingId/v1":"69f6238c2ae6c2d41b66508cf5b48048de503db06aaf4a387a785491169f3b4c"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: use addMcs \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/selinux/src/selinux_label.rs"},"region":{"startLine":251}}}],"partialFingerprints":{"codehealthFindingId/v1":"33da84c0cbdce6c49a24c6a33f0d4d24b8eec7ccdf2b283edd9494bb835f3e2f"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: use addMcs \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/selinux/src/selinux_label.rs"},"region":{"startLine":274}}}],"partialFingerprints":{"codehealthFindingId/v1":"76c03f8bc062f97b431b6edcc415fdad8c25997aa2ee69bed586833411af3f44"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: remove this skip for youki once checkpoint/restore is supported. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/contest/contest/src/tests/checkpoint_restore/mod.rs"},"region":{"startLine":31}}}],"partialFingerprints":{"codehealthFindingId/v1":"14c031a978f00f231c616ac6b1b7d8908b91e7b8ca88236cb50c0d3389a0bb88"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Implement the test cases discussed in \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/contest/contest/src/tests/exec/cgroup_test.rs"},"region":{"startLine":121}}}],"partialFingerprints":{"codehealthFindingId/v1":"11ac02d0007a5ad32d5b90e36ca3f9dd1df426ff958d9f41fab8155665824bb2"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: Once youki supports restore, move these to \u0060checkpoint_restore\u0060 as \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/contest/contest/src/tests/lifecycle/container_lifecycle.rs"},"region":{"startLine":223}}}],"partialFingerprints":{"codehealthFindingId/v1":"b9ed8805c9a8fc5c259cd56ff26d4de32849a9463a1b60d100de0f458ba34bf3"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: /// TODO: Add architecture-specific expectations for non-x86_64 hosts if possible. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/contest/contest/src/tests/personality/mod.rs"},"region":{"startLine":76}}}],"partialFingerprints":{"codehealthFindingId/v1":"3e6ec2779755e341b2c979b1067e5cc4dc3fe4b4d695ab235e3a6b8993548d6a"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: /// TODO: This test currently validates youki\u0027s existing behavior, which differs from the OCI spec. \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/contest/contest/src/tests/poststop_fail/mod.rs"},"region":{"startLine":59}}}],"partialFingerprints":{"codehealthFindingId/v1":"834ed95eeed0ba621f9c27ea7de509d6d25eafa217d68349c0ea697e5bcceb84"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO: remove is_runtime_runc() condition when youki supports full update CLI \u0026 support test for cgroup_v1 \u2014 source code is not a task system: move the work to your tracker and leave a reference instead (e.g. \u0060// REF: #123\u0060), so the task is planned where tasks live and the ticket links back to the code."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/contest/contest/src/tests/update/mod.rs"},"region":{"startLine":58}}}],"partialFingerprints":{"codehealthFindingId/v1":"5d1d3f9d315b9a2440006c36a0682b0b64510a17e22005bcc94c89f7adf2c3ce"}},{"ruleId":"D17","level":"warning","message":{"text":"TodoComment: // TODO when https://github.com/rust-lang/rust/issues/86442 stabilizes,"},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"tests/contest/runtimetest/src/tests.rs"},"region":{"startLine":57}}}],"partialFingerprints":{"codehealthFindingId/v1":"4236358123477310a713fe2f883bfee4107eeabbcb577b2d6ac69166cf0392a1"}},{"ruleId":"D20","level":"note","message":{"text":"No ADRs found: No ADRs found. No recognised ADR directory (\u0060docs/adr/\u0060, \u0060docs/decisions/\u0060, \u0060adr/\u0060, \u0060docs/rfcs/\u0060, an \u0060ADR0001/\u0060 folder, or their siblings) exists anywhere in this tree. What was searched, so you can tell an empty log from a search that missed one: every directory under the tree (build output, dependencies and VCS metadata excepted), for a document that is either any non-index page inside a recognised ADR directory, whatever its name and however deeply nested (\u0060docs/adr/use-postgres.md\u0060, \u0060docs/adr/2024/0001-x.md\u0060); or a file anywhere whose name is ADR-shaped (\u00600001-use-postgres.md\u0060, \u0060adr-012-caching.md\u0060); or, when neither turned anything up, a document carrying the decision-record signature (an \u0022Architecture Decision Record\u0022 heading, or Status / Context / Decision / Consequences as section headings). A decision log that clears none of these \u2014 unnumbered files outside any recognised directory, without those headings \u2014 is not seen by this check and this row is then wrong. If that is your case, say so rather than renaming anything; otherwise, consider recording architectural decisions in \u0060docs/adr/\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d2bea044ff79d7d275f5a91a6e2f548586178eaf480274c33960ad020c854631"}},{"ruleId":"D22","level":"warning","message":{"text":"Inconsistent naming for single vs. batch operations. \u0060CgroupManager\u0060 uses \u0060add_task\u0060 (singular) but provides no batch equivalent, while \u0060Emulator\u0060 provides both \u0060add_rule\u0060 (singular) and \u0060add_rules\u0060 (batch). This creates an inconsistent pattern for collection-based mutations across the cgroup module.: Add \u0060add_tasks\u0060 to \u0060CgroupManager\u0060 to match the \u0060Emulator\u0060 pattern, or remove \u0060add_rules\u0060 from \u0060Emulator\u0060 if batch operations are not intended to be exposed directly. (signatures: libcgroups.common.CgroupManager.add_task(pid: Pid): Result | libcgroups.v2.devices.emulator.Emulator.add_rule(rule: LinuxDeviceCgroup) | libcgroups.v2.devices.emulator.Emulator.add_rules(rules: \u0026[LinuxDeviceCgroup]))"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e5457f408f6eb180f3c1830e4700915c55da83dd9b203d9a6e4e803c67828921"}},{"ruleId":"D22","level":"warning","message":{"text":"Ambiguous naming for configuration application. \u0060CgroupManager.apply\u0060 takes a high-level \u0060ControllerOpt\u0060 struct, while \u0060Devices.apply_devices\u0060 takes a raw device list. The verb \u0027apply\u0027 is used for both, but the semantic scope differs significantly (general controller config vs. specific device cgroup rules).: Rename \u0060Devices.apply_devices\u0060 to \u0060Devices.configure\u0060 or \u0060Devices.apply_rules\u0060 to distinguish it from the general \u0060CgroupManager.apply\u0060. (signatures: libcgroups.common.CgroupManager.apply(controller_opt: