{
  "schemaVersion": 2,
  "repository": "Syndical",
  "startedAt": "2026-10-03T11:20:10.111Z",
  "source": {
    "commit": "b18c880cbbffb84ec7ef0393dba9990bb7548106",
    "dirty": false,
    "contentSha256": "bb26245c93490b4777a24d042a485cba732eb39f1a85dbbd0046bcfa2906df0c",
    "stableDuringRun": true,
    "finishedContentSha256": "bb26245c93490b4777a24d042a485cba732eb39f1a85dbbd0046bcfa2906df0c"
  },
  "policy": {
    "id": "syndical-oss-quality-v1",
    "sha256": "489e13c414b3b3ea460ebba566441fa1937dca380fee6facf5ffcbc608b259d5",
    "sastRules": [
      {
        "id": "syndical.csharp.tls-validation-always-true",
        "severity": "high",
        "languages": [
          "csharp"
        ],
        "description": "HttpClientHandler certificate callbacks that explicitly accept every certificate."
      },
      {
        "id": "syndical.typescript.tls-verification-disabled",
        "severity": "high",
        "languages": [
          "javascript",
          "typescript"
        ],
        "description": "Explicit rejectUnauthorized:false settings and NODE_TLS_REJECT_UNAUTHORIZED=0 assignments."
      },
      {
        "id": "syndical.typescript.electron-context-isolation-disabled",
        "severity": "high",
        "languages": [
          "javascript",
          "typescript"
        ],
        "description": "BrowserWindow object literals explicitly disabling context isolation."
      },
      {
        "id": "syndical.typescript.electron-node-integration-enabled",
        "severity": "medium",
        "languages": [
          "javascript",
          "typescript"
        ],
        "description": "BrowserWindow object literals explicitly enabling renderer Node integration."
      },
      {
        "id": "syndical.typescript.sensitive-value-console-log",
        "severity": "high",
        "languages": [
          "javascript",
          "typescript"
        ],
        "description": "Direct console arguments named password, token, key or client secret; this is not a dataflow rule."
      }
    ],
    "duplication": {
      "minLines": 5,
      "minTokens": 50,
      "mode": "mild"
    }
  },
  "tools": [
    {
      "name": "Lizard",
      "version": "1.24.0",
      "license": "MIT"
    },
    {
      "name": "jscpd",
      "version": "5.4.0",
      "license": "MIT"
    },
    {
      "name": "OpenGrep",
      "version": "1.30.0",
      "license": "LGPL-2.1"
    },
    {
      "name": "ESLint",
      "version": "10.12.0",
      "license": "MIT"
    },
    {
      "name": "@eslint/js",
      "version": "10.0.1",
      "license": "MIT"
    },
    {
      "name": "typescript-eslint",
      "version": "8.71.0",
      "license": "MIT"
    },
    {
      "name": "eslint-plugin-react-hooks",
      "version": "7.1.1",
      "license": "MIT"
    },
    {
      "name": "globals",
      "version": "17.13.0",
      "license": "MIT"
    },
    {
      "name": ".NET SDK analyzers",
      "version": "9.0.301",
      "license": "MIT"
    },
    {
      "name": "Microsoft (R) Visual C# Compiler",
      "version": "4.14.0-3.25262.10 (8edf7bcd)",
      "license": "MIT"
    },
    {
      "name": "TypeScript AST",
      "version": "5.9.3",
      "license": "Apache-2.0"
    }
  ],
  "scope": {
    "selectedFiles": 749,
    "byLanguage": {
      "csharp": 544,
      "javascript": 7,
      "typescript": 198
    },
    "exclusions": {
      "roots": [
        "apps/",
        "libs/"
      ],
      "extensions": [
        ".cs",
        ".ts",
        ".tsx",
        ".js",
        ".jsx",
        ".mjs"
      ],
      "excludedSegments": [
        "test",
        "tests",
        "fixtures",
        "bin",
        "obj",
        "node_modules",
        "out",
        "dist",
        "resources"
      ],
      "excludedSuffixes": [
        ".test.ts",
        ".test.tsx",
        ".spec.ts",
        ".spec.tsx",
        ".d.ts",
        ".g.cs",
        ".generated.cs"
      ],
      "excludedPrefixes": []
