{"total":146,"p":1,"ps":100,"paging":{"pageIndex":1,"pageSize":100,"total":146},"effortTotal":2965,"issues":[{"key":"790dedf2-9a45-4b54-9589-8ba25ff244bc","rule":"pythonsecurity:S6549","severity":"MAJOR","component":"rspec-tools:rspec_tools/coverage.py","project":"rspec-tools","line":201,"hash":"7f9bdbd61653950237a696bbf170a25a","textRange":{"startLine":201,"endLine":201,"startOffset":20,"endOffset":40},"flows":[{"locations":[{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":201,"endLine":201,"startOffset":20,"endOffset":40},"msg":"Sink: this invocation is not safe; a malicious value can be injected into the caller","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":201,"endLine":201,"startOffset":20,"endOffset":30},"msg":"This invocation can propagate malicious content to its return value","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":198,"endLine":198,"startOffset":27,"endOffset":31},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":198,"endLine":198,"startOffset":4,"endOffset":26},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":230,"endLine":230,"startOffset":40,"endOffset":79},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":228,"endLine":228,"startOffset":16,"endOffset":84},"msg":"A malicious value can be assigned to variable ‘path’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":228,"endLine":228,"startOffset":23,"endOffset":84},"msg":"This concatenation can propagate malicious content to the newly created string","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":228,"endLine":228,"startOffset":52,"endOffset":84},"msg":"This string operation can propagate malicious content to the returned object","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":227,"endLine":244,"startOffset":12,"endOffset":8},"msg":"A malicious value can be assigned to variable ‘metadata_path’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":227,"endLine":227,"startOffset":16,"endOffset":29},"msg":"A malicious value was previously assigned to this data structure","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":219,"endLine":219,"startOffset":12,"endOffset":64},"msg":"A malicious value can be assigned to variable ‘metadata_paths’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":219,"endLine":219,"startOffset":30,"endOffset":63},"msg":"A malicious value was previously assigned to this data structure","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":216,"endLine":216,"startOffset":12,"endOffset":43},"msg":"A malicious value can be assigned to variable ‘sonarpedia’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":216,"endLine":216,"startOffset":25,"endOffset":43},"msg":"This invocation can propagate malicious content to its return value","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/utils.py","textRange":{"startLine":209,"endLine":209,"startOffset":15,"endOffset":35},"msg":"Source: a user can craft an HTTP request with malicious content","msgFormattings":[]}]}],"resolution":"WONTFIX","status":"RESOLVED","message":"Filesystem Oracle via unsanitized user input","effort":"30min","debt":"30min","tags":["cwe"],"creationDate":"2026-09-09T09:51:00+0000","updateDate":"2026-09-09T13:14:40+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"TRUSTWORTHY","cleanCodeAttributeCategory":"RESPONSIBLE","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":["taint"],"linkedTicketStatus":"NOT_LINKED"},{"key":"06248ae9-cab9-4b72-bdf0-4801aa4f9006","rule":"kotlin:S6474","severity":"MINOR","component":"org.sonarsource.api.plugin:sonar-plugin-api","project":"org.sonarsource.api.plugin:sonar-plugin-api","flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Dependencies are not verified because the \"verification-metadata.xml\" file is missing. Make sure it is safe here.","effort":"15min","debt":"15min","tags":["cwe","dockerfile","former-hotspot"],"creationDate":"2026-08-27T14:14:15+0000","updateDate":"2026-08-31T12:13:58+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"LOW"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"a6612629-f853-49d1-a676-0857c6f61cc3","rule":"text:S8569","severity":"MAJOR","component":"org.sonarsource.api.plugin:sonar-plugin-api:build.gradle.kts","project":"org.sonarsource.api.plugin:sonar-plugin-api","flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Dependency versions are not predictable if the lock file (gradle.lockfile or gradle/verification-metadata.xml) is missing.","effort":"5min","debt":"5min","tags":[],"creationDate":"2026-08-27T14:09:29+0000","updateDate":"2026-08-31T12:13:58+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"2964284e-bda2-464b-80b2-0674499af2d8","rule":"pythonsecurity:S5144","severity":"MAJOR","component":"rspec-tools:rspec_tools/checklinks.py","project":"rspec-tools","line":191,"hash":"45c8cc2b4cb5638e7ea983399d448aee","textRange":{"startLine":191,"endLine":191,"startOffset":15,"endOffset":65},"flows":[{"locations":[{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":191,"endLine":191,"startOffset":15,"endOffset":65},"msg":"Sink: this invocation is not safe; a malicious value can be used as argument","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":189,"endLine":189,"startOffset":8,"endOffset":46},"msg":"A malicious value can be assigned to variable ‘prepped’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":189,"endLine":189,"startOffset":18,"endOffset":46},"msg":"This invocation can propagate malicious content to its return value","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":187,"endLine":187,"startOffset":8,"endOffset":60},"msg":"A malicious value can be assigned to variable ‘req’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":187,"endLine":187,"startOffset":14,"endOffset":60},"msg":"This invocation can propagate malicious content to its return value","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":184,"endLine":184,"startOffset":7,"endOffset":26},"msg":"This condition only validates inputs if evaluated to true","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":182,"endLine":182,"startOffset":13,"endOffset":21},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":182,"endLine":182,"startOffset":4,"endOffset":12},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":568,"endLine":568,"startOffset":21,"endOffset":86},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":565,"endLine":565,"startOffset":24,"endOffset":27},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":565,"endLine":565,"startOffset":4,"endOffset":23},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":623,"endLine":623,"startOffset":8,"endOffset":85},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":617,"endLine":617,"startOffset":8,"endOffset":26},"msg":"A malicious value can be assigned to variable ‘url’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":617,"endLine":617,"startOffset":14,"endOffset":26},"msg":"A malicious value was previously assigned to this data structure","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":616,"endLine":625,"startOffset":4,"endOffset":4},"msg":"A malicious value can be assigned to variable ‘entry’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":616,"endLine":616,"startOffset":8,"endOffset":13},"msg":"A malicious value was previously assigned to this data structure","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":613,"endLine":613,"startOffset":4,"endOffset":50},"msg":"A malicious value can be assigned to variable ‘exception_prefixes’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":613,"endLine":613,"startOffset":25,"endOffset":50},"msg":"This invocation can propagate malicious content to its return value","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":70,"endLine":70,"startOffset":11,"endOffset":57},"msg":"A malicious value was previously assigned to this data structure","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":70,"endLine":70,"startOffset":11,"endOffset":35},"msg":"This invocation can propagate malicious content to its return value","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":57,"endLine":57,"startOffset":11,"endOffset":51},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/checklinks.py","textRange":{"startLine":51,"endLine":51,"startOffset":15,"endOffset":27},"msg":"Source: a user can craft an HTTP request with malicious content","msgFormattings":[]}]}],"status":"OPEN","message":"Server-Side Request Forgery via unsanitized user input","effort":"30min","debt":"30min","assignee":"romain-brenguier72648","tags":["cwe"],"creationDate":"2026-08-25T07:57:57+0000","updateDate":"2026-09-07T14:14:10+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"}],"issueStatus":"OPEN","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":["taint"],"linkedTicketStatus":"NOT_LINKED"},{"key":"0f1387b7-508d-4c2a-9114-c4b4b68edfe9","rule":"java:S4790","severity":"CRITICAL","component":"sonarqube:server/sonar-ce-task-projectanalysis/src/main/java/org/sonar/ce/task/projectanalysis/issue/LocationHashesService.java","project":"sonarqube","line":234,"hash":"b2bcaf094b43b6a5f3fa1af869e78b7d","textRange":{"startLine":234,"endLine":234,"startOffset":53,"endOffset":65},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Make sure this weak hash algorithm is not used in a sensitive context here.","effort":"30min","debt":"30min","tags":["cwe","former-hotspot"],"creationDate":"2026-07-28T20:42:02+0000","updateDate":"2026-07-29T03:44:30+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"TRUSTWORTHY","cleanCodeAttributeCategory":"RESPONSIBLE","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"814af2fa-f1d5-486c-9d5d-517892b324b5","rule":"java:S9345","severity":"CRITICAL","component":"sonarqube:server/sonar-server-common/src/main/java/org/sonar/server/es/SynchronousEsHttpClient.java","project":"sonarqube","hash":"a3551621a18af777c84de54ca5b71463","textRange":{"startLine":75,"endLine":75,"startOffset":9,"endOffset":32},"flows":[{"locations":[{"component":"sonarqube:server/sonar-server-common/src/main/java/org/sonar/server/es/SynchronousEsHttpClient.java","textRange":{"startLine":69,"endLine":69,"startOffset":13,"endOffset":36},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","assignee":"lukasz-jarocki-sonarsource5125","tags":["cert"],"creationDate":"2026-07-21T11:45:06+0000","updateDate":"2026-08-27T17:50:36+0000","closeDate":"2026-08-27T17:50:36+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"b4dae298-a202-4f7e-b9c7-8ff3a2dbcadf","rule":"typescript:S2245","severity":"MAJOR","component":"SonarSource_echoes-react:stories/filters/filter-dropdown-helpers.tsx","project":"SonarSource_echoes-react","line":156,"hash":"4d98ef19257725d2a7f78ff37b4219ca","textRange":{"startLine":156,"endLine":156,"startOffset":9,"endOffset":22},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Make sure that using this pseudorandom number generator is safe here.","effort":"10min","debt":"10min","tags":["cwe","former-hotspot"],"creationDate":"2026-07-17T07:41:27+0000","updateDate":"2026-07-17T07:44:20+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"TRUSTWORTHY","cleanCodeAttributeCategory":"RESPONSIBLE","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"5d46639e-916f-48e2-b5bc-45ff25d6ea0a","rule":"typescript:S2245","severity":"MAJOR","component":"SonarSource_echoes-react:stories/filters/filter-dropdown-helpers.tsx","project":"SonarSource_echoes-react","line":164,"hash":"df6c0fa8166950a8ad14df3c86b3edd9","textRange":{"startLine":164,"endLine":164,"startOffset":24,"endOffset":37},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Make sure that using this pseudorandom number generator is safe here.","effort":"10min","debt":"10min","tags":["cwe","former-hotspot"],"creationDate":"2026-07-17T07:41:27+0000","updateDate":"2026-07-17T07:44:20+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"TRUSTWORTHY","cleanCodeAttributeCategory":"RESPONSIBLE","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"fd5f6bc5-393e-4654-b681-c9f0f0a147b1","rule":"java:S9345","severity":"CRITICAL","component":"SonarSource_sonar-iac:iac-extensions/kubernetes/src/common/java/org/sonar/iac/kubernetes/checks/HardcodedSecretsCheck.java","project":"SonarSource_sonar-iac","hash":"5ac07dd4d7ba7c24071d4ce787f0f4d3","textRange":{"startLine":31,"endLine":31,"startOffset":13,"endOffset":34},"flows":[{"locations":[{"component":"SonarSource_sonar-iac:iac-extensions/kubernetes/src/common/java/org/sonar/iac/kubernetes/checks/HardcodedSecretsCheck.java","textRange":{"startLine":54,"endLine":58,"startOffset":2,"endOffset":91},"msg":"Throwing initializer","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or add a private constructor, because initializers can throw.","effort":"5min","debt":"5min","tags":["cert"],"creationDate":"2026-07-15T09:01:27+0000","updateDate":"2026-08-27T20:26:46+0000","closeDate":"2026-08-27T20:26:46+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"a23d93c1-d477-4bbf-a970-ddada0ef8c0d","rule":"java:S9345","severity":"CRITICAL","component":"org.sonarsource.php:php:php-checks/src/main/java/org/sonar/php/checks/HardCodedSecretCheck.java","project":"org.sonarsource.php:php","hash":"c3af00be014f99f5c885c5ba83551620","textRange":{"startLine":49,"endLine":49,"startOffset":13,"endOffset":33},"flows":[{"locations":[{"component":"org.sonarsource.php:php:php-checks/src/main/java/org/sonar/php/checks/HardCodedSecretCheck.java","textRange":{"startLine":67,"endLine":71,"startOffset":2,"endOffset":91},"msg":"Throwing initializer","msgFormattings":[]}]}],"resolution":"FIXED","status":"CLOSED","message":"Make this class \"final\" or add a private constructor, because initializers can throw.","effort":"5min","debt":"5min","tags":["cert"],"creationDate":"2026-07-13T14:39:55+0000","updateDate":"2026-08-27T09:04:51+0000","closeDate":"2026-08-27T09:04:51+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"410cf20b-5df9-4351-833b-90fcf43c2d93","rule":"java:S4790","severity":"CRITICAL","component":"SonarSource_sonarqube-mcp-server:src/main/java/org/sonarsource/sonarqube/mcp/plugins/PluginsSynchronizer.java","project":"SonarSource_sonarqube-mcp-server","line":131,"hash":"4133d8538669f797b347ae14e6734c1c","textRange":{"startLine":131,"endLine":131,"startOffset":25,"endOffset":31},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Make sure this weak hash algorithm is not used in a sensitive context here.","effort":"30min","debt":"30min","tags":["cwe","former-hotspot"],"creationDate":"2026-07-07T05:33:29+0000","updateDate":"2026-07-07T05:50:07+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"TRUSTWORTHY","cleanCodeAttributeCategory":"RESPONSIBLE","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"5ebb2d13-8d80-4f0c-8bee-7995d019cd68","rule":"java:S9345","severity":"CRITICAL","component":"SonarSource_sonar-text:sonar-text-plugin/src/main/java/org/sonar/plugins/common/InputFileContext.java","project":"SonarSource_sonar-text","hash":"5728db14756d679f936ea237ef982357","textRange":{"startLine":74,"endLine":74,"startOffset":9,"endOffset":25},"flows":[{"locations":[{"component":"SonarSource_sonar-text:sonar-text-plugin/src/main/java/org/sonar/plugins/common/InputFileContext.java","textRange":{"startLine":42,"endLine":42,"startOffset":13,"endOffset":29},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","assignee":"maksim-grebeniuk-sonarsource20062","tags":["cert"],"creationDate":"2026-06-16T12:54:12+0000","updateDate":"2026-08-27T20:52:37+0000","closeDate":"2026-08-27T20:52:37+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"8a049671-623a-4fa2-86ad-a071480591fe","rule":"go:S5332","severity":"MINOR","component":"SonarSource_helm-chart-sonarqube:tests/dynamic-compatibility-test/k8s_utils.go","project":"SonarSource_helm-chart-sonarqube","line":115,"hash":"61cb89325581827f8f4ed571dd0a39f9","textRange":{"startLine":115,"endLine":115,"startOffset":25,"endOffset":54},"flows":[],"status":"OPEN","message":"Using HTTP protocol is insecure. Use HTTPS instead.","effort":"30min","debt":"30min","tags":["cwe","former-hotspot"],"creationDate":"2026-05-27T07:28:07+0000","updateDate":"2026-08-29T04:05:12+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"LOW"}],"issueStatus":"OPEN","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"26cfccd0-07fd-40e6-8cc1-442f0b324baf","rule":"kubernetes:S6865","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-tls-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":381,"hash":"d9e939dad9db0fbf12a7e7ed37d92d0f","textRange":{"startLine":381,"endLine":381,"startOffset":6,"endOffset":16},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Bind