ControllerOpt): Result | libcgroups.v2.devices.controller.Devices.apply_devices(cgroup_root: Path, linux_devices: LinuxDeviceCgroup): Result)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"0b45cf3ca2c714735289d3faa2f48051b4bc0cd0ebca14e1e097a0fdb3a24d52"}},{"ruleId":"D22","level":"warning","message":{"text":"Redundant functionality between instance method and free function. \u0060CgroupManager.get_all_pids\u0060 retrieves PIDs for the manager\u0027s cgroup, while \u0060common.get_all_pids\u0060 takes a path. Since \u0060CgroupManager\u0060 already exposes the path (via \u0060cgroup_path\u0060 in \u0060CgroupConfig\u0060 or internal state), the free function duplicates the capability of the instance method for a specific path.: Remove the free function \u0060common.get_all_pids\u0060 and require users to instantiate a temporary \u0060CgroupManager\u0060 or use the instance method, ensuring all PID retrieval goes through the manager abstraction. (signatures: libcgroups.common.CgroupManager.get_all_pids(): Result | libcgroups.common.get_all_pids(path: Path): Result)"},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"77b5d0436229ffec480a1afe65961ee98bb32b2820e9f3d91aee21af06248320"}},{"ruleId":"D26","level":"note","message":{"text":"Projects may be oversized for their cohesion: 2 of 7 project(s) overshoot their size bounds, lowering Project Cohesion to 4.3/10. The most over is \u0060crates/libcontainer\u0060 (21564 LoC, 155 public types across 9 directories). Review these for cohesion \u2014 draw the boundary inside the module first (group each responsibility into its own package or directory and keep the cross-boundary members non-public), since splitting a published package moves types between packages and breaks consumers."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"d5a94650dc74886a0f1f08eb9fb6775f1fc395279ef7e901c970c9d26f767a72"}},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d5b8f11381d61a58459ffc7c595fd52d09c03c711894a63a9578043d2338412b"},"taxa":[{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"36204a9d0f20f4e912ce582f09a1cda18e993c022acceffec889d5fa4301a268"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f17ea273fe6214ddae95d0cd5866280599c24f41797efdeddaf67d6f25b92f0e"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"348541b6088f4dd83f00f7bdd5931caa0cb777059f221e1bcf3a52a12d3dcb43"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0cc16eb821153c7a181a4b05674dea3c591470ac621b11d5dfaf28ff6a628abe"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ee839d0cb1c09b1cc11fe2d268bc9a4023eb3a267c198a4b977530d5c735a76d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c18e0624f8b96c8485b456b0085ccc1f7a5be53adb9ef4c23d4be65e4c1353de"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b547da44fbb318f218ff01cbcf7c7443f26478afaf29b1c73ae0d9768c1b7c68"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6e314ae737be40acbdd1406f828ed8b0790f18d94b9f7ec81d9a6e0315684ca9"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c057b11f52b87bc604028d0ceeade5c39048013c26c569a0e5a0933e522427d6"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d0057c2feb3d8348f830d14bebdce29c33f5e6716c3d0b948ca003e350c6ad7e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"daee8f18c158b75f8c88d3b3e65b4fe9a938a6ef16e3d5a6f617c6bbc4597014"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8a5dff7788de9229b0c064e452f640cd146333920da991b72db18ff7c9d563e1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"40d36c0fa1bef3dc4edb14343fc9f334912e00b2a281e5fb6bd32378764dcd39"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d7c8fa867fb846a81ac2cd16412cb5d48bd224ced35bf56a58b5131fa71ef25c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9e8cb300752f344bd12c1fd094bfd96282991a063630c3cf692d39ce159de37d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dfec98795e8255b07b12e9cd5807e6eab2ddb0b85d263f35fa3494a4cb01cb34"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ba4cd3450edcbc562954b91eced54c2d39fe0050b568d266955440d3c31443d1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"99e624f05b5383d63e3f0c3c12cf61e7a6775156145abe6e65d45cf49d1f8d5f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7c2ca768088042b2c5fa328e87c45ca5f18ea36aef77652eca24fa2ab5acb566"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6a36dc2fd2be52d8f2f6b2d88e1b46f5d80b24d2431646ab2581c1375efd5f90"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d43aa4f2f7ef5f214141a9e7e1fa17421dde343c4401265e607dfa52f45e901a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3d50071e923e53e25626f60fa36122f1a99492bd7ad7b0ecb881b27a2b24715a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"20118912accb777032d5776d1eac31f72d7de9b49c237084f6b49e937334bb78"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6ea9339acbab01a2b34b547685b6c8a01c0ed7614dd425d73e2404d19b2fb4b2"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ab0c8646e822e5f353dc55fd218133b94af8765b5ca7ec468066494858c67fb2"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f0a4110758d5f1a9cedcc7d92f821ae06d797a8c4dcd62c465d80b2f7ce30cc2"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"72e4f767c66d99bb7c8448eaec88797afacd9b53f94b533b0c4c95e28efa5151"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b7a4832380b6ae965c7cac8327ee0ffd2fef6e884e3731a751d6672457de141a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e6ad2084e8cb1e6fa53f0ca55587c2a93f5c80c05295532b0c8ea3c11b2eb335"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"908eab02e6a658f90b082e50cf5771fbcae22f1c85601b3f4246477995775e0b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2a732579ee9d4e1f81e2b1b80730065e9ee59c039905abc78b42e9cc415a0923"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"710ee40d91e938c27b2c0ccc534a8cb4fc54a9feba4a38df7d36b6027855b248"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f112cb2313c43bc77f3723ce504c125f8ebbb5d8d0619953355775c284c16345"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ff7a512822411a00ac94240b40bb106ad150a0f55667d9a2a3281b12baaeca81"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"616950b02e0750471df0022b0bb15c91ae86551046285fc7f754156e471b0ff1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"962dbd6f5efe21f656fa9375ca7dc34f38ce60330dd3f4abaeca4101ea21da20"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0d26a86405f77aecd77857b2c9b63e58da0c9c7746aa54f373ae23d159863a9d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"081e9b06a308376e73f53d1fc689523c2950371a5fbc69e4c93cf0772d57692a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"97d3898