{
  "$schema": "https://docs.oasis-open.org/sarif/sarif/v2.1.0/os/schemas/sarif-schema-2.1.0.json",
  "runs": [
    {
      "automationDetails": {
        "id": "45fc7c79-225a-4c49-a5d0-2d456346a5f5"
      },
      "properties": {
        "codexSecuritySchemaVersion": "1.0",
        "codexSecurityTargetKind": "git_revision"
      },
      "results": [
        {
          "level": "error",
          "locations": [
            {
              "message": {
                "text": "root_control"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/service/user/UserHealthKit.php"
                },
                "region": {
                  "endLine": 76,
                  "startLine": 60
                }
              }
            },
            {
              "message": {
                "text": "entrypoint"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "route/app.php"
                },
                "region": {
                  "endLine": 79,
                  "startLine": 79
                }
              }
            },
            {
              "message": {
                "text": "entrypoint/wrapper"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/controller/Healthkit.php"
                },
                "region": {
                  "endLine": 91,
                  "startLine": 68
                }
              }
            }
          ],
          "message": {
            "text": "Huawei HealthKit access and refresh credentials are written to application logs."
          },
          "partialFingerprints": {
            "codexSecurity/v1": "codex-security/v1:sha256:9499dae80a16fba0a6a34689b45b0e9d0e2924a6682f10d390128455fd9b6726"
          },
          "properties": {
            "candidateId": "candidate-d5aca248fb7ca848",
            "category": "Sensitive information in logs",
            "confidence": "high",
            "findingId": "csf_12f2a3bc6118b9a767dd9866",
            "occurrenceId": "occ_101bf9a10ed798d9f3aef0cf",
            "severity": "high"
          },
          "ruleId": "secret-exposure.oauth-token-logging",
          "ruleIndex": 11
        },
        {
          "level": "error",
          "locations": [
            {
              "message": {
                "text": "root_control"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/controller/BaiduFaceOffline.php"
                },
                "region": {
                  "endLine": 133,
                  "startLine": 126
                }
              }
            },
            {
              "message": {
                "text": "entrypoint"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "route/app.php"
                },
                "region": {
                  "endLine": 99,
                  "startLine": 86
                }
              }
            },
            {
              "message": {
                "text": "root_control"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "config/baidu_face.php"
                },
                "region": {
                  "endLine": 7,
                  "startLine": 7
                }
              }
            },
            {
              "message": {
                "text": "sink"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/controller/BaiduFaceOffline.php"
                },
                "region": {
                  "endLine": 114,
                  "startLine": 93
                }
              }
            },
            {
              "message": {
                "text": "concrete_implementation"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/service/BaiduFaceOfflineService.php"
                },
                "region": {
                  "endLine": 83,
                  "startLine": 21
                }
              }
            }
          ],
          "message": {
            "text": "The Baidu face API permits every caller when its IP allowlist is absent or empty."
          },
          "partialFingerprints": {
            "codexSecurity/v1": "codex-security/v1:sha256:00abcc4b81fb8ac5a5b422f875315b5ce81caa0b33f22cec1a5a79b25fc423ea"
          },
          "properties": {
            "candidateId": "candidate-6e0e1345ea493eb6",
            "category": "Access-control fail-open",
            "confidence": "high",
            "findingId": "csf_56c76a090077e2b64d2ea558",
            "occurrenceId": "occ_389b6aa8655d97e7e36813a2",
            "severity": "high"
          },
          "ruleId": "access-control.fail-open-allowlist",
          "ruleIndex": 0
        },
        {
          "level": "error",
          "locations": [
            {
              "message": {
                "text": "root_control"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/terminal/controller/Controller.php"
                },
                "region": {
                  "endLine": 116,
                  "startLine": 110
                }
              }
            },
            {
              "message": {
                "text": "entrypoint"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/terminal/controller/Controller.php"
                },
                "region": {
                  "endLine": 92,
                  "startLine": 74
                }
              }
            },
            {
              "message": {
                "text": "sink"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/terminal/controller/order/Refund.php"
                },
                "region": {
                  "endLine": 77,
                  "startLine": 53
                }
              }
            },
            {
              "message": {
                "text": "sink"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/terminal/controller/store/User.php"
                },
                "region": {
                  "endLine": 109,
                  "startLine": 71
                }
              }
            }
          ],
          "message": {
            "text": "Terminal role and API privilege enforcement is entirely commented out."