this resource\u0027s automounted service account to RBAC or disable automounting.","effort":"1h","debt":"1h","tags":[],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"01282554-173f-44d5-9d04-f62e98732ef9","rule":"kubernetes:S6864","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-tls-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":382,"hash":"64b1cada29cd5aecd6b317b3ee24ec40","textRange":{"startLine":382,"endLine":382,"startOffset":10,"endOffset":14},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Specify a memory limit for this container.","effort":"5min","debt":"5min","tags":[],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"44936f4c-4b99-4498-876b-8807e3c39a48","rule":"kubernetes:S6870","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-tls-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":382,"hash":"64b1cada29cd5aecd6b317b3ee24ec40","textRange":{"startLine":382,"endLine":382,"startOffset":10,"endOffset":14},"flows":[{"locations":[{"component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-tls-values.yaml","textRange":{"startLine":429,"endLine":429,"startOffset":14,"endOffset":18},"msg":"for this volume mount","msgFormattings":[]}]}],"resolution":"WONTFIX","status":"RESOLVED","message":"Specify a storage limit for this container.","effort":"5min","debt":"5min","tags":[],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"f933cda4-0ef6-434d-89a3-97f4cf3b5960","rule":"kubernetes:S6428","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-tls-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":686,"hash":"1e4bba206068d00cce6b7aa94fc119a1","textRange":{"startLine":686,"endLine":686,"startOffset":24,"endOffset":28},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Ensure that enabling privileged mode is safe here.","effort":"1h","debt":"1h","tags":["cwe","former-hotspot"],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"4cd79ced-7836-451f-ac9e-c285ba710c79","rule":"kubernetes:S6865","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":399,"hash":"d9e939dad9db0fbf12a7e7ed37d92d0f","textRange":{"startLine":399,"endLine":399,"startOffset":6,"endOffset":16},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Bind this resource\u0027s automounted service account to RBAC or disable automounting.","effort":"1h","debt":"1h","tags":[],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"0d7dcb7c-9d92-451e-927d-2064611b04a6","rule":"kubernetes:S6864","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":400,"hash":"64b1cada29cd5aecd6b317b3ee24ec40","textRange":{"startLine":400,"endLine":400,"startOffset":10,"endOffset":14},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Specify a memory limit for this container.","effort":"5min","debt":"5min","tags":[],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"a2a4606e-480a-4b85-8166-72fc61e1aa81","rule":"kubernetes:S6870","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":400,"hash":"64b1cada29cd5aecd6b317b3ee24ec40","textRange":{"startLine":400,"endLine":400,"startOffset":10,"endOffset":14},"flows":[{"locations":[{"component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-values.yaml","textRange":{"startLine":438,"endLine":438,"startOffset":14,"endOffset":18},"msg":"for this volume mount","msgFormattings":[]}]}],"resolution":"WONTFIX","status":"RESOLVED","message":"Specify a storage limit for this container.","effort":"5min","debt":"5min","tags":[],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"ac1303af-3756-4128-b644-2000f8a134b5","rule":"kubernetes:S6428","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":692,"hash":"1e4bba206068d00cce6b7aa94fc119a1","textRange":{"startLine":692,"endLine":692,"startOffset":24,"endOffset":28},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Ensure that enabling privileged mode is safe here.","effort":"1h","debt":"1h","tags":["cwe","former-hotspot"],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"5874fe0e-b6eb-419e-aa6d-dae137994bbd","rule":"kubernetes:S6865","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-web-context-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":399,"hash":"d9e939dad9db0fbf12a7e7ed37d92d0f","textRange":{"startLine":399,"endLine":399,"startOffset":6,"endOffset":16},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Bind this resource\u0027s automounted service account to RBAC or disable automounting.","effort":"1h","debt":"1h","tags":[],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"3254f848-669d-4130-a918-f147cd4a4b0f","rule":"kubernetes:S6870","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-web-context-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":400,"hash":"64b1cada29cd5aecd6b317b3ee24ec40","textRange":{"startLine":400,"endLine":400,"startOffset":10,"endOffset":14},"flows":[{"locations":[{"component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-web-context-values.yaml","textRange":{"startLine":438,"endLine":438,"startOffset":14,"endOffset":18},"msg":"for this volume mount","msgFormattings":[]}]}],"resolution":"WONTFIX","status":"RESOLVED","message":"Specify a storage limit for this container.","effort":"5min","debt":"5min","tags":[],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"d65465dc-cd3b-45d4-8e02-1dc56293ca84","rule":"kubernetes:S6864","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-web-context-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":400,"hash":"64b1cada29cd5aecd6b317b3ee24ec40","textRange":{"startLine":400,"endLine":400,"startOffset":10,"endOffset":14},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Specify a memory limit for this container.","effort":"5min","debt":"5min","tags":[],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"da18df03-a585-4aab-a89a-254e953a6b40","rule":"kubernetes:S6428","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-web-context-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":690,"hash":"1e4bba206068d00cce6b7aa94fc119a1","textRange":{"startLine":690,"endLine":690,"startOffset":24,"endOffset":28},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Ensure that enabling privileged mode is safe here.","effort":"1h","debt":"1h","tags":["cwe","former-hotspot"],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"23d0f9d8-411a-4b33-a10b-d2bd1552b1be","rule":"kubernetes:S6865","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/mcp-tls-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":198,"hash":"d9e939dad9db0fbf12a7e7ed37d92d0f","textRange":{"startLine":198,"endLine":198,"startOffset":6,"endOffset":16},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Bind this resource\u0027s automounted service account to RBAC or disable automounting.","effort":"1h","debt":"1h","tags":[],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"368bb884-c6fd-4da5-8d3b-b67f589b8ad3","rule":"kubernetes:S6870","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/mcp-tls-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":199,"hash":"64b1cada29cd5aecd6b317b3ee24ec40","textRange":{"startLine":199,"endLine":199,"startOffset":10,"endOffset":14},"flows":[{"locations":[{"component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/mcp-tls-values.yaml","textRange":{"startLine":246,"endLine":246,"startOffset":14,"endOffset":18},"msg":"for this volume mount","msgFormattings":[]}]}],"resolution":"WONTFIX","status":"RESOLVED","message":"Specify a storage limit for this container.","effort":"5min","debt":"5min","tags":[],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"82a16931-df73-4a49-ba2b-73d1f17a0fa8","rule":"kubernetes:S6864","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/mcp-tls-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":199,"hash":"64b1cada29cd5aecd6b317b3ee24ec40","textRange":{"startLine":199,"endLine":199,"startOffset":10,"endOffset":14},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Specify a memory limit for this container.","effort":"5min","debt":"5min","tags":[],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"e4c7a346-4162-4a4a-8407-faa32b502cdc","rule":"kubernetes:S6428","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/mcp-tls-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":301,"hash":"1e4bba206068d00cce6b7aa94fc119a1","textRange":{"startLine":301,"endLine":301,"startOffset":24,"endOffset":28},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Ensure that enabling privileged mode is safe here.","effort":"1h","debt":"1h","tags":["cwe","former-hotspot"],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"7e5b3f3d-0179-4387-9a64-9ee5b85bd585","rule":"kubernetes:S6865","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/mcp-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":216,"hash":"d9e939dad9db0fbf12a7e7ed37d92d0f","textRange":{"startLine":216,"endLine":216,"startOffset":6,"endOffset":16},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Bind this resource\u0027s automounted service account to RBAC or disable automounting.","effort":"1h","debt":"1h","tags":[],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"11e1f85e-19fe-42a4-99fe-8d82983e91fd","rule":"kubernetes:S6870","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/mcp-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":217,"hash":"64b1cada29cd5aecd6b317b3ee24ec40","textRange":{"startLine":217,"endLine":217,"startOffset":10,"endOffset":14},"flows":[{"locations":[{"component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/mcp-values.yaml","textRange":{"startLine":255,"endLine":255,"startOffset":14,"endOffset":18},"msg":"for this volume mount","msgFormattings":[]}]}],"resolution":"WONTFIX","status":"RESOLVED","message":"Specify a storage limit for this container.","effort":"5min","debt":"5min","tags":[],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"32d46b08-c4db-4742-9826-0831501f9e28","rule":"kubernetes:S6864","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/mcp-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":217,"hash":"64b1cada29cd5aecd6b317b3ee24ec40","textRange":{"startLine":217,"endLine":217,"startOffset":10,"endOffset":14},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Specify a memory limit for this container.","effort":"5min","debt":"5min","tags":[],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"b70fda35-e50d-4f87-b4ea-5429757b0adc","rule":"kubernetes:S6428","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/mcp-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":305,"hash":"1e4bba206068d00cce6b7aa94fc119a1","textRange":{"startLine":305,"endLine":305,"startOffset":24,"endOffset":28},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Ensure that enabling privileged mode is safe here.","effort":"1h","debt":"1h","tags":["cwe","former-hotspot"],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"9c6123fc-5480-4589-80b8-67415964a024","rule":"kubernetes:S6865","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/mcp-web-context-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":216,"hash":"d9e939dad9db0fbf12a7e7ed37d92d0f","textRange":{"startLine":216,"endLine":216,"startOffset":6,"endOffset":16},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Bind this resource\u0027s automounted service account to RBAC or disable automounting.","effort":"1h","debt":"1h","tags":[],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"511e3a30-ad2e-4708-b1f9-83c033301547","rule":"kubernetes:S6864","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/mcp-web-context-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":217,"hash":"64b1cada29cd5aecd6b317b3ee24ec40","textRange":{"startLine":217,"endLine":217,"startOffset":10,"endOffset":14},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Specify a memory limit for this container.","effort":"5min","debt":"5min","tags":[],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"f2760ce6-63e4-46e3-ab62-54b4ea73fde0","rule":"kubernetes:S6870","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/mcp-web-context-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":217,"hash":"64b1cada29cd5aecd6b317b3ee24ec40","textRange":{"startLine":217,"endLine":217,"startOffset":10,"endOffset":14},"flows":[{"locations":[{"component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/mcp-web-context-values.yaml","textRange":{"startLine":255,"endLine":255,"startOffset":14,"endOffset":18},"msg":"for this volume mount","msgFormattings":[]}]}],"resolution":"WONTFIX","status":"RESOLVED","message":"Specify a storage limit for this container.","effort":"5min","debt":"5min","tags":[],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"6f0b440b-4169-4f77-9e3c-1cb5b706472d","rule":"kubernetes:S6428","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/mcp-web-context-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":305,"hash":"1e4bba206068d00cce6b7aa94fc119a1","textRange":{"startLine":305,"endLine":305,"startOffset":24,"endOffset":28},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Ensure that enabling privileged mode is safe here.","effort":"1h","debt":"1h","tags":["cwe","former-hotspot"],"creationDate":"2026-05-19T15:06:16+0000","updateDate":"2026-05-19T15:06:16+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"58947378-c651-41b3-b161-2cf0c7953546","rule":"java:S9345","severity":"CRITICAL","component":"SonarSource_sonarqube-mcp-server:src/main/java/org/sonarsource/sonarqube/mcp/client/McpClientManager.java","project":"SonarSource_sonarqube-mcp-server","hash":"9d4110b1b1498aed13ba2e207e0a759f","textRange":{"startLine":57,"endLine":57,"startOffset":9,"endOffset":25},"flows":[{"locations":[{"component":"SonarSource_sonarqube-mcp-server:src/main/java/org/sonarsource/sonarqube/mcp/client/McpClientManager.java","textRange":{"startLine":41,"endLine":41,"startOffset":13,"endOffset":29},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"FIXED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","assignee":"nicolas-quinquenel22735","tags":["cert"],"creationDate":"2026-04-29T09:54:37+0000","updateDate":"2026-08-27T06:11:32+0000","closeDate":"2026-08-27T06:11:32+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"0c6b21cc-92ee-459e-99a0-69c34adbe913","rule":"text:S8569","severity":"MAJOR","component":"SonarSource_sonar-iac:build.gradle.kts","project":"SonarSource_sonar-iac","flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Dependency versions are not predictable if the lock file (gradle.lockfile or gradle/verification-metadata.xml) is missing.","effort":"5min","debt":"5min","tags":[],"creationDate":"2026-04-08T12:40:36+0000","updateDate":"2026-04-25T05:49:21+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"ad69f789-cfd0-4891-81ab-621007c41e9a","rule":"text:S8569","severity":"MAJOR","component":"SonarSource_sonar-go:build.gradle.kts","project":"SonarSource_sonar-go","flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Dependency versions are not predictable if the lock file (gradle.lockfile or gradle/verification-metadata.xml) is missing.","effort":"5min","debt":"5min","tags":[],"creationDate":"2026-04-08T12:40:16+0000","updateDate":"2026-04-30T06:16:50+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"fa457f70-c699-466a-b889-09c04bd9dd4d","rule":"text:S8569","severity":"MAJOR","component":"SonarSource_sonar-text:build.gradle.kts","project":"SonarSource_sonar-text","flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Dependency versions are not predictable if the lock file (gradle.lockfile or gradle/verification-metadata.xml) is missing.","effort":"5min","debt":"5min","tags":[],"creationDate":"2026-04-08T10:17:15+0000","updateDate":"2026-06-12T06:44:55+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"a6e4fecd-7225-413d-ae6d-c9fde17c4e8f","rule":"pythonsecurity:S8707","severity":"MAJOR","component":"SonarSource_sonar-rust:tools/clippy-metadata/workflow_summary.py","project":"SonarSource_sonar-rust","line":65,"hash":"9e14358e8976f9363e749b0683d2bc77","textRange":{"startLine":65,"endLine":65,"startOffset":25,"endOffset":70},"flows":[{"locations":[{"component":"SonarSource_sonar-rust:tools/clippy-metadata/workflow_summary.py","textRange":{"startLine":65,"endLine":65,"startOffset":25,"endOffset":70},"msg":"Sink: this invocation is not safe; a malicious value can be injected into the caller","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-metadata/workflow_summary.py","textRange":{"startLine":65,"endLine":65,"startOffset":25,"endOffset":42},"msg":"A malicious value was previously assigned to the field ‘summary_file’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-metadata/workflow_summary.py","textRange":{"startLine":63,"endLine":63,"startOffset":4,"endOffset":30},"msg":"A malicious value can be assigned to variable ‘args’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-metadata/workflow_summary.py","textRange":{"startLine":63,"endLine":63,"startOffset":11,"endOffset":30},"msg":"Source: a user can craft an HTTP request with malicious content","msgFormattings":[]}]}],"resolution":"WONTFIX","status":"RESOLVED","message":"Path Traversal via faulty LLM-supplied CLI arguments","effort":"30min","debt":"30min","tags":["cwe"],"creationDate":"2026-03-26T08:33:51+0000","updateDate":"2026-09-07T13:52:10+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":["taint","advanced"],"linkedTicketStatus":"NOT_LINKED"},{"key":"ec2fe6b2-27aa-497d-ae67-13e1fc93e3b8","rule":"java:S6418","severity":"BLOCKER","component":"SonarSource_sonarqube-mcp-server:src/main/java/org/sonarsource/sonarqube/mcp/analytics/AnalyticsClient.java","project":"SonarSource_sonarqube-mcp-server","line":35,"hash":"8224b97f261208c6cb96a4a54d869783","textRange":{"startLine":35,"endLine":35,"startOffset":30,"endOffset":37},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"\u0027API_KEY\u0027 detected in this expression, review this potentially hard-coded secret.","effort":"30min","debt":"30min","tags":["cwe","cert"],"creationDate":"2026-03-09T15:33:06+0000","updateDate":"2026-06-10T05:55:09+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"TRUSTWORTHY","cleanCodeAttributeCategory":"RESPONSIBLE","impacts":[{"softwareQuality":"SECURITY","severity":"BLOCKER"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"b9d1efff-042a-449f-8e0b-8977d22563eb","rule":"pythonsecurity:S8707","severity":"MAJOR","component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","project":"SonarSource_sonar-rust","line":112,"hash":"1aef92bd774e857e468d383997dd9966","textRange":{"startLine":112,"endLine":112,"startOffset":13,"endOffset":41},"flows":[{"locations":[{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":112,"endLine":112,"startOffset":13,"endOffset":41},"msg":"Sink: this invocation is not safe; a malicious value can be used as argument","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":111,"endLine":119,"startOffset":4,"endOffset":4},"msg":"A malicious value can be assigned to variable ‘file’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":111,"endLine":111,"startOffset":8,"endOffset":12},"msg":"A malicious value was previously assigned to this data structure","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":111,"endLine":111,"startOffset":16,"endOffset":54},"msg":"This invocation can propagate malicious content to its return value","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":92,"endLine":92,"startOffset":26,"endOffset":57},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":92,"endLine":92,"startOffset":26,"endOffset":50},"msg":"This invocation can propagate malicious content to its return value","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":89,"endLine":89,"startOffset":31,"endOffset":46},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":108,"endLine":108,"startOffset":25,"endOffset":40},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":108,"endLine":108,"startOffset":4,"endOffset":24},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":295,"endLine":295,"startOffset":19,"endOffset":67},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":295,"endLine":295,"startOffset":51,"endOffset":66},"msg":"A malicious value was previously assigned to the field ‘clippy_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":287,"endLine":287,"startOffset":4,"endOffset":30},"msg":"A malicious value can be assigned to variable ‘args’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":287,"endLine":287,"startOffset":11,"endOffset":30},"msg":"Source: a user can craft an HTTP request with malicious content","msgFormattings":[]}]}],"resolution":"WONTFIX","status":"RESOLVED","message":"Path Traversal via faulty LLM-supplied CLI arguments","effort":"30min","debt":"30min","tags":["cwe"],"creationDate":"2026-01-28T12:32:48+0000","updateDate":"2026-09-07T13:52:10+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":["taint","advanced"],"linkedTicketStatus":"NOT_LINKED"},{"key":"03f0838f-0a57-459a-9a6e-25e3263465ea","rule":"pythonsecurity:S8707","severity":"MAJOR","component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","project":"SonarSource_sonar-rust","line":253,"hash":"0e31255695baf103e720c1465160578a","textRange":{"startLine":253,"endLine":253,"startOffset":4,"endOffset":40},"flows":[{"locations":[{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":253,"endLine":253,"startOffset":4,"endOffset":40},"msg":"Sink: this invocation is not safe; a malicious value can be used as argument","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":252,"endLine":252,"startOffset":4,"endOffset":43},"msg":"A malicious value can be assigned to variable ‘temp_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":252,"endLine":252,"startOffset":15,"endOffset":43},"msg":"This concatenation can propagate malicious content to the newly created string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":252,"endLine":252,"startOffset":18,"endOffset":25},"msg":"The malicious content is concatenated into the string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":250,"endLine":250,"startOffset":38,"endOffset":45},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":250,"endLine":250,"startOffset":4,"endOffset":20},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":338,"endLine":338,"startOffset":20,"endOffset":131},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":328,"endLine":328,"startOffset":12,"endOffset":55},"msg":"A malicious value can be assigned to variable ‘lint_output_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":328,"endLine":328,"startOffset":30,"endOffset":55},"msg":"This concatenation can propagate malicious content to the newly created string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":328,"endLine":328,"startOffset":33,"endOffset":40},"msg":"The malicious content is concatenated into the string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":300,"endLine":300,"startOffset":4,"endOffset":35},"msg":"A malicious value can be assigned to variable ‘out_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":300,"endLine":300,"startOffset":14,"endOffset":26},"msg":"A malicious value was previously assigned to the field ‘out_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":287,"endLine":287,"startOffset":4,"endOffset":30},"msg":"A malicious value can be assigned to variable ‘args’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":287,"endLine":287,"startOffset":11,"endOffset":30},"msg":"Source: a user can craft an HTTP request with malicious content","msgFormattings":[]}]}],"resolution":"WONTFIX","status":"RESOLVED","message":"Path Traversal via faulty LLM-supplied CLI arguments","effort":"30min","debt":"30min","tags":["cwe"],"creationDate":"2026-01-28T12:32:48+0000","updateDate":"2026-09-07T13:52:10+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":["taint","advanced"],"linkedTicketStatus":"NOT_LINKED"},{"key":"40a21532-f559-4704-8dce-ac8095a3a10a","rule":"pythonsecurity:S8707","severity":"MAJOR","component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","project":"SonarSource_sonar-rust","line":257,"hash":"1cfe6dcd9666670773329f1743a79d61","textRange":{"startLine":257,"endLine":257,"startOffset":9,"endOffset":35},"flows":[{"locations":[{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":257,"endLine":257,"startOffset":9,"endOffset":35},"msg":"Sink: this invocation is not safe; a malicious value can be used as argument","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":256,"endLine":256,"startOffset":4,"endOffset":58},"msg":"A malicious value can be assigned to variable ‘cargo_toml_path’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":256,"endLine":256,"startOffset":22,"endOffset":58},"msg":"This invocation can propagate malicious content to its return value","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":252,"endLine":252,"startOffset":4,"endOffset":43},"msg":"A malicious value can be assigned to variable ‘temp_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":252,"endLine":252,"startOffset":15,"endOffset":43},"msg":"This concatenation can propagate malicious content to the newly created string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":252,"endLine":252,"startOffset":18,"endOffset":25},"msg":"The malicious content is concatenated into the string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":250,"endLine":250,"startOffset":38,"endOffset":45},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":250,"endLine":250,"startOffset":4,"endOffset":20},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":338,"endLine":338,"startOffset":20,"endOffset":131},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":328,"endLine":328,"startOffset":12,"endOffset":55},"msg":"A malicious value can be assigned to variable ‘lint_output_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":328,"endLine":328,"startOffset":30,"endOffset":55},"msg":"This concatenation can propagate malicious content to the newly created string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":328,"endLine":328,"startOffset":33,"endOffset":40},"msg":"The malicious content is concatenated into the string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":300,"endLine":300,"startOffset":4,"endOffset":35},"msg":"A malicious value can be assigned to variable ‘out_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":300,"endLine":300,"startOffset":14,"endOffset":26},"msg":"A malicious value was previously assigned to the field ‘out_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":287,"endLine":287,"startOffset":4,"endOffset":30},"msg":"A malicious value can be assigned to variable ‘args’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":287,"endLine":287,"startOffset":11,"endOffset":30},"msg":"Source: a user can craft an HTTP request with malicious content","msgFormattings":[]}]}],"resolution":"WONTFIX","status":"RESOLVED","message":"Path Traversal via faulty LLM-supplied CLI arguments","effort":"30min","debt":"30min","tags":["cwe"],"creationDate":"2026-01-28T12:32:48+0000","updateDate":"2026-09-07T13:52:10+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":["taint","advanced"],"linkedTicketStatus":"NOT_LINKED"},{"key":"33b779c9-2f36-49d6-af88-e459215e2986","rule":"pythonsecurity:S8707","severity":"MAJOR","component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","project":"SonarSource_sonar-rust","line":261,"hash":"7075779bedb6fb44e824c9bf263e47c4","textRange":{"startLine":261,"endLine":261,"startOffset":4,"endOffset":61},"flows":[{"locations":[{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":261,"endLine":261,"startOffset":4,"endOffset":61},"msg":"Sink: this invocation is not safe; a malicious value can be used as argument","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":261,"endLine":261,"startOffset":16,"endOffset":45},"msg":"This invocation can propagate malicious content to its return value","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":260,"endLine":260,"startOffset":4,"endOffset":59},"msg":"A malicious value can be assigned to variable ‘main_rs_path’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":260,"endLine":260,"startOffset":19,"endOffset":59},"msg":"This invocation can propagate malicious content to its return value","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":252,"endLine":252,"startOffset":4,"endOffset":43},"msg":"A malicious value can be assigned to variable ‘temp_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":252,"endLine":252,"startOffset":15,"endOffset":43},"msg":"This concatenation can propagate malicious content to the newly created string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":252,"endLine":252,"startOffset":18,"endOffset":25},"msg":"The malicious content is concatenated into the string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":250,"endLine":250,"startOffset":38,"endOffset":45},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":250,"endLine":250,"startOffset":4,"endOffset":20},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":338,"endLine":338,"startOffset":20,"endOffset":131},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":328,"endLine":328,"startOffset":12,"endOffset":55},"msg":"A malicious value can be assigned to variable ‘lint_output_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":328,"endLine":328,"startOffset":30,"endOffset":55},"msg":"This concatenation can propagate malicious content to the newly created string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":328,"endLine":328,"startOffset":33,"endOffset":40},"msg":"The malicious content is concatenated into the string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":300,"endLine":300,"startOffset":4,"endOffset":35},"msg":"A malicious value can be assigned to variable ‘out_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":300,"endLine":300,"startOffset":14,"endOffset":26},"msg":"A malicious value was previously assigned to the field ‘out_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":287,"endLine":287,"startOffset":4,"endOffset":30},"msg":"A malicious value can be assigned to variable ‘args’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":287,"endLine":287,"startOffset":11,"endOffset":30},"msg":"Source: a user can craft an HTTP request with malicious content","msgFormattings":[]}]}],"resolution":"WONTFIX","status":"RESOLVED","message":"Path Traversal via faulty LLM-supplied CLI arguments","effort":"30min","debt":"30min","tags":["cwe"],"creationDate":"2026-01-28T12:32:48+0000","updateDate":"2026-09-07T13:52:10+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":["taint","advanced"],"linkedTicketStatus":"NOT_LINKED"},{"key":"6f058853-0c21-4fc0-8769-1cb02ee2e45a","rule":"pythonsecurity:S8707","severity":"MAJOR","component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","project":"SonarSource_sonar-rust","line":262,"hash":"f362c3b07d91d6dd3ced0a277f712e0c","textRange":{"startLine":262,"endLine":262,"startOffset":9,"endOffset":32},"flows":[{"locations":[{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":262,"endLine":262,"startOffset":9,"endOffset":32},"msg":"Sink: this invocation is not safe; a malicious value can be used as argument","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":260,"endLine":260,"startOffset":4,"endOffset":59},"msg":"A malicious value can be assigned to variable ‘main_rs_path’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":260,"endLine":260,"startOffset":19,"endOffset":59},"msg":"This invocation can propagate malicious content to its return value","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":252,"endLine":252,"startOffset":4,"endOffset":43},"msg":"A malicious value can be assigned to variable ‘temp_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":252,"endLine":252,"startOffset":15,"endOffset":43},"msg":"This concatenation can propagate malicious content to the newly created string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":252,"endLine":252,"startOffset":18,"endOffset":25},"msg":"The malicious content is concatenated into the string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":250,"endLine":250,"startOffset":38,"endOffset":45},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":250,"endLine":250,"startOffset":4,"endOffset":20},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":338,"endLine":338,"startOffset":20,"endOffset":131},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":328,"endLine":328,"startOffset":12,"endOffset":55},"msg":"A