{
  "schemaVersion": 1,
  "repositories": [
    {
      "name": "Syndical",
      "reportUrl": "/quality/scorecards/20261003112103726-syndical-b18c880cbbff/report.json",
      "sha256": "b2cff48d9f15b6ee656d4f5f4b51fd6d5c80ab3d6f79d28e403237c535533f35",
      "report": {
        "schemaVersion": 2,
        "repository": "Syndical",
        "startedAt": "2026-10-03T11:20:10.111Z",
        "source": {
          "commit": "b18c880cbbffb84ec7ef0393dba9990bb7548106",
          "dirty": false,
          "contentSha256": "bb26245c93490b4777a24d042a485cba732eb39f1a85dbbd0046bcfa2906df0c",
          "stableDuringRun": true,
          "finishedContentSha256": "bb26245c93490b4777a24d042a485cba732eb39f1a85dbbd0046bcfa2906df0c"
        },
        "policy": {
          "id": "syndical-oss-quality-v1",
          "sha256": "489e13c414b3b3ea460ebba566441fa1937dca380fee6facf5ffcbc608b259d5",
          "sastRules": [
            {
              "id": "syndical.csharp.tls-validation-always-true",
              "severity": "high",
              "languages": [
                "csharp"
              ],
              "description": "HttpClientHandler certificate callbacks that explicitly accept every certificate."
            },
            {
              "id": "syndical.typescript.tls-verification-disabled",
              "severity": "high",
              "languages": [
                "javascript",
                "typescript"
              ],
              "description": "Explicit rejectUnauthorized:false settings and NODE_TLS_REJECT_UNAUTHORIZED=0 assignments."
            },
            {
              "id": "syndical.typescript.electron-context-isolation-disabled",
              "severity": "high",
              "languages": [
                "javascript",
                "typescript"
              ],
              "description": "BrowserWindow object literals explicitly disabling context isolation."
            },
            {
              "id": "syndical.typescript.electron-node-integration-enabled",
              "severity": "medium",
              "languages": [
                "javascript",
                "typescript"
              ],
              "description": "BrowserWindow object literals explicitly enabling renderer Node integration."
            },
            {
              "id": "syndical.typescript.sensitive-value-console-log",
              "severity": "high",
              "languages": [
                "javascript",
                "typescript"
              ],
              "description": "Direct console arguments named password, token, key or client secret; this is not a dataflow rule."
            }
          ],
          "duplication": {
            "minLines": 5,
            "minTokens": 50,
            "mode": "mild"
          }
        },
        "tools": [
          {
            "name": "Lizard",
            "version": "1.24.0",
            "license": "MIT"
          },
          {
            "name": "jscpd",
            "version": "5.4.0",
            "license": "MIT"
          },
          {
            "name": "OpenGrep",
            "version": "1.30.0",
            "license": "LGPL-2.1"
          },
          {
            "name": "ESLint",
            "version": "10.12.0",
            "license": "MIT"
          },
          {
            "name": "@eslint/js",
            "version": "10.0.1",
            "license": "MIT"
          },
          {
            "name": "typescript-eslint",
            "version": "8.71.0",
            "license": "MIT"
          },
          {
            "name": "eslint-plugin-react-hooks",
            "version": "7.1.1",
            "license": "MIT"
          },
          {
            "name": "globals",
            "version": "17.13.0",
            "license": "MIT"
          },
          {
            "name": ".NET SDK analyzers",
            "version": "9.0.301",
            "license": "MIT"
          },
          {
            "name": "Microsoft (R) Visual C# Compiler",
            "version": "4.14.0-3.25262.10 (8edf7bcd)",
            "license": "MIT"
          },
          {
            "name": "TypeScript AST",
            "version": "5.9.3",
            "license": "Apache-2.0"
          }
        ],
        "scope": {
          "selectedFiles": 749,
          "byLanguage": {
            "csharp": 544,
            "javascript": 7,
            "typescript": 198
          },
          "exclusions": {
            "roots": [
              "apps/",
              "libs/"
            ],
            "extensions": [
              ".cs",
              ".ts",
              ".tsx",
              ".js",
              ".jsx",
              ".mjs"
            ],
            "excludedSegments": [
              "test",
              "tests",
              "fixtures",
              "bin",
              "obj",
              "node_modules",
              "out",
              "dist",
              "resources"
            ],
            "excludedSuffixes": [
              ".test.ts",
              ".test.tsx",
              ".spec.ts",
              ".spec.tsx",
              ".d.ts",
              ".g.cs",
              ".generated.cs"
            ],
            "excludedPrefixes": []
          }
        },
        "measurements": {
          "native": {
            "status": "measured",
            "selectedFiles": 749,
            "analyzedFiles": 749,
            "filesWithFindings": 220,
            "totalFindings": 502,
            "errors": []
          },
          "functions": {
            "status": "measured",
            "selectedFiles": 749,
