{"version": "2.1.0", "$schema": "https://json.schemastore.org/sarif-2.1.0.json", "runs": [{"tool": {"driver": {"name": "Repobility", "informationUri": "https://repobility.com", "rules": [{"id": "scanner-4f508cf92621a9f6", "name": "Stray `console.log` in TS/JS \u2014 check-roster.ts:16", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 check-roster.ts:16"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-33e34f176b3ef24f", "name": "Stray `console.log` in TS/JS \u2014 check-draft.ts:15", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 check-draft.ts:15"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ae7b772ae4f6b11b", "name": "Stray `console.log` in TS/JS \u2014 test-scoring-pipeline.ts:18", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 test-scoring-pipeline.ts:18"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8bca7eb85af20236", "name": "Stray `console.log` in TS/JS \u2014 test-picks-limit.ts:19", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 test-picks-limit.ts:19"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-96d222f2839a0447", "name": "Stray `console.log` in TS/JS \u2014 seed-test-picks.js:87", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 seed-test-picks.js:87"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cbeb40d80a56f214", "name": "Stray `console.log` in TS/JS \u2014 test-full-event.ts:46", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 test-full-event.ts:46"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-17dc3e9bde531498", "name": "Stray `console.log` in TS/JS \u2014 seed-full-league.ts:74", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 seed-full-league.ts:74"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-93cd8ec8a0d1ba58", "name": "Stray `console.log` in TS/JS \u2014 test-scenarios.ts:53", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 test-scenarios.ts:53"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9d4b15491f73d789", "name": "Stray `console.log` in TS/JS \u2014 fix-roster.ts:6", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 fix-roster.ts:6"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-58b1195719a8a7a9", "name": "Stray `console.log` in TS/JS \u2014 apps/api/scripts/debug-settle.ts:20", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/scripts/debug-settle.ts:20"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b6defb1ebbe89eca", "name": "Stray `console.log` in TS/JS \u2014 apps/api/scripts/backfill-nationality.ts:20", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/scripts/backfill-nationality.ts:20"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4a62682ff2fd8863", "name": "Stray `console.log` in TS/JS \u2014 apps/api/scripts/regenerate-matchups.ts:15", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/scripts/regenerate-matchups.ts:15"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9c6d210aefe30f43", "name": "Stray `console.log` in TS/JS \u2014 apps/api/scripts/sync-nationality.ts:6", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/scripts/sync-nationality.ts:6"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bd99f59f432cf5e9", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/index.ts:26", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/index.ts:26"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-74109fd691a829f3", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/config/redis.ts:59", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/config/redis.ts:59"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-24cff137ca71d571", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/services/scoring.service.ts:237", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/services/scoring.service.ts:237"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9a1afe35a7a652bc", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/db/migrate.ts:30", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/db/migrate.ts:30"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9994359c241df033", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/db/seeds/run.ts:13", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/db/seeds/run.ts:13"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6bdc2144b6a566fd", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/db/seeds/staking_past_events.ts:37", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/db/seeds/staking_past_events.ts:37"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dab1bec447f34311", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/db/seeds/staking_league.ts:37", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/db/seeds/staking_league.ts:37"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ab308ad0c2d1e21f", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/db/seeds/fighters.ts:110", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/db/seeds/fighters.ts:110"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-823f7444cfa21f37", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/db/seeds/champion_picks_test.ts:19", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/db/seeds/champion_picks_test.ts:19"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e3e8ad2a006076bd", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/jobs/livePoller.job.ts:98", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/jobs/livePoller.job.ts:98"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b6ecd16718b3d951", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/jobs/fighterSync.job.ts:12", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/jobs/fighterSync.job.ts:12"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bf17cc336f99cc02", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/jobs/autoSchedule.job.ts:23", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/jobs/autoSchedule.job.ts:23"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-50c353f658b82169", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/jobs/preEventPrep.job.ts:19", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/jobs/preEventPrep.job.ts:19"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f69b97609b5df4e4", "name": "Stray `console.log` in TS/JS \u2014 apps/api/src/jobs/eventSync.job.ts:25", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/jobs/eventSync.job.ts:25"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-694a8c8ec75a6de2", "name": "Stray `console.log` in TS/JS \u2014 scripts/seed-events.ts:36", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/seed-events.ts:36"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5c3338cb27f1ccb4", "name": "Stray `console.log` in TS/JS \u2014 scripts/setup-supabase.ts:47", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/setup-supabase.ts:47"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e646b31347372f85", "name": "Stray `console.log` in TS/JS \u2014 scripts/fetch-fighter-images.ts:33", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/fetch-fighter-images.ts:33"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cc66f93aea4d5113", "name": "Stray `console.log` in TS/JS \u2014 scripts/simulate-seasons.ts:274", "shortDescription": {"text": "Stray `console.log` in TS/JS \u2014 scripts/simulate-seasons.ts:274"}, "fullDescription": {"text": "Replace with the toast helper, an error boundary, or remove. `console.warn` / `console.error` are acceptable.\n\nWhy: Hygiene \u2014 easy to leak debug output.\nRule id: fq.console-leak"}, "properties": {"scanner": "scanner-primary", "layer": "frontend", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aa5acaa49eb8315b", "name": "Containers defined but no K8s/orchestration manifest found", "shortDescription": {"text": "Containers defined but no K8s/orchestration manifest found"}, "fullDescription": {"text": "Repo has Dockerfiles/compose but no Kubernetes/Nomad manifests. If the target deployment is K8s, the manifests may live in a separate ops repo."}, "properties": {"scanner": "scanner-primary", "layer": "hardware", "severity": "low", "confidence": 1.0}}, {"id": "scanner-175ec9bb54be7375", "name": "Possible secret in seed-full-league.ts", "shortDescription": {"text": "Possible secret in seed-full-league.ts"}, "fullDescription": {"text": "Detected pattern matching password_literal. Rotate the credential and move to a secret manager."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "critical", "confidence": 1.0}}, {"id": "scanner-5ab86e52e78c1fd3", "name": "Insecure pattern 'node_child_process' in scripts/setup-supabase.ts:16", "shortDescription": {"text": "Insecure pattern 'node_child_process' in scripts/setup-supabase.ts:16"}, "fullDescription": {"text": "Found a known-risky pattern (node_child_process). Review and replace if possible."