malicious value can be assigned to variable ‘lint_output_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":328,"endLine":328,"startOffset":30,"endOffset":55},"msg":"This concatenation can propagate malicious content to the newly created string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":328,"endLine":328,"startOffset":33,"endOffset":40},"msg":"The malicious content is concatenated into the string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":300,"endLine":300,"startOffset":4,"endOffset":35},"msg":"A malicious value can be assigned to variable ‘out_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":300,"endLine":300,"startOffset":14,"endOffset":26},"msg":"A malicious value was previously assigned to the field ‘out_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":287,"endLine":287,"startOffset":4,"endOffset":30},"msg":"A malicious value can be assigned to variable ‘args’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":287,"endLine":287,"startOffset":11,"endOffset":30},"msg":"Source: a user can craft an HTTP request with malicious content","msgFormattings":[]}]}],"resolution":"WONTFIX","status":"RESOLVED","message":"Path Traversal via faulty LLM-supplied CLI arguments","effort":"30min","debt":"30min","tags":["cwe"],"creationDate":"2026-01-28T12:32:48+0000","updateDate":"2026-09-07T13:52:10+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":["taint","advanced"],"linkedTicketStatus":"NOT_LINKED"},{"key":"ee603fe1-d423-48a1-9d37-186819813405","rule":"pythonsecurity:S8707","severity":"MAJOR","component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","project":"SonarSource_sonar-rust","line":276,"hash":"439b08f82d35fed7166cfdf05c28b808","textRange":{"startLine":276,"endLine":276,"startOffset":9,"endOffset":29},"flows":[{"locations":[{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":276,"endLine":276,"startOffset":9,"endOffset":29},"msg":"Sink: this invocation is not safe; a malicious value can be used as argument","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":275,"endLine":275,"startOffset":15,"endOffset":24},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":275,"endLine":275,"startOffset":4,"endOffset":14},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":392,"endLine":392,"startOffset":4,"endOffset":68},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":392,"endLine":392,"startOffset":15,"endOffset":38},"msg":"This concatenation can propagate malicious content to the newly created string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":392,"endLine":392,"startOffset":18,"endOffset":25},"msg":"The malicious content is concatenated into the string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":300,"endLine":300,"startOffset":4,"endOffset":35},"msg":"A malicious value can be assigned to variable ‘out_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":300,"endLine":300,"startOffset":14,"endOffset":26},"msg":"A malicious value was previously assigned to the field ‘out_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":287,"endLine":287,"startOffset":4,"endOffset":30},"msg":"A malicious value can be assigned to variable ‘args’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":287,"endLine":287,"startOffset":11,"endOffset":30},"msg":"Source: a user can craft an HTTP request with malicious content","msgFormattings":[]}]}],"resolution":"WONTFIX","status":"RESOLVED","message":"Path Traversal via faulty LLM-supplied CLI arguments","effort":"30min","debt":"30min","tags":["cwe"],"creationDate":"2026-01-28T12:32:48+0000","updateDate":"2026-09-07T13:52:10+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":["taint","advanced"],"linkedTicketStatus":"NOT_LINKED"},{"key":"073df8d9-4e30-42f0-a834-1a29b39e28df","rule":"pythonsecurity:S8707","severity":"MAJOR","component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","project":"SonarSource_sonar-rust","line":302,"hash":"751aa4cabcd71995e2677c1505876d0d","textRange":{"startLine":302,"endLine":302,"startOffset":4,"endOffset":39},"flows":[{"locations":[{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":302,"endLine":302,"startOffset":4,"endOffset":39},"msg":"Sink: this invocation is not safe; a malicious value can be used as argument","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":300,"endLine":300,"startOffset":4,"endOffset":35},"msg":"A malicious value can be assigned to variable ‘out_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":300,"endLine":300,"startOffset":14,"endOffset":26},"msg":"A malicious value was previously assigned to the field ‘out_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":287,"endLine":287,"startOffset":4,"endOffset":30},"msg":"A malicious value can be assigned to variable ‘args’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":287,"endLine":287,"startOffset":11,"endOffset":30},"msg":"Source: a user can craft an HTTP request with malicious content","msgFormattings":[]}]}],"resolution":"WONTFIX","status":"RESOLVED","message":"Path Traversal via faulty LLM-supplied CLI arguments","effort":"30min","debt":"30min","tags":["cwe"],"creationDate":"2026-01-28T12:32:48+0000","updateDate":"2026-09-07T13:52:10+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":["taint","advanced"],"linkedTicketStatus":"NOT_LINKED"},{"key":"6670b458-bb06-42ff-900f-3f105ec42aa6","rule":"pythonsecurity:S8707","severity":"MAJOR","component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","project":"SonarSource_sonar-rust","line":329,"hash":"099ad70c36f02b2c4f8e9e156b6ef29d","textRange":{"startLine":329,"endLine":329,"startOffset":12,"endOffset":60},"flows":[{"locations":[{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":329,"endLine":329,"startOffset":12,"endOffset":60},"msg":"Sink: this invocation is not safe; a malicious value can be used as argument","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":329,"endLine":329,"startOffset":24,"endOffset":44},"msg":"This concatenation can propagate malicious content to the newly created string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":329,"endLine":329,"startOffset":27,"endOffset":42},"msg":"The malicious content is concatenated into the string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":328,"endLine":328,"startOffset":12,"endOffset":55},"msg":"A malicious value can be assigned to variable ‘lint_output_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":328,"endLine":328,"startOffset":30,"endOffset":55},"msg":"This concatenation can propagate malicious content to the newly created string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":328,"endLine":328,"startOffset":33,"endOffset":40},"msg":"The malicious content is concatenated into the string","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":300,"endLine":300,"startOffset":4,"endOffset":35},"msg":"A malicious value can be assigned to variable ‘out_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":300,"endLine":300,"startOffset":14,"endOffset":26},"msg":"A malicious value was previously assigned to the field ‘out_dir’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":287,"endLine":287,"startOffset":4,"endOffset":30},"msg":"A malicious value can be assigned to variable ‘args’","msgFormattings":[]},{"component":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","textRange":{"startLine":287,"endLine":287,"startOffset":11,"endOffset":30},"msg":"Source: a user can craft an HTTP request with malicious content","msgFormattings":[]}]}],"resolution":"WONTFIX","status":"RESOLVED","message":"Path Traversal via faulty LLM-supplied CLI arguments","effort":"30min","debt":"30min","tags":["cwe"],"creationDate":"2026-01-28T12:32:48+0000","updateDate":"2026-09-07T13:52:10+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":["taint","advanced"],"linkedTicketStatus":"NOT_LINKED"},{"key":"2e191074-e949-4fb3-825c-391a050af31c","rule":"java:S9345","severity":"CRITICAL","component":"org.sonarsource.sonarlint.core:sonarlint-core-parent:test-utils/src/main/java/org/sonarsource/sonarlint/core/test/utils/SonarLintTestRpcServer.java","project":"org.sonarsource.sonarlint.core:sonarlint-core-parent","hash":"bc4353b4add802fa92f9f0e08820573a","textRange":{"startLine":304,"endLine":304,"startOffset":11,"endOffset":32},"flows":[{"locations":[{"component":"org.sonarsource.sonarlint.core:sonarlint-core-parent:test-utils/src/main/java/org/sonarsource/sonarlint/core/test/utils/SonarLintTestRpcServer.java","textRange":{"startLine":302,"endLine":302,"startOffset":23,"endOffset":44},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"FIXED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","assignee":"dam97392","tags":["cert"],"creationDate":"2025-12-10T17:29:22+0000","updateDate":"2026-08-27T12:43:28+0000","closeDate":"2026-08-27T12:43:28+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"99dabc18-61c0-4a75-a098-5828b3bbaf7f","rule":"java:S9345","severity":"CRITICAL","component":"org.sonarsource.sonarlint.core:sonarlint-core-parent:test-utils/src/main/java/org/sonarsource/sonarlint/core/test/utils/SonarLintTestRpcServer.java","project":"org.sonarsource.sonarlint.core:sonarlint-core-parent","hash":"127377d4b5f68ce6b7c160f55668e014","textRange":{"startLine":87,"endLine":87,"startOffset":9,"endOffset":31},"flows":[{"locations":[{"component":"org.sonarsource.sonarlint.core:sonarlint-core-parent:test-utils/src/main/java/org/sonarsource/sonarlint/core/test/utils/SonarLintTestRpcServer.java","textRange":{"startLine":72,"endLine":72,"startOffset":13,"endOffset":35},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"FIXED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","assignee":"dam97392","tags":["cert"],"creationDate":"2025-12-10T17:29:22+0000","updateDate":"2026-08-27T12:43:28+0000","closeDate":"2026-08-27T12:43:28+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"d1209424-7cfd-4f61-ac94-a069fc440565","rule":"kubernetes:S6865","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/change-admin-password-hook-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":828,"hash":"5e778dc9a51a35ebce2320d5a522436b","textRange":{"startLine":828,"endLine":828,"startOffset":26,"endOffset":33},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Bind this Service Account to RBAC or disable \"automountServiceAccountToken\".","effort":"1h","debt":"1h","tags":[],"creationDate":"2025-11-26T04:06:27+0000","updateDate":"2025-11-28T17:36:58+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"f9809bb4-f198-4bb6-9b6c-ab578d464351","rule":"kubernetes:S6865","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/secret-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":828,"hash":"5e778dc9a51a35ebce2320d5a522436b","textRange":{"startLine":828,"endLine":828,"startOffset":26,"endOffset":33},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Bind this Service Account to RBAC or disable \"automountServiceAccountToken\".","effort":"1h","debt":"1h","tags":[],"creationDate":"2025-11-26T04:06:27+0000","updateDate":"2025-11-28T17:36:58+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"2e2c2811-c808-4bf2-ae51-2cdc93dfbeb8","rule":"kubernetes:S6865","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/sonar-web-context-deprecated-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":899,"hash":"5e778dc9a51a35ebce2320d5a522436b","textRange":{"startLine":899,"endLine":899,"startOffset":26,"endOffset":33},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Bind this Service Account to RBAC or disable \"automountServiceAccountToken\".","effort":"1h","debt":"1h","tags":[],"creationDate":"2025-11-26T04:06:27+0000","updateDate":"2025-11-28T17:36:58+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"bbc86f51-86a3-49b2-817a-a1826f36b647","rule":"kubernetes:S6864","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/sonar-web-context-deprecated-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":901,"hash":"fa431f0b722a5bee44993f091018e277","textRange":{"startLine":901,"endLine":901,"startOffset":8,"endOffset":12},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Specify a memory limit for this container.","effort":"5min","debt":"5min","tags":[],"creationDate":"2025-11-26T04:06:27+0000","updateDate":"2025-11-28T17:36:58+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"f4d63487-8796-4e48-8151-23b496a86d5e","rule":"kubernetes:S6865","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/sonar-web-context-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":850,"hash":"5e778dc9a51a35ebce2320d5a522436b","textRange":{"startLine":850,"endLine":850,"startOffset":26,"endOffset":33},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Bind this Service Account to RBAC or disable \"automountServiceAccountToken\".","effort":"1h","debt":"1h","tags":[],"creationDate":"2025-11-26T04:06:27+0000","updateDate":"2025-11-28T17:36:58+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"5079ed27-d2c4-4cb2-a92f-aea0d2a5d24d","rule":"kubernetes:S6864","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/sonar-web-context-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":852,"hash":"2e2db1090302239ef5b60575a8cc91a9","textRange":{"startLine":852,"endLine":852,"startOffset":8,"endOffset":12},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Specify a memory limit for this container.","effort":"5min","debt":"5min","tags":[],"creationDate":"2025-11-26T04:06:27+0000","updateDate":"2025-11-28T17:36:58+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"b9f6d28a-802c-4b67-b6b3-8fc4c01315bf","rule":"kubernetes:S6865","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/change-admin-password-hook-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":383,"hash":"5e778dc9a51a35ebce2320d5a522436b","textRange":{"startLine":383,"endLine":383,"startOffset":26,"endOffset":33},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Bind this Service Account to RBAC or disable \"automountServiceAccountToken\".","effort":"1h","debt":"1h","tags":[],"creationDate":"2025-11-26T04:06:27+0000","updateDate":"2025-11-28T17:36:58+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"8a03a9a0-ba6f-4f7d-8762-6ea3069b6a83","rule":"kubernetes:S6865","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/non-default-security-context-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":533,"hash":"5e778dc9a51a35ebce2320d5a522436b","textRange":{"startLine":533,"endLine":533,"startOffset":26,"endOffset":33},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Bind this Service Account to RBAC or disable \"automountServiceAccountToken\".","effort":"1h","debt":"1h","tags":[],"creationDate":"2025-11-26T04:06:27+0000","updateDate":"2025-11-28T17:36:58+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"3a5f1b1a-db18-4309-a233-86aaebf961d0","rule":"kubernetes:S6865","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/secret-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":383,"hash":"5e778dc9a51a35ebce2320d5a522436b","textRange":{"startLine":383,"endLine":383,"startOffset":26,"endOffset":33},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Bind this Service Account to RBAC or disable \"automountServiceAccountToken\".","effort":"1h","debt":"1h","tags":[],"creationDate":"2025-11-26T04:06:27+0000","updateDate":"2025-11-28T17:36:58+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"43f7ee97-eeae-4157-8971-ec618a3a87e2","rule":"kubernetes:S6865","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/serviceaccount-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":296,"hash":"8da56aa616611c4e6502e266ce05e850","textRange":{"startLine":296,"endLine":296,"startOffset":26,"endOffset":42},"flows":[{"locations":[{"component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/serviceaccount-values.yaml","textRange":{"startLine":14,"endLine":14,"startOffset":30,"endOffset":34},"msg":"Change this setting","msgFormattings":[]}]}],"resolution":"WONTFIX","status":"RESOLVED","message":"Bind this Service Account to RBAC or disable \"automountServiceAccountToken\".","effort":"1h","debt":"1h","tags":[],"creationDate":"2025-11-26T04:06:27+0000","updateDate":"2025-11-28T17:36:58+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"9310339d-889a-459c-a736-ca0ad4942f63","rule":"kubernetes:S6865","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/sonar-web-context-deployment-deprecated-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":406,"hash":"5e778dc9a51a35ebce2320d5a522436b","textRange":{"startLine":406,"endLine":406,"startOffset":26,"endOffset":33},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Bind this Service Account to RBAC or disable \"automountServiceAccountToken\".","effort":"1h","debt":"1h","tags":[],"creationDate":"2025-11-26T04:06:27+0000","updateDate":"2025-11-28T17:36:58+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"ee9845b4-cb7c-4faa-9610-34590e052105","rule":"kubernetes:S6865","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/sonar-web-context-sts-deprecated-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":405,"hash":"5e778dc9a51a35ebce2320d5a522436b","textRange":{"startLine":405,"endLine":405,"startOffset":26,"endOffset":33},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Bind this Service Account to RBAC or disable \"automountServiceAccountToken\".","effort":"1h","debt":"1h","tags":[],"creationDate":"2025-11-26T04:06:27+0000","updateDate":"2025-11-28T17:36:58+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"b3bd56f2-cf1a-44b6-901c-cff9f5cae242","rule":"kubernetes:S6865","severity":"MAJOR","component":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/sonar-web-context-values.yaml","project":"SonarSource_helm-chart-sonarqube","line":405,"hash":"5e778dc9a51a35ebce2320d5a522436b","textRange":{"startLine":405,"endLine":405,"startOffset":26,"endOffset":33},"flows":[],"resolution":"WONTFIX","status":"RESOLVED","message":"Bind this Service Account to RBAC or disable \"automountServiceAccountToken\".","effort":"1h","debt":"1h","tags":[],"creationDate":"2025-11-26T04:06:27+0000","updateDate":"2025-11-28T17:36:58+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"},{"softwareQuality":"MAINTAINABILITY","severity":"MEDIUM"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"05d9b6f2-e12e-42da-80a2-ba4ed30bb8bc","rule":"java:S9345","severity":"CRITICAL","component":"SonarSource_sonar-go:sonar-go-commons/src/main/java/org/sonar/go/converter/DefaultCommand.java","project":"SonarSource_sonar-go","hash":"60e0f5961a2e68db93196092cc30d402","textRange":{"startLine":51,"endLine":51,"startOffset":9,"endOffset":23},"flows":[{"locations":[{"component":"SonarSource_sonar-go:sonar-go-commons/src/main/java/org/sonar/go/converter/DefaultCommand.java","textRange":{"startLine":39,"endLine":39,"startOffset":13,"endOffset":27},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","assignee":"petertrr69165","tags":["cert"],"creationDate":"2025-10-17T10:32:09+0000","updateDate":"2026-08-27T20:26:07+0000","closeDate":"2026-08-27T20:26:07+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"36a63fc7-b419-4488-99b3-000e62bb0b6d","rule":"pythonsecurity:S6680","severity":"CRITICAL","component":"rspec-tools:rspec_tools/repo.py","project":"rspec-tools","line":123,"hash":"fb0d5a11ce15ccc3c96d65a11bec6810","textRange":{"startLine":123,"endLine":123,"startOffset":20,"endOffset":51},"flows":[{"locations":[{"component":"rspec-tools:rspec_tools/repo.py","textRange":{"startLine":123,"endLine":123,"startOffset":20,"endOffset":51},"msg":"Sink: this invocation is not safe; a malicious value can be used as argument","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/repo.py","textRange":{"startLine":109,"endLine":109,"startOffset":12,"endOffset":56},"msg":"A malicious value can be assigned to variable ‘counter’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/repo.py","textRange":{"startLine":109,"endLine":109,"startOffset":26,"endOffset":55},"msg":"Source: a user can craft an HTTP request with malicious content","msgFormattings":[]}]}],"resolution":"WONTFIX","status":"RESOLVED","message":"Unchecked Input For Loop Condition via unsanitized user input","effort":"5min","debt":"5min","tags":["cwe"],"creationDate":"2025-09-03T07:53:17+0000","updateDate":"2026-09-07T14:14:10+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":["taint"],"linkedTicketStatus":"NOT_LINKED"},{"key":"92a508ea-8443-4bc2-a4e8-3c551185e71d","rule":"java:S9345","severity":"CRITICAL","component":"org.sonarsource.sonarlint.ls:sonarlint-language-server:src/main/java/org/sonarsource/sonarlint/ls/backend/BackendServiceFacade.java","project":"org.sonarsource.sonarlint.ls:sonarlint-language-server","hash":"6a3566237a08fcac51753ef41a620692","textRange":{"startLine":84,"endLine":84,"startOffset":9,"endOffset":29},"flows":[{"locations":[{"component":"org.sonarsource.sonarlint.ls:sonarlint-language-server:src/main/java/org/sonarsource/sonarlint/ls/backend/BackendServiceFacade.java","textRange":{"startLine":68,"endLine":68,"startOffset":13,"endOffset":33},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"FIXED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","assignee":"dam97392","tags":["cert"],"creationDate":"2025-08-28T09:48:03+0000","updateDate":"2026-08-27T11:57:20+0000","closeDate":"2026-08-27T11:57:20+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"92d92800-6fce-47f1-b80d-6c173824c4d9","rule":"java:S9345","severity":"CRITICAL","component":"SonarSource_sonarqube-mcp-server:src/main/java/org/sonarsource/sonarqube/mcp/configuration/McpServerLaunchConfiguration.java","project":"SonarSource_sonarqube-mcp-server","hash":"f88904a158a94d3eb551c76a2b34ff4f","textRange":{"startLine":145,"endLine":145,"startOffset":9,"endOffset":37},"flows":[{"locations":[{"component":"SonarSource_sonarqube-mcp-server:src/main/java/org/sonarsource/sonarqube/mcp/configuration/McpServerLaunchConfiguration.java","textRange":{"startLine":37,"endLine":37,"startOffset":13,"endOffset":41},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"FIXED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","assignee":"nicolas-quinquenel22735","tags":["cert"],"creationDate":"2025-05-16T09:11:39+0000","updateDate":"2026-08-27T06:11:32+0000","closeDate":"2026-08-27T06:11:32+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"a2aad012-9004-48b4-bc9b-7fdb4ce4cab2","rule":"java:S9345","severity":"CRITICAL","component":"org.sonarsource.java:java:java-frontend/src/main/java/org/sonar/java/model/InternalSyntaxTrivia.java","project":"org.sonarsource.java:java","hash":"34b3a1e3c958701cb592ed25deb89f51","textRange":{"startLine":37,"endLine":37,"startOffset":9,"endOffset":29},"flows":[{"locations":[{"component":"org.sonarsource.java:java:java-frontend/src/main/java/org/sonar/java/model/InternalSyntaxTrivia.java","textRange":{"startLine":27,"endLine":27,"startOffset":13,"endOffset":33},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","tags":["cert"],"creationDate":"2025-04-14T12:26:26+0000","updateDate":"2026-08-27T14:51:37+0000","closeDate":"2026-08-27T14:51:37+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"32dec2d4-e31f-4b98-b67f-45fbdef58c15","rule":"pythonsecurity:S6549","severity":"MAJOR","component":"rspec-tools:rspec_tools/coverage.py","project":"rspec-tools","hash":"dd9ce01b8627aac49101bb753b7124c9","textRange":{"startLine":91,"endLine":91,"startOffset":20,"endOffset":36},"flows":[{"locations":[{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":91,"endLine":91,"startOffset":20,"endOffset":36},"msg":"Sink: this invocation is not safe; a malicious value can be used as argument","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":87,"endLine":87,"startOffset":26,"endOffset":30},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":87,"endLine":87,"startOffset":4,"endOffset":25},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":221,"endLine":221,"startOffset":48,"endOffset":86},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":216,"endLine":216,"startOffset":16,"endOffset":84},"msg":"A malicious value can be assigned to variable ‘path’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":216,"endLine":216,"startOffset":23,"endOffset":84},"msg":"This concatenation can propagate malicious content to the newly created string","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":216,"endLine":216,"startOffset":52,"endOffset":84},"msg":"This string operation can propagate malicious content to the returned object","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":215,"endLine":229,"startOffset":12,"endOffset":8},"msg":"A malicious value can be assigned to variable ‘metadata_path’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":215,"endLine":215,"startOffset":16,"endOffset":29},"msg":"A malicious value was previously assigned to this data structure","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":207,"endLine":207,"startOffset":12,"endOffset":64},"msg":"A malicious value can be assigned to variable ‘metadata_paths’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":207,"endLine":207,"startOffset":30,"endOffset":63},"msg":"A malicious value was previously assigned to this data structure","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":204,"endLine":204,"startOffset":12,"endOffset":43},"msg":"A malicious value can be assigned to variable ‘sonarpedia’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":204,"endLine":204,"startOffset":25,"endOffset":43},"msg":"This invocation can propagate malicious content to its return value","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/utils.py","textRange":{"startLine":209,"endLine":209,"startOffset":15,"endOffset":35},"msg":"Source: a user can craft an HTTP request with malicious content","msgFormattings":[]}]}],"resolution":"FIXED","status":"CLOSED","message":"Filesystem Oracle via unsanitized user input","effort":"30min","debt":"30min","tags":["cwe"],"creationDate":"2025-04-11T08:56:55+0000","updateDate":"2026-09-09T10:09:19+0000","closeDate":"2026-09-09T10:09:19+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"TRUSTWORTHY","cleanCodeAttributeCategory":"RESPONSIBLE","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":["taint"],"linkedTicketStatus":"NOT_LINKED"},{"key":"e0dac760-659a-48e1-8aa4-3fbee537f03e","rule":"pythonsecurity:S2083","severity":"BLOCKER","component":"rspec-tools:rspec_tools/create_rule.py","project":"rspec-tools","line":129,"hash":"bbdac82b1dc9a45f7764d96ae7da74a2","textRange":{"startLine":129,"endLine":129,"startOffset":16,"endOffset":51},"flows":[{"locations":[{"component":"rspec-tools:rspec_tools/create_rule.py","textRange":{"startLine":129,"endLine":129,"startOffset":16,"endOffset":51},"msg":"Sink: this invocation is not safe; a malicious value can be used as argument","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/create_rule.py","textRange":{"startLine":126,"endLine":128,"startOffset":16,"endOffset":17},"msg":"A malicious value can be assigned to variable ‘final_content’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/create_rule.py","textRange":{"startLine":126,"endLine":128,"startOffset":32,"endOffset":17},"msg":"This string operation can propagate malicious content to the returned object","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/create_rule.py","textRange":{"startLine":125,"endLine":125,"startOffset":16,"endOffset":56},"msg":"A malicious value can be assigned to variable ‘template_content’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/create_rule.py","textRange":{"startLine":125,"endLine":125,"startOffset":35,"endOffset":56},"msg":"Source: a user can craft an HTTP request with malicious content","msgFormattings":[]}]}],"resolution":"WONTFIX","status":"RESOLVED","message":"Path Traversal via unsanitized user input","effort":"30min","debt":"30min","tags":["cwe"],"creationDate":"2025-04-11T08:56:55+0000","updateDate":"2026-09-07T14:14:10+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"BLOCKER"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":["taint"],"linkedTicketStatus":"NOT_LINKED"},{"key":"2d5af5da-b4f4-4334-8505-7fb45af21133","rule":"pythonsecurity:S2083","severity":"BLOCKER","component":"rspec-tools:rspec_tools/create_rule.py","project":"rspec-tools","line":139,"hash":"bbdac82b1dc9a45f7764d96ae7da74a2","textRange":{"startLine":139,"endLine":139,"startOffset":16,"endOffset":51},"flows":[{"locations":[{"component":"rspec-tools:rspec_tools/create_rule.py","textRange":{"startLine":139,"endLine":139,"startOffset":16,"endOffset":51},"msg":"Sink: this invocation is not safe; a malicious value can be used as argument","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/create_rule.py","textRange":{"startLine":136,"endLine":138,"startOffset":16,"endOffset":17},"msg":"A malicious value can be assigned to variable ‘final_content’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/create_rule.py","textRange":{"startLine":136,"endLine":138,"startOffset":32,"endOffset":17},"msg":"This string operation can propagate malicious content to the returned object","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/create_rule.py","textRange":{"startLine":134,"endLine":134,"startOffset":16,"endOffset":56},"msg":"A malicious value can be assigned to variable ‘template_content’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/create_rule.py","textRange":{"startLine":134,"endLine":134,"startOffset":35,"endOffset":56},"msg":"Source: a user can craft an HTTP request with malicious content","msgFormattings":[]}]}],"resolution":"WONTFIX","status":"RESOLVED","message":"Path Traversal via unsanitized user input","effort":"30min","debt":"30min","tags":["cwe"],"creationDate":"2025-04-11T08:56:55+0000","updateDate":"2026-09-07T14:14:10+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"BLOCKER"}],"issueStatus":"ACCEPTED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":["taint"],"linkedTicketStatus":"NOT_LINKED"},{"key":"05fbb8a4-c174-4a8e-807c-ced29f6f3200","rule":"pythonsecurity:S2083","severity":"BLOCKER","component":"rspec-tools:rspec_tools/utils.py","project":"rspec-tools","hash":"074d7de21b0e662fd6e4d2dbd092afc0","textRange":{"startLine":208,"endLine":208,"startOffset":9,"endOffset":36},"flows":[{"locations":[{"component":"rspec-tools:rspec_tools/utils.py","textRange":{"startLine":208,"endLine":208,"startOffset":9,"endOffset":36},"msg":"Sink: this invocation is not safe; a malicious value can be used as argument","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/utils.py","textRange":{"startLine":207,"endLine":207,"startOffset":14,"endOffset":18},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/utils.py","textRange":{"startLine":207,"endLine":207,"startOffset":4,"endOffset":13},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":93,"endLine":93,"startOffset":19,"endOffset":58},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":93,"endLine":93,"startOffset":29,"endOffset":57},"msg":"This invocation can propagate malicious content to its return value","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":87,"endLine":87,"startOffset":26,"endOffset":30},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":87,"endLine":87,"startOffset":4,"endOffset":25},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":221,"endLine":221,"startOffset":48,"endOffset":86},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":216,"endLine":216,"startOffset":16,"endOffset":84},"msg":"A malicious value can be assigned to variable ‘path’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":216,"endLine":216,"startOffset":23,"endOffset":84},"msg":"This concatenation can propagate malicious content to the newly created string","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":216,"endLine":216,"startOffset":52,"endOffset":84},"msg":"This string operation can propagate malicious content to the returned object","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":215,"endLine":229,"startOffset":12,"endOffset":8},"msg":"A malicious value can be assigned to variable ‘metadata_path’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":215,"endLine":215,"startOffset":16,"endOffset":29},"msg":"A malicious value was previously assigned to this data structure","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":207,"endLine":207,"startOffset":12,"endOffset":64},"msg":"A malicious value can be assigned to variable ‘metadata_paths’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":207,"endLine":207,"startOffset":30,"endOffset":63},"msg":"A malicious value was previously assigned to this data