            "analyzedFiles": 749,
            "totalFunctions": 12145,
            "compliantFunctions": 11332,
            "violatingFunctions": 813,
            "limits": {
              "maxComplexity": 15,
              "maxFunctionLines": 80,
              "maxParameters": 5
            },
            "instruments": [
              {
                "name": "Lizard",
                "version": "1.24.0",
                "files": 544,
                "functions": 4485,
                "excludedSyntheticUnits": 268,
                "lengthDefinition": "Non-comment source lines recognized by Lizard"
              },
              {
                "name": "TypeScript AST",
                "version": "5.9.3",
                "files": 205,
                "functions": 7660,
                "lengthDefinition": "Nonempty physical lines in the full function span, including comments and nested functions"
              }
            ],
            "errors": []
          },
          "duplication": {
            "status": "measured",
            "selectedFiles": 749,
            "analyzedFiles": 749,
            "cloneEligibleFiles": 739,
            "belowMinimumTokenFiles": 10,
            "totalTokens": 1480116,
            "duplicatedTokens": 22648,
            "duplicatedTokenPercent": 1.5301503395679799,
            "errors": []
          },
          "sast": {
            "status": "measured",
            "selectedFiles": 749,
            "analyzedFiles": 749,
            "ruleCount": 5,
            "qualifiedRules": 5,
            "counts": {
              "critical": 0,
              "high": 1,
              "medium": 0,
              "low": 0,
              "info": 0
            },
            "errors": []
          }
        },
        "limitations": [
          "Scores measure compliance with this named profile; profiles can differ between languages and repositories.",
          "Quality measures configured native warnings and errors, not functional correctness or test effectiveness.",
          "C#, Swift and Python functions are recognized heuristically by Lizard; their detection is not compiler-proven complete. JavaScript/TypeScript uses the TypeScript syntax tree.",
          "Security covers only the named qualified rules. Dependencies, secrets, runtime behavior and broader dataflow are not assessed here.",
          "No overall quality or human-superiority claim is supported by this scorecard."
        ],
        "finishedAt": "2026-10-03T11:21:03.726Z",
        "scores": {
          "quality": {
            "status": "measured",
            "value": 70,
            "label": "Quality",
            "explanation": "Percentage of checked production files with no configured analyzer warnings or errors.",
            "numerator": 529,
            "denominator": 749,
            "details": {
              "filesWithFindings": 220,
              "totalFindings": 502
            }
          },
          "maintainability": {
            "status": "measured",
            "value": 93,
            "label": "Maintainability",
            "explanation": "The lower of functions within all published limits and tokens without detected duplication.",
            "numerator": 11332,
            "denominator": 12145,
            "details": {
              "functionScore": 93,
              "duplicationScore": 98,
              "duplicatedTokenPercent": 1.5301503395679799,
              "limits": {
                "maxComplexity": 15,
                "maxFunctionLines": 80,
                "maxParameters": 5
              }
            }
          },
          "security": {
            "status": "needs-fixes",
            "risk": "high",
            "label": "Security checks",
            "counts": {
              "critical": 0,
              "high": 1,
              "medium": 0,
              "low": 0,
              "info": 0
            },
            "ruleCount": 5,
            "explanation": "Highest observed risk in the named, qualified rules. No findings is not a comprehensive security audit."
          }
        },
        "gate": {
          "status": "passed",
          "baselinePresent": true,
          "newFindings": 0,
          "duplicationRegression": false,
          "reasons": []
        },
        "evidenceSha256": "e7ec65e08370d1483e3df58b50b56c14783cc4b8dabae558bfde4dab3a9bbfbf"
      }
    },
    {
      "name": "Syndical.mobile",
      "reportUrl": "/quality/scorecards/20261003114203264-syndical.mobile-cde32592f7ec/report.json",
      "sha256": "513da646fe86e25998e089b1a56148f7a4ccc610360ef32bd3723bd9359b1a9b",
      "report": {
        "schemaVersion": 2,
        "repository": "Syndical.mobile",
        "startedAt": "2026-10-03T11:41:43.942Z",
        "source": {
          "commit": "cde32592f7ecc4386774c29d0f4de574a691d5c1",
          "dirty": false,
          "contentSha256": "86ba084097417eaa1771a37e46bd69aea77a2001ccebf5a35a65fc811181c5be",
          "stableDuringRun": true,
          "finishedContentSha256": "86ba084097417eaa1771a37e46bd69aea77a2001ccebf5a35a65fc811181c5be"
        },
        "policy": {
          "id": "syndical-mobile-quality-v1",
          "sha256": "89c2ebc32ce6b26ea5a054ac3f81596d778d67bd6ab00ffc79f4a0971ab591e7",
          "sastRules": [
            {
              "id": "mobile.swift.legacy-cryptographic-hash",
              "severity": "high",
              "languages": [
                "swift"
              ],
              "description": "Direct MD5/SHA-1 calls require a non-security rationale or a modern cryptographic algorithm."