}, "properties": {"scanner": "scanner-primary", "layer": "security", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-4601e3ad3bb28677", "name": "No CI/CD pipelines detected", "shortDescription": {"text": "No CI/CD pipelines detected"}, "fullDescription": {"text": "No GitHub Actions, GitLab CI, or CircleCI configs found. Without CI you can't gate deploys on tests/lints."}, "properties": {"scanner": "scanner-primary", "layer": "cicd", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b56408c8b4af8f17", "name": "Very large file: apps/mobile/app/(app)/league/[leagueId]/picks.tsx (1180 lines)", "shortDescription": {"text": "Very large file: apps/mobile/app/(app)/league/[leagueId]/picks.tsx (1180 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a00123a5a47def89", "name": "Very large file: apps/web/src/pages/LeagueHome.tsx (1661 lines)", "shortDescription": {"text": "Very large file: apps/web/src/pages/LeagueHome.tsx (1661 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-bc79f908a7b052c0", "name": "Very large file: apps/web/src/pages/Matchup.tsx (984 lines)", "shortDescription": {"text": "Very large file: apps/web/src/pages/Matchup.tsx (984 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8f14a5b155e95777", "name": "Very large file: apps/web/src/pages/StakingPicks.tsx (1160 lines)", "shortDescription": {"text": "Very large file: apps/web/src/pages/StakingPicks.tsx (1160 lines)"}, "fullDescription": {"text": "Files with >800 lines often hide complexity hotspots and discourage tests."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6893a6c8b0861585", "name": "Very low test-to-source ratio", "shortDescription": {"text": "Very low test-to-source ratio"}, "fullDescription": {"text": "6 test file(s) for 133 source file(s) (ratio 0.05). Consider adding integration or unit tests for critical paths."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-141b30a41e03817b", "name": "No license file detected", "shortDescription": {"text": "No license file detected"}, "fullDescription": {"text": "No LICENSE/COPYING/NOTICE file was found. Generated repositories often omit licensing, which blocks reuse and automated intake."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b06b8d86f24c77f9", "name": "Node manifest has dependencies but no lockfile: apps/api/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: apps/api/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d57b3f82d2270c5b", "name": "Node manifest has dependencies but no lockfile: apps/desktop/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: apps/desktop/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d0c2205560692580", "name": "Node manifest has dependencies but no lockfile: apps/mobile/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: apps/mobile/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-4a9eb7dc7c6e3880", "name": "Node manifest has dependencies but no lockfile: apps/web/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: apps/web/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2699d5f16ae11282", "name": "Node manifest has dependencies but no lockfile: packages/shared/package.json", "shortDescription": {"text": "Node manifest has dependencies but no lockfile: packages/shared/package.json"}, "fullDescription": {"text": "`package.json` declares dependencies, but no same-directory npm/pnpm/yarn/bun lockfile was found. Generated projects without lockfiles are less reproducible and harder to secure-scan precisely."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3ab5d313dda8e5f9", "name": "Debug logging residue appears in source files", "shortDescription": {"text": "Debug logging residue appears in source files"}, "fullDescription": {"text": "Found 206 console/debugger/print-style debug statements in non-test source. This is a common fast-generation residue before production cleanup."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-72b2a6250083a784", "name": "Placeholder or mock-heavy implementation detected", "shortDescription": {"text": "Placeholder or mock-heavy implementation detected"}, "fullDescription": {"text": "Found 41 placeholder/mock markers across 16 source files. This often means the repo looks complete while core flows still use generated scaffolding or fake data."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2d0c7b7ab8f8aacf", "name": "Critical user flow still appears backed by mock or placeholder data", "shortDescription": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "fullDescription": {"text": "A payment/auth/admin/order/billing-style flow contains mock, fake, TODO, dummy, or placeholder markers in runtime source. In the Fable corpus this is a high-leverage completeness smell: the app can look finished while the money, identity, or tenant flow is still scaffolded."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-b9088664ace7f748", "name": "Composite production-readiness gap", "shortDescription": {"text": "Composite production-readiness gap"}, "fullDescription": {"text": "Multiple low-cost hardening controls are missing together: license, ci, lockfile. Opus verification showed these co-occurring gaps are a better readiness signal than reading each flag in isolation."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ea8f3013f588db25", "name": "Shallow git history limits provenance confidence", "shortDescription": {"text": "Shallow git history limits provenance confidence"}, "fullDescription": {"text": "The repository is a shallow clone. Origin/evolution analysis cannot distinguish fresh generation, imported legacy code, or long-lived human code with high confidence."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-8424db9c75e04ba4", "name": "Very short observed git history", "shortDescription": {"text": "Very short observed git history"}, "fullDescription": {"text": "The repo has multiple source files but two or fewer visible commits. This is not a failure by itself, but it lowers confidence in evolution-based diagnosis."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-fa2df777ba311110", "name": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/routes/fighters.routes.ts:93", "shortDescription": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/routes/fighters.routes.ts:93"}, "fullDescription": {"text": "Bare `fetch(...)` will throw an unhandled rejection on network failure. Wrap in try/catch, attach a `.catch(...)`, or pass an AbortSignal with a timeout."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-7dc51d3facc0ad4f", "name": "Commented-code block (6 lines) in apps/api/src/jobs/preEventPrep.job.ts:8", "shortDescription": {"text": "Commented-code block (6 lines) in apps/api/src/jobs/preEventPrep.job.ts:8"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-e2f746779913dd20", "name": "Commented-code block (5 lines) in apps/web/src/pages/Matchup.tsx:208", "shortDescription": {"text": "Commented-code block (5 lines) in apps/web/src/pages/Matchup.tsx:208"}, "fullDescription": {"text": "A long run of `//` or `#` lines usually means abandoned code. Delete or move to git history. Keeps the canvas + dead-code detection honest."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "info", "confidence": 1.0}}, {"id": "scanner-022e6399d1ef2beb", "name": "12 env vars used in code but missing from .env.example", "shortDescription": {"text": "12 env vars used in code but missing from .env.example"}, "fullDescription": {"text": "Drift between code and config docs. The first few: `CORS_ORIGIN`, `EVENTS`, `EXPO_PUBLIC_API_URL`, `EXPO_PUBLIC_SUPABASE_ANON_KEY`, `EXPO_PUBLIC_SUPABASE_URL`, `MODE`, `ODDS_API_KEY`, `SENTRY_DSN` + 4 more. Add them (with a placeholder/comment) to .env.example so onboarding doesn't break."