structure","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":204,"endLine":204,"startOffset":12,"endOffset":43},"msg":"A malicious value can be assigned to variable ‘sonarpedia’","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/coverage.py","textRange":{"startLine":204,"endLine":204,"startOffset":25,"endOffset":43},"msg":"This invocation can propagate malicious content to its return value","msgFormattings":[]},{"component":"rspec-tools:rspec_tools/utils.py","textRange":{"startLine":209,"endLine":209,"startOffset":15,"endOffset":35},"msg":"Source: a user can craft an HTTP request with malicious content","msgFormattings":[]}]}],"resolution":"FIXED","status":"CLOSED","message":"Path Traversal via unsanitized user input","effort":"30min","debt":"30min","assignee":"guillem-sarda-parreu27","tags":["cwe"],"creationDate":"2025-04-11T08:56:55+0000","updateDate":"2026-09-09T10:09:19+0000","closeDate":"2026-09-09T10:09:19+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"BLOCKER"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":["taint"],"linkedTicketStatus":"NOT_LINKED"},{"key":"8e070cec-794f-4fb2-b559-bd84d9f26563","rule":"java:S9345","severity":"CRITICAL","component":"SonarSource_sonar-rust:sonar-rust-plugin/src/main/java/org/sonarsource/rust/plugin/Analyzer.java","project":"SonarSource_sonar-rust","hash":"243376fbcec319388b5bef13bf8ddcc2","textRange":{"startLine":38,"endLine":38,"startOffset":9,"endOffset":17},"flows":[{"locations":[{"component":"SonarSource_sonar-rust:sonar-rust-plugin/src/main/java/org/sonarsource/rust/plugin/Analyzer.java","textRange":{"startLine":30,"endLine":30,"startOffset":13,"endOffset":21},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","tags":["cert"],"creationDate":"2025-03-25T12:40:50+0000","updateDate":"2026-08-28T04:47:33+0000","closeDate":"2026-08-28T04:47:33+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"07400e86-9573-4bb8-97be-5bbce84e5c92","rule":"java:S9345","severity":"CRITICAL","component":"SonarSource_sonar-go:sonar-go-frontend/src/main/java/org/sonar/go/impl/StringLiteralTreeImpl.java","project":"SonarSource_sonar-go","hash":"dd52fd3465996b78fd404bba1d1f5a55","textRange":{"startLine":26,"endLine":26,"startOffset":9,"endOffset":30},"flows":[{"locations":[{"component":"SonarSource_sonar-go:sonar-go-frontend/src/main/java/org/sonar/go/impl/StringLiteralTreeImpl.java","textRange":{"startLine":22,"endLine":22,"startOffset":13,"endOffset":34},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","assignee":"quentin-jaquier-sonarsource@github","tags":["cert"],"creationDate":"2025-01-24T16:37:31+0000","updateDate":"2026-08-27T20:26:07+0000","closeDate":"2026-08-27T20:26:07+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"b0147ea8-c896-4678-abb9-2123a6d6f66e","rule":"java:S9345","severity":"CRITICAL","component":"sonarqube:server/sonar-server-common/src/main/java/org/sonar/server/component/ComponentTypes.java","project":"sonarqube","hash":"0724fea8e337aa5e62854e652ecb230b","textRange":{"startLine":42,"endLine":42,"startOffset":9,"endOffset":23},"flows":[{"locations":[{"component":"sonarqube:server/sonar-server-common/src/main/java/org/sonar/server/component/ComponentTypes.java","textRange":{"startLine":36,"endLine":36,"startOffset":13,"endOffset":27},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","assignee":"henryju@github","tags":["cert"],"creationDate":"2024-10-24T20:02:44+0000","updateDate":"2026-08-27T17:50:36+0000","closeDate":"2026-08-27T17:50:36+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"d840fabc-6b3a-4e36-a70b-cf8991dfb6ca","rule":"java:S9345","severity":"CRITICAL","component":"org.sonarsource.python:python:python-checks/src/main/java/org/sonar/python/checks/hotspots/HardCodedCredentialsEntropyCheck.java","project":"org.sonarsource.python:python","hash":"bfa124af1bb60d99454564a428cc8542","textRange":{"startLine":42,"endLine":42,"startOffset":13,"endOffset":45},"flows":[{"locations":[{"component":"org.sonarsource.python:python:python-checks/src/main/java/org/sonar/python/checks/hotspots/HardCodedCredentialsEntropyCheck.java","textRange":{"startLine":60,"endLine":64,"startOffset":2,"endOffset":91},"msg":"Throwing initializer","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or add a private constructor, because initializers can throw.","effort":"5min","debt":"5min","assignee":"ghislain-piot33743","tags":["cert"],"creationDate":"2024-08-22T12:35:51+0000","updateDate":"2026-08-27T14:16:20+0000","closeDate":"2026-08-27T14:16:20+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"caf99e71-077f-42f4-8faa-b87850d1c95e","rule":"java:S9345","severity":"CRITICAL","component":"SonarSource_sonar-ruby:sonar-ruby-plugin/src/main/java/org/sonarsource/ruby/converter/RubyConverter.java","project":"SonarSource_sonar-ruby","hash":"d90393f174dab3e8f6b7c50b12eceadd","textRange":{"startLine":69,"endLine":69,"startOffset":2,"endOffset":15},"flows":[{"locations":[{"component":"SonarSource_sonar-ruby:sonar-ruby-plugin/src/main/java/org/sonarsource/ruby/converter/RubyConverter.java","textRange":{"startLine":56,"endLine":56,"startOffset":13,"endOffset":26},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","tags":["cert"],"creationDate":"2024-08-20T08:24:26+0000","updateDate":"2026-08-28T03:36:03+0000","closeDate":"2026-08-28T03:36:03+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"aa1928e3-c219-4ca6-9a9d-439e5c9c4f9b","rule":"java:S9345","severity":"CRITICAL","component":"org.sonarsource.javascript:javascript:sonar-plugin/bridge/src/main/java/org/sonar/plugins/javascript/bridge/EslintRule.java","project":"org.sonarsource.javascript:javascript","hash":"242a2016b7cf5e43129d8bf0951360e7","textRange":{"startLine":34,"endLine":34,"startOffset":9,"endOffset":19},"flows":[{"locations":[{"component":"org.sonarsource.javascript:javascript:sonar-plugin/bridge/src/main/java/org/sonar/plugins/javascript/bridge/EslintRule.java","textRange":{"startLine":25,"endLine":25,"startOffset":13,"endOffset":23},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","tags":["cert"],"creationDate":"2024-05-24T13:57:40+0000","updateDate":"2026-08-27T14:11:09+0000","closeDate":"2026-08-27T14:11:09+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"5f443849-e674-43b3-87b7-a28c34a86983","rule":"java:S9345","severity":"CRITICAL","component":"org.sonarsource.sonarlint.core:sonarlint-core-parent:backend/core/src/main/java/org/sonarsource/sonarlint/core/tracking/XodusKnownFindingsStore.java","project":"org.sonarsource.sonarlint.core:sonarlint-core-parent","hash":"72c36187268d12c4d58b122409865b1f","textRange":{"startLine":75,"endLine":75,"startOffset":9,"endOffset":32},"flows":[{"locations":[{"component":"org.sonarsource.sonarlint.core:sonarlint-core-parent:backend/core/src/main/java/org/sonarsource/sonarlint/core/tracking/XodusKnownFindingsStore.java","textRange":{"startLine":50,"endLine":50,"startOffset":13,"endOffset":36},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"FIXED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","tags":["cert"],"creationDate":"2024-05-13T12:05:27+0000","updateDate":"2026-08-27T12:43:28+0000","closeDate":"2026-08-27T12:43:28+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"38002063-da34-4065-85c8-b987a2020495","rule":"java:S9345","severity":"CRITICAL","component":"org.sonarsource.sonarlint.core:sonarlint-core-parent:backend/core/src/main/java/org/sonarsource/sonarlint/core/local/only/XodusLocalOnlyIssueStore.java","project":"org.sonarsource.sonarlint.core:sonarlint-core-parent","hash":"e6dfda069e6aea22f39ab9e01ac95ef3","textRange":{"startLine":77,"endLine":77,"startOffset":9,"endOffset":33},"flows":[{"locations":[{"component":"org.sonarsource.sonarlint.core:sonarlint-core-parent:backend/core/src/main/java/org/sonarsource/sonarlint/core/local/only/XodusLocalOnlyIssueStore.java","textRange":{"startLine":51,"endLine":51,"startOffset":13,"endOffset":37},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"FIXED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","assignee":"nicolas-quinquenel22735","tags":["cert"],"creationDate":"2023-08-08T13:41:54+0000","updateDate":"2026-08-27T12:43:28+0000","closeDate":"2026-08-27T12:43:28+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"62cd18c9-f189-445f-a9be-d04108303767","rule":"java:S9345","severity":"CRITICAL","component":"sonarqube:server/sonar-webserver-auth/src/main/java/org/sonar/server/user/SecurityRealmFactory.java","project":"sonarqube","hash":"6025c9a6da15e4d6e0e63a0b39d113f0","textRange":{"startLine":49,"endLine":49,"startOffset":9,"endOffset":29},"flows":[{"locations":[{"component":"sonarqube:server/sonar-webserver-auth/src/main/java/org/sonar/server/user/SecurityRealmFactory.java","textRange":{"startLine":41,"endLine":41,"startOffset":13,"endOffset":33},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","assignee":"dbmeneses@github","tags":["cert"],"creationDate":"2023-07-18T20:03:23+0000","updateDate":"2026-08-27T17:50:36+0000","closeDate":"2026-08-27T17:50:36+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"845b31e5-40e2-4803-9eae-4e32ce617abc","rule":"javasecurity:S6549","severity":"MAJOR","component":"sonarqube:server/sonar-webserver-webapi/src/main/java/org/sonar/server/batch/BatchIndex.java","project":"sonarqube","line":89,"hash":"d394f87f8fd794d4ca0f6199be693608","textRange":{"startLine":89,"endLine":89,"startOffset":102,"endOffset":116},"flows":[{"locations":[{"component":"sonarqube:server/sonar-webserver-webapi/src/main/java/org/sonar/server/batch/BatchIndex.java","textRange":{"startLine":89,"endLine":89,"startOffset":102,"endOffset":116},"msg":"Sink: this invocation is not safe; a malicious value can be injected into the caller","msgFormattings":[]},{"component":"sonarqube:server/sonar-webserver-webapi/src/main/java/org/sonar/server/batch/BatchIndex.java","textRange":{"startLine":88,"endLine":88,"startOffset":6,"endOffset":48},"msg":"A malicious value can be assigned to variable ‘input’","msgFormattings":[]},{"component":"sonarqube:server/sonar-webserver-webapi/src/main/java/org/sonar/server/batch/BatchIndex.java","textRange":{"startLine":88,"endLine":88,"startOffset":19,"endOffset":47},"msg":"This constructor can propagate malicious content to the newly created object","msgFormattings":[]},{"component":"sonarqube:server/sonar-webserver-webapi/src/main/java/org/sonar/server/batch/BatchIndex.java","textRange":{"startLine":86,"endLine":86,"startOffset":15,"endOffset":30},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"sonarqube:server/sonar-webserver-webapi/src/main/java/org/sonar/server/batch/BatchIndex.java","textRange":{"startLine":86,"endLine":86,"startOffset":7,"endOffset":14},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"sonarqube:server/sonar-webserver-webapi/src/main/java/org/sonar/server/batch/FileAction.java","textRange":{"startLine":56,"endLine":56,"startOffset":18,"endOffset":46},"msg":"This instruction can propagate malicious content","msgFormattings":[]},{"component":"sonarqube:server/sonar-webserver-webapi/src/main/java/org/sonar/server/batch/FileAction.java","textRange":{"startLine":53,"endLine":53,"startOffset":4,"endOffset":53},"msg":"A malicious value can be assigned to variable ‘filename’","msgFormattings":[]},{"component":"sonarqube:server/sonar-webserver-webapi/src/main/java/org/sonar/server/batch/FileAction.java","textRange":{"startLine":53,"endLine":53,"startOffset":22,"endOffset":52},"msg":"Source: a user can craft an HTTP request with malicious content","msgFormattings":[]}]}],"resolution":"FALSE-POSITIVE","status":"RESOLVED","message":"Filesystem Oracle via unsanitized user input in BatchIndex.getFile()","effort":"30min","debt":"30min","tags":["cwe"],"creationDate":"2023-06-08T20:03:08+0000","updateDate":"2026-09-10T14:10:50+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"TRUSTWORTHY","cleanCodeAttributeCategory":"RESPONSIBLE","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"}],"issueStatus":"FALSE_POSITIVE","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":["taint"],"linkedTicketStatus":"NOT_LINKED"},{"key":"4b699972-a10d-4ae3-b7ec-9b7dc009e20c","rule":"docker:S8544","severity":"MAJOR","component":"SonarSource_gh-action_cookiecutter_132b474b-7bf8-4672-bd75-53e55f5c758a:Dockerfile","project":"SonarSource_gh-action_cookiecutter_132b474b-7bf8-4672-bd75-53e55f5c758a","hash":"ae022ac75c77807987a3d9bdfaa9d067","textRange":{"startLine":10,"endLine":10,"startOffset":36,"endOffset":52},"flows":[],"resolution":"FIXED","status":"CLOSED","message":"Using dependencies without locking resolved versions is security-sensitive.","effort":"1h","debt":"1h","tags":[],"creationDate":"2023-04-09T09:48:24+0000","updateDate":"2026-06-30T12:35:46+0000","closeDate":"2026-06-30T12:35:46+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"b70226ec-9745-423b-86dc-6ce2fb1ae464","rule":"docker:S8541","severity":"MAJOR","component":"SonarSource_gh-action_cookiecutter_132b474b-7bf8-4672-bd75-53e55f5c758a:Dockerfile","project":"SonarSource_gh-action_cookiecutter_132b474b-7bf8-4672-bd75-53e55f5c758a","hash":"ae022ac75c77807987a3d9bdfaa9d067","textRange":{"startLine":10,"endLine":10,"startOffset":36,"endOffset":48},"flows":[],"resolution":"FIXED","status":"CLOSED","message":"Omitting \"--only-binary :all:\" can lead to the execution of setup scripts. Make sure it is safe here.","effort":"1h","debt":"1h","tags":["cwe"],"creationDate":"2023-04-09T09:48:24+0000","updateDate":"2026-06-30T12:35:46+0000","closeDate":"2026-06-30T12:35:46+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"TRUSTWORTHY","cleanCodeAttributeCategory":"RESPONSIBLE","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"cc782910-f88d-4650-b052-89d63c9bc348","rule":"docker:S8541","severity":"MAJOR","component":"SonarSource_gh-action_cookiecutter_132b474b-7bf8-4672-bd75-53e55f5c758a:Dockerfile","project":"SonarSource_gh-action_cookiecutter_132b474b-7bf8-4672-bd75-53e55f5c758a","hash":"ae022ac75c77807987a3d9bdfaa9d067","textRange":{"startLine":10,"endLine":10,"startOffset":7,"endOffset":19},"flows":[],"resolution":"FIXED","status":"CLOSED","message":"Omitting \"--only-binary :all:\" can lead to the execution of setup scripts. Make sure it is safe here.","effort":"1h","debt":"1h","tags":["cwe"],"creationDate":"2023-04-09T09:48:24+0000","updateDate":"2026-06-30T12:35:46+0000","closeDate":"2026-06-30T12:35:46+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"TRUSTWORTHY","cleanCodeAttributeCategory":"RESPONSIBLE","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"db94a8e3-7f5a-48be-a165-6aad7326dbb3","rule":"docker:S8544","severity":"MAJOR","component":"SonarSource_gh-action_cookiecutter_132b474b-7bf8-4672-bd75-53e55f5c758a:Dockerfile","project":"SonarSource_gh-action_cookiecutter_132b474b-7bf8-4672-bd75-53e55f5c758a","hash":"ae022ac75c77807987a3d9bdfaa9d067","textRange":{"startLine":10,"endLine":10,"startOffset":7,"endOffset":32},"flows":[],"resolution":"FIXED","status":"CLOSED","message":"Using dependencies without locking resolved versions is