            },
            {
              "id": "mobile.swift.credential-in-user-defaults",
              "severity": "high",
              "languages": [
                "swift"
              ],
              "description": "Direct UserDefaults.standard writes with explicit credential key names."
            },
            {
              "id": "mobile.swift.webview-universal-file-access",
              "severity": "high",
              "languages": [
                "swift"
              ],
              "description": "Enabling universal network access from WebView file URLs."
            },
            {
              "id": "mobile.swift.accepting-tls-exceptions",
              "severity": "high",
              "languages": [
                "swift"
              ],
              "description": "Passing copied trust exceptions straight back into TLS trust evaluation."
            }
          ],
          "duplication": {
            "minLines": 5,
            "minTokens": 50,
            "mode": "mild"
          }
        },
        "tools": [
          {
            "name": "Lizard",
            "version": "1.24.0",
            "license": "MIT"
          },
          {
            "name": "jscpd",
            "version": "5.4.0",
            "license": "MIT"
          },
          {
            "name": "OpenGrep",
            "version": "1.30.0",
            "license": "LGPL-2.1"
          },
          {
            "name": "SwiftLint",
            "version": "0.65.1",
            "license": "MIT",
            "source": "https://github.com/realm/SwiftLint"
          },
          {
            "name": "Swift compiler",
            "version": "swift-driver version: 1.127.15\nApple Swift version 6.2.4 (swiftlang-6.2.4.1.4 clang-1700.6.4.2)\nTarget: x86_64-apple-macosx15.0",
            "license": "Apache-2.0 with Runtime Library Exception",
            "source": "https://www.swift.org/about/"
          }
        ],
        "scope": {
          "selectedFiles": 45,
          "byLanguage": {
            "swift": 45
          },
          "exclusions": {
            "roots": [
              "SyndicalApp/Sources/",
              "SyndicalApp/App/"
            ],
            "extensions": [
              ".swift"
            ],
            "excludedSegments": [
              "tests",
              "uitests",
              "fixtures",
              ".build",
              "build",
              "deriveddata",
              "desktopviews",
              "assets.xcassets",
              "resources"
            ],
            "excludedSuffixes": [
              "Fixtures.swift",
              "ConnectionUITestFixture.swift"
            ],
            "excludedPrefixes": []
          }
        },
        "measurements": {
          "native": {
            "status": "measured",
            "selectedFiles": 45,
            "analyzedFiles": 45,
            "filesWithFindings": 13,
            "totalFindings": 23,
            "errors": []
          },
          "functions": {
            "status": "measured",
            "selectedFiles": 45,
            "analyzedFiles": 45,
            "totalFunctions": 390,
            "compliantFunctions": 369,
            "violatingFunctions": 21,
            "limits": {
              "maxComplexity": 15,
              "maxFunctionLines": 80,
              "maxParameters": 5
            },
            "instruments": [
              {
                "name": "Lizard",
                "version": "1.24.0",
                "files": 45,
                "functions": 390,
                "excludedSyntheticUnits": 0,
                "lengthDefinition": "Non-comment source lines recognized by Lizard"
              }
            ],
            "errors": []
          },
          "duplication": {
            "status": "measured",
            "selectedFiles": 45,
            "analyzedFiles": 45,
            "cloneEligibleFiles": 44,
            "belowMinimumTokenFiles": 1,
            "totalTokens": 84455,
            "duplicatedTokens": 873,
            "duplicatedTokenPercent": 1.0336865786513527,
            "errors": []
          },
          "sast": {
            "status": "measured",
            "selectedFiles": 45,
            "analyzedFiles": 45,
            "ruleCount": 4,
            "qualifiedRules": 4,
            "counts": {
              "critical": 0,
              "high": 0,
              "medium": 0,
              "low": 0,
              "info": 0
            },
            "errors": []
          }
        },
        "limitations": [
          "Scores measure compliance with this named profile; profiles can differ between languages and repositories.",
          "Quality measures configured native warnings and errors, not functional correctness or test effectiveness.",
          "C#, Swift and Python functions are recognized heuristically by Lizard; their detection is not compiler-proven complete. JavaScript/TypeScript uses the TypeScript syntax tree.",
          "Security covers only the named qualified rules. Dependencies, secrets, runtime behavior and broader dataflow are not assessed here.",
          "No overall quality or human-superiority claim is supported by this scorecard."
