HIGH
MINED115
[MINED115] Action `dotnet/arcade/.github/workflows/scheduled-action-cleanup-base.yml` pin…
.github/workflows/backport.yml:26
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.B…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.M…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.A…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting/G…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.G…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.A…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.G…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.S…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.J…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.O…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.A…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.A…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.A…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.A…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.A…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.R…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.A…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.V…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.K…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.R…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.K…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.P…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.A…:6
HIGH
MINED128
[MINED128] go.mod replaces `apphost/modules/aspire` — points to a LOCAL path: `replace ap…
tests/PolyglotAppHosts/Aspire.Hosting.M…:6
HIGH
MINED130
[MINED130] Lockfile pulls package from off-canonical host `pkgs.dev.azure.com`: `package-…
playground/TypeScriptApps/RpsArena/node…:1
HIGH
MINED130
[MINED130] Lockfile pulls package from off-canonical host `pkgs.dev.azure.com`: `package-…
playground/TypeScriptApps/AzureFunction…:1
HIGH
MINED130
[MINED130] Lockfile pulls package from off-canonical host `pkgs.dev.azure.com`: `package-…
playground/PostgresEndToEnd/PostgresEnd…:1
HIGH
MINED118
[MINED118] Dockerfile FROM `mcr.microsoft.com/oss/go/microsoft/golang (no tag)` not pinne…
playground/publishers/Publishers.AppHos…:3
HIGH
MINED118
[MINED118] Dockerfile FROM `netaspireci.azurecr.io/library/python:3.8-slim` not pinned by…
playground/AzureContainerApps/AzureCont…:2
HIGH
MINED118
[MINED118] Dockerfile FROM `mcr.microsoft.com/dotnet/nightly/yarp:2.3-preview` not pinned…
playground/yarp/Yarp.AppHost/static-gat…:1
HIGH
MINED118
[MINED118] Dockerfile FROM `mcr.microsoft.com/dotnet/runtime:9.0` not pinned by digest: `…
playground/pipelines/Pipelines.AppHost/…:1
HIGH
MINED118
[MINED118] Dockerfile FROM `node:22-alpine` not pinned by digest: `FROM node:22-alpine` r…
playground/AspireWithJavaScript/AspireJ…:8
HIGH
MINED118
[MINED118] Dockerfile FROM `node:22-alpine` not pinned by digest: `FROM node:22-alpine` r…
playground/AspireWithJavaScript/AspireJ…:2
HIGH
MINED118
[MINED118] Dockerfile FROM `node:22-slim` not pinned by digest: `FROM node:22-slim` resol…
playground/AspireWithJavaScript/AspireJ…:2
HIGH
MINED130
[MINED130] Lockfile pulls package from off-canonical host `pkgs.dev.azure.com`: `package-…
playground/AspireWithJavaScript/AspireJ…:1
HIGH
MINED118
[MINED118] Dockerfile FROM `nginx:alpine` not pinned by digest: `FROM nginx:alpine` resol…
playground/AspireWithJavaScript/AspireJ…:14
HIGH
MINED118
[MINED118] Dockerfile FROM `node:20` not pinned by digest: `FROM node:20` resolves the ta…