security-sensitive.","effort":"1h","debt":"1h","tags":[],"creationDate":"2023-04-09T09:48:24+0000","updateDate":"2026-06-30T12:35:46+0000","closeDate":"2026-06-30T12:35:46+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"MEDIUM"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":false,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"bf05baae-b025-48f0-9c3b-ac841d446bca","rule":"java:S9345","severity":"CRITICAL","component":"SonarSource_sonar-text:sonar-text-plugin/src/main/java/org/sonar/plugins/common/Check.java","project":"SonarSource_sonar-text","hash":"2fed5456d9355b46cc1c772bbfc3b22c","textRange":{"startLine":27,"endLine":27,"startOffset":12,"endOffset":17},"flows":[{"locations":[{"component":"SonarSource_sonar-text:sonar-text-plugin/src/main/java/org/sonar/plugins/common/Check.java","textRange":{"startLine":23,"endLine":23,"startOffset":22,"endOffset":27},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","assignee":"alban-auzeill@github","tags":["cert"],"creationDate":"2023-01-12T14:27:08+0000","updateDate":"2026-08-27T20:52:37+0000","closeDate":"2026-08-27T20:52:37+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"1a39ce0f-80b8-4790-b496-6d782fb45100","rule":"java:S9345","severity":"CRITICAL","component":"SonarSource_sonar-text:sonar-text-plugin/src/main/java/org/sonar/plugins/common/InputFileContext.java","project":"SonarSource_sonar-text","hash":"2f42a5170a176e83e4b0bf67842c8f8d","textRange":{"startLine":70,"endLine":70,"startOffset":9,"endOffset":25},"flows":[{"locations":[{"component":"SonarSource_sonar-text:sonar-text-plugin/src/main/java/org/sonar/plugins/common/InputFileContext.java","textRange":{"startLine":42,"endLine":42,"startOffset":13,"endOffset":29},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","assignee":"alban-auzeill@github","tags":["cert"],"creationDate":"2023-01-12T14:27:08+0000","updateDate":"2026-08-27T20:52:37+0000","closeDate":"2026-08-27T20:52:37+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"b4ac09ea-8f6b-4bca-a509-db28b9622aef","rule":"java:S9345","severity":"CRITICAL","component":"sonarqube:server/sonar-server-common/src/main/java/org/sonar/server/issue/index/IssueIteratorForSingleChunk.java","project":"sonarqube","hash":"37e4ad358d6f769b944a95f205a1f76a","textRange":{"startLine":64,"endLine":64,"startOffset":2,"endOffset":29},"flows":[{"locations":[{"component":"sonarqube:server/sonar-server-common/src/main/java/org/sonar/server/issue/index/IssueIteratorForSingleChunk.java","textRange":{"startLine":54,"endLine":54,"startOffset":6,"endOffset":33},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","assignee":"dbmeneses@github","tags":["cert"],"creationDate":"2022-10-12T20:03:43+0000","updateDate":"2026-08-27T17:50:36+0000","closeDate":"2026-08-27T17:50:36+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"ec52e6aa-d7e1-4b8d-a972-6a4d4893485b","rule":"java:S9345","severity":"CRITICAL","component":"sonarqube:sonar-core/src/main/java/org/sonar/core/util/rule/RuleSetChangedEvent.java","project":"sonarqube","hash":"3db14fdde278e36abe6506d25af8bef0","textRange":{"startLine":29,"endLine":29,"startOffset":9,"endOffset":28},"flows":[{"locations":[{"component":"sonarqube:sonar-core/src/main/java/org/sonar/core/util/rule/RuleSetChangedEvent.java","textRange":{"startLine":24,"endLine":24,"startOffset":13,"endOffset":32},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","tags":["cert"],"creationDate":"2022-07-28T20:02:56+0000","updateDate":"2026-08-27T17:50:36+0000","closeDate":"2026-08-27T17:50:36+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"1a1758c2-1a31-4838-911b-df2de2f83915","rule":"java:S9345","severity":"CRITICAL","component":"sonarqube:sonar-core/src/main/java/org/sonar/core/util/issue/IssueChangedEvent.java","project":"sonarqube","hash":"3d4ab74578d6a1eb78a39164d5f7ee66","textRange":{"startLine":38,"endLine":38,"startOffset":9,"endOffset":26},"flows":[{"locations":[{"component":"sonarqube:sonar-core/src/main/java/org/sonar/core/util/issue/IssueChangedEvent.java","textRange":{"startLine":26,"endLine":26,"startOffset":13,"endOffset":30},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","tags":["cert"],"creationDate":"2022-05-16T20:03:56+0000","updateDate":"2026-08-27T17:50:36+0000","closeDate":"2026-08-27T17:50:36+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"1c96b9ab-7e53-4726-854c-41deb228b3ba","rule":"java:S9345","severity":"CRITICAL","component":"org.sonarsource.java:java:java-checks/src/main/java/org/sonar/java/checks/HardCodedSecretCheck.java","project":"org.sonarsource.java:java","hash":"2af154360511893e3d8d4c9206c8ec4b","textRange":{"startLine":38,"endLine":38,"startOffset":13,"endOffset":33},"flows":[{"locations":[{"component":"org.sonarsource.java:java:java-checks/src/main/java/org/sonar/java/checks/HardCodedSecretCheck.java","textRange":{"startLine":53,"endLine":57,"startOffset":2,"endOffset":91},"msg":"Throwing initializer","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or add a private constructor, because initializers can throw.","effort":"5min","debt":"5min","tags":["cert"],"creationDate":"2022-04-14T08:57:49+0000","updateDate":"2026-08-27T14:51:37+0000","closeDate":"2026-08-27T14:51:37+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"31e6cff9-c829-4e01-81e9-d845fd5eb592","rule":"java:S9345","severity":"CRITICAL","component":"sonarqube:server/sonar-webserver-webapi/src/main/java/org/sonar/server/ui/WebAnalyticsLoaderImpl.java","project":"sonarqube","hash":"e4e9b55c0c4f79e4621d8486b6bd94c1","textRange":{"startLine":34,"endLine":34,"startOffset":9,"endOffset":31},"flows":[{"locations":[{"component":"sonarqube:server/sonar-webserver-webapi/src/main/java/org/sonar/server/ui/WebAnalyticsLoaderImpl.java","textRange":{"startLine":29,"endLine":29,"startOffset":13,"endOffset":35},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","assignee":"dbmeneses@github","tags":["cert"],"creationDate":"2022-02-22T20:02:46+0000","updateDate":"2026-08-27T17:50:36+0000","closeDate":"2026-08-27T17:50:36+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"0f303ea6-09b9-4c1b-b822-6aa4c43503ca","rule":"java:S9345","severity":"CRITICAL","component":"org.sonarsource.python:python:python-frontend/src/main/java/org/sonar/python/index/AmbiguousDescriptor.java","project":"org.sonarsource.python:python","hash":"093460cbc5d0bea505476035f22ce992","textRange":{"startLine":30,"endLine":30,"startOffset":9,"endOffset":28},"flows":[{"locations":[{"component":"org.sonarsource.python:python:python-frontend/src/main/java/org/sonar/python/index/AmbiguousDescriptor.java","textRange":{"startLine":24,"endLine":24,"startOffset":13,"endOffset":32},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","assignee":"guillaume-dequenne-sonarsource@github","tags":["cert"],"creationDate":"2021-12-13T14:24:18+0000","updateDate":"2026-08-27T14:16:20+0000","closeDate":"2026-08-27T14:16:20+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"c9f61928-bf83-4b02-aa63-279273ad06f6","rule":"java:S9345","severity":"CRITICAL","component":"org.sonarsource.xml:xml:sonar-xml-plugin/src/main/java/org/sonar/plugins/xml/checks/maven/helpers/MavenDependencyMatcher.java","project":"org.sonarsource.xml:xml","hash":"17fea5e4dadcde0c45af238ce2c28f45","textRange":{"startLine":52,"endLine":52,"startOffset":9,"endOffset":31},"flows":[{"locations":[{"component":"org.sonarsource.xml:xml:sonar-xml-plugin/src/main/java/org/sonar/plugins/xml/checks/maven/helpers/MavenDependencyMatcher.java","textRange":{"startLine":22,"endLine":22,"startOffset":13,"endOffset":35},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","tags":["cert"],"creationDate":"2021-11-16T10:23:52+0000","updateDate":"2026-08-28T04:18:48+0000","closeDate":"2026-08-28T04:18:48+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"82b507b0-19e8-482a-9688-06e6769a4b65","rule":"java:S9345","severity":"CRITICAL","component":"org.sonarsource.xml:xml:sonar-xml-plugin/src/main/java/org/sonar/plugins/xml/checks/maven/helpers/RangedVersionMatcher.java","project":"org.sonarsource.xml:xml","hash":"72c612fc804034a0f5402ebde88a3a90","textRange":{"startLine":28,"endLine":28,"startOffset":9,"endOffset":29},"flows":[{"locations":[{"component":"org.sonarsource.xml:xml:sonar-xml-plugin/src/main/java/org/sonar/plugins/xml/checks/maven/helpers/RangedVersionMatcher.java","textRange":{"startLine":22,"endLine":22,"startOffset":13,"endOffset":33},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","tags":["cert"],"creationDate":"2021-11-16T10:23:52+0000","updateDate":"2026-08-28T04:18:48+0000","closeDate":"2026-08-28T04:18:48+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"},{"key":"13cca103-d23d-4510-9734-c881efdc4115","rule":"java:S9345","severity":"CRITICAL","component":"SonarSource_sonar-iac:iac-extensions/terraform/src/main/java/org/sonar/iac/terraform/tree/impl/SeparatedTreesImpl.java","project":"SonarSource_sonar-iac","hash":"86bef6e1bf7d0c9f4c4480a6aacdb25b","textRange":{"startLine":32,"endLine":32,"startOffset":9,"endOffset":27},"flows":[{"locations":[{"component":"SonarSource_sonar-iac:iac-extensions/terraform/src/main/java/org/sonar/iac/terraform/tree/impl/SeparatedTreesImpl.java","textRange":{"startLine":26,"endLine":26,"startOffset":13,"endOffset":31},"msg":"Non-final class","msgFormattings":[]}]}],"resolution":"REMOVED","status":"CLOSED","message":"Make this class \"final\" or make this throwing constructor \"private\".","effort":"5min","debt":"5min","tags":["cert"],"creationDate":"2021-06-07T12:02:58+0000","updateDate":"2026-08-27T20:26:46+0000","closeDate":"2026-08-27T20:26:46+0000","type":"VULNERABILITY","scope":"MAIN","quickFixAvailable":false,"messageFormattings":[],"codeVariants":[],"cleanCodeAttribute":"COMPLETE","cleanCodeAttributeCategory":"INTENTIONAL","impacts":[{"softwareQuality":"SECURITY","severity":"HIGH"}],"issueStatus":"FIXED","prioritizedRule":false,"fromSonarQubeUpdate":true,"internalTags":[],"linkedTicketStatus":"NOT_LINKED"}],"components":[{"key":"SonarSource_sonar-text:sonar-text-plugin/src/main/java/org/sonar/plugins/common/InputFileContext.java","enabled":true,"qualifier":"FIL","name":"InputFileContext.java","longName":"sonar-text-plugin/src/main/java/org/sonar/plugins/common/InputFileContext.java","path":"sonar-text-plugin/src/main/java/org/sonar/plugins/common/InputFileContext.java"},{"key":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/mcp-tls-values.yaml","enabled":true,"qualifier":"FIL","name":"mcp-tls-values.yaml","longName":"tests/unit-compatibility-test/fixtures/sonarqube/mcp-tls-values.yaml","path":"tests/unit-compatibility-test/fixtures/sonarqube/mcp-tls-values.yaml"},{"key":"org.sonarsource.api.plugin:sonar-plugin-api:build.gradle.kts","enabled":true,"qualifier":"FIL","name":"build.gradle.kts","longName":"build.gradle.kts","path":"build.gradle.kts"},{"key":"org.sonarsource.sonarlint.ls:sonarlint-language-server","enabled":true,"qualifier":"TRK","name":"SonarLint Language Server","longName":"SonarLint Language Server"},{"key":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/non-default-security-context-values.yaml","enabled":true,"qualifier":"FIL","name":"non-default-security-context-values.yaml","longName":"tests/unit-compatibility-test/fixtures/sonarqube/non-default-security-context-values.yaml","path":"tests/unit-compatibility-test/fixtures/sonarqube/non-default-security-context-values.yaml"},{"key":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/serviceaccount-values.yaml","enabled":true,"qualifier":"FIL","name":"serviceaccount-values.yaml","longName":"tests/unit-compatibility-test/fixtures/sonarqube/serviceaccount-values.yaml","path":"tests/unit-compatibility-test/fixtures/sonarqube/serviceaccount-values.yaml"},{"key":"SonarSource_sonar-ruby","enabled":true,"qualifier":"TRK","name":"Ruby","longName":"Ruby"},{"key":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/sonar-web-context-deprecated-values.yaml","enabled":true,"qualifier":"FIL","name":"sonar-web-context-deprecated-values.yaml","longName":"tests/unit-compatibility-test/fixtures/sonarqube-dce/sonar-web-context-deprecated-values.yaml","path":"tests/unit-compatibility-test/fixtures/sonarqube-dce/sonar-web-context-deprecated-values.yaml"},{"key":"rspec-tools:rspec_tools/repo.py","enabled":true,"qualifier":"FIL","name":"repo.py","longName":"rspec_tools/repo.py","path":"rspec_tools/repo.py"},{"key":"org.sonarsource.python:python","enabled":true,"qualifier":"TRK","name":"Python Enterprise","longName":"Python Enterprise"},{"key":"org.sonarsource.java:java:java-checks/src/main/java/org/sonar/java/checks/HardCodedSecretCheck.java","enabled":true,"qualifier":"FIL","name":"HardCodedSecretCheck.java","longName":"java-checks/src/main/java/org/sonar/java/checks/HardCodedSecretCheck.java","path":"java-checks/src/main/java/org/sonar/java/checks/HardCodedSecretCheck.java"},{"key":"sonarqube:server/sonar-ce-task-projectanalysis/src/main/java/org/sonar/ce/task/projectanalysis/issue/LocationHashesService.java","enabled":true,"qualifier":"FIL","name":"LocationHashesService.java","longName":"server/sonar-ce-task-projectanalysis/src/main/java/org/sonar/ce/task/projectanalysis/issue/LocationHashesService.java","path":"server/sonar-ce-task-projectanalysis/src/main/java/org/sonar/ce/task/projectanalysis/issue/LocationHashesService.java"},{"key":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-web-context-values.yaml","enabled":true,"qualifier":"FIL","name":"mcp-web-context-values.yaml","longName":"tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-web-context-values.yaml","path":"tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-web-context-values.yaml"},{"key":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/mcp-values.yaml","enabled":true,"qualifier":"FIL","name":"mcp-values.yaml","longName":"tests/unit-compatibility-test/fixtures/sonarqube/mcp-values.yaml","path":"tests/unit-compatibility-test/fixtures/sonarqube/mcp-values.yaml"},{"key":"SonarSource_sonar-rust:tools/clippy-rspec-migration/clippy-rspec-migration.py","enabled":true,"qualifier":"FIL","name":"clippy-rspec-migration.py","longName":"tools/clippy-rspec-migration/clippy-rspec-migration.py","path":"tools/clippy-rspec-migration/clippy-rspec-migration.py"},{"key":"SonarSource_gh-action_cookiecutter_132b474b-7bf8-4672-bd75-53e55f5c758a:Dockerfile","enabled":true,"qualifier":"FIL","name":"Dockerfile","longName":"Dockerfile","path":"Dockerfile"},{"key":"SonarSource_sonar-text","enabled":true,"qualifier":"TRK","name":"SonarText","longName":"SonarText"},{"key":"org.sonarsource.java:java:java-frontend/src/main/java/org/sonar/java/model/InternalSyntaxTrivia.java","enabled":true,"qualifier":"FIL","name":"InternalSyntaxTrivia.java","longName":"java-frontend/src/main/java/org/sonar/java/model/InternalSyntaxTrivia.java","path":"java-frontend/src/main/java/org/sonar/java/model/InternalSyntaxTrivia.java"},{"key":"sonarqube:server/sonar-server-common/src/main/java/org/sonar/server/component/ComponentTypes.java","enabled":true,"qualifier":"FIL","name":"ComponentTypes.java","longName":"server/sonar-server-common/src/main/java/org/sonar/server/component/ComponentTypes.java","path":"server/sonar-server-common/src/main/java/org/sonar/server/component/ComponentTypes.java"},{"key":"sonarqube:server/sonar-webserver-webapi/src/main/java/org/sonar/server/ui/WebAnalyticsLoaderImpl.java","enabled":true,"qualifier":"FIL","name":"WebAnalyticsLoaderImpl.java","longName":"server/sonar-webserver-webapi/src/main/java/org/sonar/server/ui/WebAnalyticsLoaderImpl.java","path":"server/sonar-webserver-webapi/src/main/java/org/sonar/server/ui/WebAnalyticsLoaderImpl.java"},{"key":"sonarqube","enabled":true,"qualifier":"TRK","name":"SonarQube","longName":"SonarQube"},{"key":"SonarSource_sonar-go","enabled":true,"qualifier":"TRK","name":"SonarGo","longName":"SonarGo"},{"key":"SonarSource_sonar-rust:sonar-rust-plugin/src/main/java/org/sonarsource/rust/plugin/Analyzer.java","enabled":true,"qualifier":"FIL","name":"Analyzer.java","longName":"sonar-rust-plugin/src/main/java/org/sonarsource/rust/plugin/Analyzer.java","path":"sonar-rust-plugin/src/main/java/org/sonarsource/rust/plugin/Analyzer.java"},{"key":"SonarSource_gh-action_cookiecutter_132b474b-7bf8-4672-bd75-53e55f5c758a","enabled":true,"qualifier":"TRK","name":"gh-action_cookiecutter","longName":"gh-action_cookiecutter"},{"key":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/sonar-web-context-sts-deprecated-values.yaml","enabled":true,"qualifier":"FIL","name":"sonar-web-context-sts-deprecated-values.yaml","longName":"tests/unit-compatibility-test/fixtures/sonarqube/sonar-web-context-sts-deprecated-values.yaml","path":"tests/unit-compatibility-test/fixtures/sonarqube/sonar-web-context-sts-deprecated-values.yaml"},{"key":"org.sonarsource.xml:xml","enabled":true,"qualifier":"TRK","name":"SonarSource XML Analyzer","longName":"SonarSource XML