          },
          "partialFingerprints": {
            "codexSecurity/v1": "codex-security/v1:sha256:174ad839c65ca22c05483547cb8694659eb07a1cd89cb39b2dd98e95b060e0db"
          },
          "properties": {
            "candidateId": "candidate-5a8c091052c7bc27",
            "category": "Missing function-level authorization",
            "confidence": "high",
            "findingId": "csf_854ff8ffd6d76a8354a5b54a",
            "occurrenceId": "occ_60ff0b14aed91f05320376cb",
            "severity": "high"
          },
          "ruleId": "authorization.terminal-role-check",
          "ruleIndex": 4
        },
        {
          "level": "error",
          "locations": [
            {
              "message": {
                "text": "root_control"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": ".env.dev"
                },
                "region": {
                  "endLine": 1,
                  "startLine": 1
                }
              }
            },
            {
              "message": {
                "text": "root_control"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": ".env.prod"
                },
                "region": {
                  "endLine": 1,
                  "startLine": 1
                }
              }
            },
            {
              "message": {
                "text": "sink"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "db/aizhct_jx206.sql"
                },
                "region": {
                  "endLine": 50822,
                  "startLine": 50822
                }
              }
            },
            {
              "message": {
                "text": "evidence"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": ".env.prodaizhct_cqhw"
                },
                "region": {
                  "endLine": 1,
                  "startLine": 1
                }
              }
            },
            {
              "message": {
                "text": "evidence"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": ".env.prodaizhct_rdfz"
                },
                "region": {
                  "endLine": 1,
                  "startLine": 1
                }
              }
            },
            {
              "message": {
                "text": "evidence"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": ".env.prodaizhct_sanquan"
                },
                "region": {
                  "endLine": 1,
                  "startLine": 1
                }
              }
            }
          ],
          "message": {
            "text": "Tracked environment files and a database dump contain non-placeholder credential assignments."
          },
          "partialFingerprints": {
            "codexSecurity/v1": "codex-security/v1:sha256:5e08d43dc87225b67d092dd6dd23f48ad0e66372fd3b7c4f94022da8f9b6f009"
          },
          "properties": {
            "candidateId": "candidate-1fe163facac3c106",
            "category": "Hardcoded credentials",
            "confidence": "high",
            "findingId": "csf_37a78fc3c444c7454dafd658",
            "occurrenceId": "occ_6bc686f289a3366647c3ff46",
            "severity": "high"
          },
          "ruleId": "hardcoded-credentials.repository-artifacts",
          "ruleIndex": 7
        },
        {
          "level": "error",
          "locations": [
            {
              "message": {
                "text": "root_control"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/controller/Bank.php"
                },
                "region": {
                  "endLine": 15,
                  "startLine": 15
                }
              }
            },
            {
              "message": {
                "text": "entrypoint"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "route/app.php"
                },
                "region": {
                  "endLine": 29,
                  "startLine": 29
                }
              }
            },
            {
              "message": {
                "text": "source"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/controller/Bank.php"
                },
                "region": {
                  "endLine": 166,
                  "startLine": 149
                }
              }
            },
            {
              "message": {
                "text": "sink"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/service/Bank.php"
                },
                "region": {
                  "endLine": 299,
                  "startLine": 242
                }
              }
            }
          ],
          "message": {
            "text": "The bank identity-binding endpoint mints an application bearer token without proving control of a bank-authenticated identity."
          },
          "partialFingerprints": {
            "codexSecurity/v1": "codex-security/v1:sha256:8a70a36e73987b8e3bedfed1ea35a9b25bd07f3b138b7c52b7a92ca9170ece5b"
          },
          "properties": {
            "candidateId": "candidate-ca286d3dc96d8443",
            "category": "Authentication bypass",
            "confidence": "high",
            "findingId": "csf_a1eaedb819f3a94747cafc1c",
            "occurrenceId": "occ_7b425b476f3e36e065722cb6",
            "severity": "high"
          },
          "ruleId": "authentication.bank-identity-binding",
          "ruleIndex": 1
        },
        {
          "level": "error",
          "locations": [
            {
              "message": {
                "text": "root_control"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/controller/Bank.php"
                },
                "region": {
                  "endLine": 15,
                  "startLine": 15
                }
              }
            },
            {
              "message": {
                "text": "entrypoint"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "route/app.php"
                },
                "region": {
                  "endLine": 26,
                  "startLine": 25
                }
              }
            },
            {
              "message": {
                "text": "source"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/controller/Bank.php"
                },
                "region": {
                  "endLine": 112,
                  "startLine": 81
                }
              }
            },
            {
              "message": {
                "text": "sink"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/service/Bank.php"
                },
                "region": {
                  "endLine": 195,
                  "startLine": 105
                }
              }
            }
          ],
          "message": {
            "text": "Caller-supplied bank user identifiers allow linked-user enumeration and application token issuance."