e2b3a28c1145cf392664b7ee6114acc3c3809300cb747041d7c658e68"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1b9845e14a2e5cb4b1d226ec38807ccde50df7c9a7239b13c4d8824f60ce04b8"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6124ef06f0d1806213036c7d247ac1404613132e5cd1c1942128b6272ecc62e5"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bd61f15b6718caf3533c3f9612cf08831434e58ea02152386c03808d4273d26f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"34639774f58f6b5abb7d2222ea31d13c203b89ffe3fd765fc3c584e9aa17329f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9f9553003e2c2cf4e4896b4f9873ffb7d383350e29c59778a35772910d04aa19"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f26ec72d8dabe7e4b008e6c5d46de927cc587c09802919d6cd87145f6a2541ec"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"40c67e5f2df99af673c71f1db8efaec16f65e6ef3bd73342a90a4aec71092244"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a188a6d4ccdaa367d67e8076866a112645aca7ef1ebdd93ab1e501750ae7b531"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"78e97305fab157d859c9f10d219de05b335a2c65352adc72198f1a9f3b9cc3e6"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8b9594e55639cf270752d0ba9153fefe20e61ba2ce640ee2a84a48f93a3a437f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"440f02b3741dd0e15e8249552fbdc07742ed111187810bddcf78a3d3159dda50"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9efc57d316c6c865ffa64726555a8474f682abbf8cf2229b4aced2aa1f840252"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1f6323b160b07138c0a6eb82eb61d59bb78557799a9c159275dd8e5286454f0f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"03d9fb533724bcae0b9a058b9a41624059792a0453c28f089095ff5c7dbc691e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a6379666fac33962cddcc291a7d858a9444821429d0d16b985d5b6d0a1a494a8"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0b62caf688e812b4974b4b85f1ac1819b0d0922a6d876a6b765bef1e9d5dad31"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f648e79bec712d041f51f52d7363384564378cc8900231f35e43cf4413ba0a78"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1805961e4e503347f6fcd586d224da9e162abad638f415657a7549f9bdf3b1da"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7b73f02e41a06af7a790dc8694878d663d68ddc6d65178aa92ff5d4328a9e78c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a3a11ce2cab57f8c73d2f5138463abc74fde4ed3f826ce3fb27cfac7d1d585aa"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"140ca153f60b963bcea211cfb324c2bbda3cc17a7b18b7067d1195ba22059636"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ef34881bb3f18810d3643a9809226bacfe3185921b9da4a07d7934bad9a3e1c6"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ccbe09876c2c2c9340f5c198c3bfe7900f838928e54f994024f05bc72602c75d"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f154c7ecca7d6543a8c379eadbb26e0935963750fb833e61792f48ccf51b8d8c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a2bc29734384944597399d8e5ca73130dd88ed694708a316f5f586eb85fafff1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b0c9f10fbab4cb9b83d5c8efa2f66f0eae95a7b554024957a7450642bb85514b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"108fdab097ff4c3b15299afad08b12d9279b79fd3645b79ade7ea9f869ff693a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bee02421c61685d75b0d2716783d2e32ee930130b6e7df3ae68e3eb3042bf482"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eecaec86831790c51d796ca4e9c5147f37809840dd749ca5a3afdb37f354a251"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"952870365d2225365690abe06d0252821977cf51111f63afb70362f877d02666"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b7db045644de45d25679cfa98e4f19a616b2a93d852e2ac0cca1f73c8341e8e2"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"cf67cc928fbde83ec5be5534874f367e30de4f8c19634b9887a2a572ab45792b"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2e6227e3b1dfdd0676f5a45b10e0c277564e15507a9b17aaf8e89641a5fb5200"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bb5e76c08c5ef1a8c881e111ddeacd827f038fc55e552847a96f43cfcf315a7d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2b1f769eb71f02e5329638e5664cae1bc53faa0852bb280447cc5bb16462c4e2"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"81594bca49ba7af6d8b892b6e330de4cc344588f70e8091c3da7dde87572f03e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6beb5f80b3afd65a6b44c9dcf6cc40369623ece95c1fb3baf730fc6d0cf8f62d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f949706b60fbaaba308935688afb0404c0fd9c4bb690bfd3060f7206461687bd"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4ab6b3dfc475780a88b3b215f1282154207aac33b7693584dfe6a5a9d564c9d1"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dda56541f3d7488a5a7b008d1a3fb4dcb83506de61db69bfd685279b581c3bb5"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4703a6077032472d1f1d6086c0954e87442bc456541c050ecb16ccd6449b87a6"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"71b3fa13d96b889507d91c2bbcc08ca7a93011535a0d73aabeae7f6df68c734c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f354a1655d7d53781d4fb11f1bf39be9b4932ef910d07d8d33a5e01ce19651e5"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"75b886c1b07dd4f0520531739deb24e22daf6a4eb8a85f3d1ca471438266092d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9716a163e910cd702b5e59c0a356037af20bf319971aa61bc08f60cfe621ef6e"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b92306b8e0f2194620971fcd0cb5df18b3ebe021e06f95e57ebd4a7981e6633a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3da669cea798ee5977b4b716c093b7c2f2a8117b3220fedd52312a19b42f7d00"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c3906467e3de220803dccd35b794f444e9b6f2b70c79965dd748aa177b6fcece"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"341ae78b0544f42b6ad44c2b97326c43bc3f461be401f6abd798e15a4b812bf9"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"25a6177289053818b7f361c4b2ff007c73a88a745bdb9a46815fab404bb7ccd5"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"35c970d5f849efba9a8f0968fdc55180aca2d8725b3174f04a77652a8df48e7c"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6f4c2d96919bf22db75330b663059a6af6ecab9a7b7dfe3e0ac3fa946c3a5b3a"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e85c878f025c1af143312a37e873ddd6e3a7e88aa2f7d9d5561fe986a46b7939"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a39c73de91ac6e90ffa80240860895b580d23de08b6e6485307da1fd8d8af5ee"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9ee8a717415e899d9772965377e2301a369daa8e06fef41d4d07a6de87a5024f"