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7a3bf086370ac27b", "name": "Frontend route `/league/create` has no Link/navigate to it \u2014 apps/web/src/App.tsx", "shortDescription": {"text": "Frontend route `/league/create` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-aecfece317f7f071", "name": "Frontend route `/league/:leagueId` has no Link/navigate to it \u2014 apps/web/src/App.tsx", "shortDescription": {"text": "Frontend route `/league/:leagueId` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-acf5e1b8d96b0454", "name": "Frontend route `/league/:leagueId/matchup` has no Link/navigate to it \u2014 apps/web/src/App.tsx", "shortDescription": {"text": "Frontend route `/league/:leagueId/matchup` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-447fcbc0f14ac33c", "name": "Frontend route `/league/:leagueId/standings` has no Link/navigate to it \u2014 apps/web/src/App.tsx", "shortDescription": {"text": "Frontend route `/league/:leagueId/standings` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-402a9af74b59c8c0", "name": "Frontend route `/league/:leagueId/schedule` has no Link/navigate to it \u2014 apps/web/src/App.tsx", "shortDescription": {"text": "Frontend route `/league/:leagueId/schedule` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-f269b799a3342211", "name": "Frontend route `/league/:leagueId/picks` has no Link/navigate to it \u2014 apps/web/src/App.tsx", "shortDescription": {"text": "Frontend route `/league/:leagueId/picks` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-bb75520d9d841436", "name": "Frontend route `/league/:leagueId/picks/comparison` has no Link/navigate to it \u2014 apps/web/src/App.tsx", "shortDescription": {"text": "Frontend route `/league/:leagueId/picks/comparison` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-cd8ead24d7783b70", "name": "Frontend route `/league/:leagueId/staking` has no Link/navigate to it \u2014 apps/web/src/App.tsx", "shortDescription": {"text": "Frontend route `/league/:leagueId/staking` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-2041c6578aa34b82", "name": "Frontend route `/league/:leagueId/team/:memberId` has no Link/navigate to it \u2014 apps/web/src/App.tsx", "shortDescription": {"text": "Frontend route `/league/:leagueId/team/:memberId` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-60ace9bae93df512", "name": "Frontend route `/league/:leagueId/rules` has no Link/navigate to it \u2014 apps/web/src/App.tsx", "shortDescription": {"text": "Frontend route `/league/:leagueId/rules` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-247478bd2482da27", "name": "Frontend route `/league/:leagueId/playoffs` has no Link/navigate to it \u2014 apps/web/src/App.tsx", "shortDescription": {"text": "Frontend route `/league/:leagueId/playoffs` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-598d866af3028a41", "name": "Frontend route `/league/:leagueId/commissioner` has no Link/navigate to it \u2014 apps/web/src/App.tsx", "shortDescription": {"text": "Frontend route `/league/:leagueId/commissioner` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "fullDescription": {"text": "The route is registered but no `<Link to=\u2026>` or `navigate(\u2026)` in the codebase navigates here. Either it's reachable only via direct URL (intentional), it's dead, or the link broke during a refactor."}, "properties": {"scanner": "scanner-primary", "layer": "quality", "severity": "medium", "confidence": 1.0}}, {"id": "scanner-ff06e4e2befaeff4", "name": "Dangling fetch: POST https://exp.host/--/api/v2/push/send (apps/api/src/services/notification.service.ts:28)", "shortDescription": {"text": "Dangling fetch: POST https://exp.host/--/api/v2/push/send (apps/api/src/services/notification.service.ts:28)"}, "fullDescription": {"text": "`apps/api/src/services/notification.service.ts:28` calls `POST https://exp.host/--/api/v2/push/send` but no backend route matches that path. This is a runtime 404 waiting to happen.\n\nTool: fetch\nNormalized path used for matching: `/https:/exp.host/--/api/v2/push/send`\nIf this points at an external API, prefix it with `https://` so the matcher skips it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "high", "confidence": 1.0}}, {"id": "scanner-94da1aaaf36cc41f", "name": "Unused endpoint: USE /api/v1", "shortDescription": {"text": "Unused endpoint: USE /api/v1"}, "fullDescription": {"text": "`apps/api/src/app.ts` declares `USE /api/v1` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-1de80da0b27387f7", "name": "Unused endpoint: GET /unread-count", "shortDescription": {"text": "Unused endpoint: GET /unread-count"}, "fullDescription": {"text": "`apps/api/src/routes/notifications.routes.ts` declares `GET /unread-count` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-5baa8971ebe192a1", "name": "Unused endpoint: GET /", "shortDescription": {"text": "Unused endpoint: GET /"}, "fullDescription": {"text": "`apps/api/src/routes/notifications.routes.ts` declares `GET /` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-afd4ed162f8ab9b0", "name": "Unused endpoint: PATCH /:id/read", "shortDescription": {"text": "Unused endpoint: PATCH /:id/read"}, "fullDescription": {"text": "`apps/api/src/routes/notifications.routes.ts` declares `PATCH /:id/read` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f8d576f6bf0f5660", "name": "Unused endpoint: POST /read-all", "shortDescription": {"text": "Unused endpoint: POST /read-all"}, "fullDescription": {"text": "`apps/api/src/routes/notifications.routes.ts` declares `POST /read-all` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-df79136948177ff1", "name": "Unused endpoint: GET /season-events", "shortDescription": {"text": "Unused endpoint: GET /season-events"}, "fullDescription": {"text": "`apps/api/src/routes/matchups.routes.ts` declares `GET /season-events` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-959e83c0a87139d8", "name": "Unused endpoint: GET /current", "shortDescription": {"text": "Unused endpoint: GET /current"}, "fullDescription": {"text": "`apps/api/src/routes/matchups.routes.ts` declares `GET /current` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fa5ca8f5ddd49bd7", "name": "Unused endpoint: GET /standings", "shortDescription": {"text": "Unused endpoint: GET /standings"}, "fullDescription": {"text": "`apps/api/src/routes/matchups.routes.ts` declares `GET /standings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e86a2b6d6894106f", "name": "Unused endpoint: GET /:matchupId", "shortDescription": {"text": "Unused endpoint: GET /:matchupId"}, "fullDescription": {"text": "`apps/api/src/routes/matchups.routes.ts` declares `GET /:matchupId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-35b60788ce6a4516", "name": "Unused endpoint: GET /bracket", "shortDescription": {"text": "Unused endpoint: GET /bracket"}, "fullDescription": {"text": "`apps/api/src/routes/playoffs.routes.ts` declares `GET /bracket` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a13a7e97aeacf55f", "name": "Unused endpoint: POST /start", "shortDescription": {"text": "Unused endpoint: POST /start"}, "fullDescription": {"text": "`apps/api/src/routes/playoffs.routes.ts` declares `POST /start` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-3e40f540760a41d3", "name": "Unused endpoint: DELETE /cancel", "shortDescription": {"text": "Unused endpoint: DELETE /cancel"}, "fullDescription": {"text": "`apps/api/src/routes/playoffs.routes.ts` declares `DELETE /cancel` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d5862d006ad5664e", "name": "Unused endpoint: POST /advance", "shortDescription": {"text": "Unused endpoint: POST /advance"}, "fullDescription": {"text": "`apps/api/src/routes/playoffs.routes.ts` declares `POST /advance` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d3d67bf0e61d5999", "name": "Unused endpoint: GET /current-event", "shortDescription": {"text": "Unused endpoint: GET /current-event"}, "fullDescription": {"text": "`apps/api/src/routes/picks.routes.ts` declares `GET /current-event` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6d7ccdb2a2bbc47d", "name": "Unused endpoint: GET /:eventId", "shortDescription": {"text": "Unused endpoint: GET /:eventId"}, "fullDescription": {"text": "`apps/api/src/routes/picks.routes.ts` declares `GET /:eventId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0d4cbc44776f474d", "name": "Unused endpoint: POST /:eventId", "shortDescription": {"text": "Unused endpoint: POST /:eventId"}, "fullDescription": {"text": "`apps/api/src/routes/picks.routes.ts` declares `POST /:eventId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-0bfbf4e07f7fc6bf", "name": "Unused endpoint: GET /:eventId/champion", "shortDescription": {"text": "Unused endpoint: GET /:eventId/champion"}, "fullDescription": {"text": "`apps/api/src/routes/picks.routes.ts` declares `GET /:eventId/champion` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-d2831d2dba4719c2", "name": "Unused endpoint: PUT /:eventId/champion", "shortDescription": {"text": "Unused endpoint: PUT /:eventId/champion"}, "fullDescription": {"text": "`apps/api/src/routes/picks.routes.ts` declares `PUT /:eventId/champion` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f2a1ddddf953e1c6", "name": "Unused endpoint: GET /:eventId/all", "shortDescription": {"text": "Unused endpoint: GET /:eventId/all"}, "fullDescription": {"text": "`apps/api/src/routes/picks.routes.ts` declares `GET /:eventId/all` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f5a324d0cefb0225", "name": "Unused endpoint: GET /live-card", "shortDescription": {"text": "Unused endpoint: GET /live-card"}, "fullDescription": {"text": "`apps/api/src/routes/events.routes.ts` declares `GET /live-card` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-18de36ede59b6ad2", "name": "Unused endpoint: GET /:eventId/fights", "shortDescription": {"text": "Unused endpoint: GET /:eventId/fights"}, "fullDescription": {"text": "`apps/api/src/routes/events.routes.ts` declares `GET /:eventId/fights` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-6d0b9e05a8a25076", "name": "Unused endpoint: GET /:eventId/results", "shortDescription": {"text": "Unused endpoint: GET /:eventId/results"}, "fullDescription": {"text": "`apps/api/src/routes/events.routes.ts` declares `GET /:eventId/results` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-aef2403f8b7c37fc", "name": "Unused endpoint: POST /admin/:eventId/results", "shortDescription": {"text": "Unused endpoint: POST /admin/:eventId/results"}, "fullDescription": {"text": "`apps/api/src/routes/events.routes.ts` declares `POST /admin/:eventId/results` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-304b6f2b403d93f7", "name": "Unused endpoint: POST /register", "shortDescription": {"text": "Unused endpoint: POST /register"}, "fullDescription": {"text": "`apps/api/src/routes/auth.routes.ts` declares `POST /register` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd1dc91abf32142d", "name": "Unused endpoint: GET /me", "shortDescription": {"text": "Unused endpoint: GET /me"}, "fullDescription": {"text": "`apps/api/src/routes/auth.routes.ts` declares `GET /me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ea575b61c121b733", "name": "Unused endpoint: PATCH /me", "shortDescription": {"text": "Unused endpoint: PATCH /me"}, "fullDescription": {"text": "`apps/api/src/routes/auth.routes.ts` declares `PATCH /me` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-fd5d0983a06d98f9", "name": "Unused endpoint: POST /push-token", "shortDescription": {"text": "Unused endpoint: POST /push-token"}, "fullDescription": {"text": "`apps/api/src/routes/auth.routes.ts` declares `POST /push-token` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2a26b60c1372b056", "name": "Unused endpoint: POST /sync/events", "shortDescription": {"text": "Unused endpoint: POST /sync/events"}, "fullDescription": {"text": "`apps/api/src/routes/admin.routes.ts` declares `POST /sync/events` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-c4fe4ad8769173cc", "name": "Unused endpoint: POST /sync/events/date/:yyyymmdd", "shortDescription": {"text": "Unused endpoint: POST /sync/events/date/:yyyymmdd"}, "fullDescription": {"text": "`apps/api/src/routes/admin.routes.ts` declares `POST /sync/events/date/:yyyymmdd` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e66753c971005e6f", "name": "Unused endpoint: POST /sync/fighters", "shortDescription": {"text": "Unused endpoint: POST /sync/fighters"}, "fullDescription": {"text": "`apps/api/src/routes/admin.routes.ts` declares `POST /sync/fighters` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e48c41dca24b277e", "name": "Unused endpoint: POST /schedule/auto", "shortDescription": {"text": "Unused endpoint: POST /schedule/auto"}, "fullDescription": {"text": "`apps/api/src/routes/admin.routes.ts` declares `POST /schedule/auto` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-43269e4e79c2e69e", "name": "Unused endpoint: GET /events", "shortDescription": {"text": "Unused endpoint: GET /events"}, "fullDescription": {"text": "`apps/api/src/routes/admin.routes.ts` declares `GET /events` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-eb866d1f30fb5458", "name": "Unused endpoint: POST /events/deduplicate", "shortDescription": {"text": "Unused endpoint: POST /events/deduplicate"}, "fullDescription": {"text": "`apps/api/src/routes/admin.routes.ts` declares `POST /events/deduplicate` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-2ec9e6a1de31d37d", "name": "Unused endpoint: PATCH /events/:eventId/status", "shortDescription": {"text": "Unused endpoint: PATCH /events/:eventId/status"}, "fullDescription": {"text": "`apps/api/src/routes/admin.routes.ts` declares `PATCH /events/:eventId/status` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ccd6aab0588f99d6", "name": "Unused endpoint: POST /events/:eventId/resync-fights", "shortDescription": {"text": "Unused endpoint: POST /events/:eventId/resync-fights"}, "fullDescription": {"text": "`apps/api/src/routes/admin.routes.ts` declares `POST /events/:eventId/resync-fights` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f8474e4a8b7f9f75", "name": "Unused endpoint: POST /events/:eventId/push-to-leagues", "shortDescription": {"text": "Unused endpoint: POST /events/:eventId/push-to-leagues"}, "fullDescription": {"text": "`apps/api/src/routes/admin.routes.ts` declares `POST /events/:eventId/push-to-leagues` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-48a7a249624b464a", "name": "Unused endpoint: POST /fights/:fightId/result", "shortDescription": {"text": "Unused endpoint: POST /fights/:fightId/result"}, "fullDescription": {"text": "`apps/api/src/routes/admin.routes.ts` declares `POST /fights/:fightId/result` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e54ac9c12aa02784", "name": "Unused endpoint: GET /events/:eventId/fights", "shortDescription": {"text": "Unused endpoint: GET /events/:eventId/fights"}, "fullDescription": {"text": "`apps/api/src/routes/admin.routes.ts` declares `GET /events/:eventId/fights` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7d56b817fdb991ef", "name": "Unused endpoint: PATCH /fights/:fightId/odds", "shortDescription": {"text": "Unused endpoint: PATCH /fights/:fightId/odds"}, "fullDescription": {"text": "`apps/api/src/routes/admin.routes.ts` declares `PATCH /fights/:fightId/odds` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-dc98a42e7809aeb5", "name": "Unused endpoint: POST /events/:eventId/odds/bulk", "shortDescription": {"text": "Unused endpoint: POST /events/:eventId/odds/bulk"}, "fullDescription": {"text": "`apps/api/src/routes/admin.routes.ts` declares `POST /events/:eventId/odds/bulk` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-33df0973e572c5bd", "name": "Unused endpoint: POST /events/:eventId/sync-odds", "shortDescription": {"text": "Unused endpoint: POST /events/:eventId/sync-odds"}, "fullDescription": {"text": "`apps/api/src/routes/admin.routes.ts` declares `POST /events/:eventId/sync-odds` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-a46c6b334cb3777c", "name": "Unused endpoint: GET /:fighterId", "shortDescription": {"text": "Unused endpoint: GET /:fighterId"}, "fullDescription": {"text": "`apps/api/src/routes/fighters.routes.ts` declares `GET /:fighterId` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-311e4d5cabc33ff8", "name": "Unused endpoint: GET /:fighterId/history", "shortDescription": {"text": "Unused endpoint: GET /:fighterId/history"}, "fullDescription": {"text": "`apps/api/src/routes/fighters.routes.ts` declares `GET /:fighterId/history` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-f0f0918ed6de0acb", "name": "Unused endpoint: GET /:fighterId/live-stats", "shortDescription": {"text": "Unused endpoint: GET /:fighterId/live-stats"}, "fullDescription": {"text": "`apps/api/src/routes/fighters.routes.ts` declares `GET /:fighterId/live-stats` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-7fd4142cd9887c6a", "name": "Unused endpoint: GET /leagues/:leagueId/free-agents", "shortDescription": {"text": "Unused endpoint: GET /leagues/:leagueId/free-agents"}, "fullDescription": {"text": "`apps/api/src/routes/fighters.routes.ts` declares `GET /leagues/:leagueId/free-agents` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-b28d92215a503990", "name": "Unused endpoint: USE /auth", "shortDescription": {"text": "Unused endpoint: USE /auth"}, "fullDescription": {"text": "`apps/api/src/routes/index.ts` declares `USE /auth` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-e42c77b8e018b4b8", "name": "Unused endpoint: USE /leagues", "shortDescription": {"text": "Unused endpoint: USE /leagues"}, "fullDescription": {"text": "`apps/api/src/routes/index.ts` declares `USE /leagues` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-ccab5374b4ccec6c", "name": "Unused endpoint: USE /leagues/:leagueId/roster", "shortDescription": {"text": "Unused endpoint: USE /leagues/:leagueId/roster"}, "fullDescription": {"text": "`apps/api/src/routes/index.ts` declares `USE /leagues/:leagueId/roster` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-cd687653094aeeab", "name": "Unused endpoint: USE /leagues/:leagueId/matchups", "shortDescription": {"text": "Unused endpoint: USE /leagues/:leagueId/matchups"}, "fullDescription": {"text": "`apps/api/src/routes/index.ts` declares `USE /leagues/:leagueId/matchups` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}, {"id": "scanner-9150bed35d0a98d3", "name": "Unused endpoint: USE /leagues/:leagueId/standings", "shortDescription": {"text": "Unused endpoint: USE /leagues/:leagueId/standings"}, "fullDescription": {"text": "`apps/api/src/routes/index.ts` declares `USE /leagues/:leagueId/standings` but no frontend code we scanned calls it. This is fine if the endpoint serves external clients (mobile app, third-party, server-side webhooks). Otherwise it's dead code \u2014 consider removing or documenting who consumes it."