Analyzer"},{"key":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/secret-values.yaml","enabled":true,"qualifier":"FIL","name":"secret-values.yaml","longName":"tests/unit-compatibility-test/fixtures/sonarqube/secret-values.yaml","path":"tests/unit-compatibility-test/fixtures/sonarqube/secret-values.yaml"},{"key":"org.sonarsource.python:python:python-checks/src/main/java/org/sonar/python/checks/hotspots/HardCodedCredentialsEntropyCheck.java","enabled":true,"qualifier":"FIL","name":"HardCodedCredentialsEntropyCheck.java","longName":"python-checks/src/main/java/org/sonar/python/checks/hotspots/HardCodedCredentialsEntropyCheck.java","path":"python-checks/src/main/java/org/sonar/python/checks/hotspots/HardCodedCredentialsEntropyCheck.java"},{"key":"org.sonarsource.api.plugin:sonar-plugin-api","enabled":true,"qualifier":"TRK","name":"sonar-plugin-api","longName":"sonar-plugin-api"},{"key":"org.sonarsource.sonarlint.ls:sonarlint-language-server:src/main/java/org/sonarsource/sonarlint/ls/backend/BackendServiceFacade.java","enabled":true,"qualifier":"FIL","name":"BackendServiceFacade.java","longName":"src/main/java/org/sonarsource/sonarlint/ls/backend/BackendServiceFacade.java","path":"src/main/java/org/sonarsource/sonarlint/ls/backend/BackendServiceFacade.java"},{"key":"sonarqube:sonar-core/src/main/java/org/sonar/core/util/issue/IssueChangedEvent.java","enabled":true,"qualifier":"FIL","name":"IssueChangedEvent.java","longName":"sonar-core/src/main/java/org/sonar/core/util/issue/IssueChangedEvent.java","path":"sonar-core/src/main/java/org/sonar/core/util/issue/IssueChangedEvent.java"},{"key":"org.sonarsource.javascript:javascript:sonar-plugin/bridge/src/main/java/org/sonar/plugins/javascript/bridge/EslintRule.java","enabled":true,"qualifier":"FIL","name":"EslintRule.java","longName":"sonar-plugin/bridge/src/main/java/org/sonar/plugins/javascript/bridge/EslintRule.java","path":"sonar-plugin/bridge/src/main/java/org/sonar/plugins/javascript/bridge/EslintRule.java"},{"key":"SonarSource_sonar-rust:tools/clippy-metadata/workflow_summary.py","enabled":true,"qualifier":"FIL","name":"workflow_summary.py","longName":"tools/clippy-metadata/workflow_summary.py","path":"tools/clippy-metadata/workflow_summary.py"},{"key":"SonarSource_sonar-ruby:sonar-ruby-plugin/src/main/java/org/sonarsource/ruby/converter/RubyConverter.java","enabled":true,"qualifier":"FIL","name":"RubyConverter.java","longName":"sonar-ruby-plugin/src/main/java/org/sonarsource/ruby/converter/RubyConverter.java","path":"sonar-ruby-plugin/src/main/java/org/sonarsource/ruby/converter/RubyConverter.java"},{"key":"SonarSource_sonar-rust","enabled":true,"qualifier":"TRK","name":"sonar-rust","longName":"sonar-rust"},{"key":"org.sonarsource.java:java","enabled":true,"qualifier":"TRK","name":"SonarJava","longName":"SonarJava"},{"key":"SonarSource_helm-chart-sonarqube:tests/dynamic-compatibility-test/k8s_utils.go","enabled":true,"qualifier":"FIL","name":"k8s_utils.go","longName":"tests/dynamic-compatibility-test/k8s_utils.go","path":"tests/dynamic-compatibility-test/k8s_utils.go"},{"key":"sonarqube:sonar-core/src/main/java/org/sonar/core/util/rule/RuleSetChangedEvent.java","enabled":true,"qualifier":"FIL","name":"RuleSetChangedEvent.java","longName":"sonar-core/src/main/java/org/sonar/core/util/rule/RuleSetChangedEvent.java","path":"sonar-core/src/main/java/org/sonar/core/util/rule/RuleSetChangedEvent.java"},{"key":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/mcp-web-context-values.yaml","enabled":true,"qualifier":"FIL","name":"mcp-web-context-values.yaml","longName":"tests/unit-compatibility-test/fixtures/sonarqube/mcp-web-context-values.yaml","path":"tests/unit-compatibility-test/fixtures/sonarqube/mcp-web-context-values.yaml"},{"key":"org.sonarsource.sonarlint.core:sonarlint-core-parent","enabled":true,"qualifier":"TRK","name":"SonarLint Core","longName":"SonarLint Core"},{"key":"rspec-tools:rspec_tools/coverage.py","enabled":true,"qualifier":"FIL","name":"coverage.py","longName":"rspec_tools/coverage.py","path":"rspec_tools/coverage.py"},{"key":"rspec-tools:rspec_tools/create_rule.py","enabled":true,"qualifier":"FIL","name":"create_rule.py","longName":"rspec_tools/create_rule.py","path":"rspec_tools/create_rule.py"},{"key":"SonarSource_sonar-iac","enabled":true,"qualifier":"TRK","name":"SonarIaC","longName":"SonarIaC"},{"key":"sonarqube:server/sonar-server-common/src/main/java/org/sonar/server/es/SynchronousEsHttpClient.java","enabled":true,"qualifier":"FIL","name":"SynchronousEsHttpClient.java","longName":"server/sonar-server-common/src/main/java/org/sonar/server/es/SynchronousEsHttpClient.java","path":"server/sonar-server-common/src/main/java/org/sonar/server/es/SynchronousEsHttpClient.java"},{"key":"rspec-tools:rspec_tools/utils.py","enabled":true,"qualifier":"FIL","name":"utils.py","longName":"rspec_tools/utils.py","path":"rspec_tools/utils.py"},{"key":"SonarSource_helm-chart-sonarqube","enabled":true,"qualifier":"TRK","name":"helm-chart-sonarqube","longName":"helm-chart-sonarqube"},{"key":"rspec-tools:rspec_tools/checklinks.py","enabled":true,"qualifier":"FIL","name":"checklinks.py","longName":"rspec_tools/checklinks.py","path":"rspec_tools/checklinks.py"},{"key":"org.sonarsource.php:php:php-checks/src/main/java/org/sonar/php/checks/HardCodedSecretCheck.java","enabled":true,"qualifier":"FIL","name":"HardCodedSecretCheck.java","longName":"php-checks/src/main/java/org/sonar/php/checks/HardCodedSecretCheck.java","path":"php-checks/src/main/java/org/sonar/php/checks/HardCodedSecretCheck.java"},{"key":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/change-admin-password-hook-values.yaml","enabled":true,"qualifier":"FIL","name":"change-admin-password-hook-values.yaml","longName":"tests/unit-compatibility-test/fixtures/sonarqube-dce/change-admin-password-hook-values.yaml","path":"tests/unit-compatibility-test/fixtures/sonarqube-dce/change-admin-password-hook-values.yaml"},{"key":"org.sonarsource.sonarlint.core:sonarlint-core-parent:backend/core/src/main/java/org/sonarsource/sonarlint/core/local/only/XodusLocalOnlyIssueStore.java","enabled":true,"qualifier":"FIL","name":"XodusLocalOnlyIssueStore.java","longName":"backend/core/src/main/java/org/sonarsource/sonarlint/core/local/only/XodusLocalOnlyIssueStore.java","path":"backend/core/src/main/java/org/sonarsource/sonarlint/core/local/only/XodusLocalOnlyIssueStore.java"},{"key":"sonarqube:server/sonar-webserver-webapi/src/main/java/org/sonar/server/batch/BatchIndex.java","enabled":true,"qualifier":"FIL","name":"BatchIndex.java","longName":"server/sonar-webserver-webapi/src/main/java/org/sonar/server/batch/BatchIndex.java","path":"server/sonar-webserver-webapi/src/main/java/org/sonar/server/batch/BatchIndex.java"},{"key":"SonarSource_sonar-go:sonar-go-frontend/src/main/java/org/sonar/go/impl/StringLiteralTreeImpl.java","enabled":true,"qualifier":"FIL","name":"StringLiteralTreeImpl.java","longName":"sonar-go-frontend/src/main/java/org/sonar/go/impl/StringLiteralTreeImpl.java","path":"sonar-go-frontend/src/main/java/org/sonar/go/impl/StringLiteralTreeImpl.java"},{"key":"org.sonarsource.sonarlint.core:sonarlint-core-parent:backend/core/src/main/java/org/sonarsource/sonarlint/core/tracking/XodusKnownFindingsStore.java","enabled":true,"qualifier":"FIL","name":"XodusKnownFindingsStore.java","longName":"backend/core/src/main/java/org/sonarsource/sonarlint/core/tracking/XodusKnownFindingsStore.java","path":"backend/core/src/main/java/org/sonarsource/sonarlint/core/tracking/XodusKnownFindingsStore.java"},{"key":"SonarSource_echoes-react","enabled":true,"qualifier":"TRK","name":"@sonarsource/echoes-react","longName":"@sonarsource/echoes-react"},{"key":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/sonar-web-context-values.yaml","enabled":true,"qualifier":"FIL","name":"sonar-web-context-values.yaml","longName":"tests/unit-compatibility-test/fixtures/sonarqube-dce/sonar-web-context-values.yaml","path":"tests/unit-compatibility-test/fixtures/sonarqube-dce/sonar-web-context-values.yaml"},{"key":"SonarSource_sonarqube-mcp-server:src/main/java/org/sonarsource/sonarqube/mcp/configuration/McpServerLaunchConfiguration.java","enabled":true,"qualifier":"FIL","name":"McpServerLaunchConfiguration.java","longName":"src/main/java/org/sonarsource/sonarqube/mcp/configuration/McpServerLaunchConfiguration.java","path":"src/main/java/org/sonarsource/sonarqube/mcp/configuration/McpServerLaunchConfiguration.java"},{"key":"org.sonarsource.xml:xml:sonar-xml-plugin/src/main/java/org/sonar/plugins/xml/checks/maven/helpers/RangedVersionMatcher.java","enabled":true,"qualifier":"FIL","name":"RangedVersionMatcher.java","longName":"sonar-xml-plugin/src/main/java/org/sonar/plugins/xml/checks/maven/helpers/RangedVersionMatcher.java","path":"sonar-xml-plugin/src/main/java/org/sonar/plugins/xml/checks/maven/helpers/RangedVersionMatcher.java"},{"key":"sonarqube:server/sonar-webserver-webapi/src/main/java/org/sonar/server/batch/FileAction.java","enabled":true,"qualifier":"FIL","name":"FileAction.java","longName":"server/sonar-webserver-webapi/src/main/java/org/sonar/server/batch/FileAction.java","path":"server/sonar-webserver-webapi/src/main/java/org/sonar/server/batch/FileAction.java"},{"key":"SonarSource_sonarqube-mcp-server:src/main/java/org/sonarsource/sonarqube/mcp/analytics/AnalyticsClient.java","enabled":true,"qualifier":"FIL","name":"AnalyticsClient.java","longName":"src/main/java/org/sonarsource/sonarqube/mcp/analytics/AnalyticsClient.java","path":"src/main/java/org/sonarsource/sonarqube/mcp/analytics/AnalyticsClient.java"},{"key":"SonarSource_sonar-text:build.gradle.kts","enabled":true,"qualifier":"FIL","name":"build.gradle.kts","longName":"build.gradle.kts","path":"build.gradle.kts"},{"key":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/sonar-web-context-deployment-deprecated-values.yaml","enabled":true,"qualifier":"FIL","name":"sonar-web-context-deployment-deprecated-values.yaml","longName":"tests/unit-compatibility-test/fixtures/sonarqube/sonar-web-context-deployment-deprecated-values.yaml","path":"tests/unit-compatibility-test/fixtures/sonarqube/sonar-web-context-deployment-deprecated-values.yaml"},{"key":"SonarSource_sonarqube-mcp-server:src/main/java/org/sonarsource/sonarqube/mcp/plugins/PluginsSynchronizer.java","enabled":true,"qualifier":"FIL","name":"PluginsSynchronizer.java","longName":"src/main/java/org/sonarsource/sonarqube/mcp/plugins/PluginsSynchronizer.java","path":"src/main/java/org/sonarsource/sonarqube/mcp/plugins/PluginsSynchronizer.java"},{"key":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-values.yaml","enabled":true,"qualifier":"FIL","name":"mcp-values.yaml","longName":"tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-values.yaml","path":"tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-values.yaml"},{"key":"org.sonarsource.xml:xml:sonar-xml-plugin/src/main/java/org/sonar/plugins/xml/checks/maven/helpers/MavenDependencyMatcher.java","enabled":true,"qualifier":"FIL","name":"MavenDependencyMatcher.java","longName":"sonar-xml-plugin/src/main/java/org/sonar/plugins/xml/checks/maven/helpers/MavenDependencyMatcher.java","path":"sonar-xml-plugin/src/main/java/org/sonar/plugins/xml/checks/maven/helpers/MavenDependencyMatcher.java"},{"key":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-tls-values.yaml","enabled":true,"qualifier":"FIL","name":"mcp-tls-values.yaml","longName":"tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-tls-values.yaml","path":"tests/unit-compatibility-test/fixtures/sonarqube-dce/mcp-tls-values.yaml"},{"key":"SonarSource_sonar-iac:iac-extensions/kubernetes/src/common/java/org/sonar/iac/kubernetes/checks/HardcodedSecretsCheck.java","enabled":true,"qualifier":"FIL","name":"HardcodedSecretsCheck.java","longName":"iac-extensions/kubernetes/src/common/java/org/sonar/iac/kubernetes/checks/HardcodedSecretsCheck.java","path":"iac-extensions/kubernetes/src/common/java/org/sonar/iac/kubernetes/checks/HardcodedSecretsCheck.java"},{"key":"SonarSource_sonar-iac:iac-extensions/terraform/src/main/java/org/sonar/iac/terraform/tree/impl/SeparatedTreesImpl.java","enabled":true,"qualifier":"FIL","name":"SeparatedTreesImpl.java","longName":"iac-extensions/terraform/src/main/java/org/sonar/iac/terraform/tree/impl/SeparatedTreesImpl.java","path":"iac-extensions/terraform/src/main/java/org/sonar/iac/terraform/tree/impl/SeparatedTreesImpl.java"},{"key":"org.sonarsource.python:python:python-frontend/src/main/java/org/sonar/python/index/AmbiguousDescriptor.java","enabled":true,"qualifier":"FIL","name":"AmbiguousDescriptor.java","longName":"python-frontend/src/main/java/org/sonar/python/index/AmbiguousDescriptor.java","path":"python-frontend/src/main/java/org/sonar/python/index/AmbiguousDescriptor.java"},{"key":"sonarqube:server/sonar-server-common/src/main/java/org/sonar/server/issue/index/IssueIteratorForSingleChunk.java","enabled":true,"qualifier":"FIL","name":"IssueIteratorForSingleChunk.java","longName":"server/sonar-server-common/src/main/java/org/sonar/server/issue/index/IssueIteratorForSingleChunk.java","path":"server/sonar-server-common/src/main/java/org/sonar/server/issue/index/IssueIteratorForSingleChunk.java"},{"key":"SonarSource_sonarqube-mcp-server","enabled":true,"qualifier":"TRK","name":"SonarQube MCP Server","longName":"SonarQube MCP Server"},{"key":"org.sonarsource.php:php","enabled":true,"qualifier":"TRK","name":"SonarPHP","longName":"SonarPHP"},{"key":"org.sonarsource.javascript:javascript","enabled":true,"qualifier":"TRK","name":"SonarJS","longName":"SonarJS"},{"key":"SonarSource_sonar-go:sonar-go-commons/src/main/java/org/sonar/go/converter/DefaultCommand.java","enabled":true,"qualifier":"FIL","name":"DefaultCommand.java","longName":"sonar-go-commons/src/main/java/org/sonar/go/converter/DefaultCommand.java","path":"sonar-go-commons/src/main/java/org/sonar/go/converter/DefaultCommand.java"},{"key":"org.sonarsource.sonarlint.core:sonarlint-core-parent:test-utils/src/main/java/org/sonarsource/sonarlint/core/test/utils/SonarLintTestRpcServer.java","enabled":true,"qualifier":"FIL","name":"SonarLintTestRpcServer.java","longName":"test-utils/src/main/java/org/sonarsource/sonarlint/core/test/utils/SonarLintTestRpcServer.java","path":"test-utils/src/main/java/org/sonarsource/sonarlint/core/test/utils/SonarLintTestRpcServer.java"},{"key":"rspec-tools","enabled":true,"qualifier":"TRK","name":"rspec-tools","longName":"rspec-tools"},{"key":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/sonar-web-context-values.yaml","enabled":true,"qualifier":"FIL","name":"sonar-web-context-values.yaml","longName":"tests/unit-compatibility-test/fixtures/sonarqube/sonar-web-context-values.yaml","path":"tests/unit-compatibility-test/fixtures/sonarqube/sonar-web-context-values.yaml"},{"key":"SonarSource_sonar-go:build.gradle.kts","enabled":true,"qualifier":"FIL","name":"build.gradle.kts","longName":"build.gradle.kts","path":"build.gradle.kts"},{"key":"sonarqube:server/sonar-webserver-auth/src/main/java/org/sonar/server/user/SecurityRealmFactory.java","enabled":true,"qualifier":"FIL","name":"SecurityRealmFactory.java","longName":"server/sonar-webserver-auth/src/main/java/org/sonar/server/user/SecurityRealmFactory.java","path":"server/sonar-webserver-auth/src/main/java/org/sonar/server/user/SecurityRealmFactory.java"},{"key":"SonarSource_sonar-iac:build.gradle.kts","enabled":true,"qualifier":"FIL","name":"build.gradle.kts","longName":"build.gradle.kts","path":"build.gradle.kts"},{"key":"SonarSource_sonar-text:sonar-text-plugin/src/main/java/org/sonar/plugins/common/Check.java","enabled":true,"qualifier":"FIL","name":"Check.java","longName":"sonar-text-plugin/src/main/java/org/sonar/plugins/common/Check.java","path":"sonar-text-plugin/src/main/java/org/sonar/plugins/common/Check.java"},{"key":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube/change-admin-password-hook-values.yaml","enabled":true,"qualifier":"FIL","name":"change-admin-password-hook-values.yaml","longName":"tests/unit-compatibility-test/fixtures/sonarqube/change-admin-password-hook-values.yaml","path":"tests/unit-compatibility-test/fixtures/sonarqube/change-admin-password-hook-values.yaml"},{"key":"SonarSource_helm-chart-sonarqube:tests/unit-compatibility-test/fixtures/sonarqube-dce/secret-values.yaml","enabled":true,"qualifier":"FIL","name":"secret-values.yaml","longName":"tests/unit-compatibility-test/fixtures/sonarqube-dce/secret-values.yaml","path":"tests/unit-compatibility-test/fixtures/sonarqube-dce/secret-values.yaml"},{"key":"SonarSource_sonarqube-mcp-server:src/main/java/org/sonarsource/sonarqube/mcp/client/McpClientManager.java","enabled":true,"qualifier":"FIL","name":"McpClientManager.java","longName":"src/main/java/org/sonarsource/sonarqube/mcp/client/McpClientManager.java","path":"src/main/java/org/sonarsource/sonarqube/mcp/client/McpClientManager.java"},{"key":"SonarSource_echoes-react:stories/filters/filter-dropdown-helpers.tsx","enabled":true,"qualifier":"FIL","name":"filter-dropdown-helpers.tsx","longName":"stories/filters/filter-dropdown-helpers.tsx","path":"stories/filters/filter-dropdown-helpers.tsx"}],"facets":[]}