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"58ef75dc2e5cc1550056aee56a24d48fa8945676a32c58339ffddaf36604908d"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3862712a8811135b0f69a102a9de675a9b4041360ec01cdaf731c78b07a2ca01"},"taxa":[{"id":"CWE-78","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"77fb7bad6dab9c4de28a0f9337b23aafcf930fa866ac3140059ffdd766006396"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"adf689ae3b9a9cc633355acd7a2ca10309a084d817eb03b7a86e5ceec202779d"},"taxa":[{"id":"CWE-522","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-829","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f3978d1efcfb5d8e45414dc2db82d4fb6aaaa16dae4d66659613ac3ade298306"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1352","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b8882f6923923b3e9b05522e2abdbfd012cee9c85ce8d2d1ee9eb6799dc19590"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1352","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2bea8a8d374c25a1aa7c621f770cc103bfd2120d3c2b94a1e8f61c993927bac3"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1352","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d569f4adee8cc3f9801e3624c26c6bac0bee66278b9ac5bea47a3a4df7dd9e33"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1352","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"98fd29a158b3d65803eab3ec4596b283c929f283842d372eaf597ab8b2eaaeff"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-1329","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D29","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"267222415026b1a20450c19e6c3542d60906c3cbdfa24f08e7d4e6de44061b89"},"taxa":[{"id":"CWE-732","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D30","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0d3d2c2346bccaaa14c1bd0f0713c18ae4de849fffdc7282dbd533ab105c9398"},"properties":{"dependency":{"package":"rustls-webpki","version":"0.101.7","advisory":"[GHSA redacted]","aliases":["[CVE redacted]","[CVE redacted]","[CVE redacted]","[GHSA redacted]","[GHSA redacted]","RUSTSEC-2026-0098","RUSTSEC-2026-0099","RUSTSEC-2026-0104"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5922a5beeab5ac077ffb485a783ad545036e79b56239f83da38f3fb84336b113"},"properties":{"dependency":{"package":"paste","version":"1.0.15","advisory":"RUSTSEC-2024-0436","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b5524f25221308ec94b7206b58afaa59996104c20abaa242285d451f5344e44b"},"properties":{"dependency":{"package":"rustls-pemfile","version":"1.0.4","advisory":"RUSTSEC-2025-0134","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4975822701b3b96654c82dada9bad969e348a6adefa52cd3bba1b6cfd71c3bb7"},"properties":{"dependency":{"package":"bincode","version":"2.0.1","advisory":"RUSTSEC-2025-0141","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d469c4cdd0b2892278c4ee90c01a5a8ea4872a98733c483777e04c904cfebdfc"},"properties":{"dependency":{"package":"proc-macro-error2","version":"2.0.1","advisory":"RUSTSEC-2026-0173","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2a461caaaec15fef28940ccf35ef0cb7166346564b54a0482181856a41c5b524"},"properties":{"dependency":{"package":"memmap2","version":"0.6.2","advisory":"RUSTSEC-2026-0186","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"497eaf912f0ba05fdddec76264b47685d1f54edd1c30dfe139c5e04bab0bfc83"},"properties":{"dependency":{"package":"memmap2","version":"0.9.10","advisory":"RUSTSEC-2026-0186","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c4a0c58aca13bc848c37d4c3d5bcb90f8e046f8df5b386f5a3743d0625ad8dae"},"properties":{"dependency":{"package":"crossbeam-epoch","version":"0.9.18","advisory":"RUSTSEC-2026-0204","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"724dc287344d7132b72d1f16bb1fc253c8392cf978fd4bf6d454481b72775b59"},"properties":{"dependency":{"package":"rkyv","version":"0.8.16","advisory":"RUSTSEC-2026-0233","aliases":["RUSTSEC-2026-0234","RUSTSEC-2026-0235"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"80b5c22beae306eb623d7a60ec13361ab89285e1cc30fcf5b8daa2e87ffb5c69"},"properties":{"dependency":{"package":"h2","version":"0.3.27","advisory":"RUSTSEC-2026-0258","aliases":["[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3035e85b1a9c0c33df37dc333f490439b3fa52aefda24a401e2e75a177cdf778"},"properties":{"dependency":{"package":"rustls","version":"0.23.39","advisory":"RUSTSEC-2026-0285","aliases":["[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"55929e491a317abec73a7f767e416b5b9e572eb252b936c912fc2b9f6f8bb501"},"properties":{"dependency":{"package":"wasmtime","version":"46.0.3","advisory":"RUSTSEC-2026-0316","aliases":["[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9d2317e120cc6802c2468e5f9d0480ee099f394275fbd6ad416ab2e7667e4615"},"properties":{"dependency":{"package":"adler","version":"1.0.2","advisory":"RUSTSEC-2025-0056","reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"01350bdc315520e3575c512bcb62e904d6d41ee3d3289a2f6c5e8a38bb4d1ce2"},"properties":{"dependency":{"package":"tokio","version":"1.37.0","advisory":"RUSTSEC-2025-0023","aliases":["[GHSA redacted]"],"reachability":{"kind":"unknown"}}}},{"ruleId":"D30","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"bc413681109e4ea690d14326fc5c04f9c7015d35d62a2fc339ac9c752aa4f2f6"},"properties":{"dependency":{"package":"anyhow","version":"1.0.81","advisory":"RUSTSEC-2026-0190","reachability":{"kind":"unknown"}}}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7abb4b705d8a21adfbbb5ef5251323ca16e84f0c2e4a584860f577e97c6843bf"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"71169d282b063fc46e719b5dd130c2e534fd93b286a1ba5294c2d29fab5731d0"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7207a315cad4e995f842eebc642746cc2b88413e8d07f6f8f8cb9c52b77e0315"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ea1e40484b6c32ee8f93a000c9b0b55cce858a7a6881ed47b4d156e285716f23"},"taxa":[{"id":"CWE-1104","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"886e4ee4a6812a60dddd59f8daa2ba1e360f4a9dbf7ec6c55804ad7826b90954"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"41de5d0c09423f07c1c39f9634de7d7810695e40463194562df66155da77fa48"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"900a326d50e522a3849e86f1ef61f751c837281cc0e530e3fa63490a62103789"},"taxa":[{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6e00a9d6ff3e7f8669ac2742bb740e2b6e539a2b774b28eec0cff97a3e64aaef"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"244b0186bac8fadf5a2654db7a2d383076c59bc808f266e4c2f062e0fdb93fb7"}},{"ruleId":"D31","level":"error","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