playground/AspireWithJavaScript/AspireJ…:2
HIGH
MINED118
[MINED118] Dockerfile FROM `nginx:alpine` not pinned by digest: `FROM nginx:alpine` resol…
playground/AspireWithJavaScript/AspireJ…:14
HIGH
MINED118
[MINED118] Dockerfile FROM `node:20` not pinned by digest: `FROM node:20` resolves the ta…
playground/AspireWithJavaScript/AspireJ…:2
HIGH
MINED130
[MINED130] Lockfile pulls package from off-canonical host `pkgs.dev.azure.com`: `package-…
playground/AspireWithJavaScript/AspireJ…:1
HIGH
MINED118
[MINED118] Dockerfile FROM `nginx:alpine` not pinned by digest: `FROM nginx:alpine` resol…
playground/AspireWithJavaScript/AspireJ…:14
HIGH
MINED118
[MINED118] Dockerfile FROM `node:20` not pinned by digest: `FROM node:20` resolves the ta…
playground/AspireWithJavaScript/AspireJ…:2
HIGH
MINED118
[MINED118] Dockerfile FROM `mcr.microsoft.com/cbl-mariner/base/core:2.0.20260311` not pin…
playground/withdockerfile/WithDockerfil…:9
HIGH
MINED118
[MINED118] Dockerfile FROM `mcr.microsoft.com/oss/go/microsoft/golang (no tag)` not pinne…
playground/withdockerfile/WithDockerfil…:3
HIGH
MINED118
[MINED118] Dockerfile FROM `mcr.microsoft.com/cbl-mariner/base/core:2.0` not pinned by di…
playground/withdockerfile/WithDockerfil…:5
HIGH
MINED118
[MINED118] Dockerfile FROM `mcr.microsoft.com/oss/go/microsoft/golang:1.23` not pinned by…
playground/withdockerfile/WithDockerfil…:1
HIGH
MINED118
[MINED118] Dockerfile FROM `mcr.microsoft.com/cbl-mariner/base/core:2.0` not pinned by di…
playground/withdockerfile/WithDockerfil…:6
HIGH
MINED118
[MINED118] Dockerfile FROM `mcr.microsoft.com/oss/go/microsoft/golang:1.23` not pinned by…
playground/withdockerfile/WithDockerfil…:1
HIGH
MINED118
[MINED118] Dockerfile FROM `netaspireci.azurecr.io/library/redis:8.6` not pinned by diges…
playground/withdockerfile/WithDockerfil…:1
HIGH
MINED118
[MINED118] Dockerfile FROM `netaspireci.azurecr.io/library/redis:8.6` not pinned by diges…
playground/withdockerfile/WithDockerfil…:1
HIGH
MINED130
[MINED130] Lockfile pulls package from off-canonical host `pkgs.dev.azure.com`: `package-…
playground/TypeScriptAppHost/express-ap…:1
HIGH
MINED118
[MINED118] Dockerfile FROM `node:22-alpine` not pinned by digest: `FROM node:22-alpine` r…
playground/AspireWithNode/AspireWithNod…:14
HIGH
MINED118
[MINED118] Dockerfile FROM `node:22-slim` not pinned by digest: `FROM node:22-slim` resol…
playground/AspireWithNode/AspireWithNod…:8
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
eng/common/cross/install-debs.py:92
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
playground/deployers/Deployers.Dockerfi…:81
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
playground/FoundryAgents/app/main.py:45
MED
MINED111
[MINED111] Bare except continues silently: Bare `except:` (or `except Exception:`) that r…
playground/FoundryAgentBasic/app/main.py:49
MED
SEC136
[SEC136] AI-typical over-broad exception handler swallowing all errors: Catch-all excepti…
src/Aspire.Cli/Projects/AppHostRpcClien…:161
MED
SEC136
[SEC136] AI-typical over-broad exception handler swallowing all errors: Catch-all excepti…
src/Aspire.Cli/Commands/AppHostFollowDi…:41
MED
SEC123
[SEC123] Production stack trace / debug output exposed: Debug mode left on in production …
playground/python/flask_app/app.py:40
MED
SEC068
[SEC068] Dockerfile: base image uses :latest or no tag: FROM uses :latest or no tag — bui…
playground/deployers/Deployers.Dockerfi…:1
MED
ERR002
[ERR002] Empty Catch Block: Empty catch blocks hide errors.