    }
  },
  "measurements": {
    "native": {
      "status": "measured",
      "selectedFiles": 749,
      "analyzedFiles": 749,
      "filesWithFindings": 220,
      "totalFindings": 502,
      "errors": []
    },
    "functions": {
      "status": "measured",
      "selectedFiles": 749,
      "analyzedFiles": 749,
      "totalFunctions": 12145,
      "compliantFunctions": 11332,
      "violatingFunctions": 813,
      "limits": {
        "maxComplexity": 15,
        "maxFunctionLines": 80,
        "maxParameters": 5
      },
      "instruments": [
        {
          "name": "Lizard",
          "version": "1.24.0",
          "files": 544,
          "functions": 4485,
          "excludedSyntheticUnits": 268,
          "lengthDefinition": "Non-comment source lines recognized by Lizard"
        },
        {
          "name": "TypeScript AST",
          "version": "5.9.3",
          "files": 205,
          "functions": 7660,
          "lengthDefinition": "Nonempty physical lines in the full function span, including comments and nested functions"
        }
      ],
      "errors": []
    },
    "duplication": {
      "status": "measured",
      "selectedFiles": 749,
      "analyzedFiles": 749,
      "cloneEligibleFiles": 739,
      "belowMinimumTokenFiles": 10,
      "totalTokens": 1480116,
      "duplicatedTokens": 22648,
      "duplicatedTokenPercent": 1.5301503395679799,
      "errors": []
    },
    "sast": {
      "status": "measured",
      "selectedFiles": 749,
      "analyzedFiles": 749,
      "ruleCount": 5,
      "qualifiedRules": 5,
      "counts": {
        "critical": 0,
        "high": 1,
        "medium": 0,
        "low": 0,
        "info": 0
      },
      "errors": []
    }
  },
  "limitations": [
    "Scores measure compliance with this named profile; profiles can differ between languages and repositories.",
    "Quality measures configured native warnings and errors, not functional correctness or test effectiveness.",
    "C#, Swift and Python functions are recognized heuristically by Lizard; their detection is not compiler-proven complete. JavaScript/TypeScript uses the TypeScript syntax tree.",
    "Security covers only the named qualified rules. Dependencies, secrets, runtime behavior and broader dataflow are not assessed here.",
    "No overall quality or human-superiority claim is supported by this scorecard."
  ],
  "finishedAt": "2026-10-03T11:21:03.726Z",
  "scores": {
    "quality": {
      "status": "measured",
      "value": 70,
      "label": "Quality",
      "explanation": "Percentage of checked production files with no configured analyzer warnings or errors.",
      "numerator": 529,
      "denominator": 749,
      "details": {
        "filesWithFindings": 220,
        "totalFindings": 502
      }
    },
    "maintainability": {
      "status": "measured",
      "value": 93,
      "label": "Maintainability",
      "explanation": "The lower of functions within all published limits and tokens without detected duplication.",
      "numerator": 11332,
      "denominator": 12145,
      "details": {
        "functionScore": 93,
        "duplicationScore": 98,
        "duplicatedTokenPercent": 1.5301503395679799,
        "limits": {
          "maxComplexity": 15,
          "maxFunctionLines": 80,
          "maxParameters": 5
        }
      }
    },
    "security": {
      "status": "needs-fixes",
      "risk": "high",
      "label": "Security checks",
      "counts": {
        "critical": 0,
        "high": 1,
        "medium": 0,
        "low": 0,
        "info": 0
      },
      "ruleCount": 5,
      "explanation": "Highest observed risk in the named, qualified rules. No findings is not a comprehensive security audit."
    }
  },
  "gate": {
    "status": "passed",
    "baselinePresent": true,
    "newFindings": 0,
    "duplicationRegression": false,
    "reasons": []
  },
  "evidenceSha256": "e7ec65e08370d1483e3df58b50b56c14783cc4b8dabae558bfde4dab3a9bbfbf"
}