b5b05c642c45a8a5e1a19c96e2d0c0e9257534160724e9c6c9bb15d1f1d92a66"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e1e6fdd9693494344fae08e17fc190a7474dcac4171ba778d431ec1395e422b6"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"aab196cb0c159c69587710484d3e816f3ae6d59504aad72388e5ee25021343e8"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f7aa41b73dbf7ec1c81606b23f59edfd7b9644e435392a6acb7e873a2ecbff46"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7d4e785e21fbf2ee28fe8e6640fae5ebb27848d2fd1cd1fa943307f2fcbadc02"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4ad5545a15bc8f0af312b77cd5ba0b2c1847eda07294b5747017961992463592"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"f8fd4c79c9e96a9b48c09c2869a04433c49e48c78f8e871c706296ac048b9745"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"8f14dda6aaba53c5e926f1c749daeb31077fbe6f50c91a553272d305b13e5f83"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"905e424fbd836cf59d4c74752a0c3e86208db728d2acc0b862cab0e0fd947834"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"2160c69a22a7b6da6d7bae22e5565e9e66da5682461bb7a3a3115d2fd71c0d5b"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9f6779b3f6450a0703636a704c7003d1d90b85efe81595cd7e2949b07381d53d"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"9ca4e5ab7ee7f9578409730168c617ddacd9290360377b82a5e8285af0b5e62f"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a777ae97c497a3916716a1ed388733c9d23f41afc98537d95e8619001c425038"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5f669aca29209fed7cd115d92c0370d6ea20252cfd9187f3fcf691d2c5d9f664"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"faa4c8fa5b77f78f0003e44f5a1deb15313729e10296750746f0c7db7236ce47"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"565d00ede46429ae67039eeb121b466b6d71b11692de2d124c7f8347a628a932"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4eb8fecd3fc2b7bc13aa289d96d7df26d56c5b3f066f582c95fc15b1549eec7a"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1fb201986107aabc7f0f68e650d8becb99e054656d118512deff2983a2c19823"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"6df93ab2b2631a5a8d696c183e8085442b15e8cf5f9608aa1e5eff6ae9e498aa"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1812b546c543b8ea654166f09c598130fa669c3e3886e72ae794bb3ea899a506"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"dfdcc1a6ee7695b993c26f120feb6a906987f27018dcdfc75a47cea371415917"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e45b3f603f209f98467849aadbb7734d547893e6fe3e3da36684abb0330b5cf0"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"829ff937b46b8c69ab1a31bec6472b359049b9e40d83ff38a5edd77c6880cf8f"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"e610875c672c00d1a89b43267ef4e9103bdd47706222841c3c7a268b981bd2ed"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0718959280d4340efaeb8e5be3c3b6093ddbe9c3ac7ba1487232df553d17ea47"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"4d9d5395e027e287ac9f83b293385fc37f5f3ab6911bf65f97691a1e5b8094ea"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0d3b822f4ecb540b6f3213c54071e40e343c12a5f878fcf7bf466487da80367b"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"86a248f4d0c687b59a941ce936cc9994cf5e8435c5dcd711b18290af634e991e"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"ed7b88f615c26c8a34680859340cd1cfe5f2fc1a5cb004abf12f4b7b58fe2396"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"21db80931460c10ffa5e6395b7fff39a497d5411e108de4de93d483f99079fa9"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a9729ceb6d28025415e4987efe51245a5e70827a37f86e64cf2bd27d08ae0d37"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"82d5b18fc25a64da81a731c70a84fd7b9f2c430c4c4de9ccb063f8d20c21c2a2"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d9defeb9e702fbed3539ebbea956e6666ff3a48364f6488ec00132316cfc8040"}},{"ruleId":"D31","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1f4a01abbf0e20a57b465b24aaa19500fca74fba4d685d3dd7df37dc3768d377"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3adeb5ca433f8377e0513466abe226661632e2c7a65ab03d48b79033987746ab"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"3b1568673c97a5ce9b1ec5a08dba083d705b7ca92047378b6f33333438b27491"},"taxa":[{"id":"CWE-1357","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}},{"id":"CWE-353","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"c790f76cf70ef3b7e11b2b2e046aa998549442297137ee1873617b41f8d8e165"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"a0253cdb433485d93f1259fe935cad7c5df0486a99bae72ae65dbbacb158f6f3"},"taxa":[{"id":"CWE-494","toolComponent":{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d"}}]},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"7e84d396b5ad272ce3a4b3679578c175ab67edb6f1d3803ece2a287e4f6461cb"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"b612f4555455b3d38c765f45ab8eeef5230d508ba4f5ec24dfa2feb7e7e2e5fc"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5bdd11c78a3fcf60c2d97908220f8c43666ca28fb02769100774d0df9a452884"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"caf7c88ce3d6888c2e0dea52340b161a13730bf0ab583f6b27a8fcb597c639d2"}},{"ruleId":"D31","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"47c56526c3e5cf419543fbd7d1c10be1ab4c9a728ff96a78ab594dd9a7a3965d"}},{"ruleId":"D34","level":"error","message":{"text":"Orphaned knowledge: No living knowledge remains for this large file \u2014 its last meaningful change has decayed away, so if it breaks, no one currently understands it. It does carry its own tests, so the behaviour is pinned even though the understanding is gone: schedule a read-through, using those tests as the specification, before the next change lands here."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/systemd/dbus_native/message.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"59c5ef51f7ac469e8ed658b9cf8fd307c331676a2df61b600e1cab77f63ce2cb"}},{"ruleId":"D34","level":"error","message":{"text":"Orphaned knowledge: No living knowledge remains for this large file \u2014 its last meaningful change has decayed away, so if it breaks, no one currently understands it. It does carry its own tests, so the behaviour is pinned even though the understanding is gone: schedule a read-through, using those tests as the specification, before the next change lands here."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/v1/memory.