playground/aspireify-eval/polyglot/fron…:15
MED
SEC091
[SEC091] Go: net/http server without timeouts: HTTP server without ReadHeaderTimeout/Read…
src/Aspire.Cli/Templating/Templates/go-…:65
MED
SEC091
[SEC091] Go: net/http server without timeouts: HTTP server without ReadHeaderTimeout/Read…
playground/aspireify-eval/polyglot/api-…:46
MED
SEC091
[SEC091] Go: net/http server without timeouts: HTTP server without ReadHeaderTimeout/Read…
playground/GoDebugging/api/main.go:37
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
extension/src/editor/parsers/csharpAppH…:140
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
extension/scripts/prepareCorepackYarn.m…:38
MED
SEC045
[SEC045] eval()/exec() on stored or user-supplied data: eval() and exec() on data — even …
.github/workflows/create-failing-test-i…:2
MED
DKR003
Compose service `env-dashboard` image uses the latest tag
playground/publishers/aspire-output/doc…:1
MED
AUC001
[AUC001] No Repobility access matrix policy found: The repository uses web/API frameworks…
—
MED
MINED124
[MINED124] requirements.txt: `opentelemetry-distro[otlp]` has no version pin: Unpinned pi…
playground/python/instrumented_script/r…:1
MED
DKR002
Dockerfile base image has no explicit tag
tests/Shared/Docker/Dockerfile.e2e-poly…:4
MED
DKC015
Database service has no healthcheck
playground/publishers/aspire-output/doc…:57
MED
DKC015
Database service has no healthcheck
playground/publishers/aspire-output/doc…:9
MED
DKC015
Database service has no healthcheck
playground/publishers/Publishers.AppHos…:45
MED
DKC015
Database service has no healthcheck
playground/publishers/Publishers.AppHos…:1
MED
DKR018
Database dump or local database file is included in Docker build context
.dockerignore
MED
DKR001
Docker final stage has no non-root USER
tests/Shared/Docker/Dockerfile.e2e-poly…:4
MED
DKR001
Docker final stage has no non-root USER
tests/Shared/Docker/Dockerfile.e2e-poly…:52
MED
DKR001
Docker final stage has no non-root USER
tests/Shared/Docker/Dockerfile.e2e-podm…:5
MED
DKR001
Docker final stage has no non-root USER
tests/Shared/Docker/Dockerfile.e2e:51
MED
DKR001
Docker final stage has no non-root USER
playground/withdockerfile/WithDockerfil…:9
MED
DKR001
Docker final stage has no non-root USER
playground/publishers/Publishers.AppHos…:9
MED
DKR001
Docker final stage has no non-root USER
playground/pipelines/Pipelines.AppHost/…:1
MED
DKR001
Docker final stage has no non-root USER
playground/deployers/Deployers.Dockerfi…:2
MED
DKR001
Docker final stage has no non-root USER
playground/PostgresEndToEnd/PostgresEnd…:23
MED
DKR001
Docker final stage has no non-root USER
playground/AzureFunctionsEndToEnd/Azure…:10
MED
DKR001
Docker final stage has no non-root USER
playground/AzureContainerApps/AzureCont…:2
MED
DKR001
Docker final stage has no non-root USER
playground/AspireWithJavaScript/AspireJ…:15
MED
DKR001
Docker final stage has no non-root USER
playground/AspireWithJavaScript/AspireJ…:15
MED
DKR001
Docker final stage has no non-root USER
playground/AspireWithJavaScript/AspireJ…:15
MED
DKR001
Docker final stage has no non-root USER
eng/scripts/aspire-pr-container/Dockerf…:1
MED
DKR001
Docker final stage has no non-root USER
.github/workflows/polyglot-validation/D…:14
MED
DKR001
Docker final stage has no non-root USER
.github/workflows/polyglot-validation/D…:13
MED
DKR001
Docker final stage has no non-root USER
.github/workflows/polyglot-validation/D…:13
MED
DKR001
Docker final stage has no non-root USER
.github/workflows/polyglot-validation/D…:13
MED
DKR001
Docker final stage has no non-root USER
.github/workflows/polyglot-validation/D…:13
MED
DKR001
Docker final stage has no non-root USER
.devcontainer/Dockerfile:1
MED
DKR014
Dockerfile copies broad context with incomplete .dockerignore