        ],
        "finishedAt": "2026-10-03T11:42:03.264Z",
        "scores": {
          "quality": {
            "status": "measured",
            "value": 71,
            "label": "Quality",
            "explanation": "Percentage of checked production files with no configured analyzer warnings or errors.",
            "numerator": 32,
            "denominator": 45,
            "details": {
              "filesWithFindings": 13,
              "totalFindings": 23
            }
          },
          "maintainability": {
            "status": "measured",
            "value": 94,
            "label": "Maintainability",
            "explanation": "The lower of functions within all published limits and tokens without detected duplication.",
            "numerator": 369,
            "denominator": 390,
            "details": {
              "functionScore": 94,
              "duplicationScore": 98,
              "duplicatedTokenPercent": 1.0336865786513527,
              "limits": {
                "maxComplexity": 15,
                "maxFunctionLines": 80,
                "maxParameters": 5
              }
            }
          },
          "security": {
            "status": "no-findings",
            "risk": "none",
            "label": "Security checks",
            "counts": {
              "critical": 0,
              "high": 0,
              "medium": 0,
              "low": 0,
              "info": 0
            },
            "ruleCount": 4,
            "explanation": "Highest observed risk in the named, qualified rules. No findings is not a comprehensive security audit."
          }
        },
        "gate": {
          "status": "passed",
          "baselinePresent": true,
          "newFindings": 0,
          "duplicationRegression": false,
          "reasons": []
        },
        "evidenceSha256": "d6a790351268505b2cc0cfb3ab1df9623af921b0b84fa2f413dc662f6847332d"
      }
    },
    {
      "name": "Syndical.site",
      "reportUrl": "/quality/scorecards/20261003155713764-syndical.site-013f14f35db5/report.json",
      "sha256": "4db59e116288327819e1209c22c3565d0b3afe80566d504b601a4d0cc7da5406",
      "report": {
        "schemaVersion": 2,
        "repository": "Syndical.site",
        "startedAt": "2026-10-03T15:57:02.836Z",
        "source": {
          "commit": "013f14f35db52a74f2a50d7c0c5ed5d8da22f3d0",
          "dirty": false,
          "contentSha256": "2d49df9e087a861298ac5fda720ebe8f6e9c6cfe641e61d1a1636c0c6e0112d5",
          "stableDuringRun": true,
          "finishedContentSha256": "2d49df9e087a861298ac5fda720ebe8f6e9c6cfe641e61d1a1636c0c6e0112d5"
        },
        "policy": {
          "id": "syndical-site-quality-v1",
          "sha256": "f1d1ba016b895e1a8351efc63fe6d4cf82a65bd1274e04e144d1935ac80f6921",
          "sastRules": [
            {
              "id": "syndical-site-credential-console",
              "severity": "high",
              "languages": [
                "typescript",
                "javascript"
              ],
              "description": "Credential-shaped values passed directly to browser console methods"
            },
            {
              "id": "syndical-site-python-shell",
              "severity": "medium",
              "languages": [
                "python"
              ],
              "description": "Explicit shell=True subprocess calls require review"
            }
          ],
          "duplication": {
            "minLines": 5,
            "minTokens": 50,
            "mode": "mild"
          }
        },
        "tools": [
          {
            "name": "Lizard",
            "version": "1.24.0",
            "license": "MIT"
          },
          {
            "name": "jscpd",
            "version": "5.4.0",
            "license": "MIT"
          },
          {
            "name": "OpenGrep",
            "version": "1.30.0",
            "license": "LGPL-2.1"
          },
          {
            "name": "eslint",
            "version": "10.12.0",
            "license": "MIT"
          },
          {
            "name": "ruff",
            "version": "0.16.10",
            "license": "MIT"
          },
          {
            "name": "TypeScript AST",
            "version": "5.9.3",
            "license": "Apache-2.0"
          }
        ],
        "scope": {
          "selectedFiles": 67,
          "byLanguage": {
            "javascript": 5,
            "python": 8,
            "typescript": 54
          },
          "exclusions": {
            "roots": [
              "app/",
              "components/",
              "icons/",
              "illustrations/",
              "lib/",
              "providers/",
              "infra/",
              "next.config.ts",
              "postcss.config.mjs"
            ],
            "extensions": [
              ".ts",
              ".tsx",
              ".js",
              ".mjs",
              ".py"
            ],
            "excludedSegments": [
              "test",
              "tests",
              "fixtures",