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"b212e5989c53d01b9e27da4a0c2d1ebeec87bb432bb28f7062a6e7aa49b5de33"}},{"ruleId":"D34","level":"error","message":{"text":"Orphaned knowledge: No living knowledge remains for this large file \u2014 its last meaningful change has decayed away, so if it breaks, no one currently understands it. It does carry its own tests, so the behaviour is pinned even though the understanding is gone: schedule a read-through, using those tests as the specification, before the next change lands here."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcgroups/src/stats.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"857ed4038ad6ae9639bd89d659484c02a551ac22e1852b8f0793f674fa5c4f28"}},{"ruleId":"D34","level":"error","message":{"text":"Orphaned knowledge: No living knowledge remains for this large file \u2014 its last meaningful change has decayed away, so if it breaks, no one currently understands it. It does carry its own tests, so the behaviour is pinned even though the understanding is gone: schedule a read-through, using those tests as the specification, before the next change lands here."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"experiment/selinux/src/selinux.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"0038e30dc907077cc48f05a8030a45c39de714ff038e177183012d4bbc96c4a2"}},{"ruleId":"D34","level":"error","message":{"text":"Orphaned knowledge: No living knowledge remains for this large file \u2014 its last meaningful change has decayed away, so if it breaks, no one currently understands it. It does carry its own tests, so the behaviour is pinned even though the understanding is gone: schedule a read-through, using those tests as the specification, before the next change lands here."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/memory_policy.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"db46d06cf003c46483447abf4b660000710057767b94a5212ce50bf7c22146e7"}},{"ruleId":"D34","level":"note","message":{"text":"Further orphaned files (smaller): 31 smaller file(s) also have no living knowledge \u2014 folded into the freshness score and metrics rather than raised one row each \u2014 most significant first: crates/libcontainer/src/process/fork.rs, crates/libcgroups/src/systemd/dbus_native/serialize.rs, experiment/selinux/src/selinux_label.rs, crates/libcgroups/src/v1/blkio.rs, crates/libcgroups/src/v2/memory.rs, crates/libcgroups/src/v2/devices/program.rs, crates/libcgroups/src/v1/freezer.rs, crates/libcgroups/src/v1/hugetlb.rs (and 23 more) (36 orphaned of 111 analysed files in total, counted over production source files of roughly 2,400 bytes or more, excluding vendored, generated and example/demo trees and test files identified by path convention, largest first; 111 of the 192 production source files in this repository met that bar). Attach the read to the next change that touches one of them: have a second person review that change, and leave behind a short comment or test recording what the file is for, so the knowledge comes back at the cost of a change you were making anyway."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"ce861fd78f6935114d3a342cb90ad25870f984e1042954fcbbe27c0e23be3658"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: process.rs \u2194 default.rs: \u0060crates/libcontainer/src/process/init/process.rs\u0060 and \u0060crates/libcontainer/src/workload/default.rs\u0060 change together 80% of the time (8 of the 10 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 8 shared commits counted here, the most recent 3 are \u0060bdd5aabd\u0060 Add new \u0060setup_envs\u0060 method for the \u0060Executor\u0060 trait (#2820) (at that commit the file was still \u0060crates/libcontainer/src/process/container_init_process.rs\u0060); \u00607f8422f2\u0060 Add channel message when exec fails (at that commit the file was still \u0060crates/libcontainer/src/process/container_init_process.rs\u0060); \u00605f3f4ce8\u0060 move the validation logic into executor (#2258) (at that commit the file was still \u0060crates/libcontainer/src/process/container_init_process.rs\u0060) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/init/process.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"777d6a90073fcb431f7e86f3cedf1da681361e1c19ac185bb7ed82c82bd3a4b8"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: init_builder.rs \u2194 tenant_builder.rs: \u0060crates/libcontainer/src/container/init_builder.rs\u0060 and \u0060crates/libcontainer/src/container/tenant_builder.rs\u0060 change together 58% of the time (33 of the 57 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency between them. They sit in the same directory, but in this ecosystem each file is its own module \u2014 a sibling reference still needs an import \u2014 so the missing import edge is real: the coupling runs through shared behaviour, not a declared dependency. If they duplicate structure, extract the common part into one unit; otherwise the coupling is hidden and worth breaking. You can check this without leaving the row: of the 33 shared commits counted here, the most recent 3 are \u00609bf18a56\u0060 [FEATURE]: consolidate validate functions from utils into validator.r\u2026; \u00603c20fcb6\u0060 [ID-Mapped Mount] add idmapped mount spec validation (#3572); \u00607cc04812\u0060 fix: validation differences between youki and runc (#3556) \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/container/init_builder.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"a96567b673a87fbc183a97c58d1ad7342c4ebd04c94c8e7fb009d32c41ebbd60"}},{"ruleId":"D35","level":"warning","message":{"text":"Change coupling: init_builder.rs \u2194 run.rs: \u0060crates/libcontainer/src/container/init_builder.rs\u0060 and \u0060crates/youki/src/commands/run.rs\u0060 change together 55% of the time (6 of the 11 commits that touched whichever of the two files changed less often, counting a file under its earlier names as well \u2014 a repo-wide or module-wide sweep is evidence about the sweep rather than about any pair inside it and is left out of BOTH sides of this ratio, while a dependency bump, a formatter/rename sweep, or a commit whose edit to one of the two files was a tool directive such as //go:generate or whitespace only is left out of the shared count ONLY, so the two sides are not taken over identical commit sets) with no explicit dependency \u2014 the edge is real but nothing declares it. Read the pair before acting: if one registers itself into the other through a hook or an initialiser, the missing dependency is DELIBERATE \u2014 the registration is the link, and it is meant not to be an import \u2014 and the thing to add is a comment on each side naming the other, not a merge; if they simply belong together, co-locate them; if neither holds, the coupling is hidden and worth breaking. You can check this without leaving the row: of the 6 shared commits counted here, the most recent 3 are \u0060d0715969\u0060 fix(libcontainer) no_pivot args is not used (#2923); \u0060c3559e4a\u0060 refactored executor and executor manager (#2186); \u0060816739c1\u0060 Minor fixes \u2014 run \u0060git show\u0060 on any of them."