          },
          "partialFingerprints": {
            "codexSecurity/v1": "codex-security/v1:sha256:e5114fcb609f72ae4c2fbe78172b07f7444ac24c309449ba05add1e6c314bdcd"
          },
          "properties": {
            "candidateId": "candidate-240f9187df004512",
            "category": "Authorization bypass / IDOR",
            "confidence": "high",
            "findingId": "csf_8b52eea445dd701a16360395",
            "occurrenceId": "occ_7d62b823ead4c7b63b050ff3",
            "severity": "high"
          },
          "ruleId": "authorization.bank-account-switch",
          "ruleIndex": 2
        },
        {
          "level": "warning",
          "locations": [
            {
              "message": {
                "text": "root_control"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/service/PrepayOrder.php"
                },
                "region": {
                  "endLine": 69,
                  "startLine": 23
                }
              }
            },
            {
              "message": {
                "text": "entrypoint"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "route/app.php"
                },
                "region": {
                  "endLine": 147,
                  "startLine": 145
                }
              }
            },
            {
              "message": {
                "text": "entrypoint/wrapper"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/controller/PrepayOrder.php"
                },
                "region": {
                  "endLine": 17,
                  "startLine": 14
                }
              }
            },
            {
              "message": {
                "text": "sink"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/service/PrepayOrder.php"
                },
                "region": {
                  "endLine": 126,
                  "startLine": 81
                }
              }
            }
          ],
          "message": {
            "text": "Concurrent prepay scans can both create meal orders while only one links to the prepay row."
          },
          "partialFingerprints": {
            "codexSecurity/v1": "codex-security/v1:sha256:64377dd5def453376276adb752f27192010510c45a0ec2fa21b292e9b729f7b3"
          },
          "properties": {
            "candidateId": "candidate-8d7ad69adfd638b8",
            "category": "Race condition / missing idempotency",
            "confidence": "high",
            "findingId": "csf_56976f6f3a2d9b7cf84d3a28",
            "occurrenceId": "occ_95c8cd7cb1f916589b69414c",
            "severity": "medium"
          },
          "ruleId": "race-condition.prepay-order",
          "ruleIndex": 9
        },
        {
          "level": "warning",
          "locations": [
            {
              "message": {
                "text": "root_control"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/controller/Healthkit.php"
                },
                "region": {
                  "endLine": 190,
                  "startLine": 147
                }
              }
            },
            {
              "message": {
                "text": "entrypoint"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "route/app.php"
                },
                "region": {
                  "endLine": 79,
                  "startLine": 79
                }
              }
            },
            {
              "message": {
                "text": "sink"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/controller/Healthkit.php"
                },
                "region": {
                  "endLine": 91,
                  "startLine": 68
                }
              }
            },
            {
              "message": {
                "text": "concrete_implementation"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/service/user/UserHealthKit.php"
                },
                "region": {
                  "endLine": 76,
                  "startLine": 60
                }
              }
            }
          ],
          "message": {
            "text": "HealthKit OAuth state is caller-selected, unbound to a session, and not single-use."
          },
          "partialFingerprints": {
            "codexSecurity/v1": "codex-security/v1:sha256:096955932e9afd74bec9ef3d1acf4ab465d3d9c837d76d8432caf00b14f1090b"
          },
          "properties": {
            "candidateId": "candidate-c6ec4b0f980d4e56",
            "category": "OAuth login CSRF / account misbinding",
            "confidence": "medium",
            "findingId": "csf_a6374d43c6eda5040043a45f",
            "occurrenceId": "occ_9cf11255b2415e83e6765037",
            "severity": "medium"
          },
          "ruleId": "oauth.state-binding",
          "ruleIndex": 8
        },
        {
          "level": "error",
          "locations": [
            {
              "message": {
                "text": "root_control"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/controller/zhaiker/Callback.php"
                },
                "region": {
                  "endLine": 36,
                  "startLine": 12
                }
              }
            },
            {
              "message": {
                "text": "entrypoint"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "route/app.php"
                },
                "region": {
                  "endLine": 68,
                  "startLine": 68
                }
              }
            },
            {
              "message": {
                "text": "source"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/service/ZhaikerExamImporter.php"
                },
                "region": {
                  "endLine": 54,
                  "startLine": 38
                }
              }
            },
            {
              "message": {
                "text": "sink"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/service/ZhaikerExamImporter.php"
                },
                "region": {
                  "endLine": 100,
                  "startLine": 85
                }
              }
            },
            {
              "message": {
                "text": "sink"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/service/ZhaikerExamImporter.php"
                },
                "region": {
                  "endLine": 221,
                  "startLine": 211
                }
              }
            },
            {
              "message": {
                "text": "concrete_implementation"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/service/user/UserWeight.php"
                },
                "region": {
                  "endLine": 294,
                  "startLine": 163
                }
              }
            }
          ],
          "message": {
            "text": "The Zhaiker callback accepts unsigned caller-controlled health records for an arbitrary numeric user ID."