}, "properties": {"scanner": "scanner-primary", "layer": "api", "severity": "low", "confidence": 1.0}}]}}, "automationDetails": {"id": "repobility/23505"}, "properties": {"repository": "zachpardee/fantasyufc", "repoUrl": "https://github.com/zachpardee/fantasyufc", "branch": "main"}, "results": [{"ruleId": "scanner-4f508cf92621a9f6", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 check-roster.ts:16"}, "properties": {"repobilityId": "09e91c5a9a679701", "scanner": "scanner-primary", "fingerprint": "4f508cf92621a9f6", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-33e34f176b3ef24f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 check-draft.ts:15"}, "properties": {"repobilityId": "645084a4790e07da", "scanner": "scanner-primary", "fingerprint": "33e34f176b3ef24f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ae7b772ae4f6b11b", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 test-scoring-pipeline.ts:18"}, "properties": {"repobilityId": "9f92b21b09c27c67", "scanner": "scanner-primary", "fingerprint": "ae7b772ae4f6b11b", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-8bca7eb85af20236", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 test-picks-limit.ts:19"}, "properties": {"repobilityId": "a848dae8a1445dcc", "scanner": "scanner-primary", "fingerprint": "8bca7eb85af20236", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-96d222f2839a0447", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 seed-test-picks.js:87"}, "properties": {"repobilityId": "f1287256d17fb894", "scanner": "scanner-primary", "fingerprint": "96d222f2839a0447", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cbeb40d80a56f214", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 test-full-event.ts:46"}, "properties": {"repobilityId": "1b2ff0d91e36c581", "scanner": "scanner-primary", "fingerprint": "cbeb40d80a56f214", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-17dc3e9bde531498", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 seed-full-league.ts:74"}, "properties": {"repobilityId": "44aa4133f4637bed", "scanner": "scanner-primary", "fingerprint": "17dc3e9bde531498", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-93cd8ec8a0d1ba58", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 test-scenarios.ts:53"}, "properties": {"repobilityId": "0117d05fc521f214", "scanner": "scanner-primary", "fingerprint": "93cd8ec8a0d1ba58", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9d4b15491f73d789", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 fix-roster.ts:6"}, "properties": {"repobilityId": "cdb405d8b6067095", "scanner": "scanner-primary", "fingerprint": "9d4b15491f73d789", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-58b1195719a8a7a9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/scripts/debug-settle.ts:20"}, "properties": {"repobilityId": "4081e2d25276f1d8", "scanner": "scanner-primary", "fingerprint": "58b1195719a8a7a9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b6defb1ebbe89eca", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/scripts/backfill-nationality.ts:20"}, "properties": {"repobilityId": "808344dd60dc7bfc", "scanner": "scanner-primary", "fingerprint": "b6defb1ebbe89eca", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-4a62682ff2fd8863", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/scripts/regenerate-matchups.ts:15"}, "properties": {"repobilityId": "f8cc6409dc9b4e63", "scanner": "scanner-primary", "fingerprint": "4a62682ff2fd8863", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9c6d210aefe30f43", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/scripts/sync-nationality.ts:6"}, "properties": {"repobilityId": "8db3813236f16bca", "scanner": "scanner-primary", "fingerprint": "9c6d210aefe30f43", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-bd99f59f432cf5e9", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/index.ts:26"}, "properties": {"repobilityId": "a178156af585d748", "scanner": "scanner-primary", "fingerprint": "bd99f59f432cf5e9", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-74109fd691a829f3", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/config/redis.ts:59"}, "properties": {"repobilityId": "ca8fb0e557573285", "scanner": "scanner-primary", "fingerprint": "74109fd691a829f3", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-24cff137ca71d571", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/services/scoring.service.ts:237"}, "properties": {"repobilityId": "977403b75585609f", "scanner": "scanner-primary", "fingerprint": "24cff137ca71d571", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9a1afe35a7a652bc", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/db/migrate.ts:30"}, "properties": {"repobilityId": "4c947c823da5fa9d", "scanner": "scanner-primary", "fingerprint": "9a1afe35a7a652bc", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-9994359c241df033", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/db/seeds/run.ts:13"}, "properties": {"repobilityId": "04f6b2e8b70a62f8", "scanner": "scanner-primary", "fingerprint": "9994359c241df033", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-6bdc2144b6a566fd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/db/seeds/staking_past_events.ts:37"}, "properties": {"repobilityId": "3f17579a819873ff", "scanner": "scanner-primary", "fingerprint": "6bdc2144b6a566fd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-dab1bec447f34311", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/db/seeds/staking_league.ts:37"}, "properties": {"repobilityId": "af776007799b948a", "scanner": "scanner-primary", "fingerprint": "dab1bec447f34311", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-ab308ad0c2d1e21f", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/db/seeds/fighters.ts:110"}, "properties": {"repobilityId": "2f47f68ff8672438", "scanner": "scanner-primary", "fingerprint": "ab308ad0c2d1e21f", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-823f7444cfa21f37", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/db/seeds/champion_picks_test.ts:19"}, "properties": {"repobilityId": "1185d829abcdbe91", "scanner": "scanner-primary", "fingerprint": "823f7444cfa21f37", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e3e8ad2a006076bd", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/jobs/livePoller.job.ts:98"}, "properties": {"repobilityId": "633a0414d305c433", "scanner": "scanner-primary", "fingerprint": "e3e8ad2a006076bd", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-b6ecd16718b3d951", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/jobs/fighterSync.job.ts:12"}, "properties": {"repobilityId": "064900843195dca8", "scanner": "scanner-primary", "fingerprint": "b6ecd16718b3d951", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-bf17cc336f99cc02", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/jobs/autoSchedule.job.ts:23"}, "properties": {"repobilityId": "95b300246b4adc47", "scanner": "scanner-primary", "fingerprint": "bf17cc336f99cc02", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-50c353f658b82169", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/jobs/preEventPrep.job.ts:19"}, "properties": {"repobilityId": "3d13728c6f7e7313", "scanner": "scanner-primary", "fingerprint": "50c353f658b82169", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-f69b97609b5df4e4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 apps/api/src/jobs/eventSync.job.ts:25"}, "properties": {"repobilityId": "1d5a710abd146f76", "scanner": "scanner-primary", "fingerprint": "f69b97609b5df4e4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-694a8c8ec75a6de2", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/seed-events.ts:36"}, "properties": {"repobilityId": "14e4f86161af12b5", "scanner": "scanner-primary", "fingerprint": "694a8c8ec75a6de2", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-5c3338cb27f1ccb4", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/setup-supabase.ts:47"}, "properties": {"repobilityId": "f12ba5b05be89cc8", "scanner": "scanner-primary", "fingerprint": "5c3338cb27f1ccb4", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-e646b31347372f85", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/fetch-fighter-images.ts:33"}, "properties": {"repobilityId": "ff20bba69783aaeb", "scanner": "scanner-primary", "fingerprint": "e646b31347372f85", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-cc66f93aea4d5113", "level": "note", "message": {"text": "Stray `console.log` in TS/JS \u2014 scripts/simulate-seasons.ts:274"}, "properties": {"repobilityId": "72e48ddd94a13502", "scanner": "scanner-primary", "fingerprint": "cc66f93aea4d5113", "layer": "frontend", "severity": "low", "confidence": 1.0, "tags": ["frontend-quality", "fq.console-leak"]}}, {"ruleId": "scanner-aa5acaa49eb8315b", "level": "note", "message": {"text": "Containers