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/container/init_builder.rs"},"region":{"startLine":1}}}],"partialFingerprints":{"codehealthFindingId/v1":"eaaa890162e6098ac1b6db3c3dbdef79db71d080e2e3c84c6b5b43e857530137"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"1b213f6eedd4b140d0bc37bdf1496f72811a643f34064f12518b32e9e83bcfc7"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0e17f71490e4d120a48b2b2881ab866c93b272bef2febb673a3e8e42b2c288ab"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"759dca709f1a032fb6f624ce672e6afb5558fce53ecf01fb73618c4d33923164"}},{"ruleId":"D36","level":"note","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"eb00976a698a5d68999b7ee6d27206fd374e916853e7ff1ead5eed42386f043f"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"90f83b4fa27db32740afe9540c905f3c0499caed87f61049a8a903ecc95b41c3"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"5a41e66474510f07f802b8229c5795b05fabbe57e855ab4fa38c40af050df559"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"0752d0df7434000fcabf1048e2de30a7a1a8b982b3db9a19898c4dec199856b4"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"329f0ef4132322722fbf83ac33f5bb7ad638ed99d037a66c3aa244b1e2ee654e"}},{"ruleId":"D36","level":"warning","message":{"text":"A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."},"partialFingerprints":{"codehealthFindingId/v1":"d068c977b62d9a977df1bb6f53e8b00b586c3abee955f91d715f92b8e019d624"}},{"ruleId":"D40","level":"note","message":{"text":"No network policy: No Kubernetes NetworkPolicy (or Cilium policy) found. Without one, every pod can talk to every other pod and reach out to the internet by default. Add a default-deny policy and open only the flows you need."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"295828650a2aaa1b03ae9b32ae6843a0c38011e5a70b1926442c4fa7187de5f0"}},{"ruleId":"D41","level":"note","message":{"text":"No seccomp profile: Workloads do not set a seccomp profile (RuntimeDefault or a Localhost profile). Seccomp blocks the syscalls a container never needs, shrinking the kernel attack surface a container escape would use."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"3f418e9f76c3ac90484e0e94a454bfe9b08e914e1cdd218e1fc9e3b261a3bf6e"}},{"ruleId":"D41","level":"note","message":{"text":"No AppArmor/SELinux confinement: Workloads declare no AppArmor or SELinux profile. A mandatory-access-control profile confines what a compromised container can touch on the host, complementing seccomp\u0027s syscall filter."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"e83fbc31033373d6c51983ed230eb4ba61f7775ed02afb30f5fc1840bde01d4f"}},{"ruleId":"D42","level":"note","message":{"text":"No runtime threat detection: No runtime threat-detection engine (Tetragon TracingPolicy / Falco) is committed. These observe process, file and network activity in-kernel and can alert or kill on malicious behaviour a static scan cannot catch."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"aade9827a37dfc7ee064f80a997f47b5d11e31bc09704e26b9252bef00aa0c58"}},{"ruleId":"D44","level":"warning","message":{"text":"End-of-life runtime: Rust 1.96: rust-toolchain.toml declares Rust 1.96 as this project\u0027s toolchain file, and Rust 1.96, superseded by 1.97 on 2026-07-09 (the Rust project patches only the current stable). An unsupported runtime receives no security patches, so every vulnerability disclosed in it since 2026-07-09 is present and unfixable without moving off it. This is a migration rather than an upgrade: there is no newer release of a runtime that has ended."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"b4d8e9b51cd4b2493b326110bfe409c9598039c510d25150fcc40f653a675ac1"}},{"ruleId":"AX7","level":"warning","message":{"text":"Cross-slice coupling: libcontainer \u2192 libcgroups: \u0060ContainerArgs\u0060 (slice \u0027libcontainer\u0027) depends on \u0060CgroupConfig\u0060 from slice \u0027libcgroups\u0027."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/libcontainer/src/process/args.rs"},"region":{"startLine":20}}}],"partialFingerprints":{"codehealthFindingId/v1":"80aeff3e85bc645ec26384af73b095c54029388dcf99438cca02320ba3fb2e0e"}},{"ruleId":"AX7","level":"warning","message":{"text":"Cross-slice coupling: youki \u2192 libcontainer: \u0060StateExporter\u0060 (slice \u0027youki\u0027) depends on \u0060ContainerStatus\u0060 from slice \u0027libcontainer\u0027."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/youki/src/commands/state.rs"},"region":{"startLine":21}}}],"partialFingerprints":{"codehealthFindingId/v1":"00ec47f054fd6819e4ada02de8eb89a099e4bff1cb1f056d2d38b18009068c3f"}},{"ruleId":"AX7","level":"warning","message":{"text":"Cross-slice coupling: youki \u2192 liboci_cli: \u0060Opts\u0060 (slice \u0027youki\u0027) depends on \u0060GlobalOpts\u0060 from slice \u0027liboci_cli\u0027."},"locations":[{"physicalLocation":{"artifactLocation":{"uri":"crates/youki/src/main.rs"},"region":{"startLine":33}}}],"partialFingerprints":{"codehealthFindingId/v1":"9b1ad1c3e023e93e22d48aa4d7ab7e2d14b7707dda37cf664b5edf2d9aacd439"}},{"ruleId":"M2","level":"note","message":{"text":"No ADRs: No Architecture Decision Records found \u2014 no conventional ADR directory, no numbered \u0060NNNN-title\u0060 documents in any markup this check reads, and nothing ADR-shaped by content. Design rationale recorded elsewhere (a design-notes tree, a mailing list, pull-request discussion) is not visible to this check and is not re-findable per decision, so a future maintainer cannot ask why one choice was made and get an answer."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"670b3d6e36a756d63097d0dfbf90afd5fc761308800b9354894a07c3f4e4aa14"}},{"ruleId":"P12","level":"warning","message":{"text":"Coverage collected but not gated: CI collects a coverage report but no step enforces a minimum \u2014 coverage could halve and CI stays green. Add a step that fails the build when coverage drops below a floor (your coverage tool\u0027s minimum-threshold flag, or a coverage-gate action) so the number guards something. What was searched, so you can tell an absence from a miss: this repository\u0027s CI files AND its coverage configuration \u2014 the well-known coverage and test-runner config files, read at the repository root and inside workspace package directories two levels down, so a floor declared beside the tests rather than in the pipeline is credited \u2014 matched against the threshold settings this check knows by name. A floor set in your coverage service\u0027s web UI rather than in a committed file, or under a setting whose name is not one of those, is not seen here."