tests/Shared/Docker/Dockerfile.e2e-poly…:38
MED
DKR014
Dockerfile copies broad context with incomplete .dockerignore
tests/Shared/Docker/Dockerfile.e2e:37
MED
DKR014
Dockerfile copies broad context with incomplete .dockerignore
playground/withdockerfile/WithDockerfil…:5
MED
DKR014
Dockerfile copies broad context with incomplete .dockerignore
playground/publishers/Publishers.AppHos…:5
MED
DKR014
Dockerfile copies broad context with incomplete .dockerignore
playground/deployers/Deployers.Dockerfi…:36
MED
DKR014
Dockerfile copies broad context with incomplete .dockerignore
playground/AzureFunctionsEndToEnd/Azure…:3
MED
DKR014
Dockerfile copies broad context with incomplete .dockerignore
playground/AzureContainerApps/AzureCont…:8
MED
DKR014
Dockerfile copies broad context with incomplete .dockerignore
playground/AspireWithJavaScript/AspireJ…:11
MED
DKR014
Dockerfile copies broad context with incomplete .dockerignore
playground/AspireWithJavaScript/AspireJ…:11
MED
DKR014
Dockerfile copies broad context with incomplete .dockerignore
playground/AspireWithJavaScript/AspireJ…:11
MED
AGT015
Remote install command pipes network code directly to a shell
docs/using-latest-daily.md:22
MED
AGT015
Remote install command pipes network code directly to a shell
README.md:78
MED
AGT015
Remote install command pipes network code directly to a shell
.github/workflows/dogfood-comment.yml:45
LOW
CFG003
[CFG003] Docker COPY Everything: Copying entire directory may include secrets and build a…
playground/withdockerfile/WithDockerfil…:27
LOW
SEC075
[SEC075] Dockerfile: no HEALTHCHECK: No HEALTHCHECK directive — orchestrators can't detec…
playground/withdockerfile/WithDockerfil…:1
LOW
SEC075
[SEC075] Dockerfile: no HEALTHCHECK: No HEALTHCHECK directive — orchestrators can't detec…
playground/deployers/Deployers.Dockerfi…:1
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
src/Aspire.Cli/Templating/Templates/go-…:100
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
src/Aspire.Cli/Templating/Templates/go-…:46
LOW
ERR003
[ERR003] Ignored Error (Go): Ignoring error return values.
playground/GoDebugging/api/main.go:56
LOW
COMP001
[COMP001] High cognitive complexity: Function `create` has cognitive complexity 11 (Sonar…
src/Aspire.Hosting.CodeGeneration.Pytho…:42
LOW
COMP001
[COMP001] High cognitive complexity: Function `weather_forecast` has cognitive complexity…
playground/PythonAppHost/app/main.py:57
LOW
AIC003
Duplicated implementation block across source files
playground/PythonAppHost/app/telemetry.…:9
LOW
AIC003
Duplicated implementation block across source files
playground/PythonAppHost/app/main.py:59
LOW
AIC003
Duplicated implementation block across source files
playground/PythonAppHost/app/main.py:57
LOW
AIC003
Duplicated implementation block across source files
playground/Playground.ServiceDefaults/E…:22
LOW
AIC003
Duplicated implementation block across source files
playground/Playground.ServiceDefaults/E…:12
LOW
AIC003
Duplicated implementation block across source files
playground/OpenAIEndToEnd/OpenAIEndToEn…:5
LOW
AIC003
Duplicated implementation block across source files
playground/JavaAppHost/frontend/src/App…:42
LOW
AIC003
Duplicated implementation block across source files
playground/JavaAppHost/frontend/eslint.…:13
LOW
AIC003
Duplicated implementation block across source files
playground/GitHubModelsEndToEnd/GitHubM…:8
LOW
AIC003
Duplicated implementation block across source files
playground/FoundryEndToEnd/FoundryEndTo…:5
LOW
AIC003
Duplicated implementation block across source files
playground/FoundryAgents/app/main.py:16
LOW
AIC003
Duplicated implementation block across source files
playground/FileBasedApps/FileBasedApps.…:4
LOW
AIC003
Duplicated implementation block across source files
playground/FileBasedApps/FileBasedApps.…:2