              "node_modules",
              "dist",
              "__pycache__"
            ],
            "excludedSuffixes": [
              ".test.ts",
              ".test.tsx",
              ".test.mjs",
              ".d.ts"
            ],
            "excludedPrefixes": [
              "infra/test_"
            ]
          }
        },
        "measurements": {
          "native": {
            "status": "measured",
            "selectedFiles": 67,
            "analyzedFiles": 67,
            "filesWithFindings": 0,
            "totalFindings": 0,
            "errors": []
          },
          "functions": {
            "status": "measured",
            "selectedFiles": 67,
            "analyzedFiles": 67,
            "totalFunctions": 303,
            "compliantFunctions": 303,
            "violatingFunctions": 0,
            "limits": {
              "maxComplexity": 15,
              "maxFunctionLines": 80,
              "maxParameters": 5
            },
            "instruments": [
              {
                "name": "Lizard",
                "version": "1.24.0",
                "files": 8,
                "functions": 70,
                "excludedSyntheticUnits": 0,
                "lengthDefinition": "Non-comment source lines recognized by Lizard"
              },
              {
                "name": "TypeScript AST",
                "version": "5.9.3",
                "files": 59,
                "functions": 233,
                "lengthDefinition": "Nonempty physical lines in the full function span, including comments and nested functions"
              }
            ],
            "errors": []
          },
          "duplication": {
            "status": "measured",
            "selectedFiles": 67,
            "analyzedFiles": 67,
            "cloneEligibleFiles": 62,
            "belowMinimumTokenFiles": 5,
            "totalTokens": 39077,
            "duplicatedTokens": 0,
            "duplicatedTokenPercent": 0,
            "errors": []
          },
          "sast": {
            "status": "measured",
            "selectedFiles": 67,
            "analyzedFiles": 67,
            "ruleCount": 2,
            "qualifiedRules": 2,
            "counts": {
              "critical": 0,
              "high": 0,
              "medium": 0,
              "low": 0,
              "info": 0
            },
            "errors": []
          }
        },
        "limitations": [
          "Scores measure compliance with this named profile; profiles can differ between languages and repositories.",
          "Quality measures configured native warnings and errors, not functional correctness or test effectiveness.",
          "C#, Swift and Python functions are recognized heuristically by Lizard; their detection is not compiler-proven complete. JavaScript/TypeScript uses the TypeScript syntax tree.",
          "Security covers only the named qualified rules. Dependencies, secrets, runtime behavior and broader dataflow are not assessed here.",
          "No overall quality or human-superiority claim is supported by this scorecard."
        ],
        "finishedAt": "2026-10-03T15:57:13.764Z",
        "scores": {
          "quality": {
            "status": "measured",
            "value": 100,
            "label": "Quality",
            "explanation": "Percentage of checked production files with no configured analyzer warnings or errors.",
            "numerator": 67,
            "denominator": 67,
            "details": {
              "filesWithFindings": 0,
              "totalFindings": 0
            }
          },
          "maintainability": {
            "status": "measured",
            "value": 100,
            "label": "Maintainability",
            "explanation": "The lower of functions within all published limits and tokens without detected duplication.",
            "numerator": 303,
            "denominator": 303,
            "details": {
              "functionScore": 100,
              "duplicationScore": 100,
              "duplicatedTokenPercent": 0,
              "limits": {
                "maxComplexity": 15,
                "maxFunctionLines": 80,
                "maxParameters": 5
              }
            }
          },
          "security": {
            "status": "no-findings",
            "risk": "none",
            "label": "Security checks",
            "counts": {
              "critical": 0,
              "high": 0,
              "medium": 0,
              "low": 0,
              "info": 0
            },
            "ruleCount": 2,
            "explanation": "Highest observed risk in the named, qualified rules. No findings is not a comprehensive security audit."
          }
        },
        "gate": {
          "status": "passed",
          "baselinePresent": true,
          "newFindings": 0,
          "duplicationRegression": false,
          "reasons": []
        },
        "evidenceSha256": "bacac947c7084328908406c2bea17d06402413a2c20aebd2720f9706664014f5"
      }
    }
  ]
}