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"7f63c06044cf998d9a0698692df30d8873e29bc9b0c98ee829255017c1193d33"}},{"ruleId":"P2","level":"note","message":{"text":"Logging is not universal: Only 3/4 runnable modules use logging (modules with no entry point or server are excluded \u2014 they are libraries a runnable module hosts). Silent: \u0060experiment/selinux\u0060."},"locations":[],"partialFingerprints":{"codehealthFindingId/v1":"91a94e21d6d4d0e6a2003f94505b0b02b157176f0b24c4820f3f82b4447a97fe"}}],"taxonomies":[{"name":"CWE","guid":"c3a2b1d0-7f3e-4b2a-9c1d-5e6f7a8b9c0d","organization":"MITRE","informationUri":"https://cwe.mitre.org/","isComprehensive":false,"shortDescription":{"text":"The MITRE Common Weakness Enumeration (CWE)."},"taxa":[{"id":"CWE-1032","guid":"5f21e517-68aa-a650-9a25-5771ef024637","name":"OWASP Top Ten \u2014 Security Misconfiguration category","shortDescription":{"text":"OWASP Top Ten \u2014 Security Misconfiguration category"},"helpUri":"https://cwe.mitre.org/data/definitions/1032.html"},{"id":"CWE-1059","guid":"a2381a08-60f6-9554-a8b8-f3018cfaaca5","name":"Insufficient Technical Documentation","shortDescription":{"text":"Insufficient Technical Documentation"},"helpUri":"https://cwe.mitre.org/data/definitions/1059.html"},{"id":"CWE-1104","guid":"4c918cb5-b2a6-6c55-9963-a44ee464305e","name":"CWE-1104","shortDescription":{"text":"CWE-1104"},"helpUri":"https://cwe.mitre.org/data/definitions/1104.html"},{"id":"CWE-1329","guid":"f70f1c3f-4ccf-cb5e-bdd3-03ba4868d36d","name":"CWE-1329","shortDescription":{"text":"CWE-1329"},"helpUri":"https://cwe.mitre.org/data/definitions/1329.html"},{"id":"CWE-1352","guid":"5257f322-5cfc-6b52-bedd-0b9a526b4c7d","name":"CWE-1352","shortDescription":{"text":"CWE-1352"},"helpUri":"https://cwe.mitre.org/data/definitions/1352.html"},{"id":"CWE-1357","guid":"e4d2e772-757e-0a5c-bd7d-77052949d866","name":"Reliance on Insufficiently Trustworthy Component","shortDescription":{"text":"Reliance on Insufficiently Trustworthy Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1357.html"},{"id":"CWE-1395","guid":"800e09e7-c11a-8654-9fa6-86f398995fed","name":"Dependency on Vulnerable Third-Party Component","shortDescription":{"text":"Dependency on Vulnerable Third-Party Component"},"helpUri":"https://cwe.mitre.org/data/definitions/1395.html"},{"id":"CWE-16","guid":"659db3ea-affc-8453-8add-c1218fbfcb92","name":"Configuration","shortDescription":{"text":"Configuration"},"helpUri":"https://cwe.mitre.org/data/definitions/16.html"},{"id":"CWE-259","guid":"ae9ad959-fbb6-9d5e-892d-3dca66da0b69","name":"Use of Hard-coded Password","shortDescription":{"text":"Use of Hard-coded Password"},"helpUri":"https://cwe.mitre.org/data/definitions/259.html"},{"id":"CWE-353","guid":"09d7e902-d4ee-f05d-ae6c-0a1554d0c18f","name":"CWE-353","shortDescription":{"text":"CWE-353"},"helpUri":"https://cwe.mitre.org/data/definitions/353.html"},{"id":"CWE-494","guid":"b8a65e0d-e459-4a55-a931-fc1136482375","name":"Download of Code Without Integrity Check","shortDescription":{"text":"Download of Code Without Integrity Check"},"helpUri":"https://cwe.mitre.org/data/definitions/494.html"},{"id":"CWE-506","guid":"401d6455-56e3-0552-9a39-f77461673e3f","name":"CWE-506","shortDescription":{"text":"CWE-506"},"helpUri":"https://cwe.mitre.org/data/definitions/506.html"},{"id":"CWE-522","guid":"71fb233e-ce6a-ae57-9419-ef8373540b09","name":"CWE-522","shortDescription":{"text":"CWE-522"},"helpUri":"https://cwe.mitre.org/data/definitions/522.html"},{"id":"CWE-732","guid":"1da27e8f-b330-7650-ab63-bd61953eae5d","name":"Incorrect Permission Assignment for Critical Resource","shortDescription":{"text":"Incorrect Permission Assignment for Critical Resource"},"helpUri":"https://cwe.mitre.org/data/definitions/732.html"},{"id":"CWE-77","guid":"332c8ade-6612-9f56-a06b-d8d90b1a8750","name":"Command Injection","shortDescription":{"text":"Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/77.html"},{"id":"CWE-78","guid":"2e31ceaf-c7ae-2e5e-9661-cfb1362789cf","name":"OS Command Injection","shortDescription":{"text":"OS Command Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/78.html"},{"id":"CWE-79","guid":"fd45580b-e8c4-fc5e-8c2f-aa8fab0b4dbf","name":"Cross-site Scripting (XSS)","shortDescription":{"text":"Cross-site Scripting (XSS)"},"helpUri":"https://cwe.mitre.org/data/definitions/79.html"},{"id":"CWE-798","guid":"5e8f057d-fee3-995a-a0cb-9fc5b0d174d1","name":"Use of Hard-coded Credentials","shortDescription":{"text":"Use of Hard-coded Credentials"},"helpUri":"https://cwe.mitre.org/data/definitions/798.html"},{"id":"CWE-829","guid":"13c33925-97fb-5a5e-b40c-56d328b8a4d7","name":"CWE-829","shortDescription":{"text":"CWE-829"},"helpUri":"https://cwe.mitre.org/data/definitions/829.html"},{"id":"CWE-89","guid":"6d08fdad-37eb-c150-bbf0-d7d946863407","name":"SQL Injection","shortDescription":{"text":"SQL Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/89.html"},{"id":"CWE-937","guid":"16f316ae-415c-b354-a59b-1f7905f756e9","name":"Using Components with Known Vulnerabilities","shortDescription":{"text":"Using Components with Known Vulnerabilities"},"helpUri":"https://cwe.mitre.org/data/definitions/937.html"},{"id":"CWE-94","guid":"75e7f50c-6c2f-dd52-bf40-bf6c52b861fd","name":"Code Injection","shortDescription":{"text":"Code Injection"},"helpUri":"https://cwe.mitre.org/data/definitions/94.html"}]}],"properties":{"codehealthPublication":{"public":true,"notice":"This is the PUBLIC form of this artifact. Findings are listed in full, but the details of SECURITY findings \u2014 which rule fired, in which file, on which line, and how to fix it \u2014 are deliberately withheld, and any secret-scanner results are excluded entirely. Where detail is absent here it was REMOVED FOR PUBLICATION; it is not missing from the analysis. The complete artifact is available from the repository owner.","securityFindingsRedacted":182,"secretScannerRunsExcluded":0}},"redactionTokens":["A security finding was recorded here. Its details are withheld on the public artifact \u2014 ask the repository owner for the full report."]}]}