LOW
AIC003
Duplicated implementation block across source files
playground/DevTunnels/DevTunnels.WebFro…:4
LOW
AIC003
Duplicated implementation block across source files
playground/CertManagerDemo/CertManagerD…:23
LOW
AIC003
Duplicated implementation block across source files
playground/BlazorStandalone/BlazorStand…:13
LOW
AIC003
Duplicated implementation block across source files
playground/BlazorStandalone/BlazorStand…:11
LOW
AIC003
Duplicated implementation block across source files
playground/BlazorStandalone/BlazorStand…:10
LOW
AIC003
Duplicated implementation block across source files
playground/BlazorStandalone/BlazorStand…:1
LOW
AIC003
Duplicated implementation block across source files
playground/BlazorStandalone/BlazorStand…:1
LOW
AIC003
Duplicated implementation block across source files
playground/BlazorStandalone/BlazorStand…:3
LOW
AIC003
Duplicated implementation block across source files
playground/BlazorStandalone/BlazorStand…:9
LOW
AIC003
Duplicated implementation block across source files
playground/BlazorStandalone/BlazorStand…:1
LOW
AIC003
Duplicated implementation block across source files
playground/BlazorHosted/BlazorHosted.We…:11
LOW
AIC003
Duplicated implementation block across source files
playground/BlazorHosted/BlazorHosted.We…:1
LOW
AIC003
Duplicated implementation block across source files
playground/AzureContainerApps/AzureCont…:23
LOW
AIC003
Duplicated implementation block across source files
playground/AspireWithNode/AspireWithNod…:5
LOW
AIC003
Duplicated implementation block across source files
playground/AspireWithMaui/AspireWithMau…:27
LOW
AIC003
Duplicated implementation block across source files
playground/AspireWithMaui/AspireWithMau…:24
LOW
AIC003
Duplicated implementation block across source files
playground/AspireWithJavaScript/AspireJ…:6
LOW
DKR011
Dockerfile installs recommended OS packages
playground/PostgresEndToEnd/PostgresEnd…:5
LOW
DKR011
Dockerfile installs recommended OS packages
.github/workflows/polyglot-validation/D…:22
LOW
DKR011
Dockerfile installs recommended OS packages
.github/workflows/polyglot-validation/D…:19
LOW
DKR011
Dockerfile installs recommended OS packages
.github/workflows/polyglot-validation/D…:19
LOW
DKR011
Dockerfile installs recommended OS packages
.github/workflows/polyglot-validation/D…:19
LOW
DKR011
Dockerfile installs recommended OS packages
.github/workflows/polyglot-validation/D…:16
LOW
DKR008
.dockerignore misses sensitive defaults
.dockerignore
LOW
DKC016
App service does not wait for database health
playground/publishers/aspire-output/doc…:37
LOW
DKC016
App service does not wait for database health
playground/publishers/aspire-output/doc…:20
LOW
DKC016
App service does not wait for database health
playground/publishers/Publishers.AppHos…:27
LOW
DKC016
App service does not wait for database health
playground/publishers/Publishers.AppHos…:12
LOW
DKC010
Compose service lacks no-new-privileges hardening
playground/publishers/aspire-output/doc…:71
LOW
DKC010
Compose service lacks no-new-privileges hardening
playground/publishers/aspire-output/doc…:57
LOW
DKC010
Compose service lacks no-new-privileges hardening
playground/publishers/aspire-output/doc…:37
LOW
DKC010
Compose service lacks no-new-privileges hardening
playground/publishers/aspire-output/doc…:20
LOW
DKC010
Compose service lacks no-new-privileges hardening
playground/publishers/aspire-output/doc…:1
LOW
DKC010
Compose service lacks no-new-privileges hardening
playground/publishers/Publishers.AppHos…:59
LOW
DKC010
Compose service lacks no-new-privileges hardening
playground/publishers/Publishers.AppHos…:45
LOW
DKC010
Compose service lacks no-new-privileges hardening
playground/publishers/Publishers.AppHos…:27
LOW
DKC010
Compose service lacks no-new-privileges hardening