          },
          "partialFingerprints": {
            "codexSecurity/v1": "codex-security/v1:sha256:7190eb92eda8990b3bd392e5a8ca32e77257932b0a817c2906c7471ffed086d5"
          },
          "properties": {
            "candidateId": "candidate-2d26714434a20001",
            "category": "Missing callback authentication",
            "confidence": "high",
            "findingId": "csf_cfc725b1aa3de712de05af0d",
            "occurrenceId": "occ_cf4ede526278c9aa00e82058",
            "severity": "high"
          },
          "ruleId": "callback-authenticity.health-import",
          "ruleIndex": 5
        },
        {
          "level": "warning",
          "locations": [
            {
              "message": {
                "text": "root_control"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/controller/Upload.php"
                },
                "region": {
                  "endLine": 38,
                  "startLine": 30
                }
              }
            },
            {
              "message": {
                "text": "sink"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/service/Upload.php"
                },
                "region": {
                  "endLine": 63,
                  "startLine": 50
                }
              }
            },
            {
              "message": {
                "text": "concrete_implementation"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/common/library/storage/FileValidate.php"
                },
                "region": {
                  "endLine": 24,
                  "startLine": 17
                }
              }
            }
          ],
          "message": {
            "text": "Omitting a request flag disables login for the image-upload endpoint."
          },
          "partialFingerprints": {
            "codexSecurity/v1": "codex-security/v1:sha256:925a8c562907f61a953a08d8fd0cb9e4f6c0c8af6fe5b48a9309a2ce47d3f3bf"
          },
          "properties": {
            "candidateId": "candidate-ad924a1115f04ffe",
            "category": "Unauthenticated resource consumption",
            "confidence": "medium",
            "findingId": "csf_acb53b2eeb75f430fdb8bc91",
            "occurrenceId": "occ_dc67cebd1c27baf96d490955",
            "severity": "medium"
          },
          "ruleId": "resource-abuse.anonymous-upload",
          "ruleIndex": 10
        },
        {
          "level": "error",
          "locations": [
            {
              "message": {
                "text": "root_control"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/terminal/controller/Controller.php"
                },
                "region": {
                  "endLine": 58,
                  "startLine": 42
                }
              }
            },
            {
              "message": {
                "text": "entrypoint"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/terminal/controller/store/Face.php"
                },
                "region": {
                  "endLine": 70,
                  "startLine": 51
                }
              }
            },
            {
              "message": {
                "text": "root_control"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/terminal/controller/Controller.php"
                },
                "region": {
                  "endLine": 153,
                  "startLine": 147
                }
              }
            },
            {
              "message": {
                "text": "sink"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/terminal/service/staff/Face.php"
                },
                "region": {
                  "endLine": 180,
                  "startLine": 99
                }
              }
            }
          ],
          "message": {
            "text": "Terminal face synchronization is whitelisted from login and discloses biometric synchronization data using identifiers rather than device authentication."
          },
          "partialFingerprints": {
            "codexSecurity/v1": "codex-security/v1:sha256:229f7a744c2e5c9b7a2c24c7212fdf29ad96c620c356d00a43ba57dc19e06e82"
          },
          "properties": {
            "candidateId": "candidate-63b43fe82deb5555",
            "category": "Missing device authentication",
            "confidence": "high",
            "findingId": "csf_c4d99c0c4dad8cb2e6d96bb1",
            "occurrenceId": "occ_ed31674f4bf15780bbb8d8fe",
            "severity": "high"
          },
          "ruleId": "device-authentication.face-sync",
          "ruleIndex": 6
        },
        {
          "level": "warning",
          "locations": [
            {
              "message": {
                "text": "root_control"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/controller/Controller.php"
                },
                "region": {
                  "endLine": 43,
                  "startLine": 35
                }
              }
            },
            {
              "message": {
                "text": "source"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/controller/Refund.php"
                },
                "region": {
                  "endLine": 56,
                  "startLine": 39
                }
              }
            },
            {
              "message": {
                "text": "root_control"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/model/OrderRefund.php"
                },
                "region": {
                  "endLine": 143,
                  "startLine": 137
                }
              }
            },
            {
              "message": {
                "text": "sink"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/api/model/OrderRefund.php"
                },
                "region": {
                  "endLine": 199,
                  "startLine": 184
                }
              }
            },
            {
              "message": {
                "text": "concrete_implementation"
              },
              "physicalLocation": {
                "artifactLocation": {
                  "uri": "app/store/model/OrderRefund.php"
                },
                "region": {
                  "endLine": 160,
                  "startLine": 137
                }
              }
            }
          ],
          "message": {
            "text": "Refund application accepts a same-store order-goods identifier without binding it to the current user."