defined but no K8s/orchestration manifest found"}, "properties": {"repobilityId": "b230ea9b68736081", "scanner": "scanner-primary", "fingerprint": "aa5acaa49eb8315b", "layer": "hardware", "severity": "low", "confidence": 1.0, "tags": ["coverage", "deployment"]}}, {"ruleId": "scanner-175ec9bb54be7375", "level": "error", "message": {"text": "Possible secret in seed-full-league.ts"}, "properties": {"repobilityId": "b8fc5fe2aaaaec99", "scanner": "scanner-primary", "fingerprint": "175ec9bb54be7375", "layer": "security", "severity": "critical", "confidence": 1.0, "tags": ["secrets"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "seed-full-league.ts"}, "region": {"startLine": 93}}}]}, {"ruleId": "scanner-5ab86e52e78c1fd3", "level": "warning", "message": {"text": "Insecure pattern 'node_child_process' in scripts/setup-supabase.ts:16"}, "properties": {"repobilityId": "da8a24aa4b0533a0", "scanner": "scanner-primary", "fingerprint": "5ab86e52e78c1fd3", "layer": "security", "severity": "medium", "confidence": 1.0, "tags": ["owasp", "node_child_process"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "scripts/setup-supabase.ts"}, "region": {"startLine": 16}}}]}, {"ruleId": "scanner-4601e3ad3bb28677", "level": "warning", "message": {"text": "No CI/CD pipelines detected"}, "properties": {"repobilityId": "c3ee439bce2bc51e", "scanner": "scanner-primary", "fingerprint": "4601e3ad3bb28677", "layer": "cicd", "severity": "medium", "confidence": 1.0, "tags": ["coverage"]}}, {"ruleId": "scanner-b56408c8b4af8f17", "level": "note", "message": {"text": "Very large file: apps/mobile/app/(app)/league/[leagueId]/picks.tsx (1180 lines)"}, "properties": {"repobilityId": "77ca40b4bf21b3f8", "scanner": "scanner-primary", "fingerprint": "b56408c8b4af8f17", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-a00123a5a47def89", "level": "note", "message": {"text": "Very large file: apps/web/src/pages/LeagueHome.tsx (1661 lines)"}, "properties": {"repobilityId": "b7fe848a050b01b6", "scanner": "scanner-primary", "fingerprint": "a00123a5a47def89", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-bc79f908a7b052c0", "level": "note", "message": {"text": "Very large file: apps/web/src/pages/Matchup.tsx (984 lines)"}, "properties": {"repobilityId": "324427753c7639e8", "scanner": "scanner-primary", "fingerprint": "bc79f908a7b052c0", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-8f14a5b155e95777", "level": "note", "message": {"text": "Very large file: apps/web/src/pages/StakingPicks.tsx (1160 lines)"}, "properties": {"repobilityId": "2c1faf0f2e5e92cb", "scanner": "scanner-primary", "fingerprint": "8f14a5b155e95777", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["complexity"]}}, {"ruleId": "scanner-6893a6c8b0861585", "level": "warning", "message": {"text": "Very low test-to-source ratio"}, "properties": {"repobilityId": "54a7de3f06314bf0", "scanner": "scanner-primary", "fingerprint": "6893a6c8b0861585", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["tests", "coverage"]}}, {"ruleId": "scanner-141b30a41e03817b", "level": "note", "message": {"text": "No license file detected"}, "properties": {"repobilityId": "f676676d2d5f0b84", "scanner": "scanner-primary", "fingerprint": "141b30a41e03817b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["license", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-b06b8d86f24c77f9", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: apps/api/package.json"}, "properties": {"repobilityId": "ce77cd34ed0306d4", "scanner": "scanner-primary", "fingerprint": "b06b8d86f24c77f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/api/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d57b3f82d2270c5b", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: apps/desktop/package.json"}, "properties": {"repobilityId": "a5d1a254ecc349f8", "scanner": "scanner-primary", "fingerprint": "d57b3f82d2270c5b", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/desktop/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-d0c2205560692580", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: apps/mobile/package.json"}, "properties": {"repobilityId": "b3dfed7bb3d70ed3", "scanner": "scanner-primary", "fingerprint": "d0c2205560692580", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/mobile/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-4a9eb7dc7c6e3880", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: apps/web/package.json"}, "properties": {"repobilityId": "6c1704bf24cf19ac", "scanner": "scanner-primary", "fingerprint": "4a9eb7dc7c6e3880", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "apps/web/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-2699d5f16ae11282", "level": "note", "message": {"text": "Node manifest has dependencies but no lockfile: packages/shared/package.json"}, "properties": {"repobilityId": "37ac218a4ef9b430", "scanner": "scanner-primary", "fingerprint": "2699d5f16ae11282", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["dependency", "lockfile", "reproducibility", "generated-repo-pattern"]}, "locations": [{"physicalLocation": {"artifactLocation": {"uri": "packages/shared/package.json"}, "region": {"startLine": 1}}}]}, {"ruleId": "scanner-3ab5d313dda8e5f9", "level": "note", "message": {"text": "Debug logging residue appears in source files"}, "properties": {"repobilityId": "f6b908654fd06e16", "scanner": "scanner-primary", "fingerprint": "3ab5d313dda8e5f9", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["debug", "cleanup", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-72b2a6250083a784", "level": "warning", "message": {"text": "Placeholder or mock-heavy implementation detected"}, "properties": {"repobilityId": "d4a17b8a3a8cfcb7", "scanner": "scanner-primary", "fingerprint": "72b2a6250083a784", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "incomplete", "generated-repo-pattern"]}}, {"ruleId": "scanner-2d0c7b7ab8f8aacf", "level": "warning", "message": {"text": "Critical user flow still appears backed by mock or placeholder data"}, "properties": {"repobilityId": "eb0df1c3194bffe5", "scanner": "scanner-primary", "fingerprint": "2d0c7b7ab8f8aacf", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["placeholder", "mock-data", "critical-flow", "generated-repo-pattern"]}}, {"ruleId": "scanner-b9088664ace7f748", "level": "warning", "message": {"text": "Composite production-readiness gap"}, "properties": {"repobilityId": "57a77310c16834da", "scanner": "scanner-primary", "fingerprint": "b9088664ace7f748", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["production-readiness", "repo-hardening", "generated-repo-pattern"]}}, {"ruleId": "scanner-ea8f3013f588db25", "level": "note", "message": {"text": "Shallow git history limits provenance confidence"}, "properties": {"repobilityId": "7a93564d4f99edfb", "scanner": "scanner-primary", "fingerprint": "ea8f3013f588db25", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-8424db9c75e04ba4", "level": "none", "message": {"text": "Very short observed git history"}, "properties": {"repobilityId": "bdf383333e2f3465", "scanner": "scanner-primary", "fingerprint": "8424db9c75e04ba4", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["provenance", "git-history", "generated-repo-pattern"]}}, {"ruleId": "scanner-fa2df777ba311110", "level": "warning", "message": {"text": "`fetch()` without try/.catch or AbortSignal \u2014 apps/api/src/routes/fighters.routes.ts:93"}, "properties": {"repobilityId": "5dd14b1f8e87e94c", "scanner": "scanner-primary", "fingerprint": "fa2df777ba311110", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "fragile-runtime", "robustness"]}}, {"ruleId": "scanner-7dc51d3facc0ad4f", "level": "none", "message": {"text": "Commented-code block (6 lines) in apps/api/src/jobs/preEventPrep.job.ts:8"}, "properties": {"repobilityId": "14e5deaae3cef7a5", "scanner": "scanner-primary", "fingerprint": "7dc51d3facc0ad4f", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-e2f746779913dd20", "level": "none", "message": {"text": "Commented-code block (5 lines) in apps/web/src/pages/Matchup.tsx:208"}, "properties": {"repobilityId": "1ca5010cc60ac6fe", "scanner": "scanner-primary", "fingerprint": "e2f746779913dd20", "layer": "quality", "severity": "info", "confidence": 1.0, "tags": ["integrity", "commented-code", "dead-code"]}}, {"ruleId": "scanner-022e6399d1ef2beb", "level": "note", "message": {"text": "12 env vars used in code but missing from .env.example"}, "properties": {"repobilityId": "7bf4178327da75a2", "scanner": "scanner-primary", "fingerprint": "022e6399d1ef2beb", "layer": "quality", "severity": "low", "confidence": 1.0, "tags": ["integrity", "config-drift"]}}, {"ruleId": "scanner-7a3bf086370ac27b", "level": "warning", "message": {"text": "Frontend route `/league/create` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "properties": {"repobilityId": "7999b4bce2995677", "scanner": "scanner-primary", "fingerprint": "7a3bf086370ac27b", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-aecfece317f7f071", "level": "warning", "message": {"text": "Frontend route `/league/:leagueId` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "properties": {"repobilityId": "da3a2a9e62b75ab6", "scanner": "scanner-primary", "fingerprint": "aecfece317f7f071", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-acf5e1b8d96b0454", "level": "warning", "message": {"text": "Frontend route `/league/:leagueId/matchup` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "properties": {"repobilityId": "1fd4cf4c57c5aad2", "scanner": "scanner-primary", "fingerprint": "acf5e1b8d96b0454", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-447fcbc0f14ac33c", "level": "warning", "message": {"text": "Frontend route `/league/:leagueId/standings` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "properties": {"repobilityId": "15f694f9713551f8", "scanner": "scanner-primary", "fingerprint": "447fcbc0f14ac33c", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-402a9af74b59c8c0", "level": "warning", "message": {"text": "Frontend route `/league/:leagueId/schedule` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "properties": {"repobilityId": "e03acda75a49b9a6", "scanner": "scanner-primary", "fingerprint": "402a9af74b59c8c0", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-f269b799a3342211", "level": "warning", "message": {"text": "Frontend route `/league/:leagueId/picks` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "properties": {"repobilityId": "2d5177a833fc8ed1", "scanner": "scanner-primary", "fingerprint": "f269b799a3342211", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-bb75520d9d841436", "level": "warning", "message": {"text": "Frontend route `/league/:leagueId/picks/comparison` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "properties": {"repobilityId": "033d982c37b10781", "scanner": "scanner-primary", "fingerprint": "bb75520d9d841436", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-cd8ead24d7783b70", "level": "warning", "message": {"text": "Frontend route `/league/:leagueId/staking` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "properties": {"repobilityId": "7a608344efcab339", "scanner": "scanner-primary", "fingerprint": "cd8ead24d7783b70", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-2041c6578aa34b82", "level": "warning", "message": {"text": "Frontend route `/league/:leagueId/team/:memberId` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "properties": {"repobilityId": "55a9a4a5c516ed25", "scanner": "scanner-primary", "fingerprint": "2041c6578aa34b82", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-60ace9bae93df512", "level": "warning", "message": {"text": "Frontend route `/league/:leagueId/rules` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "properties": {"repobilityId": "ffddfdec69d919f1", "scanner": "scanner-primary", "fingerprint": "60ace9bae93df512", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-247478bd2482da27", "level": "warning", "message": {"text": "Frontend route `/league/:leagueId/playoffs` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "properties": {"repobilityId": "7e959dcc88e49d3e", "scanner": "scanner-primary", "fingerprint": "247478bd2482da27", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-598d866af3028a41", "level": "warning", "message": {"text": "Frontend route `/league/:leagueId/commissioner` has no Link/navigate to it \u2014 apps/web/src/App.tsx"}, "properties": {"repobilityId": "2133dc84dce86ab9", "scanner": "scanner-primary", "fingerprint": "598d866af3028a41", "layer": "quality", "severity": "medium", "confidence": 1.0, "tags": ["integrity", "orphan-page", "wiring"]}}, {"ruleId": "scanner-ff06e4e2befaeff4", "level": "error", "message": {"text": "Dangling fetch: POST https://exp.host/--/api/v2/push/send (apps/api/src/services/notification.service.ts:28)"}, "properties": {"repobilityId": "e6367099e0836557", "scanner": "scanner-primary", "fingerprint": "ff06e4e2befaeff4", "layer": "api", "severity": "high", "confidence": 1.0, "tags": ["wiring", "dangling-fetch", "fetch"]}}, {"ruleId": "scanner-94da1aaaf36cc41f", "level": "note", "message": {"text": "Unused endpoint: USE /api/v1"}, "properties": {"repobilityId": "36a458fd2305e647", "scanner": "scanner-primary", "fingerprint": "94da1aaaf36cc41f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-1de80da0b27387f7", "level": "note", "message": {"text": "Unused endpoint: GET /unread-count"}, "properties": {"repobilityId": "33e3b25226e718c9", "scanner": "scanner-primary", "fingerprint": "1de80da0b27387f7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-5baa8971ebe192a1", "level": "note", "message": {"text": "Unused endpoint: GET /"}, "properties": {"repobilityId": "5bc0ec121932b118", "scanner": "scanner-primary", "fingerprint": "5baa8971ebe192a1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-afd4ed162f8ab9b0", "level": "note", "message": {"text": "Unused endpoint: PATCH /:id/read"}, "properties": {"repobilityId": "7aecaa137041499b", "scanner": "scanner-primary", "fingerprint": "afd4ed162f8ab9b0", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f8d576f6bf0f5660", "level": "note", "message": {"text": "Unused endpoint: POST /read-all"}, "properties": {"repobilityId": "42fb6fa4eaa0d85b", "scanner": "scanner-primary", "fingerprint": "f8d576f6bf0f5660", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-df79136948177ff1", "level": "note", "message": {"text": "Unused endpoint: GET /season-events"}, "properties": {"repobilityId": "5ae2acb6513db356", "scanner": "scanner-primary", "fingerprint": "df79136948177ff1", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-959e83c0a87139d8", "level": "note", "message": {"text": "Unused endpoint: GET /current"}, "properties": {"repobilityId": "60b5eb49a9157cb8", "scanner": "scanner-primary", "fingerprint": "959e83c0a87139d8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fa5ca8f5ddd49bd7", "level": "note", "message": {"text": "Unused endpoint: GET /standings"}, "properties": {"repobilityId": "a035711075c28d7d", "scanner": "scanner-primary", "fingerprint": "fa5ca8f5ddd49bd7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e86a2b6d6894106f", "level": "note", "message": {"text": "Unused endpoint: GET /:matchupId"}, "properties": {"repobilityId": "b8ab5b4415ce9922", "scanner": "scanner-primary", "fingerprint": "e86a2b6d6894106f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-35b60788ce6a4516", "level": "note", "message": {"text": "Unused endpoint: GET /bracket"}, "properties": {"repobilityId": "33a9c93717eb1d54", "scanner": "scanner-primary", "fingerprint": "35b60788ce6a4516", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a13a7e97aeacf55f", "level": "note", "message": {"text": "Unused endpoint: POST /start"}, "properties": {"repobilityId": "f1b17c06d0e48310", "scanner": "scanner-primary", "fingerprint": "a13a7e97aeacf55f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-3e40f540760a41d3", "level": "note", "message": {"text": "Unused endpoint: DELETE /cancel"}, "properties": {"repobilityId": "f20bf08643a849b2", "scanner": "scanner-primary", "fingerprint": "3e40f540760a41d3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d5862d006ad5664e", "level": "note", "message": {"text": "Unused endpoint: POST /advance"}, "properties": {"repobilityId": "45b288553ec95a28", "scanner": "scanner-primary", "fingerprint": "d5862d006ad5664e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d3d67bf0e61d5999", "level": "note", "message": {"text": "Unused endpoint: GET /current-event"}, "properties": {"repobilityId": "4329778a582105d2", "scanner": "scanner-primary", "fingerprint": "d3d67bf0e61d5999", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6d7ccdb2a2bbc47d", "level": "note", "message": {"text": "Unused endpoint: GET /:eventId"}, "properties": {"repobilityId": "3136da58138f945c", "scanner": "scanner-primary", "fingerprint": "6d7ccdb2a2bbc47d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0d4cbc44776f474d", "level": "note", "message": {"text": "Unused endpoint: POST /:eventId"}, "properties": {"repobilityId": "d9496268ea3baf77", "scanner": "scanner-primary", "fingerprint": "0d4cbc44776f474d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-0bfbf4e07f7fc6bf", "level": "note", "message": {"text": "Unused endpoint: GET /:eventId/champion"}, "properties": {"repobilityId": "fe84778913ca4e6f", "scanner": "scanner-primary", "fingerprint": "0bfbf4e07f7fc6bf", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-d2831d2dba4719c2", "level": "note", "message": {"text": "Unused endpoint: PUT /:eventId/champion"}, "properties": {"repobilityId": "014a2d1df3454ba9", "scanner": "scanner-primary", "fingerprint": "d2831d2dba4719c2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f2a1ddddf953e1c6", "level": "note", "message": {"text": "Unused endpoint: GET /:eventId/all"}, "properties": {"repobilityId": "39617988c193463b", "scanner": "scanner-primary", "fingerprint": "f2a1ddddf953e1c6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f5a324d0cefb0225", "level": "note", "message": {"text": "Unused endpoint: GET /live-card"}, "properties": {"repobilityId": "286157dfa708c829", "scanner": "scanner-primary", "fingerprint": "f5a324d0cefb0225", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-18de36ede59b6ad2", "level": "note", "message": {"text": "Unused endpoint: GET /:eventId/fights"}, "properties": {"repobilityId": "94410a1f1790c51e", "scanner": "scanner-primary", "fingerprint": "18de36ede59b6ad2", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-6d0b9e05a8a25076", "level": "note", "message": {"text": "Unused endpoint: GET /:eventId/results"}, "properties": {"repobilityId": "858f19e5914885b1", "scanner": "scanner-primary", "fingerprint": "6d0b9e05a8a25076", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-aef2403f8b7c37fc", "level": "note", "message": {"text": "Unused endpoint: POST /admin/:eventId/results"}, "properties": {"repobilityId": "ab468299f28041cb", "scanner": "scanner-primary", "fingerprint": "aef2403f8b7c37fc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-304b6f2b403d93f7", "level": "note", "message": {"text": "Unused endpoint: POST /register"}, "properties": {"repobilityId": "a37a0d9d358f7bcb", "scanner": "scanner-primary", "fingerprint": "304b6f2b403d93f7", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd1dc91abf32142d", "level": "note", "message": {"text": "Unused endpoint: GET /me"}, "properties": {"repobilityId": "32ae1293a9e76546", "scanner": "scanner-primary", "fingerprint": "fd1dc91abf32142d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ea575b61c121b733", "level": "note", "message": {"text": "Unused endpoint: PATCH /me"}, "properties": {"repobilityId": "98a8d1fb8d4266d3", "scanner": "scanner-primary", "fingerprint": "ea575b61c121b733", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-fd5d0983a06d98f9", "level": "note", "message": {"text": "Unused endpoint: POST /push-token"}, "properties": {"repobilityId": "6f20f0469625ac0c", "scanner": "scanner-primary", "fingerprint": "fd5d0983a06d98f9", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2a26b60c1372b056", "level": "note", "message": {"text": "Unused endpoint: POST /sync/events"}, "properties": {"repobilityId": "63ba5f80cbea59d8", "scanner": "scanner-primary", "fingerprint": "2a26b60c1372b056", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-c4fe4ad8769173cc", "level": "note", "message": {"text": "Unused endpoint: POST /sync/events/date/:yyyymmdd"}, "properties": {"repobilityId": "28c40241644a4203", "scanner": "scanner-primary", "fingerprint": "c4fe4ad8769173cc", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e66753c971005e6f", "level": "note", "message": {"text": "Unused endpoint: POST /sync/fighters"}, "properties": {"repobilityId": "630a3aa7d09d37e0", "scanner": "scanner-primary", "fingerprint": "e66753c971005e6f", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e48c41dca24b277e", "level": "note", "message": {"text": "Unused endpoint: POST /schedule/auto"}, "properties": {"repobilityId": "24704e26d2e7ee77", "scanner": "scanner-primary", "fingerprint": "e48c41dca24b277e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-43269e4e79c2e69e", "level": "note", "message": {"text": "Unused endpoint: GET /events"}, "properties": {"repobilityId": "24cb42928111688c", "scanner": "scanner-primary", "fingerprint": "43269e4e79c2e69e", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-eb866d1f30fb5458", "level": "note", "message": {"text": "Unused endpoint: POST /events/deduplicate"}, "properties": {"repobilityId": "ae96c0d0c249cc95", "scanner": "scanner-primary", "fingerprint": "eb866d1f30fb5458", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-2ec9e6a1de31d37d", "level": "note", "message": {"text": "Unused endpoint: PATCH /events/:eventId/status"}, "properties": {"repobilityId": "ff31f63b2805eed3", "scanner": "scanner-primary", "fingerprint": "2ec9e6a1de31d37d", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ccd6aab0588f99d6", "level": "note", "message": {"text": "Unused endpoint: POST /events/:eventId/resync-fights"}, "properties": {"repobilityId": "cd963b60543d1425", "scanner": "scanner-primary", "fingerprint": "ccd6aab0588f99d6", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f8474e4a8b7f9f75", "level": "note", "message": {"text": "Unused endpoint: POST /events/:eventId/push-to-leagues"}, "properties": {"repobilityId": "0865925a69886703", "scanner": "scanner-primary", "fingerprint": "f8474e4a8b7f9f75", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-48a7a249624b464a", "level": "note", "message": {"text": "Unused endpoint: POST /fights/:fightId/result"}, "properties": {"repobilityId": "2a46143738a75638", "scanner": "scanner-primary", "fingerprint": "48a7a249624b464a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e54ac9c12aa02784", "level": "note", "message": {"text": "Unused endpoint: GET /events/:eventId/fights"}, "properties": {"repobilityId": "19729bb6e5745ae4", "scanner": "scanner-primary", "fingerprint": "e54ac9c12aa02784", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7d56b817fdb991ef", "level": "note", "message": {"text": "Unused endpoint: PATCH /fights/:fightId/odds"}, "properties": {"repobilityId": "25056b43d4dd3dbc", "scanner": "scanner-primary", "fingerprint": "7d56b817fdb991ef", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-dc98a42e7809aeb5", "level": "note", "message": {"text": "Unused endpoint: POST /events/:eventId/odds/bulk"}, "properties": {"repobilityId": "18f9b0cf44c63063", "scanner": "scanner-primary", "fingerprint": "dc98a42e7809aeb5", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-33df0973e572c5bd", "level": "note", "message": {"text": "Unused endpoint: POST /events/:eventId/sync-odds"}, "properties": {"repobilityId": "ee58cfadf7f9f3a2", "scanner": "scanner-primary", "fingerprint": "33df0973e572c5bd", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-a46c6b334cb3777c", "level": "note", "message": {"text": "Unused endpoint: GET /:fighterId"}, "properties": {"repobilityId": "8f1791cdfe6cc01e", "scanner": "scanner-primary", "fingerprint": "a46c6b334cb3777c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-311e4d5cabc33ff8", "level": "note", "message": {"text": "Unused endpoint: GET /:fighterId/history"}, "properties": {"repobilityId": "be4b2422a75c67ff", "scanner": "scanner-primary", "fingerprint": "311e4d5cabc33ff8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-f0f0918ed6de0acb", "level": "note", "message": {"text": "Unused endpoint: GET /:fighterId/live-stats"}, "properties": {"repobilityId": "84268cb8eb9dc4e9", "scanner": "scanner-primary", "fingerprint": "f0f0918ed6de0acb", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-7fd4142cd9887c6a", "level": "note", "message": {"text": "Unused endpoint: GET /leagues/:leagueId/free-agents"}, "properties": {"repobilityId": "6fa7e183c053c0b3", "scanner": "scanner-primary", "fingerprint": "7fd4142cd9887c6a", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-b28d92215a503990", "level": "note", "message": {"text": "Unused endpoint: USE /auth"}, "properties": {"repobilityId": "257220f6da01d692", "scanner": "scanner-primary", "fingerprint": "b28d92215a503990", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-e42c77b8e018b4b8", "level": "note", "message": {"text": "Unused endpoint: USE /leagues"}, "properties": {"repobilityId": "9c595ce3250b859e", "scanner": "scanner-primary", "fingerprint": "e42c77b8e018b4b8", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-ccab5374b4ccec6c", "level": "note", "message": {"text": "Unused endpoint: USE /leagues/:leagueId/roster"}, "properties": {"repobilityId": "662317db195c96bc", "scanner": "scanner-primary", "fingerprint": "ccab5374b4ccec6c", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-cd687653094aeeab", "level": "note", "message": {"text": "Unused endpoint: USE /leagues/:leagueId/matchups"}, "properties": {"repobilityId": "c8fcdf0e4b1f459e", "scanner": "scanner-primary", "fingerprint": "cd687653094aeeab", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}, {"ruleId": "scanner-9150bed35d0a98d3", "level": "note", "message": {"text": "Unused endpoint: USE /leagues/:leagueId/standings"}, "properties": {"repobilityId": "76d14d738063deae", "scanner": "scanner-primary", "fingerprint": "9150bed35d0a98d3", "layer": "api", "severity": "low", "confidence": 1.0, "tags": ["wiring", "unused-endpoint"]}}]}]}