playground/publishers/Publishers.AppHos…:12
LOW
DKC017
Database password is wired through an environment variable placeholder
playground/publishers/aspire-output/doc…:9
LOW
DKC017
Database password is wired through an environment variable placeholder
playground/publishers/Publishers.AppHos…:1
LOW
DKC006
Compose service does not declare a runtime user
playground/publishers/aspire-output/doc…:37
LOW
DKC006
Compose service does not declare a runtime user
playground/publishers/Publishers.AppHos…:59
LOW
DKC006
Compose service does not declare a runtime user
playground/publishers/Publishers.AppHos…:45
LOW
DKC006
Compose service does not declare a runtime user
playground/publishers/Publishers.AppHos…:27
LOW
DKC006
Compose service does not declare a runtime user
playground/publishers/Publishers.AppHos…:12
INFO
MINED050
[MINED050] Stub Only Function: Function declared but body is just pass, return None, rais…
src/Aspire.Hosting.CodeGeneration.Pytho…:99
INFO
MINED069
[MINED069] Debug True Prod: Django/Flask DEBUG=True or app.debug=True in non-test files.
playground/python/flask_app/app.py:40
INFO
MINED051
[MINED051] Csharp Null Forgive: x! tells compiler "definitely not null" — bypasses nullab…
src/Aspire.Cli/Commands/DoctorCommand.cs:191
INFO
MINED051
[MINED051] Csharp Null Forgive: x! tells compiler "definitely not null" — bypasses nullab…
src/Aspire.Cli/Backchannel/AppHostConne…:75
INFO
MINED051
[MINED051] Csharp Null Forgive: x! tells compiler "definitely not null" — bypasses nullab…
playground/kafka/Consumer/ConsumerWorke…:36
INFO
MINED060
[MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g…
src/Aspire.Cli/Templating/Templates/go-…:35
INFO
MINED060
[MINED060] Go Context No Cancel: context.Background() at request handler boundary leaks g…
playground/GoDebugging/api/main.go:50
INFO
MINED056
[MINED056] React Key As Index: key={index} in map() — re-renders the wrong elements on re…
playground/PythonAppHost/frontend/src/A…:133
INFO
MINED056
[MINED056] React Key As Index: key={index} in map() — re-renders the wrong elements on re…
playground/JavaAppHost/frontend/src/App…:133
INFO
MINED056
[MINED056] React Key As Index: key={index} in map() — re-renders the wrong elements on re…
playground/FoundryAgentEnterprise/front…:133
INFO
MINED054
[MINED054] Ts As Any: Casting to any (as any) bypasses type checking entirely.
extension/src/server/AspireRpcServer.ts:66
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
extension/src/server/progressNotifier.ts:77
INFO
MINED045
[MINED045] Ts Non Null Assertion: x! asserts not null - bypasses null checks - TypeError …
extension/src/editor/AspireGutterDecora…:215
INFO
MINED052
[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety.
extension/src/server/progressNotifier.ts:98
INFO
MINED052
[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety.
extension/src/dcp/types.ts:28
INFO
MINED052
[MINED052] Ts Any Typed: : any used as type annotation. Defeats TypeScript type safety.
extension/src/commands/configureLaunchJ…:29
INFO
MINED055
[MINED055] Npm Install No Lockfile: Production image runs npm install (resolves new versi…
extension/build.sh:98
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
extension/scripts/generate-schema.js:21
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
extension/gulpfile.js:42
INFO
MINED044
[MINED044] Js Console Log Prod: console.log left in code. Should be replaced with logger …
extension/.mocharc.e2e.js:35
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
playground/AzureFunctionsEndToEnd/Azure…:85
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
playground/AspireWithBun/BunFrontend/se…:18
INFO
MINED043
[MINED043] Http Not Https: Hardcoded http:// (not localhost) for endpoints that handle cr…
eng/common/cross/tizen-fetch.sh:56