          },
          "partialFingerprints": {
            "codexSecurity/v1": "codex-security/v1:sha256:f3b91aa56ee14782605ff00ff0282a4fa940392575105d60c64eb0c6a6a2046c"
          },
          "properties": {
            "candidateId": "candidate-e589ab1543013d97",
            "category": "Authorization bypass / IDOR",
            "confidence": "high",
            "findingId": "csf_cb9b93a3db8581ef53001ebe",
            "occurrenceId": "occ_f97718ab8de37b4e13031ead",
            "severity": "medium"
          },
          "ruleId": "authorization.refund-order-object",
          "ruleIndex": 3
        }
      ],
      "tool": {
        "driver": {
          "name": "Codex Security",
          "rules": [
            {
              "id": "access-control.fail-open-allowlist",
              "name": "access-control.fail-open-allowlist",
              "properties": {
                "tags": [
                  "security"
                ]
              },
              "shortDescription": {
                "text": "access-control.fail-open-allowlist"
              }
            },
            {
              "id": "authentication.bank-identity-binding",
              "name": "authentication.bank-identity-binding",
              "properties": {
                "tags": [
                  "security"
                ]
              },
              "shortDescription": {
                "text": "authentication.bank-identity-binding"
              }
            },
            {
              "id": "authorization.bank-account-switch",
              "name": "authorization.bank-account-switch",
              "properties": {
                "tags": [
                  "security"
                ]
              },
              "shortDescription": {
                "text": "authorization.bank-account-switch"
              }
            },
            {
              "id": "authorization.refund-order-object",
              "name": "authorization.refund-order-object",
              "properties": {
                "tags": [
                  "security"
                ]
              },
              "shortDescription": {
                "text": "authorization.refund-order-object"
              }
            },
            {
              "id": "authorization.terminal-role-check",
              "name": "authorization.terminal-role-check",
              "properties": {
                "tags": [
                  "security"
                ]
              },
              "shortDescription": {
                "text": "authorization.terminal-role-check"
              }
            },
            {
              "id": "callback-authenticity.health-import",
              "name": "callback-authenticity.health-import",
              "properties": {
                "tags": [
                  "security"
                ]
              },
              "shortDescription": {
                "text": "callback-authenticity.health-import"
              }
            },
            {
              "id": "device-authentication.face-sync",
              "name": "device-authentication.face-sync",
              "properties": {
                "tags": [
                  "security"
                ]
              },
              "shortDescription": {
                "text": "device-authentication.face-sync"
              }
            },
            {
              "id": "hardcoded-credentials.repository-artifacts",
              "name": "hardcoded-credentials.repository-artifacts",
              "properties": {
                "tags": [
                  "security"
                ]
              },
              "shortDescription": {
                "text": "hardcoded-credentials.repository-artifacts"
              }
            },
            {
              "id": "oauth.state-binding",
              "name": "oauth.state-binding",
              "properties": {
                "tags": [
                  "security"
                ]
              },
              "shortDescription": {
                "text": "oauth.state-binding"
              }
            },
            {
              "id": "race-condition.prepay-order",
              "name": "race-condition.prepay-order",
              "properties": {
                "tags": [
                  "security"
                ]
              },
              "shortDescription": {
                "text": "race-condition.prepay-order"
              }
            },
            {
              "id": "resource-abuse.anonymous-upload",
              "name": "resource-abuse.anonymous-upload",
              "properties": {
                "tags": [
                  "security"
                ]
              },
              "shortDescription": {
                "text": "resource-abuse.anonymous-upload"
              }
            },
            {
              "id": "secret-exposure.oauth-token-logging",
              "name": "secret-exposure.oauth-token-logging",
              "properties": {
                "tags": [
                  "security"
                ]
              },
              "shortDescription": {
                "text": "secret-exposure.oauth-token-logging"
              }
            }
          ],
          "version": "0.1.14"
        }
      }
    }
  ],
  "version": "2.1.0"
}
